Fix CVE-2017-15088 (Buffer overflow in get_matching_data()) ---- Remove build dependency on python-pyrad. It is only used on the test suite, and we gracefully skip the tests if it is not present.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-2dd6c320a4 2017-11-11 13:29:22.451238 --------------------------------------------------------------------------------Name : krb5 Product : Fedora 27 Version : 1.15.2 Release : 4.fc27 URL : http://web.mit.edu/kerberos/www/ Summary : The Kerberos network authentication system Description : Kerberos V5 is a trusted-third-party network authentication system, which can improve your network's security by eliminating the insecure practice of sending passwords over the network in unencrypted form. --------------------------------------------------------------------------------Update Information: Fix CVE-2017-15088 (Buffer overflow in get_matching_data()) ---- Remove build dependency on python-pyrad. It is only used on the test suite, and we gracefully skip the tests if it is not present. --------------------------------------------------------------------------------References: [ 1 ] Bug #1506622 - CVE-2017-15088 krb5: Buffer overflow in get_matching_data() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1506622 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade krb5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
The update adds a patch for the security issue in bug 1241907.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-11691 2015-07-17 23:26:02 -------------------------------------------------------------------------------- Name : wpa_supplicant Product : Fedora 21 Version : 2.0 Release : 14.fc21 URL : http://w1.fi/wpa_supplicant/ Summary : WPA/WPA2/IEEE 802.1X Supplicant Description : wpa_supplicant is a WPA Supplicant for Linux, BSD and Windows with support for WPA and WPA2 (IEEE 802.11i / RSN). Supplicant is the IEEE 802.1X/WPA component that is used in the client stations. It implements key negotiation with a WPA Authenticator and it controls the roaming and IEEE 802.11 authentication/association of the wlan driver. -------------------------------------------------------------------------------- Update Information: The update adds a patch for the security issue in bug 1241907. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 15 2015 Jiřà Klimeš - 1:2.0-14 - Fix for NDEF record payload length checking (rh #1241907) * Thu Apr 23 2015 Adam Williamson - 1:2.0-13 - backport fix for CVE-2015-1863 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1241907 - hostapd and wpa_supplicant: Incomplete WPS and P2P NFC NDEF record payload length validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1241907 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update wpa_supplicant' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network: . Enterprise Linux Security Advisory ELSA-2008-1001 https://access.redhat.com/errata/RHSA-2008:1001.html The following updated rpms for Enterprise Linux 5 have been uploaded to the Unbreakable Linux Network: i386: tog-pegasus-2.7.0-2.0.1.el5_2.1.i386.rpm tog-pegasus-devel-2.7.0-2.0.1.el5_2.1.i386.rpm x86_64: tog-pegasus-2.7.0-2.0.1.el5_2.1.i386.rpm tog-pegasus-2.7.0-2.0.1.el5_2.1.x86_64.rpm tog-pegasus-devel-2.7.0-2.0.1.el5_2.1.i386.rpm tog-pegasus-devel-2.7.0-2.0.1.el5_2.1.x86_64.rpm SRPMS: https://oss.oracle.com:443/el5/SRPMS-updates/tog-pegasus-2.7.0-2.0.1.el5_2.1.src.rpm Description of changes: [2.7.0-2.0.1.el5_2.1] - Added pegasus-enterprise.patch to allow detection of enterprise-release [2.7.0-2.el5_2.1] - Fix local-or-remote-auth patch and enhance PAM security settings Resolves: #471370 . The Enterprise Linux Security Announcement ELSA-2008-1002 provides critical enhancements for app-guardian, bolstering protection protocols.. Enterprise Linux Update, Tog Pegasus Security, Linux Patch Management, ELSA-2008-1001. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.