CVE-2019-2014
published 2019-06-19CVE-2019-2014: In rw_t3t_handle_get_sc_poll_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of…
PriorityP343high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.81%
53.2th percentile
In rw_t3t_handle_get_sc_poll_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120499324
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| spoon | library | >= 0 < 1.4.1 | 1.4.1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cq32-55vv-jj8h: In rw_t3t_handle_get_sc_poll_rsp of rw_t3t
ghsa_unreviewed·2022-05-24
CVE-2019-2014 [HIGH] CWE-787 GHSA-cq32-55vv-jj8h: In rw_t3t_handle_get_sc_poll_rsp of rw_t3t
In rw_t3t_handle_get_sc_poll_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120499324
GHSA
Spoon Library as used in Fork CMS allows PHP object injection
ghsa·2022-05-24
CVE-2019-15521 [CRITICAL] CWE-502 Spoon Library as used in Fork CMS allows PHP object injection
Spoon Library as used in Fork CMS allows PHP object injection
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.
Kernel
btrfs: Don't submit any btree write bio if the fs has errors
kernel_security·2020-02-12
CVE-2019-19377 btrfs: Don't submit any btree write bio if the fs has errors
btrfs: Don't submit any btree write bio if the fs has errors
[BUG]
There is a fuzzed image which could cause KASAN report at unmount time.
BUG: KASAN: use-after-free in btrfs_queue_work+0x2c1/0x390
Read of size 8 at addr ffff888067cf6848 by task umount/1922
CPU: 0 PID: 1922 Comm: umount Tainted: G W 5.0.21 #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.2-1ubuntu1 04/01/2014
Call Trace:
dump_stack+0x5b/0x8b
print_address_description+0x70/0x280
kasan_report+0x13a/0x19b
btrfs_queue_work+0x2c1/0x390
btrfs_wq_submit_bio+0x1cd/0x240
btree_submit_bio_hook+0x18c/0x2a0
submit_one_bio+0x1be/0x320
flush_write_bio.isra.41+0x2c/0x70
btree_write_cache_pages+0x3bb/0x7f0
do_writepages+0x5c/0x130
__writeback_single_inode+0xa3/0x9a0
writeback_single_inode+0x23d/0x390
write_inode_now+
Red Hat
JON: struts1 reversion of fix for CVE-2014-0114
vendor_redhat·2019-10-02·CVSS 7.5
CVE-2019-3834 [HIGH] CWE-470 JON: struts1 reversion of fix for CVE-2014-0114
JON: struts1 reversion of fix for CVE-2014-0114
It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vulnerable server. Exploits that have been published rely on ClassLoader properties that are exposed such as those in JON 3. Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/site/solutions/869353. Note that while multiple products released patches for the original CVE-2014-0114 flaw, the reversion described by this CVE-2019-3834 flaw only occurred in JON 3.
It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vul
Red Hat
qpid-proton: TLS Man in the Middle Vulnerability
vendor_redhat·2019-04-23·CVSS 7.4
CVE-2019-0223 [HIGH] CWE-358 qpid-proton: TLS Man in the Middle Vulnerability
qpid-proton: TLS Man in the Middle Vulnerability
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
A cryptographic weakness was discovered in qpid-proton's use of TLS. If the qpid-proton client was used without client certificates, it would accept an anonymous cipher offered by the server. A man-in-the-middle attacker could use this to silently intercept traffic that should have been encrypted.
