Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-710d9bad0b 2025-03-15 00:23:42.169970+00:00 -------------------------------------------------------------------------------- Name : man2html Product : Fedora 42 Version : 1.6 Release : 39.g.fc42 URL : Summary : Convert man pages to HTML - CGI scripts Description : man2html is a man page to HTML converter. This package contains CGI scripts that allow you to view, browse, and search man pages using a web server. -------------------------------------------------------------------------------- Update Information: Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 26 2025 Sérgio Basto - 1.6-39.g - Add more patches from Debian 004-spelling.patch 011-man2html-doctype-status.patch 012-man2html-TH.patch 013-man2html-file-link.patch 030-man2html-man-hyphens.patch 032-man2html-man-remove-LO-tags.patch 034-UTF8-charset.patch 036-fix-tbl-font-parsing.patch 037-man2html-Nm-and-Bk-mdoc.patch 038-man2html-colon-escape-sequence.patch 042-man2html-CVE-2021-40647.patch 043-man2html-fix-asan-issues.patch man2html-ungzip.patch rename to 024-man2html-uncompress.patch * Tue Feb 25 2025 Sérgio Basto - 1.6-38.g - Add -std=gnu17 to CFLAGS to fix the build * Fri Jan 17 2025 Fedora Release Engineering - 1.6-37.g - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2126813 - CVE-2021-40647 man2html: sys-apps/man2html: multiple vulnerabilities[epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126813 [ 2 ] Bug #2126814 - CVE-2021-40647 man2html: sys-apps/man2html: multiple vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126814 [ 3 ] Bug #2340816 - man2html: FTBFS in Fedora rawhide/f42 https://bugzilla.redhat.com/show_bug.cgi?id=2340816 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-710d9bad0b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . Revisions made in Fedora 42 for man2html, tackling compilation challenges and implementing updates to enhance both security and usability.. man page converter, Fedora Project updates, software patching. . Severity: Critical. LinuxSecurity.com Team
Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-538f2e492d 2025-03-07 02:22:25.692724+00:00 -------------------------------------------------------------------------------- Name : man2html Product : Fedora 41 Version : 1.6 Release : 39.g.fc41 URL : Summary : Convert man pages to HTML - CGI scripts Description : man2html is a man page to HTML converter. This package contains CGI scripts that allow you to view, browse, and search man pages using a web server. -------------------------------------------------------------------------------- Update Information: Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 26 2025 Sérgio Basto - 1.6-39.g - Add more patches from Debian 004-spelling.patch 011-man2html-doctype-status.patch 012-man2html-TH.patch 013-man2html-file-link.patch 030-man2html-man-hyphens.patch 032-man2html-man-remove-LO-tags.patch 034-UTF8-charset.patch 036-fix-tbl-font-parsing.patch 037-man2html-Nm-and-Bk-mdoc.patch 038-man2html-colon-escape-sequence.patch 042-man2html-CVE-2021-40647.patch 043-man2html-fix-asan-issues.patch man2html-ungzip.patch rename to 024-man2html-uncompress.patch * Tue Feb 25 2025 Sérgio Basto - 1.6-38.g - Add -std=gnu17 to CFLAGS to fix the build * Fri Jan 17 2025 Fedora Release Engineering - 1.6-37.g - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2126814 - CVE-2021-40647 man2html: sys-apps/man2html: multiple vulnerabilities[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126814 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-538f2e492d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . The latest man2html update for Fedora 41 introduces several patches and enhancements aimed at resolving security vulnerabilities. Discover all the details today.. Fedora updates, man2html security, patch management, build fixes for Linux, software updates. . LinuxSecurity.com Team
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ce2936b568 2024-05-26 01:25:15.719720 -------------------------------------------------------------------------------- Name : rust-sequoia-chameleon-gnupg Product : Fedora 40 Version : 0.9.0 Release : 2.fc40 URL : Summary : Sequoia's reimplementation of the GnuPG interface Description : Sequoia's reimplementation of the GnuPG interface. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 0.9.0-2 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ce2936b568' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ce2936b568 2024-05-26 01:25:15.719720 -------------------------------------------------------------------------------- Name : rust-bitvec_helpers Product : Fedora 40 Version : 3.1.4 Release : 1.fc40 URL : Summary : BitVec based bitstream reader and writer Description : BitVec based bitstream reader and writer. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 25 2024 Dominik 'Rathann' Mierzejewski - 3.1.4-1 - update to 3.1.4 (resolves rhbz#2271214) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2024-ce2936b568' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
fix gcc14 build error and another epub crash use https://github.com/mate-desktop/atril/commit/479e927 use https://github.com/mate-desktop/atril/commit/d901a9d update to 1.26.2 fix security security advisory. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-59a7d96d84 2024-02-09 01:50:00.832060 -------------------------------------------------------------------------------- Name : atril Product : Fedora 38 Version : 1.26.2 Release : 2.fc38 URL : https://mate-desktop.org/ Summary : Document viewer Description : Mate-document-viewer is simple document viewer. It can display and print Portable Document Format (PDF), PostScript (PS), Encapsulated PostScript (EPS), DVI, DJVU, epub and XPS files. When supported by the document format, mate-document-viewer allows searching for text, copying text to the clipboard, hypertext navigation, table-of-contents bookmarks and editing of forms. -------------------------------------------------------------------------------- Update Information: fix gcc14 build error and another epub crash use https://github.com/mate-desktop/atril/commit/479e927 use https://github.com/mate-desktop/atril/commit/d901a9d update to 1.26.2 fix security security advisory -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 31 2024 Wolfgang Ulbrich - 1.26.2-2 - fix gcc14 build error and another epub crash - use https://github.com/mate-desktop/atril/commit/479e927 - use https://github.com/mate-desktop/atril/commit/d901a9d * Wed Jan 24 2024 Wolfgang Ulbrich - 1.26.2-1 - update to 1.26.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2258392 - CVE-2023-51698 atril: vulnerable to Command Injection Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2258392 [ 2 ] Bug #2258393 - CVE-2023-51698 atril: vulnerable to CommandInjection Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2258393 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-59a7d96d84' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --- See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-37aef44d1e 2022-07-30 01:52:05.591856 --------------------------------------------------------------------------------Name : golang-github-prometheus-node-exporter Product : Fedora 36 Version : 1.3.1 Release : 10.fc36 URL : https://github.com/prometheus/node_exporter Summary : Exporter for machine metrics Description : Prometheus exporter for hardware and OS metrics exposed by *NIX kernels, written in Go with pluggable metric collectors. --------------------------------------------------------------------------------Update Information: Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028) --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Maxwell G 1.3.1-10 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-37aef44d1e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Rebuild for CVE-2022-27191 ---- Fix FTBFS Close: rhbz#2045471. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-08ae2dd481 2022-05-07 04:08:14.315797 --------------------------------------------------------------------------------Name : golang-github-francoispqt-gojay Product : Fedora 36 Version : 1.2.13 Release : 6.fc36 URL : https://github.com/francoispqt/gojay Summary : Fastest JSON encoder/decoder with powerful stream API for Golang Description : GoJay is a performant JSON encoder/decoder for Golang (currently the most performant, see benchmarks). It has a simple API and doesn't use reflection. It relies on small interfaces to decode/encode structures and slices. Gojay also comes with powerful stream decoding features and an even faster Unsafe API. --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-27191 ---- Fix FTBFS Close: rhbz#2045471 --------------------------------------------------------------------------------ChangeLog: * Sat Apr 16 2022 Fabio Alessandro Locati - 1.2.13-6 - Rebuilt for CVE-2022-27191 --------------------------------------------------------------------------------References: [ 1 ] Bug #2045471 - golang-github-appc-goaci: FTBFS in Fedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045471 [ 2 ] Bug #2074262 - CVE-2022-27191 golang-x-crypto: golang: crash in a golang.org/x/crypto/ssh server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2074262 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-08ae2dd481' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora ProjectGPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
geary 3.36.3.1 release: * Fixed handling of pinned, invalid TLS certificates: CVE-2020-24661 * Build bug fixes. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-d445fb484a 2020-09-03 16:38:32.949710 --------------------------------------------------------------------------------Name : geary Product : Fedora 32 Version : 3.36.3.1 Release : 1.fc32 URL : https://wiki.gnome.org/Apps/Geary Summary : A lightweight email program designed around conversations Description : Geary is a new email reader for GNOME designed to let you read your email quickly and effortlessly. Its interface is based on conversations, so you can easily read an entire discussion without having to click from message to message. Geary is still in early development and has limited features today, but we're planning to add drag-and-drop attachments, lightning-fast searching, multiple account support and much more. Eventually we'd like Geary to have an extensible plugin architecture so that developers will be able to add all kinds of nifty features in a modular way. --------------------------------------------------------------------------------Update Information: geary 3.36.3.1 release: * Fixed handling of pinned, invalid TLS certificates: CVE-2020-24661 * Build bug fixes --------------------------------------------------------------------------------ChangeLog: * Thu Aug 27 2020 Kalev Lember - 3.36.3.1-1 - Update to 3.36.3.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1872968 - CVE-2020-24661 geary: mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates https://bugzilla.redhat.com/show_bug.cgi?id=1872968 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2020-d445fb484a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.