Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 34 Nicotine+: FEDORA-2022-066232000e Moderate DoS Fix

fedora
Calendar Grey March 24, 2022
Dist Fedora Esm H88
The nicotine+ version 3.2.1 release includes a fix for a denial-of-service vulnerability associated with harmful download requests on Fedora 34.
Update to 3.2.1 (fix CVE-2021-45848: DoS via malicious download request)

Summary

Nicotine+ is a graphical client for the Soulseek peer-to-peer file sharing

network. It is an attempt to keep Nicotine working with the latest libraries,

kill bugs, keep current with the Soulseek protocol, and add some new features

that users want and/or need.

Update to 3.2.1 (fix CVE-2021-45848: DoS via malicious download request)

* Wed Mar 16 2022 Mohamed El Morabity - 3.2.1-1

- Update to 3.2.1 (fix CVE-2021-45848)

[ 1 ] Bug #2064525 - CVE-2021-45848 nicotine+: DoS via malicious download request [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2064525

su -c 'dnf upgrade --advisory FEDORA-2022-066232000e' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
medium
Lowest
Low
Medium
High
Critical

Product: Fedora 34
Version: 3.2.1
Release: 1.fc34
Summary: A graphical client for Soulseek

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here