Statement: Red
Android
CVE-2019-2014: Android Security Bulletin 2019-03-01
CVE: CVE-2019-2014
Severity: HIGH
Type: EoP
Affected AOSP versions: 7
vendor_android·2019-03-01·CVSS 8.8
CVE-2019-2014 [HIGH] CVE-2019-2014: Android Security Bulletin 2019-03-01
CVE: CVE-2019-2014
Severity: HIGH
Type: EoP
Affected AOSP versions: 7
Android Security Bulletin 2019-03-01
CVE: CVE-2019-2014
Severity: HIGH
Type: EoP
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-120499324
Red Hat
struts2: predictable generation of form submission token
vendor_redhat·2014-12-08·CVSS 6.8
CVE-2014-7809 [MEDIUM] CWE-330 struts2: predictable generation of form submission token
struts2: predictable generation of form submission token
Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable values, which allows remote attackers to bypass the CSRF protection mechanism.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages. The inclusion was part of an import of the Google Guice repository, which includes struts2-core. Customers that build artefacts from our source code could be at risk. Re
Red Hat
struts2: ClassLoader manipulation via request parameters
vendor_redhat·2014-03-06·CVSS 5.0
CVE-2014-0094 [MEDIUM] struts2: ClassLoader manipulation via request parameters
struts2: ClassLoader manipulation via request parameters
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages. The inclusion was part of an import of the Google Guice repository, which includes struts2-core. Customers that build artefacts from
Suricata
ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361 - Outbound
suricata·2019-05-08·CVSS 9.8
CVE-2014-8361 [CRITICAL] ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361 - Outbound
ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361 - Outbound
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361 - Outbound"; flow:established,to_server; http.method; content:"POST"; http.request_header; header_lowercase; content:"soapaction|3a 20|urn|3a|schemas-upnp-org|3a|service|3a|WANIPConnection|3a|"; fast_pattern; startswith; http.request_body; content:"|3c|u|3a|AddPortMapping"; content:"|3c|NewRemoteHost|3e|"; distance:0; content:"|3c|NewInternalClient"; distance:0; content:"|3c 2f|NewInternalClient|3e|"; distance:0; content:"NewEnabled|3e|1"; distance:0; classtype:trojan-activity; sid:2027339; rev:4; metadata:attack_target IoT, created_at 2019_05_08, cve CVE_2014_8361, deployment
Suricata
ET WEB_SERVER Possible CVE-2014-6271 Attempt
suricata·2015-11-04·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET WEB_SERVER Possible CVE-2014-6271 Attempt
ET WEB_SERVER Possible CVE-2014-6271 Attempt
Rule: alert tcp any any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SERVER Possible CVE-2014-6271 Attempt"; flow:established,to_server; content:" HTTP/1."; pcre:"/^[^\r\n]*?HTTP\/1(?:(?!\r?\n\r?\n)[\x20-\x7e\s]){1,500}\n[\x20-\x7e]{1,100}\x3a[\x20-\x7e]{0,500}\x28\x29\x20\x7b/s"; content:"|28 29 20 7b|"; fast_pattern; reference:url,blogs.akamai.com/2014/09/environment-bashing.html; classtype:attempted-admin; sid:2022028; rev:2; metadata:created_at 2015_11_04, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2019_10_08;)
Suricata
ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DNS
suricata·2014-10-15·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DNS
ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DNS
Rule: alert tcp $EXTERNAL_NET 53 -> $HOME_NET any (msg:"ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DNS"; byte_test:1,&,128,4; content:"|28 29 20 7b|"; fast_pattern; reference:cve,2014-6271; reference:url,packetstormsecurity.com/files/128650; classtype:attempted-admin; sid:2019403; rev:2; metadata:created_at 2014_10_15, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_10_08;)
Suricata
ET EXPLOIT Possible CVE-2014-6271 malicious DNS response
suricata·2014-10-15·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT Possible CVE-2014-6271 malicious DNS response
ET EXPLOIT Possible CVE-2014-6271 malicious DNS response
Rule: alert udp $EXTERNAL_NET 53 -> $HOME_NET any (msg:"ET EXPLOIT Possible CVE-2014-6271 malicious DNS response"; byte_test:1,&,128,2; content:"|28 29 20 7b|"; fast_pattern; reference:cve,2014-6271; reference:url,packetstormsecurity.com/files/128650; classtype:attempted-admin; sid:2019402; rev:2; metadata:created_at 2014_10_15, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_10_08;)
Suricata
ET MALWARE Linux/ShellshockCampaign.DDOSBot Execute Shell Command CnC Server Message
suricata·2014-09-29
CVE-2014-6271 ET MALWARE Linux/ShellshockCampaign.DDOSBot Execute Shell Command CnC Server Message
ET MALWARE Linux/ShellshockCampaign.DDOSBot Execute Shell Command CnC Server Message
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Linux/ShellshockCampaign.DDOSBot Execute Shell Command CnC Server Message"; flow:established,to_client; content:"! SH"; depth:4; pcre:"/^[^\r\n]+?\n$/R"; reference:url,research.zscaler.com/2014/09/shellshock-attacks-spotted-in-wild.html; reference:cve,2014-6271; classtype:command-and-control; sid:2019298; rev:2; metadata:created_at 2014_09_29, cve CVE_2014_6271, signature_severity Major, updated_at 2019_07_26;)
Suricata
ET MALWARE Linux/ShellshockCampaign.DDOSBot UDP Flood CnC Server Message
suricata·2014-09-29
CVE-2014-6271 ET MALWARE Linux/ShellshockCampaign.DDOSBot UDP Flood CnC Server Message
