Rebuild dependent packages for vm-memory v0.12.2 to address CVE-2023-41051 / RUSTSEC-2023-0056. - - bin/cvename.cgi?name=CVE-2023-41051 - https://rustsec.org/advisories/RUSTSEC-2023-0056.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-c19aaa2283 2023-09-28 01:34:46.976714 -------------------------------------------------------------------------------- Name : virtiofsd Product : Fedora 38 Version : 1.7.0 Release : 4.fc38 URL : https://gitlab.com/virtio-fs/virtiofsd Summary : Virtio-fs vhost-user device daemon (Rust version) Description : Virtio-fs vhost-user device daemon (Rust version). -------------------------------------------------------------------------------- Update Information: Rebuild dependent packages for vm-memory v0.12.2 to address CVE-2023-41051 / RUSTSEC-2023-0056. - - bin/cvename.cgi?name=CVE-2023-41051 - https://rustsec.org/advisories/RUSTSEC-2023-0056.html -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 19 2023 Fabio Valentini - 1.7.0-4 - Rebuild for vm-memory v0.12.2 / CVE-2023-41051. * Sat Jul 22 2023 Fedora Release Engineering - 1.7.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2236894 - CVE-2023-41051 rust-vm-memory: vm-memory: out-of-bounds access in memory functions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2236894 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-c19aaa2283' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Rebuild for CVE-2022-27191. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3a63897745 2022-04-28 05:50:06.248389 --------------------------------------------------------------------------------Name : containerd Product : Fedora 35 Version : 1.6.2 Release : 2.fc35 URL : https://github.com/containerd/containerd Summary : Open and reliable container runtime Description : Containerd is an industry-standard container runtime with an emphasis on simplicity, robustness and portability. It is available as a daemon for Linux and Windows, which can manage the complete container lifecycle of its host system: image transfer and storage, container execution and supervision, low-level storage and network attachments, etc. --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-27191 --------------------------------------------------------------------------------ChangeLog: * Sat Apr 16 2022 Fabio Alessandro Locati 1.6.2-2 - Rebuilt for CVE-2022-27191 --------------------------------------------------------------------------------References: [ 1 ] Bug #2074262 - CVE-2022-27191 golang-x-crypto: golang: crash in a golang.org/x/crypto/ssh server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2074262 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3a63897745' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to 0.12.13. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-6cb474b8ff 2018-01-23 21:42:17.541788 --------------------------------------------------------------------------------Name : python-bottle Product : Fedora 27 Version : 0.12.13 Release : 1.fc27 URL : https://bottlepy.org/docs/dev/ Summary : Fast and simple WSGI-framework for small web-applications Description : Bottle is a fast and simple micro-framework for small web-applications. It offers request dispatching (Routes) with URL parameter support, Templates, a built-in HTTP Server and adapters for many third party WSGI/HTTP-server and template engines. All in a single file and with no dependencies other than the Python Standard Library. --------------------------------------------------------------------------------Update Information: Update to 0.12.13 --------------------------------------------------------------------------------References: [ 1 ] Bug #1405417 - CVE-2016-9964 python-bottle: redirect() doesn't filter "\r\n" which allows for CRLF attack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1405417 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade python-bottle' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.