* bsc#1231795 * bsc#1234290 Cross-References: * CVE-2024-12254 . # Security update for python312 Announcement ID: SUSE-SU-2024:4291-1 Release Date: 2024-12-11T11:24:51Z Rating: important References: * bsc#1231795 * bsc#1234290 Cross-References: * CVE-2024-12254 CVSS scores: * CVE-2024-12254 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-12254 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-12254 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for python312 fixes the following issues: * CVE-2024-12254: Fixed unbounded memory buffering in SelectorSocketTransport.writelines() (bsc#1234290) Other fixes: \- Updated to version 3.12.8 \- Remove -IVendor/ from python-config (bsc#1231795) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-4291=1 openSUSE-SLE-15.6-2024-4291=1 * Python 3 Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Python3-15-SP6-2024-4291=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * python312-doc-devhelp-3.12.8-150600.3.12.1 * python312-tools-3.12.8-150600.3.12.1 * libpython3_12-1_0-debuginfo-3.12.8-150600.3.12.1 *python312-dbm-debuginfo-3.12.8-150600.3.12.1 * python312-tk-3.12.8-150600.3.12.1 * python312-idle-3.12.8-150600.3.12.1 * python312-base-3.12.8-150600.3.12.1 * python312-curses-3.12.8-150600.3.12.1 * python312-testsuite-debuginfo-3.12.8-150600.3.12.1 * python312-debugsource-3.12.8-150600.3.12.1 * libpython3_12-1_0-3.12.8-150600.3.12.1 * python312-tk-debuginfo-3.12.8-150600.3.12.1 * python312-testsuite-3.12.8-150600.3.12.1 * python312-3.12.8-150600.3.12.1 * python312-curses-debuginfo-3.12.8-150600.3.12.1 * python312-doc-3.12.8-150600.3.12.1 * python312-base-debuginfo-3.12.8-150600.3.12.1 * python312-dbm-3.12.8-150600.3.12.1 * python312-debuginfo-3.12.8-150600.3.12.1 * python312-devel-3.12.8-150600.3.12.1 * python312-core-debugsource-3.12.8-150600.3.12.1 * openSUSE Leap 15.6 (x86_64) * python312-32bit-3.12.8-150600.3.12.1 * libpython3_12-1_0-32bit-debuginfo-3.12.8-150600.3.12.1 * libpython3_12-1_0-32bit-3.12.8-150600.3.12.1 * python312-base-32bit-debuginfo-3.12.8-150600.3.12.1 * python312-32bit-debuginfo-3.12.8-150600.3.12.1 * python312-base-32bit-3.12.8-150600.3.12.1 * openSUSE Leap 15.6 (aarch64_ilp32) * python312-64bit-debuginfo-3.12.8-150600.3.12.1 * libpython3_12-1_0-64bit-debuginfo-3.12.8-150600.3.12.1 * python312-64bit-3.12.8-150600.3.12.1 * python312-base-64bit-3.12.8-150600.3.12.1 * python312-base-64bit-debuginfo-3.12.8-150600.3.12.1 * libpython3_12-1_0-64bit-3.12.8-150600.3.12.1 * Python 3 Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python312-dbm-debuginfo-3.12.8-150600.3.12.1 * python312-tk-debuginfo-3.12.8-150600.3.12.1 * python312-3.12.8-150600.3.12.1 * python312-curses-debuginfo-3.12.8-150600.3.12.1 * python312-debugsource-3.12.8-150600.3.12.1 * python312-tools-3.12.8-150600.3.12.1 * python312-tk-3.12.8-150600.3.12.1 * python312-devel-3.12.8-150600.3.12.1 * python312-curses-3.12.8-150600.3.12.1 *python312-base-debuginfo-3.12.8-150600.3.12.1 * libpython3_12-1_0-3.12.8-150600.3.12.1 * python312-idle-3.12.8-150600.3.12.1 * python312-dbm-3.12.8-150600.3.12.1 * python312-debuginfo-3.12.8-150600.3.12.1 * python312-core-debugsource-3.12.8-150600.3.12.1 * python312-base-3.12.8-150600.3.12.1 * libpython3_12-1_0-debuginfo-3.12.8-150600.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12254.html * https://bugzilla.suse.com/show_bug.cgi?id=1231795 * https://bugzilla.suse.com/show_bug.cgi?id=1234290 . The recent security notice for python312 underscores significant vulnerabilities and enhancements for SUSE offerings, taking effect on December 11, 2024.. python312 security update,SUSE advisory,buffering issue fix,SUSE Linux application. . Severity: Critical. LinuxSecurity.com Team
* Fix scrolling issues in some sites having fixed background. * Fix prolonged buffering during progressive live playback. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-42799, CVE-2022-42823, CVE-2022-42824. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-08fdc4138a 2022-11-09 00:09:40.867638 --------------------------------------------------------------------------------Name : webkitgtk Product : Fedora 37 Version : 2.38.2 Release : 1.fc37 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. --------------------------------------------------------------------------------Update Information: * Fix scrolling issues in some sites having fixed background. * Fix prolonged buffering during progressive live playback. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-42799, CVE-2022-42823, CVE-2022-42824 --------------------------------------------------------------------------------ChangeLog: * Fri Nov 4 2022 Michael Catanzaro 2.38.2-1 - Update to 2.38.2 --------------------------------------------------------------------------------References: [ 1 ] Bug #2140194 - Freeze exception for WebKitGTK 2.38.2 https://bugzilla.redhat.com/show_bug.cgi?id=2140194 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-08fdc4138a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
