RHSA-2016:0497-1: Important: git19-git security update

Red Hat Enterprise Linux: Updated git19-git packages that fix two security issues are now available
for Red Hat Software Collections.

Red Hat Product Security has rated this update as having Important security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2016-2315, CVE-2016-2324

RHSA-2016:0496-1: Important: git security update

Red Hat Enterprise Linux: Updated git packages that fix two security issues are now available for Red
Hat Enterprise Linux 6 and 7.

Red Hat Product Security has rated this update as having Important security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2016-2315, CVE-2016-2324

RHSA-2016:0495-1: Critical: nss-util security update

Red Hat Enterprise Linux: Updated nss-util packages that fix one security issue are now available for
Red Hat Enterprise Linux 6.2, 6.4, and 6.5 Advanced Update Support, and Red
Hat Enterprise Linux 6.6 and 7.1 Extended Update Support.

Red Hat Product Security has rated this update as having Critical security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2016-1950

Login one time – Critical – Cross Site Scripting (XSS) – SA-CONTRIB-2016-017

Description

The Login one time module provides the ability to email one-time login links to users.

The module doesn’t sufficiently sanitize user input supplied to an ajax callback function.

CVE identifier(s) issued

  • A CVE identifier will be requested, and added upon issuance, in accordance with Drupal Security Team processes.

Versions affected

  • Login one time 7.x-2.x versions prior to 7.x-2.10.

Drupal core is not affected. If you do not use the contributed Login one time module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Login one time project page.

Reported by

Fixed by

Coordinated by

Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at https://www.drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Follow the Drupal Security Team on Twitter at https://twitter.com/drupalsecurity

Drupal version: