Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-1529

Опубликовано: 30 июл. 2019
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2019-1529: pki-deps:10.6 security update (IMPORTANT)

apache-commons-collections [3.2.2-10]

[3.2.2-9]

  • Remove workaround for symlink->directory rpm bug

jackson-bom [2.9.8-1]

  • Update to latest upstream release

[2.9.4-2]

[2.9.4-1]

  • Update to latest upstream release

[2.9.3-1]

  • Initial packaging

pki-servlet-container [1:9.0.7-14]

  • Update to JWS 5.0.2 distribution
  • Resolves: rhbz#1658846 CVE-2018-8034 pki-servlet-container: tomcat: host name verification missing in WebSocket client
  • Resolves: rhbz#1579614 CVE-2018-8014 pki-servlet-container: tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
  • Resolves: rhbz#1619232 - CVE-2018-8037 pki-servlet-container: tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up
  • Resolves: rhbz#1641874 - CVE-2018-11784 pki-servlet-container: tomcat: Open redirect in default servlet

velocity [0:1.7-24]

  • Repack the tarball without binaries

[0:1.7-23]

xerces-j2 [2.11.0-34]

  • Fix license tag to include W3C

[2.11.0-33]

  • Add requirement on javapackages-tools since scripts use java-functions.

[2.11.0-32]

xml-commons-resolver [0:1.2-26]

  • Add requirement on javapackages-tools since scripts use java-functions.

[0:1.2-25]

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module pki-deps:10.6 is enabled

apache-commons-collections

3.2.2-10.module+el8.0.0+5231+3e842911

apache-commons-lang

2.6-21.module+el8.0.0+5231+3e842911

bea-stax-api

1.2.0-16.module+el8.0.0+5231+3e842911

glassfish-fastinfoset

1.2.13-9.module+el8.0.0+5231+3e842911

glassfish-jaxb-api

2.2.12-8.module+el8.0.0+5231+3e842911

glassfish-jaxb-core

2.2.11-11.module+el8.0.0+5231+3e842911

glassfish-jaxb-runtime

2.2.11-11.module+el8.0.0+5231+3e842911

glassfish-jaxb-txw2

2.2.11-11.module+el8.0.0+5231+3e842911

jackson-annotations

2.9.8-1.module+el8.0.0+5231+3e842911

jackson-core

2.9.8-1.module+el8.0.0+5231+3e842911

jackson-databind

2.9.8-1.module+el8.0.0+5231+3e842911

jackson-jaxrs-json-provider

2.9.8-1.module+el8.0.0+5231+3e842911

jackson-jaxrs-providers

2.9.8-1.module+el8.0.0+5231+3e842911

jackson-module-jaxb-annotations

2.7.6-4.module+el8.0.0+5231+3e842911

jakarta-commons-httpclient

3.1-28.module+el8.0.0+5231+3e842911

javassist

3.18.1-8.module+el8.0.0+5231+3e842911

javassist-javadoc

3.18.1-8.module+el8.0.0+5231+3e842911

pki-servlet-4.0-api

9.0.7-14.module+el8.0.0+5231+3e842911

pki-servlet-container

9.0.7-14.module+el8.0.0+5231+3e842911

python-nss-doc

1.0.1-10.module+el8.0.0+5231+3e842911

python3-nss

1.0.1-10.module+el8.0.0+5231+3e842911

relaxngDatatype

2011.1-7.module+el8.0.0+5231+3e842911

resteasy

3.0.26-3.module+el8.0.0+5231+3e842911

slf4j

1.7.25-4.module+el8.0.0+5231+3e842911

slf4j-jdk14

1.7.25-4.module+el8.0.0+5231+3e842911

stax-ex

1.7.7-8.module+el8.0.0+5231+3e842911

velocity

1.7-24.module+el8.0.0+5231+3e842911

xalan-j2

2.7.1-38.module+el8.0.0+5231+3e842911

xerces-j2

2.11.0-34.module+el8.0.0+5231+3e842911

xml-commons-apis

1.4.01-25.module+el8.0.0+5231+3e842911

xml-commons-resolver

1.2-26.module+el8.0.0+5231+3e842911

xmlstreambuffer

1.5.4-8.module+el8.0.0+5231+3e842911

xsom

0-19.20110809svn.module+el8.0.0+5231+3e842911

Oracle Linux x86_64

Module pki-deps:10.6 is enabled

apache-commons-collections

3.2.2-10.module+el8.0.0+5231+3e842911

apache-commons-lang

2.6-21.module+el8.0.0+5231+3e842911

bea-stax-api

1.2.0-16.module+el8.0.0+5231+3e842911

glassfish-fastinfoset

1.2.13-9.module+el8.0.0+5231+3e842911

glassfish-jaxb-api

2.2.12-8.module+el8.0.0+5231+3e842911

glassfish-jaxb-core

2.2.11-11.module+el8.0.0+5231+3e842911

glassfish-jaxb-runtime

2.2.11-11.module+el8.0.0+5231+3e842911

glassfish-jaxb-txw2

2.2.11-11.module+el8.0.0+5231+3e842911

jackson-annotations

2.9.8-1.module+el8.0.0+5231+3e842911

jackson-core

2.9.8-1.module+el8.0.0+5231+3e842911

jackson-databind

2.9.8-1.module+el8.0.0+5231+3e842911

jackson-jaxrs-json-provider

2.9.8-1.module+el8.0.0+5231+3e842911

jackson-jaxrs-providers

2.9.8-1.module+el8.0.0+5231+3e842911

jackson-module-jaxb-annotations

2.7.6-4.module+el8.0.0+5231+3e842911

jakarta-commons-httpclient

3.1-28.module+el8.0.0+5231+3e842911

javassist

3.18.1-8.module+el8.0.0+5231+3e842911

javassist-javadoc

3.18.1-8.module+el8.0.0+5231+3e842911

pki-servlet-4.0-api

9.0.7-14.module+el8.0.0+5231+3e842911

pki-servlet-container

9.0.7-14.module+el8.0.0+5231+3e842911

python-nss-doc

1.0.1-10.module+el8.0.0+5231+3e842911

python3-nss

1.0.1-10.module+el8.0.0+5231+3e842911

relaxngDatatype

2011.1-7.module+el8.0.0+5231+3e842911

resteasy

3.0.26-3.module+el8.0.0+5231+3e842911

slf4j

1.7.25-4.module+el8.0.0+5231+3e842911

slf4j-jdk14

1.7.25-4.module+el8.0.0+5231+3e842911

stax-ex

1.7.7-8.module+el8.0.0+5231+3e842911

velocity

1.7-24.module+el8.0.0+5231+3e842911

xalan-j2

2.7.1-38.module+el8.0.0+5231+3e842911

xerces-j2

2.11.0-34.module+el8.0.0+5231+3e842911

xml-commons-apis

1.4.01-25.module+el8.0.0+5231+3e842911

xml-commons-resolver

1.2-26.module+el8.0.0+5231+3e842911

xmlstreambuffer

1.5.4-8.module+el8.0.0+5231+3e842911

xsom

0-19.20110809svn.module+el8.0.0+5231+3e842911

Связанные уязвимости

rocky
около 6 лет назад

Important: pki-deps:10.6 security update

suse-cvrf
больше 6 лет назад

Security update for tomcat

suse-cvrf
больше 6 лет назад

Security update for tomcat

suse-cvrf
почти 7 лет назад

Security update for tomcat

suse-cvrf
больше 6 лет назад

Security update for tomcat