Several security issues were fixed in OpenJDK 8 ...
USN-3087-1 introduced a regression in OpenSSL ...
Several security issues were fixed in OpenSSL ...
Several security issues were fixed in OpenJDK 7 ...
Several security issues were fixed in OpenJDK 6 ...
Several security issues were fixed in NSS ...
Several security issues were fixed in NSS ...
It was discovered that OpenSSL did not always use constant time operations when computing Digital Signature Algorithm (DSA) signatures A local attacker could possibly use this flaw to obtain a private DSA key belonging to another user or service running on the same system (CVE-2016-2178)
It was discovered that the Datagram TLS (DTLS) implementati ...
It was discovered that the RMI registry and DCG implementations in the RMI component of OpenJDK performed deserialization of untrusted inputs A remote attacker could possibly use this flaw to execute arbitrary code with the privileges of RMI registry or a Java RMI application (CVE-2017-3241) This issue was addressed by introducing whitelists of c ...
A flaw was found in the way the DES/3DES cipher was used as part of the TLS/SSL protocol A man-in-the-middle attacker could use this flaw to recover some plaintext data by capturing large amounts of encrypted traffic between TLS/SSL server and client if the communication used a DES/3DES based ciphersuite ...
Synopsis
Important: OpenShift Container Platform 4616 security and bug fix update
Type/Severity
Security Advisory: Important
Topic
Red Hat OpenShift Container Platform release 4616 is now available withupdates to packages and images that fix several bugsRed Hat Product Security has rated this update as ...
Synopsis
Moderate: OpenShift Container Platform 4513 openshift-enterprise-console-container security update
Type/Severity
Security Advisory: Moderate
Topic
An update for openshift-enterprise-console-container is now available for Red Hat OpenShift Container Platform 45Red Hat Product Security has rated ...
Synopsis
Moderate: Red Hat Quay 302 security and bug fix update
Type/Severity
Security Advisory: Moderate
Topic
An update is now available for Red Hat Quay 3Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVSS) base score, whic ...
Synopsis
Moderate: python security update
Type/Severity
Security Advisory: Moderate
Topic
An update for python is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, whic ...
Synopsis
Moderate: java-180-ibm security update
Type/Severity
Security Advisory: Moderate
Topic
An update for java-180-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 SupplementaryRed Hat Product Security has rated this update as having a security impact ...
Synopsis
Important: Red Hat JBoss Core Services security update
Type/Severity
Security Advisory: Important
Topic
An update is now available for JBoss Core Services on Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sc ...
Synopsis
Important: Red Hat JBoss Core Services security update
Type/Severity
Security Advisory: Important
Topic
An update is now available for Red Hat JBoss Core ServicesRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis
Moderate: OpenShift Container Platform 4118 security update
Type/Severity
Security Advisory: Moderate
Topic
An update for golang-github-openshift-oauth-proxy-container is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as having a security ...
Synopsis
Moderate: OpenShift Container Platform 311 security update
Type/Severity
Security Advisory: Moderate
Topic
Red Hat OpenShift Container Platform release 311170 is now available withupdates to packages and images that fix several bugsRed Hat Product Security has rated this update as having a secu ...
Synopsis
Critical: java-170-ibm security update
Type/Severity
Security Advisory: Critical
Topic
An update for java-170-ibm is now available for Red Hat Enterprise Linux 5SupplementaryRed Hat Product Security has rated this update as having a security impact ofCritical A Common Vulnerability Scoring Sy ...
Synopsis
Moderate: java-171-ibm security update
Type/Severity
Security Advisory: Moderate
Topic
An update for java-171-ibm is now available for Red HatSatellite 57 and Red Hat Satellite 56Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Sc ...
Synopsis
Important: Red Hat JBoss Enterprise Application Platform 6418 security update
Type/Severity
Security Advisory: Important
Topic
An update is now available for Red Hat JBoss Enterprise Application Platform 64 for RHEL 6 and Red Hat JBoss Enterprise Application Platform 64 for RHEL 7Red Hat Produ ...
