<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from osv_almalinux</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:59:05 +0000</lastBuildDate>
    <item>
      <title>ALSA-2019:0975 — Important: container-tools:rhel8 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:0975</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: oci-systemd-hook, AlmaLinux:8: oci-umount&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* A flaw was found in the way runc handled system file descriptors when running containers. A malicious container could use this flaw to overwrite contents of the runc binary and consequently run arbitrary commands on the container host system. (CVE-2019-5736)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* [stream rhel8] rebase container-selinux to 2.94 (BZ#1693675)&lt;/p&gt;
&lt;p&gt;* [stream rhel8] unable to mount disk at `/var/lib/containers` via `systemd` unit when `container-selinux` policy installed (BZ#1695669)&lt;/p&gt;
&lt;p&gt;* [stream rhel8] don&amp;#39;t allow a container to connect to random services (BZ#1695689)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: oci-systemd-hook, AlmaLinux:8: oci-umount&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* A flaw was found in the way runc handled system file descriptors when running containers. A malicious container could use this flaw to overwrite contents of the runc binary and consequently run arbitrary commands on the container host system. (CVE-2019-5736)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* [stream rhel8] rebase container-selinux to 2.94 (BZ#1693675)&lt;/p&gt;
&lt;p&gt;* [stream rhel8] unable to mount disk at `/var/lib/containers` via `systemd` unit when `container-selinux` policy installed (BZ#1695669)&lt;/p&gt;
&lt;p&gt;* [stream rhel8] don&amp;#39;t allow a container to connect to random services (BZ#1695689)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:0975</guid>
      <pubDate>Tue, 07 May 2019 03:39:11 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2019:0981 — Important: python27:2.7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:0981</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python-psycopg2-doc, AlmaLinux:8: python2-Cython, AlmaLinux:8: python2-PyMySQL, AlmaLinux:8: python2-attrs, AlmaLinux:8: python2-chardet, AlmaLinux:8: python2-coverage, AlmaLinux:8: python2-docutils, AlmaLinux:8: python2-funcsigs, AlmaLinux:8: python2-idna, AlmaLinux:8: python2-ipaddress and 14 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing.&lt;/p&gt;
&lt;p&gt;SQLAlchemy is an Object Relational Mapper (ORM) that provides a flexible, high-level interface to SQL databases.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Information Disclosure due to urlsplit improper NFKC normalization (CVE-2019-9636)&lt;/p&gt;
&lt;p&gt;* python-sqlalchemy: SQL Injection when the order_by parameter can be controlled (CVE-2019-7164)&lt;/p&gt;
&lt;p&gt;* python-sqlalchemy: SQL Injection when the group_by parameter can be controlled (CVE-2019-7548)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python-psycopg2-doc, AlmaLinux:8: python2-Cython, AlmaLinux:8: python2-PyMySQL, AlmaLinux:8: python2-attrs, AlmaLinux:8: python2-chardet, AlmaLinux:8: python2-coverage, AlmaLinux:8: python2-docutils, AlmaLinux:8: python2-funcsigs, AlmaLinux:8: python2-idna, AlmaLinux:8: python2-ipaddress and 14 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing.&lt;/p&gt;
&lt;p&gt;SQLAlchemy is an Object Relational Mapper (ORM) that provides a flexible, high-level interface to SQL databases.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Information Disclosure due to urlsplit improper NFKC normalization (CVE-2019-9636)&lt;/p&gt;
&lt;p&gt;* python-sqlalchemy: SQL Injection when the order_by parameter can be controlled (CVE-2019-7164)&lt;/p&gt;
&lt;p&gt;* python-sqlalchemy: SQL Injection when the group_by parameter can be controlled (CVE-2019-7548)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:0981</guid>
      <pubDate>Tue, 07 May 2019 03:40:00 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2019:0984 — Moderate: python36:3.6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:0984</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-docs, AlmaLinux:8: python3-docutils&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;SQLAlchemy is an Object Relational Mapper (ORM) that provides a flexible, high-level interface to SQL databases.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-sqlalchemy: SQL Injection when the order_by parameter can be controlled (CVE-2019-7164)&lt;/p&gt;
&lt;p&gt;* python-sqlalchemy: SQL Injection when the group_by parameter can be controlled (CVE-2019-7548)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-docs, AlmaLinux:8: python3-docutils&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;SQLAlchemy is an Object Relational Mapper (ORM) that provides a flexible, high-level interface to SQL databases.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-sqlalchemy: SQL Injection when the order_by parameter can be controlled (CVE-2019-7164)&lt;/p&gt;
