Vulnerability Database
Blog
FAQ
Docs
RHBA-2019:3416
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHBA-2019:3416
Import Source
https://security.access.redhat.com/data/osv/RHBA-2019:3416.json
JSON Data
https://api.osv.dev/v1/vulns/RHBA-2019:3416
Related
CVE-2019-12086
CVE-2019-12814
Published
2024-09-13T19:48:58Z
Modified
2024-09-13T19:48:58Z
Severity
7.5 (High)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Calculator
Summary
Red Hat Bug Fix Advisory: pki-core:10.6 and pki-deps:10:6 bug fix and enhancement update
Details
References
https://access.redhat.com/errata/RHBA-2019:3416
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.1_release_notes/
https://bugzilla.redhat.com/show_bug.cgi?id=1666859
https://bugzilla.redhat.com/show_bug.cgi?id=1666921
https://bugzilla.redhat.com/show_bug.cgi?id=1673296
https://bugzilla.redhat.com/show_bug.cgi?id=1679480
https://bugzilla.redhat.com/show_bug.cgi?id=1695302
https://bugzilla.redhat.com/show_bug.cgi?id=1696849
https://bugzilla.redhat.com/show_bug.cgi?id=1698059
https://bugzilla.redhat.com/show_bug.cgi?id=1715950
https://bugzilla.redhat.com/show_bug.cgi?id=1721135
https://access.redhat.com/security/data/csaf/v2/advisories/2019/rhba-2019_3416.json
https://access.redhat.com/security/cve/CVE-2019-12086
https://bugzilla.redhat.com/show_bug.cgi?id=1713468
https://www.cve.org/CVERecord?id=CVE-2019-12086
https://nvd.nist.gov/vuln/detail/CVE-2019-12086
https://access.redhat.com/security/cve/CVE-2019-12814
https://bugzilla.redhat.com/show_bug.cgi?id=1725795
https://www.cve.org/CVERecord?id=CVE-2019-12814
https://nvd.nist.gov/vuln/detail/CVE-2019-12814
Affected packages
Red Hat:enterprise_linux:8::appstream
/
jss
Package
Name
jss
Purl
pkg:rpm/redhat/jss
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.0-5.module+el8.1.0+4218+3fd65c36
Red Hat:enterprise_linux:8::appstream
/
jss-debuginfo
Package
Name
jss-debuginfo
Purl
pkg:rpm/redhat/jss-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.0-5.module+el8.1.0+4218+3fd65c36
Red Hat:enterprise_linux:8::appstream
/
jss-debugsource
Package
Name
jss-debugsource
Purl
pkg:rpm/redhat/jss-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.0-5.module+el8.1.0+4218+3fd65c36
Red Hat:enterprise_linux:8::appstream
/
jss-javadoc
Package
Name
jss-javadoc
Purl
pkg:rpm/redhat/jss-javadoc
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.0-5.module+el8.1.0+4218+3fd65c36
Red Hat:enterprise_linux:8::appstream
/
ldapjdk
Package
Name
ldapjdk
Purl
pkg:rpm/redhat/ldapjdk
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.21.0-1.module+el8.1.0+3370+6d076660
Red Hat:enterprise_linux:8::appstream
/
ldapjdk-javadoc
Package
Name
ldapjdk-javadoc
Purl
pkg:rpm/redhat/ldapjdk-javadoc
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.21.0-1.module+el8.1.0+3370+6d076660
Red Hat:enterprise_linux:8::appstream
/
pki-base
Package
Name
pki-base
Purl
pkg:rpm/redhat/pki-base
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
pki-base-java
Package
Name
pki-base-java
Purl
pkg:rpm/redhat/pki-base-java
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
pki-ca
Package
Name
pki-ca
Purl
pkg:rpm/redhat/pki-ca
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
pki-core
Package
Name
pki-core
Purl
pkg:rpm/redhat/pki-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
pki-core-debuginfo
Package
Name
pki-core-debuginfo
Purl
pkg:rpm/redhat/pki-core-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
pki-core-debugsource
Package
Name
pki-core-debugsource
Purl
pkg:rpm/redhat/pki-core-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
pki-kra
Package
Name
pki-kra
Purl
pkg:rpm/redhat/pki-kra
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
pki-server
Package
Name
pki-server
Purl
pkg:rpm/redhat/pki-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
pki-symkey
Package
Name
pki-symkey
Purl
pkg:rpm/redhat/pki-symkey
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
pki-symkey-debuginfo
Package
Name
pki-symkey-debuginfo
Purl
pkg:rpm/redhat/pki-symkey-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
pki-tools
Package
Name
pki-tools
Purl
pkg:rpm/redhat/pki-tools
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
pki-tools-debuginfo
Package
Name
pki-tools-debuginfo
Purl
pkg:rpm/redhat/pki-tools-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
python3-pki
Package
Name
python3-pki
Purl
pkg:rpm/redhat/python3-pki
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.7.3-1.module+el8.1.0+3964+500fc130
Red Hat:enterprise_linux:8::appstream
/
tomcatjss
Package
Name
tomcatjss
Purl
pkg:rpm/redhat/tomcatjss
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.4.1-1.module+el8.1.0+3370+6d076660
Red Hat:enterprise_linux:8::appstream
/
apache-commons-collections
Package
Name
apache-commons-collections
Purl
pkg:rpm/redhat/apache-commons-collections
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.2.2-10.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
apache-commons-lang
Package
Name
apache-commons-lang
Purl
pkg:rpm/redhat/apache-commons-lang
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.6-21.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
bea-stax
Package
Name
bea-stax
Purl
pkg:rpm/redhat/bea-stax
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2.0-16.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
bea-stax-api
Package
Name
bea-stax-api
Purl
pkg:rpm/redhat/bea-stax-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2.0-16.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
glassfish-fastinfoset
Package
Name
glassfish-fastinfoset
Purl
pkg:rpm/redhat/glassfish-fastinfoset
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2.13-9.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb
Package
Name
glassfish-jaxb
Purl
pkg:rpm/redhat/glassfish-jaxb
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.11-11.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb-api
Package
Name
glassfish-jaxb-api
Purl
pkg:rpm/redhat/glassfish-jaxb-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.12-8.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb-core
Package
Name
