Alerts This Week
Warning Icon 1 929
Alerts This Week
Warning Icon 1 929

Ubuntu 20.04: 2022-abc2d1f3b2 Major: AppArmor Denial of Service

fedora
Calendar Grey February 12, 2021
Dist Fedora Esm H88
Patch for DNF in Fedora 34 resolves vulnerabilities related to leaked credentials in system logs.
Update to Zypper 1.14.42 and libzypp 17.25.6 to remediate CVE-2017-9271

Summary

Zypper is a command line package manager tool using libzypp,

which can be used to manage software for RPM based systems.

Update to Zypper 1.14.42 and libzypp 17.25.6 to remediate CVE-2017-9271

* Thu Feb 11 2021 Neal Gompa - 1.14.42-1

- Update to 1.14.42 (#1823433)

* Thu Jan 28 2021 Fedora Release Engineering - 1.14.37-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild

[ 1 ] Bug #1817137 - libzypp-17.25.6 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1817137

[ 2 ] Bug #1823433 - zypper-1.14.42 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1823433

[ 3 ] Bug #1922190 - CVE-2017-9271 zypper: proxy credentials written to log files leads to information explosure [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1922190

[ 4 ] Bug #1922191 - CVE-2017-9271 libzypp: zypper: proxy credentials written to log files leads to information explosure [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1922191

su -c 'dnf upgrade --advisory FEDORA-2021-ebc1c35c5d' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 33
Version: 1.14.42
Release: 1.fc33
URL:
Summary: Command line package manager using libzypp

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here