Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --- See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-37aef44d1e 2022-07-30 01:52:05.591856 --------------------------------------------------------------------------------Name : golang-github-posener-complete Product : Fedora 36 Version : 1.2.3 Release : 9.fc36 URL : https://github.com/posener/complete Summary : Bash completion written in go + bash completion for Go command Description : Package Complete provides a tool for bash writing bash completion in go, and bash completion for the go command line. Writing bash completion scripts is a hard work. This package provides an easy way to create bash completion scripts for any command, and also an easy way to install/uninstall the completion of the command. --------------------------------------------------------------------------------Update Information: Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028) --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Maxwell G - 1.2.3-9 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-37aef44d1e' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
util-linux could be made to run programs when performing bash completion.. =========================================================================Ubuntu Security Notice USN-4512-1 September 17, 2020 util-linux vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: util-linux could be made to run programs when performing bash completion. Software Description: - util-linux: miscellaneous system utilities Details: It was discovered that the umount bash completion script shipped in util-linux incorrectly handled certain mountpoints. If a local attacker were able to create arbitrary mountpoints, another user could be tricked into executing arbitrary code when attempting to run the umount command with bash completion. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: util-linux 2.31.1-0.4ubuntu3.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4512-1 CVE-2018-7738 Package Information: https://launchpad.net/ubuntu/+source/util-linux/2.31.1-0.4ubuntu3.7 . Ubuntu 2020 Security Advisory USN-4512-1 concerns a util-linux vulnerability that permits the execution of arbitrary code through bash completion.. Util-Linux Update, Ubuntu Security Patch, System Utilities Vulnerability. . Severity: Critical. LinuxSecurity.com Team
Bjorn Bosselmann discovered that the umount bash completion from util-linux does not properly handle embedded shell commands in a mountpoint name. An attacker with rights to mount filesystems can take advantage of this flaw for privilege escalation if a user (in particular . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4134-1
Get the latest Linux and open source security news straight to your inbox.