glassfish-jaxb-core
Purl
pkg:rpm/redhat/glassfish-jaxb-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.11-11.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb-runtime
Package
Name
glassfish-jaxb-runtime
Purl
pkg:rpm/redhat/glassfish-jaxb-runtime
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.11-11.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb-txw2
Package
Name
glassfish-jaxb-txw2
Purl
pkg:rpm/redhat/glassfish-jaxb-txw2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.11-11.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
jackson-annotations
Package
Name
jackson-annotations
Purl
pkg:rpm/redhat/jackson-annotations
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.9.9-1.module+el8.1.0+3832+9784644d
Red Hat:enterprise_linux:8::appstream
/
jackson-core
Package
Name
jackson-core
Purl
pkg:rpm/redhat/jackson-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.9.9-1.module+el8.1.0+3832+9784644d
Red Hat:enterprise_linux:8::appstream
/
jackson-databind
Package
Name
jackson-databind
Purl
pkg:rpm/redhat/jackson-databind
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.9.9.2-1.module+el8.1.0+3832+9784644d
Red Hat:enterprise_linux:8::appstream
/
jackson-jaxrs-json-provider
Package
Name
jackson-jaxrs-json-provider
Purl
pkg:rpm/redhat/jackson-jaxrs-json-provider
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.9.9-1.module+el8.1.0+3832+9784644d
Red Hat:enterprise_linux:8::appstream
/
jackson-jaxrs-providers
Package
Name
jackson-jaxrs-providers
Purl
pkg:rpm/redhat/jackson-jaxrs-providers
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.9.9-1.module+el8.1.0+3832+9784644d
Red Hat:enterprise_linux:8::appstream
/
jackson-module-jaxb-annotations
Package
Name
jackson-module-jaxb-annotations
Purl
pkg:rpm/redhat/jackson-module-jaxb-annotations
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.7.6-4.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
jakarta-commons-httpclient
Package
Name
jakarta-commons-httpclient
Purl
pkg:rpm/redhat/jakarta-commons-httpclient
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.1-28.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
javassist
Package
Name
javassist
Purl
pkg:rpm/redhat/javassist
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.18.1-8.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
javassist-javadoc
Package
Name
javassist-javadoc
Purl
pkg:rpm/redhat/javassist-javadoc
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.18.1-8.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
pki-servlet-4.0-api
Package
Name
pki-servlet-4.0-api
Purl
pkg:rpm/redhat/pki-servlet-4.0-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.7-16.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
pki-servlet-engine
Package
Name
pki-servlet-engine
Purl
pkg:rpm/redhat/pki-servlet-engine
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.7-16.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
python-nss
Package
Name
python-nss
Purl
pkg:rpm/redhat/python-nss
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.1-10.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
python-nss-debugsource
Package
Name
python-nss-debugsource
Purl
pkg:rpm/redhat/python-nss-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.1-10.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
python-nss-doc
Package
Name
python-nss-doc
Purl
pkg:rpm/redhat/python-nss-doc
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.1-10.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
python3-nss
Package
Name
python3-nss
Purl
pkg:rpm/redhat/python3-nss
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.1-10.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
python3-nss-debuginfo
Package
Name
python3-nss-debuginfo
Purl
pkg:rpm/redhat/python3-nss-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.1-10.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
relaxngDatatype
Package
Name
relaxngDatatype
Purl
pkg:rpm/redhat/relaxngDatatype
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2011.1-7.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
resteasy
Package
Name
resteasy
Purl
pkg:rpm/redhat/resteasy
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.26-3.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
slf4j
Package
Name
slf4j
Purl
pkg:rpm/redhat/slf4j
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.25-4.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
slf4j-jdk14
Package
Name
slf4j-jdk14
Purl
pkg:rpm/redhat/slf4j-jdk14
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.25-4.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
stax-ex
Package
Name
stax-ex
Purl
pkg:rpm/redhat/stax-ex
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.7-8.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
velocity
Package
Name
velocity
Purl
pkg:rpm/redhat/velocity
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7-24.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
xalan-j2
Package
Name
xalan-j2
Purl
pkg:rpm/redhat/xalan-j2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.7.1-38.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
xerces-j2
Package
Name
xerces-j2
Purl
pkg:rpm/redhat/xerces-j2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.11.0-34.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
xml-commons-apis
Package
Name
xml-commons-apis
Purl
pkg:rpm/redhat/xml-commons-apis
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.4.01-25.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
xml-commons-resolver
Package
Name
xml-commons-resolver
Purl
pkg:rpm/redhat/xml-commons-resolver
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2-26.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
xmlstreambuffer
Package
Name
xmlstreambuffer
Purl
pkg:rpm/redhat/xmlstreambuffer
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.4-8.module+el8.1.0+3366+6dfb954c
Red Hat:enterprise_linux:8::appstream
/
xsom
Package
Name
xsom
Purl
pkg:rpm/redhat/xsom
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0-19.20110809svn.module+el8.1.0+3366+6dfb954c
RHBA-2019:3416 - OSV