-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-ac1aa963e4 2023-09-14 00:42:52.692906 -------------------------------------------------------------------------------- Name : salt Product : Fedora 37 Version : 3005.2 Release : 1.fc37 URL : https://saltproject.io/ Summary : A parallel remote execution system Description : Salt is a distributed remote execution system used to execute commands and query data. It was developed in order to bring the best solutions found in the world of remote execution together and make them better, faster and more malleable. Salt accomplishes this via its ability to handle larger loads of information, and not just dozens, but hundreds or even thousands of individual servers, handle them quickly and through a simple and manageable interface. -------------------------------------------------------------------------------- Update Information: Fixes for CVE-2023-20897 and CVE-2023-20898 -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 5 2023 Gwyn Ciesla- 3005.2-1 - 3005.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2237512 - CVE-2023-20898 salt: Git Providers can read from the wrong environment [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2237512 [ 2 ] Bug #2237514 - CVE-2023-20897 salt: DOS in minion return [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2237514 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ac1aa963e4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue