Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE: 2019:1779-1 Moderate Ledger Security Update Advisory

opensuse
Calendar Grey July 21, 2019
Dist Opensuse Esm H88
Vital openSUSE patch for ledger addresses numerous vulnerabilities with comprehensive guidelines for deployment.
An update that fixes four vulnerabilities is now available.

Description

This update for ledger fixes the following issues:

ledger was updated to 3.1.3:

+ Properly reject postings with a comment right after the flag (bug #1753)

+ Make sorting order of lot information deterministic (bug #1747)

+ Fix bug in tag value parsing (bug #1702)

+ Remove the org command, which was always a hack to begin with (bug #1706)

+ Provide Docker information in README

+ Various small documentation improvements

This also includes the update to 3.1.2:

+ Increase maximum length for regex from 255 to 4095 (bug #981)

+ Initialize periods from from/since clause rather than earliest

transaction date (bug #1159)

+ Check balance assertions against the amount after the posting (bug #1147)

+ Allow balance assertions with multiple posts to same account (bug #1187)

+ Fix period duration of "every X days" and similar statements (bug #370)

+ Make option --force-color not require --color anymore (bug #1109)

+ Add quoted_rfc4180 to...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2019-1779=1

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-1779=1

Package List

- openSUSE Leap 15.1 (x86_64):

ledger-3.1.3-lp151.3.3.1

ledger-debuginfo-3.1.3-lp151.3.3.1

ledger-debugsource-3.1.3-lp151.3.3.1

- openSUSE Leap 15.0 (x86_64):

ledger-3.1.3-lp150.2.3.1

ledger-debuginfo-3.1.3-lp150.2.3.1

ledger-debugsource-3.1.3-lp150.2.3.1

References

https://www.suse.com/security/cve/CVE-2017-12481.html

https://www.suse.com/security/cve/CVE-2017-12482.html

https://www.suse.com/security/cve/CVE-2017-2807.html

https://www.suse.com/security/cve/CVE-2017-2808.html

https://bugzilla.suse.com/1052478

https://bugzilla.suse.com/1052484

https://bugzilla.suse.com/1105084

--

Announcement ID: openSUSE-SU-2019:1779-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here