An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for canna ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10091-1 Rating: important References: #1199280 Cross-References: CVE-2022-21950 CVSS scores: CVE-2022-21950 (SUSE): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for canna fixes the following issues: - CVE-2022-21950: Move UNIX socket dir from /tmp to /run to avoid local attackers being able to place bogus directories in its stead. Use systemd-tmpfiles for cleaning old sockets (boo#1199280). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10091=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): canna-3.7p3-bp154.3.3.1 canna-devel-3.7p3-bp154.3.3.1 canna-libs-3.7p3-bp154.3.3.1 - openSUSE Backports SLE-15-SP4 (aarch64_ilp32): canna-libs-64bit-3.7p3-bp154.3.3.1 - openSUSE Backports SLE-15-SP4 (x86_64): canna-libs-32bit-3.7p3-bp154.3.3.1 References: https://www.suse.com/security/cve/CVE-2022-21950.html https://bugzilla.suse.com/1199280 . This important enhancement for canna tackles a regional vulnerability and strengthens protection. Please consult the bulletin openSUSE-SU-2022:10091-2. openSUSE Security Update,canna software,local attack fix. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for canna ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10090-1 Rating: important References: #1199280 Cross-References: CVE-2022-21950 CVSS scores: CVE-2022-21950 (SUSE): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for canna fixes the following issues: - CVE-2022-21950: move UNIX socket dir from /tmp to /run to avoid local attackers being able to place bogus directories in its stead. Use systemd-tmpfiles for cleaning old sockets (boo#1199280). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-10090=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): canna-3.7p3-bp153.2.3.1 canna-devel-3.7p3-bp153.2.3.1 canna-libs-3.7p3-bp153.2.3.1 - openSUSE Backports SLE-15-SP3 (aarch64_ilp32): canna-libs-64bit-3.7p3-bp153.2.3.1 - openSUSE Backports SLE-15-SP3 (x86_64): canna-libs-32bit-3.7p3-bp153.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-21950.html https://bugzilla.suse.com/1199280 . Critical patch released for canna service addressing socket directory flaw affecting openSUSE installations.. openSUSE Backports, canna issue, socket vulnerability, systemd-tmpfiles. . Severity: Important. LinuxSecurity.com Team
Several vulnerabilities have been discovered in canna, a Japanese input system.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 224-1
A heap overflow vulnerability was discovered in the irw_through function in canna server version 3.6 and earlier.. - -------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200212-8 - -------------------------------------------------------------------- PACKAGE : canna SUMMARY : multiple vulnerabilities in canna DATE : 2002-12-20 17:12 UTC EXPLOIT : remote - -------------------------------------------------------------------- Quotes from advisory: "hsj" of Shadow Penguin Security discovered a heap overflow vulnerability in the irw_through function in canna server version 3.6 and earlier." "AIDA Shinra of Canna project found lack of validations of requests in canna version 3.6 and earlier." Read the full advisory at SOLUTION It is recommended that all Gentoo Linux users who are running app-i18n/canna-3.6 and earlier update their systems as follows: emerge rsync emerge canna emerge clean - --------------------------------------------------------------------
Buffer overflow has been fixed for Debian GNU/Linux 2.1. -----BEGIN PGP SIGNED MESSAGE----- - ------------------------------------------------------------------------ Debian Security Advisory
Get the latest Linux and open source security news straight to your inbox.