Two vunerabilities were discovered in c-ares, an asynchronous name resolver library: CVE-2023-31130 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3471-1
An issue has been found in c-ares, an asynchronous name resolver. Missing input validation of host names returned by Domain Name Servers can lead to output of wrong hostnames. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2738-1
libasr-1.0.4, opensmtpd-6.6.2p1 update. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-a861033a4d 2020-02-09 01:31:24.825632 --------------------------------------------------------------------------------Name : libasr Product : Fedora 31 Version : 1.0.4 Release : 1.fc31 URL : https://github.com/OpenSMTPD/libasr Summary : Free, simple and portable asynchronous resolver library Description : Libasr allows to run DNS queries and perform hostname resolutions in a fully asynchronous fashion. The implementation is thread-less, fork-less, and does not make use of signals or other "tricks" that might get in the developer's way. The API was initially developed for the OpenBSD operating system, where it is natively supported. This library is intended to bring this interface to other systems. It is originally provided as a support library for the portable version of the OpenSMTPD daemon, but it can be used in any other contexts. --------------------------------------------------------------------------------Update Information: libasr-1.0.4, opensmtpd-6.6.2p1 update --------------------------------------------------------------------------------ChangeLog: * Thu Jan 30 2020 Denis Fateyev - 1.0.4-1 - Update to 1.0.4 release * Wed Jan 29 2020 Fedora Release Engineering - 1.0.2-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Wed Aug 28 2019 Denis Fateyev - 1.0.2-11 - Spec cleanup from deprecated items --------------------------------------------------------------------------------References: [ 1 ] Bug #1765905 - libasr-1.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1765905 [ 2 ] Bug #1778424 - OpenSMTPD Does not deliver offline messages https://bugzilla.redhat.com/show_bug.cgi?id=1778424 [ 3 ] Bug #1742449 - opensmtpd-6.6.2p1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1742449 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-a861033a4d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.