Synopsis
Critical: java-171-ibm security update
Type/Severity
Security Advisory: Critical
Topic
An update for java-171-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 SupplementaryRed Hat Product Security has rated this update as having a security impact ...
Synopsis
Critical: java-170-openjdk security update
Type/Severity
Security Advisory: Critical
Topic
An update for java-170-openjdk is now available for Red Hat Enterprise Linux5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a securit ...
Synopsis
Critical: java-180-oracle security update
Type/Severity
Security Advisory: Critical
Topic
An update for java-180-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a secur ...
Synopsis
Critical: java-160-sun security update
Type/Severity
Security Advisory: Critical
Topic
An update for java-160-sun is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7Red Hat Product Security ...
Synopsis
Important: Red Hat JBoss Web Server security and bug fix update
Type/Severity
Security Advisory: Important
Topic
An update is now available for Red Hat JBoss Enterprise Web Server 212 for RHEL 6 and Red Hat JBoss Enterprise Web Server 212 for RHEL 7Red Hat Product Security has rated this updat ...
Synopsis
Critical: java-180-openjdk security update
Type/Severity
Security Advisory: Critical
Topic
An update for java-180-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Critical A Comm ...
Synopsis
Important: Red Hat JBoss Enterprise Application Platform 6418 security update
Type/Severity
Security Advisory: Important
Topic
An update is now available for Red Hat JBoss Enterprise Application PlatformRed Hat Product Security has rated this update as having a security impact of Important A Co ...
Synopsis
Important: Red Hat JBoss Core Services security update
Type/Severity
Security Advisory: Important
Topic
An update is now available for JBoss Core Services on Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sc ...
Synopsis
Critical: java-170-oracle security update
Type/Severity
Security Advisory: Critical
Topic
An update for java-170-oracle is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7Red Hat Product Sec ...
Synopsis
Critical: java-160-ibm security update
Type/Severity
Security Advisory: Critical
Topic
An update for java-160-ibm is now available for Red Hat Enterprise Linux 5Supplementary and Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact ...
Synopsis
Important: openssl security update
Type/Severity
Security Advisory: Important
Topic
An update for openssl is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sc ...
Synopsis
Important: Red Hat JBoss Web Server security and bug fix update
Type/Severity
Security Advisory: Important
Topic
An update is now available for Red Hat JBoss Enterprise Web Server 212Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability S ...
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity”
Subsequently, on September 26, the OpenSSL Software Foundatio ...
SWEET32 (sweet32info) is an attack on older block cipher algorithms that use a block size of 64 bits In mitigation for the SWEET32 attack DES based ciphersuites have been moved from the HIGH cipherstring group to MEDIUM ...
Log Correlation Engine (LCE) 500 is impacted by multiple vulnerabilities reported in a third-party library and an encryption algorithm LCE was errantly using 3DES on TCP port 1243
The following vulnerabilities have been resolved with the updated libraries
cURL / libcurl lib/urlc allocate_conn() Function OCSP Stapling Validation Failure MitM ...
Nessus is potentially impacted by several vulnerabilities in OpenSSL (20160926) that were recently disclosed and fixed Note that due to the time involved in doing a full analysis of each issue, Tenable has opted to upgrade the included version of OpenSSL as a precaution, and to save time These vulnerabilities may impact Nessus and include:
CVE-2 ...
LCE 481 is possibly impacted by multiple vulnerabilities reported in third-party libraries Tenable has not investigated each one to determine if it is exploitable or the vulnerable code path can be reached Instead, Dev has upgraded the impacted libraries as a faster and safer alternative Due to the number of library upgrades and the potential ...
Tenable's Passive Vulnerability Scanner (PVS) uses third-party libraries to provide certain standardized functionality Four of these libraries were found to contain vulnerabilities and were fixed upstream Those fixes have been integrated despite there being no known exploitation scenarios related to PVS
OpenSSL ssl/statem/statemc read_state_ma ...