An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for capnproto ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4478-1 Rating: moderate References: #1205968 Cross-References: CVE-2022-46149 CVSS scores: CVE-2022-46149 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L CVE-2022-46149 (SUSE): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L Affected Products: SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Desktop Applications 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for capnproto fixes the following issues: - CVE-2022-46149: Fixed out of bounds read when handling a list of lists (bsc#1205968). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-4478=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP4: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2022-4478=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): capnproto-0.9.1-150400.3.4.1 capnproto-debuginfo-0.9.1-150400.3.4.1 capnproto-debugsource-0.9.1-150400.3.4.1 libcapnp-0_9-0.9.1-150400.3.4.1 libcapnp-0_9-debuginfo-0.9.1-150400.3.4.1 libcapnp-devel-0.9.1-150400.3.4.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (aarch64 ppc64le s390x x86_64): capnproto-debuginfo-0.9.1-150400.3.4.1 capnproto-debugsource-0.9.1-150400.3.4.1 libcapnp-0_9-0.9.1-150400.3.4.1 libcapnp-0_9-debuginfo-0.9.1-150400.3.4.1 References: https://www.suse.com/security/cve/CVE-2022-46149.html https://bugzilla.suse.com/1205968 . Important update released for capnproto on SUSE Linux due to a vulnerability involving out of bounds read. Discover more details within.. SUSE Linux, Capnproto Update, Security Patch, 2022 Update, Linux Enterprise. . Severity: Important. LinuxSecurity.com Team
Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-18023b665f 2022-12-03 02:00:54.871650 --------------------------------------------------------------------------------Name : librime Product : Fedora 37 Version : 1.7.3 Release : 3.fc37 URL : https://rime.im/ Summary : Rime Input Method Engine Library Description : Rime Input Method Engine Library Support for shape-based and phonetic-based input methods, including those for Chinese dialects. A selected dictionary in Traditional Chinese, powered by opencc for Simplified Chinese output. --------------------------------------------------------------------------------Update Information: Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump. --------------------------------------------------------------------------------ChangeLog: * Fri Dec 2 2022 Fabio Valentini - 1.7.3-3 - Rebuild for capnproto 0.9.2 / CVE-2022-46149 --------------------------------------------------------------------------------References: [ 1 ] Bug #2150076 - CVE-2022-46149 capnproto: out of bounds read when handling a list of lists. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2150076 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-18023b665f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-18023b665f 2022-12-03 02:00:54.871650 --------------------------------------------------------------------------------Name : rr Product : Fedora 37 Version : 5.6.0 Release : 2.fc37 URL : https://rr-project.org/ Summary : Tool to record and replay execution of applications Description : rr is a lightweight tool for recording and replaying execution of applications (trees of processes and threads). For more information, please visit https://rr-project.org/ --------------------------------------------------------------------------------Update Information: Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump. --------------------------------------------------------------------------------ChangeLog: * Fri Dec 2 2022 Fabio Valentini - 5.6.0-2 - Rebuild for capnproto 0.9.2 / CVE-2022-46149 --------------------------------------------------------------------------------References: [ 1 ] Bug #2150076 - CVE-2022-46149 capnproto: out of bounds read when handling a list of lists. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2150076 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-18023b665f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-5d37367673 2022-12-03 01:41:59.480594 --------------------------------------------------------------------------------Name : librime Product : Fedora 36 Version : 1.7.3 Release : 2.fc36 URL : https://rime.im/ Summary : Rime Input Method Engine Library Description : Rime Input Method Engine Library Support for shape-based and phonetic-based input methods, including those for Chinese dialects. A selected dictionary in Traditional Chinese, powered by opencc for Simplified Chinese output. --------------------------------------------------------------------------------Update Information: Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump. --------------------------------------------------------------------------------ChangeLog: * Fri Dec 2 2022 Fabio Valentini - 1.7.3-2 - Rebuild for capnproto 0.9.2 / CVE-2022-46149 --------------------------------------------------------------------------------References: [ 1 ] Bug #2150076 - CVE-2022-46149 capnproto: out of bounds read when handling a list of lists. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2150076 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-5d37367673' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-5d37367673 2022-12-03 01:41:59.480594 --------------------------------------------------------------------------------Name : rr Product : Fedora 36 Version : 5.6.0 Release : 2.fc36 URL : https://rr-project.org/ Summary : Tool to record and replay execution of applications Description : rr is a lightweight tool for recording and replaying execution of applications (trees of processes and threads). For more information, please visit https://rr-project.org/ --------------------------------------------------------------------------------Update Information: Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump. --------------------------------------------------------------------------------ChangeLog: * Fri Dec 2 2022 Fabio Valentini - 5.6.0-2 - Rebuild for capnproto 0.9.2 / CVE-2022-46149 --------------------------------------------------------------------------------References: [ 1 ] Bug #2150076 - CVE-2022-46149 capnproto: out of bounds read when handling a list of lists. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2150076 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-5d37367673' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-5d37367673 2022-12-03 01:41:59.480594 --------------------------------------------------------------------------------Name : fastnetmon Product : Fedora 36 Version : 1.2.1 Release : 2.20220528git420e7b8.fc36 URL : https://fastnetmon.com Summary : DDoS detection tool with sFlow, Netflow, IPFIX and port mirror support Description : DDoS detection tool with sFlow, Netflow, IPFIX and port mirror support. --------------------------------------------------------------------------------Update Information: Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump. --------------------------------------------------------------------------------ChangeLog: * Fri Dec 2 2022 Fabio Valentini - 1.2.1-2.20220528git420e7b8 - Rebuild for capnproto 0.9.2 / CVE-2022-46149 --------------------------------------------------------------------------------References: [ 1 ] Bug #2150076 - CVE-2022-46149 capnproto: out of bounds read when handling a list of lists. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2150076 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-5d37367673' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.