# New in release OpenJDK 8u282 (2021-01-19) Live versions of these release notes can be found at: * https://mail.openjdk.org/pipermail/jdk8u-dev/2021-January/013337.html * https://builds.shipilev.net/backports-monitor/release-notes-openjdk8u282.txt ## Security fixes * JDK-8247619: Improve Direct Buffering of Characters ## Other changes * [JDK-8230839](https://bugs.openjdk.org/browse/JDK-8230839):. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-09272cf059 2021-02-11 01:42:27.185532 --------------------------------------------------------------------------------Name : java-1.8.0-openjdk Product : Fedora 33 Version : 1.8.0.282.b08 Release : 0.fc33 URL : https://openjdk.org/ Summary : OpenJDK 8 Runtime Environment Description : The OpenJDK 8 runtime environment. --------------------------------------------------------------------------------Update Information: # New in release OpenJDK 8u282 (2021-01-19) Live versions of these release notes can be found at: * https://mail.openjdk.org/pipermail/jdk8u-dev/2021-January/013337.html * https://builds.shipilev.net/backports-monitor/release-notes-openjdk8u282.txt ## Security fixes * JDK-8247619: Improve Direct Buffering of Characters ## Other changes * [JDK-8230839](https://bugs.openjdk.org/browse/JDK-8230839): Updated XML Signature Implementation to Apache Santuario 2.1.3, adding support for embedding elliptic curve public keys in the KeyValue element * Default to RSA when using keytool, as DSA is only supported by the LEGACY crypto policy. * Make java-1.8.0-openjdk-demo own its directories as well as its files --------------------------------------------------------------------------------ChangeLog: * Sat Jan 30 2021 Andrew Hughes - 1:1.8.0.282.b08-0 - Update to aarch64-shenandoah-jdk8u282-b08 (GA) - Update release notes for 8u282. - Remove PR3601, covered upstream by JDK-8062808. - Remove upstreamed JDK-8197981/PR3548,JDK-8062808/PR3548 & JDK-8254177. - Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 - Adapt JDK-8143245 patch, following JDK-8254166 - Remove upstreamed patch PR3519 - Use RSA as default for keytool, as DSA is disabled in all crypto policies except LEGACY - Add directories to files directive for demo package. - Include a test in the RPM to check the build has the correct vendor information. - Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value. - Cleanup package descriptions and version number placement. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-09272cf059' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection". (CVE-2020-15953). . MGASA-2020-0366 - Updated libetpan packages fix a security vulnerability Publication date: 15 Sep 2020 URL: https://advisories.mageia.org/MGASA-2020-0366.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-15953 LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection". (CVE-2020-15953). References: - https://bugs.mageia.org/show_bug.cgi?id=27168 - https://lists.debian.org/debian-lts-announce/2020/08/msg00026.html - https://lists.fedoraproject.org/archives/list/
Two vulnerabilities have been discovered in mutt, a console email client. CVE-2020-14093 . Package : mutt Version : 1.5.23-3+deb8u3 CVE ID : CVE-2020-14093 CVE-2020-14954 Debian Bug : Two vulnerabilities have been discovered in mutt, a console email client. CVE-2020-14093 Mutt allowed an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response. CVE-2020-14954 Mutt had a STARTTLS buffering issue that affected IMAP, SMTP, and POP3. When a server had sent a "begin TLS" response, the client read additional data (e.g., from a man-in-the-middle attacker) and evaluated it in a TLS context, aka "response injection." In Debian jessie, the mutt source package builds two variants of mutt: mutt and mutt-patched. The previous package version (1.5.23-3+deb8u2, DLA-2268-1) provided fixes for the issues referenced above, but they were only applied for the mutt-patched package build, not for the (vanilla) mutt package build. For Debian 8 "Jessie", this problem has been fixed in version 1.5.23-3+deb8u3. We recommend that you upgrade your mutt packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail:
Two vulnerabilities have been discovered in mutt, a console email client. CVE-2020-14093 . Package : mutt Version : 1.5.23-3+deb8u2 CVE ID : CVE-2020-14093 CVE-2020-14954 Debian Bug : 962897 Two vulnerabilities have been discovered in mutt, a console email client. CVE-2020-14093 Mutt allowed an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response. CVE-2020-14954 Mutt had a STARTTLS buffering issue that affected IMAP, SMTP, and POP3. When a server had sent a "begin TLS" response, the client read additional data (e.g., from a man-in-the-middle attacker) and evaluated it in a TLS context, aka "response injection." For Debian 8 "Jessie", these problems have been fixed in version 1.5.23-3+deb8u2. We recommend that you upgrade your mutt packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail:
Get the latest Linux and open source security news straight to your inbox.