Advisory: Fedora Essential and Critical Security Patch Updates
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
This is a new upstream feature and security release. Improvements include: bypass; pre-filter -- fast packet keywords; TLS improvements; ICS protocol additions: DNP3 CIP/ENIP; SHA1/SHA256 for file matching, logging & extraction; NIC offloading disabled by default; unix socket enabled by default; and App Layer stats. Documentation: https://docs.suricata.io/en/suricata-3.2/
Fixed CVE 2017-2590: freeipa: ipa: Insufficient permission check for ca-del, ca- disable and ca-enable commands [fedora-all]
* [7.x-1.21](https://www.drupal.org/project/metatag/releases/7.x-1.21) * [Moderately Critical - Information disclosure - SA-CONTRIB-2017-019](https://www.drupal.org/node/2852937)
cirrus_bitblt_cputovideo does not check if memory region is safe [XSA-209, CVE-2017-2620] (#1425420)
* [7.x-1.21](https://www.drupal.org/project/metatag/releases/7.x-1.21) * [Moderately Critical - Information disclosure - SA-CONTRIB-2017-019](https://www.drupal.org/node/2852937)
This is a new upstream feature and security release. Improvements include: bypass; pre-filter -- fast packet keywords; TLS improvements; ICS protocol additions: DNP3 CIP/ENIP; SHA1/SHA256 for file matching, logging & extraction; NIC offloading disabled by default; unix socket enabled by default; and App Layer stats. Documentation: https://docs.suricata.io/en/suricata-3.2/
Security fix for CVE-2017-6060 CVE-2017-5896 ---- Add comment with explanation of disabled debuginfo
Security fix in CA certificate chain verification (better check untrusted CA certificates from peer, more strict error handling).
Security fix for CVE-2017-3135 (unaffected), fixes regression made by CVE-2016-8864
Security fix for CVE-2017-3135 (unaffected), fixes regression made by CVE-2016-8864