ET MALWARE Linux/ShellshockCampaign.DDOSBot UDP Flood CnC Server Message
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Linux/ShellshockCampaign.DDOSBot UDP Flood CnC Server Message"; flow:established,to_client; content:"! UDP "; depth:6; pcre:"/\x21\x20UDP\x20\d{1,3}\x2E\d{1,3}\x2E\d{1,3}\x2E\d{1,3}/"; reference:url,research.zscaler.com/2014/09/shellshock-attacks-spotted-in-wild.html; reference:cve,2014-6271; classtype:command-and-control; sid:2019300; rev:2; metadata:created_at 2014_09_29, cve CVE_2014_6271, signature_severity Major, updated_at 2019_07_26;)
Exploit-DB
Adobe Acrobat CoolType (AFDKO) - Memory Corruption in the Handling of Type 1 Font load/store Operators
exploitdb·2019-08-15
CVE-2019-8016 Adobe Acrobat CoolType (AFDKO) - Memory Corruption in the Handling of Type 1 Font load/store Operators
Adobe Acrobat CoolType (AFDKO) - Memory Corruption in the Handling of Type 1 Font load/store Operators
---
-----=====[ Background ]=====-----
AFDKO (Adobe Font Development Kit for OpenType) is a set of tools for examining, modifying and building fonts. The core part of this toolset is a font handling library written in C, which provides interfaces for reading and writing Type 1, OpenType, TrueType (to some extent) and several other font formats. While the library existed as early as 2000, it was open-sourced by Adobe in 2014 on GitHub [1, 2], and is still actively developed. The font parsing code can be generally found under afdko/c/public/lib/source/*read/*.c in the project directory tree.
We have recently discovered that parts of AFDKO are compiled in in Adobe's desktop software such
Exploit-DB
Adobe Acrobat CoolType (AFDKO) - Call from Uninitialized Memory due to Empty FDArray in Type 1 Fonts
exploitdb·2019-08-15
CVE-2019-8017 Adobe Acrobat CoolType (AFDKO) - Call from Uninitialized Memory due to Empty FDArray in Type 1 Fonts
Adobe Acrobat CoolType (AFDKO) - Call from Uninitialized Memory due to Empty FDArray in Type 1 Fonts
---
-----=====[ Background ]=====-----
AFDKO (Adobe Font Development Kit for OpenType) is a set of tools for examining, modifying and building fonts. The core part of this toolset is a font handling library written in C, which provides interfaces for reading and writing Type 1, OpenType, TrueType (to some extent) and several other font formats. While the library existed as early as 2000, it was open-sourced by Adobe in 2014 on GitHub [1, 2], and is still actively developed. The font parsing code can be generally found under afdko/c/public/lib/source/*read/*.c in the project directory tree.
We have recently discovered that parts of AFDKO are compiled in in Adobe's desktop software such a
Exploit-DB
CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities
exploitdb·2019-07-15·CVSS 4.7
CVE-2019-1943 [MEDIUM] CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities
CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities
---
# Exploit Title: CISCO Small Business 200, 300, 500 Switches Multiple Vulnerabilities.
# Shodan query: /config/log_off_page.html
# Discovered Date: 07/03/2014
# Reported Date: 08/04/2019
# Exploit Author: Ramikan
# Website: http://fact-in-hack.blogspot.com
# Vendor Homepage:https://www.cisco.com/c/en/us/products/switches/small-business-300-series-managed-switches/index.html
# Affected Devices: The affected products are all Cisco Small Business 200, 300, and 500 Series Managed Switches with the web management interface enabled,
# Tested On: Cisco C300 Switch
# Version: 1.3.7.18
# CVE : CVE-2019-1943
# CVSS v3: 4.7 (AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N)
# Category:Hardware, Web Apps
# Reference : https://tools.cisc
Exploit-DB
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Unbounded iFD
exploitdb·2019-07-10
CVE-2019-1121 Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Unbounded iFD
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Unbounded iFD
---
-----=====[ Background ]=====-----
AFDKO (Adobe Font Development Kit for OpenType) is a set of tools for examining, modifying and building fonts. The core part of this toolset is a font handling library written in C, which provides interfaces for reading and writing Type 1, OpenType, TrueType (to some extent) and several other font formats. While the library existed as early as 2000, it was open-sourced by Adobe in 2014 on GitHub [1, 2], and is still actively developed. The font parsing code can be generally found under afdko/c/public/lib/source/*read/*.c in the project directory tree.
At the time of this writing, based on the available source code, we conclude that AF
Exploit-DB
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readCharset
exploitdb·2019-07-10
CVE-2019-1128 Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readCharset
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readCharset
---
-----=====[ Background ]=====-----
AFDKO (Adobe Font Development Kit for OpenType) is a set of tools for examining, modifying and building fonts. The core part of this toolset is a font handling library written in C, which provides interfaces for reading and writing Type 1, OpenType, TrueType (to some extent) and several other font formats. While the library existed as early as 2000, it was open-sourced by Adobe in 2014 on GitHub [1, 2], and is still actively developed. The font parsing code can be generally found under afdko/c/public/lib/source/*read/*.c in the project directory tree.
At the time of this writing, based on the available source code, we conclude that AFDKO was origina
Exploit-DB
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling Due to Negative nAxes
exploitdb·2019-07-10
CVE-2019-1127 Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling Due to Negative nAxes
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling Due to Negative nAxes
---
-----=====[ Background ]=====-----
AFDKO (Adobe Font Development Kit for OpenType) is a set of tools for examining, modifying and building fonts. The core part of this toolset is a font handling library written in C, which provides interfaces for reading and writing Type 1, OpenType, TrueType (to some extent) and several other font formats. While the library existed as early as 2000, it was open-sourced by Adobe in 2014 on GitHub [1, 2], and is still actively developed. The font parsing code can be generally found under afdko/c/public/lib/source/*read/*.c in the project directory tree.
At the time of this writing, based on the available source code, we conclude that AFDKO was originally
Bugzilla
CVE-2019-13178 calamares: race condition in modules/luksbootkeyfile/main.py
bugzilla·2019-07-03·CVSS 8.1
CVE-2019-13178 [HIGH] CVE-2019-13178 calamares: race condition in modules/luksbootkeyfile/main.py
CVE-2019-13178 calamares: race condition in modules/luksbootkeyfile/main.py
modules/luksbootkeyfile/main.py in Calamares through 3.2.4 has a race condition between the time when the LUKS encryption keyfile is created and when secure permissions are set.
Reference:
https://github.com/calamares/calamares/issues/1190
https://www.pavelkogan.com/2014/05/23/luks-full-disk-encryption/
https://www.pavelkogan.com/2015/01/25/linux-mint-encryption/
Discussion:
Created calamares tracking bugs for this issue:
Affects: fedora-all [bug 1726566]
---
I will prepare an update when upstream releases a release with the fix, which should happen this week.
---
Please note that the upstream version numbers in both CVEs are incorrect, all versions of Calamares up to and including 3.2.10 are affected.
--
Bugzilla
CVE-2014-7809 struts2: predictable generation of form submission token
bugzilla·2014-12-09·CVSS 6.8
CVE-2014-7809 [MEDIUM] CVE-2014-7809 struts2: predictable generation of form submission token
CVE-2014-7809 struts2: predictable generation of form submission token
It was found that the Struts 2 Random Number Generator component generates predictable form submission tokens. A remote attacker able to acquire a victim's form submission token could predict the next value of this token and perform Cross-Site Request Forgery (CSRF) attacks against that victim.
This flaw is reported to affect Struts 2.0.0 through 2.3.16.3. It is corrected in Struts 2.3.20.
External References:
https://cwiki.apache.org/confluence/display/WW/S2-023
Discussion:
Statement:
A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, u
Bugzilla
CVE-2014-0116 struts2: Struts internals manipulation via cookie request headers
bugzilla·2014-05-06·CVSS 5.8
CVE-2014-0116 [MEDIUM] CVE-2014-0116 struts2: Struts internals manipulation via cookie request headers
CVE-2014-0116 struts2: Struts internals manipulation via cookie request headers
It was found that the Struts 2 CookieInterceptor allows access to Struts internal classes. A remote attacker could use this flaw to manipulate the state of session and request data on an application server running Struts 2.
This flaw is reported to affect Struts 2.0.0 through to Struts 2.3.16.2. It is corrected in 2.3.16.3.
External References:
https://cwiki.apache.org/confluence/display/WW/S2-022
Discussion:
Statement:
A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, an
Bugzilla
CVE-2014-0094 struts2: ClassLoader manipulation via request parameters
bugzilla·2014-03-07·CVSS 5.0
CVE-2014-0094 [MEDIUM] CVE-2014-0094 struts2: ClassLoader manipulation via request parameters
CVE-2014-0094 struts2: ClassLoader manipulation via request parameters
It was found that the Struts 2 ParametersInterceptor allows access to the 'class' parameter, which is directly mapped to the getClass() method. A remote attacker could use this flaw to manipulate the ClassLoader used by the application server running Struts 2. This could lead to arbitrary remote code execution under certain conditions.
This flaw is reported to affect Struts 2.0.0 through to Struts 2.3.16. It is corrected in 2.3.16.1.
External References:
https://cwiki.apache.org/confluence/display/WW/S2-020
Discussion:
Statement:
A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While
2019-06-19
Published