Security fix for CVE-2019-5010 in Python. Anaconda is joined because an unrelated fix was done there that allowed to remove a workaround in Python.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-00870e8bfc 2019-01-24 04:30:29.366094 --------------------------------------------------------------------------------Name : anaconda Product : Fedora 29 Version : 29.24.7 Release : 2.fc29 URL : https://fedoraproject.org/wiki/Anaconda Summary : Graphical system installer Description : The anaconda package is a metapackage for the Anaconda installer. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-5010 in Python. Anaconda is joined because an unrelated fix was done there that allowed to remove a workaround in Python. --------------------------------------------------------------------------------ChangeLog: * Wed Jan 16 2019 Martin Kolman - 29.24.7-2 - Backport compatibility fix for latest Python 3.7 (#1644936) (vponcova) --------------------------------------------------------------------------------References: [ 1 ] Bug #1666519 - CVE-2019-5010 python: NULL pointer dereference using a specially crafted X509 certificate https://bugzilla.redhat.com/show_bug.cgi?id=1666519 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-00870e8bfc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several security issues were fixed in MySQL.. =========================================================================Ubuntu Security Notice USN-2291-1 July 17, 2014 mysql-5.5 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: - mysql-5.5: MySQL database Details: Multiple security issues were discovered in MySQL and this update includes a new upstream MySQL version to fix these issues. MySQL has been updated to 5.5.38. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-38.html https://www.oracle.com/security-alerts/cpujul2014.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: mysql-server-5.5 5.5.38-0ubuntu0.14.04.1 Ubuntu 12.04 LTS: mysql-server-5.5 5.5.38-0ubuntu0.12.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2291-1 CVE-2014-2494, CVE-2014-4207, CVE-2014-4258, CVE-2014-4260 Package Information: https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.38-0ubuntu0.14.04.1 https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.38-0ubuntu0.12.04.1 . Critical vulnerabilities addressed in MySQL for Ubuntu LTS versions. Upgrade promptly to protect your database infrastructures today.. MySQL Security Update, Ubuntu Database Security, USN-2291-1. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.