&lt;p&gt;* python-sqlalchemy: SQL Injection when the group_by parameter can be controlled (CVE-2019-7548)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:0984</guid>
      <pubDate>Tue, 07 May 2019 03:40:33 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2019:1529 — Important: pki-deps:10.6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:1529</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-module-jaxb-annotations, AlmaLinux:8: jakarta-commons-httpclient and 15 more&lt;/p&gt;
&lt;p&gt;The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by AlmaLinux Certificate System.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)&lt;/p&gt;
&lt;p&gt;* tomcat: Insecure defaults in CORS filter enable &amp;#39;supportsCredentials&amp;#39; for all origins (CVE-2018-8014)&lt;/p&gt;
&lt;p&gt;* tomcat: Open redirect in default servlet (CVE-2018-11784)&lt;/p&gt;
&lt;p&gt;* tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-module-jaxb-annotations, AlmaLinux:8: jakarta-commons-httpclient and 15 more&lt;/p&gt;
&lt;p&gt;The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by AlmaLinux Certificate System.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)&lt;/p&gt;
&lt;p&gt;* tomcat: Insecure defaults in CORS filter enable &amp;#39;supportsCredentials&amp;#39; for all origins (CVE-2018-8014)&lt;/p&gt;
&lt;p&gt;* tomcat: Open redirect in default servlet (CVE-2018-11784)&lt;/p&gt;
&lt;p&gt;* tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:1529</guid>
      <pubDate>Tue, 18 Jun 2019 16:36:21 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2019:1972 — Important: ruby:2.5 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:1972</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bson, AlmaLinux:8: rubygem-bson-doc, AlmaLinux:8: rubygem-mongo, AlmaLinux:8: rubygem-mongo-doc, AlmaLinux:8: rubygem-mysql2, AlmaLinux:8: rubygem-mysql2-doc, AlmaLinux:8: rubygem-pg, AlmaLinux:8: rubygem-pg-doc&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rubygems: Installing a malicious gem may lead to arbitrary code execution (CVE-2019-8324)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bson, AlmaLinux:8: rubygem-bson-doc, AlmaLinux:8: rubygem-mongo, AlmaLinux:8: rubygem-mongo-doc, AlmaLinux:8: rubygem-mysql2, AlmaLinux:8: rubygem-mysql2-doc, AlmaLinux:8: rubygem-pg, AlmaLinux:8: rubygem-pg-doc&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rubygems: Installing a malicious gem may lead to arbitrary code execution (CVE-2019-8324)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:1972</guid>
      <pubDate>Tue, 30 Jul 2019 11:16:25 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2019:2511 — Important: mysql:8.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:2511</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: mecab, AlmaLinux:8: mecab-ipadic, AlmaLinux:8: mecab-ipadic-EUCJP&lt;/p&gt;
&lt;p&gt;MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon, mysqld, and many client programs.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: mysql (8.0.17).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* mysql: Server: Replication multiple unspecified vulnerabilities (CVE-2019-2800, CVE-2019-2436, CVE-2019-2531, CVE-2019-2534, CVE-2019-2614, CVE-2019-2617, CVE-2019-2630, CVE-2019-2634, CVE-2019-2635, CVE-2019-2755)&lt;/p&gt;
&lt;p&gt;* mysql: Server: Optimizer multiple unspecified vulnerabilities (CVE-2019-2420, CVE-2019-2481, CVE-2019-2507, CVE-2019-2529, CVE-2019-2530, CVE-2019-2581, CVE-2019-2596, CVE-2019-2607, CVE-2019-2625, CVE-2019-2681, CVE-2019-2685, CVE-2019-2686, CVE-2019-2687, CVE-2019-2688, CVE-2019-2689, CVE-2019-2693, CVE-2019-2694, CVE-2019-2695, CVE-2019-2757, CVE-2019-2774, CVE-2019-2796, CVE-2019-2802, CVE-2019-2803, CVE-2019-2808, CVE-2019-2810, CVE-2019-2812, CVE-2019-2815, CVE-2019-2830, CVE-2019-2834)&lt;/p&gt;
&lt;p&gt;* mysql: Server: Parser multiple unspecified vulnerabilities (CVE-2019-2434, CVE-2019-2455, CVE-2019-2805)&lt;/p&gt;
&lt;p&gt;* mysql: Server: PS multiple unspecified vulnerabilities (CVE-2019-2482, CVE-2019-2592)&lt;/p&gt;
&lt;p&gt;* mysql: Server: Security: Privileges multiple unspecified vulnerabilities (CVE-2019-2486, CVE-2019-2532, CVE-2019-2533, CVE-2019-2584, CVE-2019-2589, CVE-2019-2606, CVE-2019-2620, CVE-2019-2627, CVE-2019-2739, CVE-2019-2778, CVE-2019-2811, CVE-2019-2789)&lt;/p&gt;
&lt;p&gt;* mysql: Server: DDL multiple unspecified vulnerabilities (CVE-2019-2494, CVE-2019-24…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: mecab, AlmaLinux:8: mecab-ipadic, AlmaLinux:8: mecab-ipadic-EUCJP&lt;/p&gt;
&lt;p&gt;MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon, mysqld, and many client programs.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: mysql (8.0.17).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* mysql: Server: Replication multiple unspecified vulnerabilities (CVE-2019-2800, CVE-2019-2436, CVE-2019-2531, CVE-2019-2534, CVE-2019-2614, CVE-2019-2617, CVE-2019-2630, CVE-2019-2634, CVE-2019-2635, CVE-2019-2755)&lt;/p&gt;
&lt;p&gt;* mysql: Server: Optimizer multiple unspecified vulnerabilities (CVE-2019-2420, CVE-2019-2481, CVE-2019-2507, CVE-2019-2529, CVE-2019-2530, CVE-2019-2581, CVE-2019-2596, CVE-2019-2607, CVE-2019-2625, CVE-2019-2681, CVE-2019-2685, CVE-2019-2686, CVE-2019-2687, CVE-2019-2688, CVE-2019-2689, CVE-2019-2693, CVE-2019-2694, CVE-2019-2695, CVE-2019-2757, CVE-2019-2774, CVE-2019-2796, CVE-2019-2802, CVE-2019-2803, CVE-2019-2808, CVE-2019-2810, CVE-2019-2812, CVE-2019-2815, CVE-2019-2830, CVE-2019-2834)&lt;/p&gt;
&lt;p&gt;* mysql: Server: Parser multiple unspecified vulnerabilities (CVE-2019-2434, CVE-2019-2455, CVE-2019-2805)&lt;/p&gt;
&lt;p&gt;* mysql: Server: PS multiple unspecified vulnerabilities (CVE-2019-2482, CVE-2019-2592)&lt;/p&gt;
&lt;p&gt;* mysql: Server: Security: Privileges multiple unspecified vulnerabilities (CVE-2019-2486, CVE-2019-2532, CVE-2019-2533, CVE-2019-2584, CVE-2019-2589, CVE-2019-2606, CVE-2019-2620, CVE-2019-2627, CVE-2019-2739, CVE-2019-2778, CVE-2019-2811, CVE-2019-2789)&lt;/p&gt;
&lt;p&gt;* mysql: Server: DDL multiple unspecified vulnerabilities (CVE-2019-2494, CVE-2019-24…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:2511</guid>
      <pubDate>Thu, 15 Aug 2019 17:31:05 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2019:2512 — Important: subversion:1.10 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:2512</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libserf, AlmaLinux:8: utf8proc&lt;/p&gt;
&lt;p&gt;Subversion (SVN) is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* subversion: NULL pointer dereference in svnserve leading to an unauthenticated remote DoS (CVE-2019-0203)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libserf, AlmaLinux:8: utf8proc&lt;/p&gt;
&lt;p&gt;Subversion (SVN) is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* subversion: NULL pointer dereference in svnserve leading to an unauthenticated remote DoS (CVE-2019-0203)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:2512</guid>
      <pubDate>Thu, 15 Aug 2019 17:34:10 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2019:2593 — Important: squid:4 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:2593</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libecap, AlmaLinux:8: libecap-devel&lt;/p&gt;
&lt;p&gt;Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* squid: heap-based buffer overflow in HttpHeader::getAuth (CVE-2019-12527)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libecap, AlmaLinux:8: libecap-devel&lt;/p&gt;
&lt;p&gt;Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* squid: heap-based buffer overflow in HttpHeader::getAuth (CVE-2019-12527)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:2593</guid>
      <pubDate>Mon, 02 Sep 2019 10:22:04 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2019:2720 — Important: pki-deps:10.6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:2720</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-jaxrs-json-provider, AlmaLinux:8: jackson-jaxrs-providers and 17 more&lt;/p&gt;
&lt;p&gt;The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by AlmaLinux Certificate System.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution (CVE-2019-12384)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-jaxrs-json-provider, AlmaLinux:8: jackson-jaxrs-providers and 17 more&lt;/p&gt;
&lt;p&gt;The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by AlmaLinux Certificate System.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution (CVE-2019-12384)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:2720</guid>
      <pubDate>Tue, 10 Sep 2019 15:32:49 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2019:2722 — Low: libwmf security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:2722</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libwmf, AlmaLinux:8: libwmf-devel, AlmaLinux:8: libwmf-lite&lt;/p&gt;
&lt;p&gt;The libwmf packages provide a library for reading and converting Windows Metafile Format (WMF) vector graphics. The library is used by applications such as GIMP and ImageMagick.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gd: double free in the gdImage*Ptr in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c (CVE-2019-6978)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libwmf, AlmaLinux:8: libwmf-devel, AlmaLinux:8: libwmf-lite&lt;/p&gt;
&lt;p&gt;The libwmf packages provide a library for reading and converting Windows Metafile Format (WMF) vector graphics. The library is used by applications such as GIMP and ImageMagick.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gd: double free in the gdImage*Ptr in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c (CVE-2019-6978)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:2722</guid>
      <pubDate>Tue, 10 Sep 2019 15:32:59 +0000</pubDate>
    </item>
  </channel>
</rss>
