Backported patch for CVE-2018-10756.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-3ef028d53f 2020-05-27 03:01:29.403223 --------------------------------------------------------------------------------Name : transmission Product : Fedora 31 Version : 2.94 Release : 9.fc31 URL : https://transmissionbt.com/ Summary : A lightweight GTK+ BitTorrent client Description : Transmission is a free, lightweight BitTorrent client. It features a simple, intuitive interface on top on an efficient, cross-platform back-end. --------------------------------------------------------------------------------Update Information: Backported patch for CVE-2018-10756. --------------------------------------------------------------------------------ChangeLog: * Mon May 18 2020 Gwyn Ciesla - 2.94-9 - Backported patch for CVE-2018-10756 * Fri Jan 31 2020 Fedora Release Engineering - 2.94-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1836918 - CVE-2018-10756 transmission: use-after-free in libtransmission/variant.c allows remote attackers to cause a DoS [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1836918 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-3ef028d53f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announcemailing list --
Backported patch for CVE-2018-10756.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-e67318b4b4 2020-05-20 03:18:46.261124 --------------------------------------------------------------------------------Name : transmission Product : Fedora 32 Version : 2.94 Release : 9.fc32 URL : https://transmissionbt.com/ Summary : A lightweight GTK+ BitTorrent client Description : Transmission is a free, lightweight BitTorrent client. It features a simple, intuitive interface on top on an efficient, cross-platform back-end. --------------------------------------------------------------------------------Update Information: Backported patch for CVE-2018-10756. --------------------------------------------------------------------------------ChangeLog: * Mon May 18 2020 Gwyn Ciesla - 2.94-9 - Backported patch for CVE-2018-10756 --------------------------------------------------------------------------------References: [ 1 ] Bug #1836918 - CVE-2018-10756 transmission: use-after-free in libtransmission/variant.c allows remote attackers to cause a DoS [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1836918 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-e67318b4b4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Moderate: evolution28-pango security update. Date: Thu, 22 Sep 2011 09:28:50 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Moderate: evolution28-pango on SL4.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: evolution28-pango security update Issue Date: 2011-09-21 CVE Numbers: CVE-2011-3193 Pango is a library used for the layout and rendering of internationalized text. A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping engine used in Pango. If a user loaded a specially-crafted font file with an application that uses Pango, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. (CVE-2011-3193) Users of evolution28-pango are advised to upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing this update, you must restart your system or restart the X server for the update to take effect. SL4: i386 evolution28-pango-1.14.9-13.el4_11.i386.rpm evolution28-pango-debuginfo-1.14.9-13.el4_11.i386.rpm evolution28-pango-devel-1.14.9-13.el4_11.i386.rpm x86_64 evolution28-pango-1.14.9-13.el4_11.x86_64.rpm evolution28-pango-debuginfo-1.14.9-13.el4_11.x86_64.rpm evolution28-pango-devel-1.14.9-13.el4_11.x86_64.rpm - Scientific Linux Development Team . Patch release for kernel-legacy fixes minor memory leak vulnerability on XR5.0 arm/arm64.. evolution28-pango, scientific linux, security advisory, patch management, buffer overflow. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.