Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE: 2019:1895-1 Moderate: Ledger Security Issues Update

opensuse
Calendar Grey August 14, 2019
Dist Opensuse Esm H88
This revision addresses three concerns in Ledger for openSUSE. Information regarding the amendment is provided.
An update that fixes four vulnerabilities is now available.

Description

This update for ledger fixes the following issues:

ledger was updated to 3.1.3:

+ Properly reject postings with a comment right after the flag (bug #1753)

+ Make sorting order of lot information deterministic (bug #1747)

+ Fix bug in tag value parsing (bug #1702)

+ Remove the org command, which was always a hack to begin with (bug #1706)

+ Provide Docker information in README

+ Various small documentation improvements

This also includes the update to 3.1.2:

+ Increase maximum length for regex from 255 to 4095 (bug #981)

+ Initialize periods from from/since clause rather than earliest

transaction date (bug #1159)

+ Check balance assertions against the amount after the posting (bug #1147)

+ Allow balance assertions with multiple posts to same account (bug #1187)

+ Fix period duration of "every X days" and similar statements (bug #370)

+ Make option --force-color not require --color anymore (bug #1109)

+ Add quoted_rfc4180 to...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP1:

zypper in -t patch openSUSE-2019-1895=1

Package List

- openSUSE Backports SLE-15-SP1 (ppc64le s390x x86_64):

ledger-3.1.3-bp151.4.3.1

References

https://www.suse.com/security/cve/CVE-2017-12481.html

https://www.suse.com/security/cve/CVE-2017-12482.html

https://www.suse.com/security/cve/CVE-2017-2807.html

https://www.suse.com/security/cve/CVE-2017-2808.html

https://bugzilla.suse.com/1052478

https://bugzilla.suse.com/1052484

https://bugzilla.suse.com/1105084

--

Announcement ID: openSUSE-SU-2019:1895-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here