Upgrade to 4.3.5 upstream version.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-54d78b9fed 2025-12-12 01:45:35.303645+00:00 -------------------------------------------------------------------------------- Name : singularity-ce Product : Fedora 42 Version : 4.3.5 Release : 1.fc42 URL : Summary : Application and environment virtualization Description : SingularityCE is the Community Edition of Singularity, an open source container platform designed to be simple, fast, and secure. -------------------------------------------------------------------------------- Update Information: Upgrade to 4.3.5 upstream version. -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 3 2025 David Trudgian - 4.3.5-1 - Upgrade to 4.3.5 upstream version. - Fixes CVE-2025-64750 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-54d78b9fed' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-5061 https://linux.oracle.com/errata/ELSA-2022-5061.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-3.1-3.1.26-1.0.1.el8_6.x86_64.rpm aspnetcore-targeting-pack-3.1-3.1.26-1.0.1.el8_6.x86_64.rpm dotnet-apphost-pack-3.1-3.1.26-1.0.1.el8_6.x86_64.rpm dotnet-hostfxr-3.1-3.1.26-1.0.1.el8_6.x86_64.rpm dotnet-runtime-3.1-3.1.26-1.0.1.el8_6.x86_64.rpm dotnet-sdk-3.1-3.1.420-1.0.1.el8_6.x86_64.rpm dotnet-targeting-pack-3.1-3.1.26-1.0.1.el8_6.x86_64.rpm dotnet-templates-3.1-3.1.420-1.0.1.el8_6.x86_64.rpm dotnet-sdk-3.1-source-built-artifacts-3.1.420-1.0.1.el8_6.x86_64.rpm aarch64: SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/dotnet3.1-3.1.420-1.0.1.el8_6.src.rpm Related CVEs: CVE-2022-30184 Description of changes: [3.1.420-1.0.1] - Add missing Oracle Linux Runtime IDs - Update to .NET SDK 3.1.417 and Runtime 3.1.23 - Resolves: RHBZ#2060566 [3.1.420-1] - Update to .NET SDK 3.1.420 and Runtime 3.1.26 - Resolves: RHBZ#2096319 [3.1.419-1] - Update to .NET SDK 3.1.419 and Runtime 3.1.25 - Resolves: RHBZ#2081443 _______________________________________________ El-errata mailing list
This update upgrades Thunderbird to version 91.2.0. * Mozilla: Use-after-free in MessageTask (CVE-2021-38496) * Mozilla: Memory safety bugs fixed in Firefox 93, Firefox ESR 78.15, and Firefox ESR 91.2 (CVE-2021-38500) * Mozilla: Memory safety bugs fixed in Firefox 93 and Firefox ESR 91.2 (CVE-2021-38501) * Mozilla: Downgrade attack on SMTP STARTTLS connections (CVE-2021-38502) * rust-crossb [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2021:3841-1 Issue Date: 2021-10-18 CVE Numbers: CVE-2021-32810 CVE-2021-38496 CVE-2021-38497 CVE-2021-38498 CVE-2021-38500 CVE-2021-38501 CVE-2021-38502 -- This update upgrades Thunderbird to version 91.2.0. Security Fix(es): * Mozilla: Use-after-free in MessageTask (CVE-2021-38496) * Mozilla: Memory safety bugs fixed in Firefox 93, Firefox ESR 78.15, and Firefox ESR 91.2 (CVE-2021-38500) * Mozilla: Memory safety bugs fixed in Firefox 93 and Firefox ESR 91.2 (CVE-2021-38501) * Mozilla: Downgrade attack on SMTP STARTTLS connections (CVE-2021-38502) * rust-crossbeam-deque: race condition may lead to double free (CVE-2021-32810) * Mozilla: Validation message could have been overlaid on another origin (CVE-2021-38497) * Mozilla: Use-after-free of nsLanguageAtomService object (CVE-2021-38498) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE --- SL7 x86_64 thunderbird-91.2.0-1.el7_9.x86_64.rpm thunderbird-debuginfo-91.2.0-1.el7_9.x86_64.rpm -- - Scientific Linux Development Team . Significant security patch for Thunderbird launched to address several severe vulnerabilities and improve user protection.. Mozilla Thunderbird Update, Thunderbird Security Issues, SL7 Updates. . Severity: Critical. LinuxSecurity.com Team
Upgrade to upstream security release 3.7.3. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-601ee898f7 2021-04-16 14:33:16.807391 --------------------------------------------------------------------------------Name : singularity Product : Fedora 33 Version : 3.7.3 Release : 1.fc33 URL : Summary : Application and environment virtualization Description : Singularity provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: Upgrade to upstream security release 3.7.3 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 7 2021 Dave Dykstra - 3.7.3-1 - Upgrade to upstream security release 3.7.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1946970 - singularity-3.7.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1946970 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-601ee898f7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
New mozilla-thunderbird packages are available for Slackware 13.37, 14.0, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] mozilla-thunderbird (SSA:2012-304-01) New mozilla-thunderbird packages are available for Slackware 13.37, 14.0, and -current to fix security issues. Here are the details from the Slackware 14.0 ChangeLog: +--------------------------+ patches/packages/mozilla-thunderbird-16.0.2-i486-1_slack14.0.txz: Upgraded. This release contains security fixes and improvements. For more information, see: https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/ (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.37: Updated package for Slackware x86_64 13.37: Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.37 package: 499becfd3981e540bd91cad3d7b749ba mozilla-thunderbird-16.0.2-i486-1_slack13.37.txz Slackware x86_64 13.37 package: be575adecff3c132da9e5376485aa96c mozilla-thunderbird-16.0.2-x86_64-1_slack13.37.txz Slackware 14.0 package: 3d1a7dee1f79f5aacf4588f95128d257 mozilla-thunderbird-16.0.2-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 84a3e3b99269103c8c49ad27d1f562dd mozilla-thunderbird-16.0.2-x86_64-1_slack14.0.txz Slackware -current package: 204aeca58599008b68a8aab2cd55b00a xap/mozilla-thunderbird-16.0.2-i486-1.txz Slackware x86_64 -current package: fb94573a76fb74f00f774c954d2dfc89 xap/mozilla-thunderbird-16.0.2-x86_64-1.txz Installation instructions: +------------------------+ Upgradethe package as root: # upgradepkg mozilla-thunderbird-16.0.2-i486-1_slack14.0.txz +-----+ . Updated mozilla-thunderbird versions for Slackware released to tackle essential vulnerabilities and improve overall security framework.. Mozilla-Thunderbird Update, Slackware Packages, Security Fixes. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.