Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 32: FEDORA-2020-cf8ef2f333 Critical: Apache Lucene Security Fixes

fedora
Calendar Grey August 31, 2020
Dist Fedora Esm H88
Crucial Fedora update incorporating security enhancements for Lucene, tackling vulnerabilities recognized by CVE-2020-14746, CVE-2020-14818.
Updates to the latest upstream release of Eclipse

Summary

Apache Lucene is a high-performance, full-featured text search

engine library written entirely in Java. It is a technology suitable

for nearly any application that requires full-text search, especially

cross-platform.

Updates to the latest upstream release of Eclipse. See the upstream release

notes for details: https://eclipseide.org/release/noteworthy/ Also

contains security fixes for CVE-2019-17566 and CVE-2019-17638.

* Thu Aug 6 2020 Mat Booth - 0:8.4.1-9

- Add optional resolution on internal JDK APIs that might not be present on Java

11

* Thu Aug 6 2020 Mat Booth - 0:8.4.1-8

- Avoid requirement on com.sun.management package

* Tue Jul 28 2020 Fedora Release Engineering - 0:8.4.1-7

- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild

* Tue Jul 21 2020 Mat Booth - 0:8.4.1-6

- Fix NIO linkage error when running on Java 8 due to incorrect

cross-compilation

* Sat Jul 11 2020 Jiri Vanek - 0:8.4.1-5

- Rebuilt for JDK-11, see https://fedoraproject.org/wiki/Changes/Java11

* Wed May 6 2020 Mat Booth - 0:8.4.1-4

- Fix jp_minimal mode

* Tue May 5 2020 Alexander Kurtakov - 0:8.4.1-3

- Disable test-framework as its dependency (randomizedtesting) is removed.

* Sat Mar 21 2020 Mat Booth - 0:8.4.1-2

- Fix deps for minimal mode

* Sat Mar 21 2020 Mat Booth - 0:8.4.1-1

- Update to latest upstream release

[ 1 ] Bug #1848617 - CVE-2019-17566 batik: SSRF via "xlink:href"

https://bugzilla.redhat.com/show_bug.cgi?id=1848617

[ 2 ] Bug #1864680 - CVE-2019-17638 jetty: double release of resource can lead to information disclosure

https://bugzilla.redhat.com/show_bug.cgi?id=1864680

su -c 'dnf upgrade --advisory FEDORA-2020-cf8ef2f333' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 8.4.1
Release: 9.fc32
Summary: High-performance, full-featured text search engine

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here