Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

openSUSE 15 Backports: 2022:10018-1 Important: Atheme Authentication Issue

opensuse
Calendar Grey June 20, 2022
Dist Opensuse Esm H88
Upgrade your platform with this openSUSE security bulletin for atheme that tackles severe authentication vulnerabilities.
An update that solves one vulnerability and has one errata is now available

Description

This update for atheme fixes the following issues:

atheme was updated to release 7.2.12:

* CVE-2022-24976: Fixed General authentication bypass in Atheme IRC

services with InspIRCd 3 [boo#1195989]

* Track SASL login EID

Update to release 7.2.11

* Add a preliminary Turkish translation

* Add HMAC-MD5 verify-only support to crypto/pbkdf2v2

* modules/chanserv/akick: fix unload crash with akicks that have timeouts

* modules/nickserv/multimark: use IRC case canonicalisation for restored

nicks

* modules/nickserv/multimark: forbid unloading due to the potential for

data loss

* CA_ constants: include CA_EXEMPT (+e) where appropriate

Update to new upstream release 7.2.10.r2

* Fix potential NULL dereference in modules/crypto/posix.

* Bump E-Mail address maximum length to 254 characters.

* Use flags setter information in modules/chanserv/access &

modules/chanserv/flags.

* Fix issue where modules/misc/httpd was not closing...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP3:

zypper in -t patch openSUSE-2022-10018=1

Package List

- openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64):

atheme-7.2.12-bp153.2.3.1

atheme-devel-7.2.12-bp153.2.3.1

libathemecore1-7.2.12-bp153.2.3.1

References

https://www.suse.com/security/cve/CVE-2022-24976.html

https://bugzilla.suse.com/1174075

https://bugzilla.suse.com/1195989

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:10018-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here