Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Warning: Undefined array key "Description" in /var/www/www.linuxsecurity.com-443/html/lsadvisories/lsadvisories.php on line 220

Fedora 37: FEDORA-2023-c0696d7b53 High: matrix-synapse DoS Fix

fedora
Calendar Grey September 18, 2023
Dist Fedora Esm H88
Upgrade matrix-synapse to 1.80.0 to resolve various security vulnerabilities for Fedora 37 systems.
Update matrix-synapse to v1.80.0 to fix CVE-2022-39374, CVE-2023-32323

Summary

Common utilities for Synapse, Sydent and Sygnal.

Update Information:

Update matrix-synapse to v1.80.0 to fix CVE-2022-39374, CVE-2023-32323

Change Log

* Sun Aug 20 2023 Kai A. Hiller - 1.3.0-7 - SPDX migration * Sun Aug 20 2023 Kai A. Hiller - 1.3.0-6 - Inline %{srcname} * Fri Jul 21 2023 Fedora Release Engineering - 1.3.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Wed Jun 28 2023 Python Maint - 1.3.0-3 - Rebuilt for Python 3.12 * Fri Jan 20 2023 Fedora Release Engineering - 1.3.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Mon Oct 10 2022 Kai A. Hiller - 1.3.0-1 - Update to v1.3.0

References


[ 1 ] Bug #2209956 - CVE-2022-39374 matrix-synapse: Synapse Denial of service due to incorrect application of event authorization rules during state resolution https://bugzilla.redhat.com/show_bug.cgi?id=2209956 [ 2 ] Bug #2209958 - CVE-2023-32323 matrix-synapse: Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites https://bugzilla.redhat.com/show_bug.cgi?id=2209958

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-c0696d7b53' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Name: python-matrix-common
Product: Fedora 37
Version: 1.3.0
Release: 7.fc37
Summary: Common utilities for Synapse, Sydent and Sygnal

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here