Disable bundled Trustcor root cerificate signatures generated after Wednesday November 30 00:00:00 2022. (CVE-2022-23491) References: - https://bugs.mageia.org/show_bug.cgi?id=31248 . MGASA-2023-0140 - Updated python-certifi packages fix security vulnerability Publication date: 15 Apr 2023 URL: https://advisories.mageia.org/MGASA-2023-0140.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-23491 Disable bundled Trustcor root cerificate signatures generated after Wednesday November 30 00:00:00 2022. (CVE-2022-23491) References: - https://bugs.mageia.org/show_bug.cgi?id=31248 - https://ubuntu.com/security/notices/USN-5761-1 - - https://github.com/certifi/python-certifi/security/advisories/GHSA-43fp-rhv2-5gv8 - https://lists.suse.com/pipermail/sle-security-updates/2023-January/013525.html - - https://lists.fedoraproject.org/archives/list/
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters (CVE-2022-4254) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * smartcards: special characters must be escaped when building search filter SL7 x86_64 libipa_hbac-1.16.5-10.el7_9.15.i686.rpm l [More...]. Synopsis: Important: sssd security and bug fix update Advisory ID: SLSA-2023:0403-1 Issue Date: 2023-01-24 CVE Numbers: CVE-2022-4254 -- Security Fix(es): * sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters (CVE-2022-4254) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * smartcards: special characters must be escaped when building search filter -- SL7 x86_64 libipa_hbac-1.16.5-10.el7_9.15.i686.rpm libipa_hbac-1.16.5-10.el7_9.15.x86_64.rpm libsss_autofs-1.16.5-10.el7_9.15.x86_64.rpm libsss_certmap-1.16.5-10.el7_9.15.i686.rpm libsss_certmap-1.16.5-10.el7_9.15.x86_64.rpm libsss_idmap-1.16.5-10.el7_9.15.i686.rpm libsss_idmap-1.16.5-10.el7_9.15.x86_64.rpm libsss_nss_idmap-1.16.5-10.el7_9.15.i686.rpm libsss_nss_idmap-1.16.5-10.el7_9.15.x86_64.rpm libsss_simpleifp-1.16.5-10.el7_9.15.i686.rpm libsss_simpleifp-1.16.5-10.el7_9.15.x86_64.rpm libsss_sudo-1.16.5-10.el7_9.15.x86_64.rpm python-libipa_hbac-1.16.5-10.el7_9.15.x86_64.rpm python-sss-1.16.5-10.el7_9.15.x86_64.rpm python-sss-murmur-1.16.5-10.el7_9.15.x86_64.rpm sssd-1.16.5-10.el7_9.15.x86_64.rpm sssd-ad-1.16.5-10.el7_9.15.x86_64.rpm sssd-client-1.16.5-10.el7_9.15.i686.rpm sssd-client-1.16.5-10.el7_9.15.x86_64.rpm sssd-common-1.16.5-10.el7_9.15.x86_64.rpm sssd-common-pac-1.16.5-10.el7_9.15.x86_64.rpm sssd-dbus-1.16.5-10.el7_9.15.x86_64.rpm sssd-debuginfo-1.16.5-10.el7_9.15.i686.rpm sssd-debuginfo-1.16.5-10.el7_9.15.x86_64.rpm sssd-ipa-1.16.5-10.el7_9.15.x86_64.rpm sssd-kcm-1.16.5-10.el7_9.15.x86_64.rpm sssd-krb5-1.16.5-10.el7_9.15.x86_64.rpm sssd-krb5-common-1.16.5-10.el7_9.15.x86_64.rpm sssd-ldap-1.16.5-10.el7_9.15.x86_64.rpm sssd-libwbclient-1.16.5-10.el7_9.15.x86_64.rpm sssd-polkit-rules-1.16.5-10.el7_9.15.x86_64.rpm sssd-proxy-1.16.5-10.el7_9.15.x86_64.rpm sssd-tools-1.16.5-10.el7_9.15.x86_64.rpm sssd-winbind-idmap-1.16.5-10.el7_9.15.x86_64.rpm libipa_hbac-devel-1.16.5-10.el7_9.15.i686.rpm libipa_hbac-devel-1.16.5-10.el7_9.15.x86_64.rpm libsss_certmap-devel-1.16.5-10.el7_9.15.i686.rpm libsss_certmap-devel-1.16.5-10.el7_9.15.x86_64.rpm libsss_idmap-devel-1.16.5-10.el7_9.15.i686.rpm libsss_idmap-devel-1.16.5-10.el7_9.15.x86_64.rpm libsss_nss_idmap-devel-1.16.5-10.el7_9.15.i686.rpm libsss_nss_idmap-devel-1.16.5-10.el7_9.15.x86_64.rpm libsss_simpleifp-devel-1.16.5-10.el7_9.15.i686.rpm libsss_simpleifp-devel-1.16.5-10.el7_9.15.x86_64.rpm python-libsss_nss_idmap-1.16.5-10.el7_9.15.x86_64.rpm sssd-libwbclient-devel-1.16.5-10.el7_9.15.i686.rpm sssd-libwbclient-devel-1.16.5-10.el7_9.15.x86_64.rpm noarch python-sssdconfig-1.16.5-10.el7_9.15.noarch.rpm - Scientific Linux Development Team . Important sssd security patch rollout for Scientific Linux SL7.x targeting vulnerabilities related to certificate validation. This update rectifies significant sanitization flaws.. Scientific Linux, SSSD, Certificate Fix, Security Update. . Severity: Critical. LinuxSecurity.com Team
Fix certificate validation to work without legacy CAs. ---- empathy 3.12.13 release. For details, see https://mail.gnome.org/archives/ftp-release-list/2017-March/msg00077.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-8840ec0204 2017-04-01 16:46:19.662323 -------------------------------------------------------------------------------- Name : empathy Product : Fedora 26 Version : 3.12.13 Release : 2.fc26 URL : Summary : Instant Messaging Client for GNOME Description : Empathy is powerful multi-protocol instant messaging client which supports Jabber, GTalk, MSN, IRC, Salut, and other protocols. It is built on top of the Telepathy framework. -------------------------------------------------------------------------------- Update Information: Fix certificate validation to work without legacy CAs. ---- empathy 3.12.13 release. For details, see https://mail.gnome.org/archives/ftp-release-list/2017-March/msg00077.html -------------------------------------------------------------------------------- References: [ 1 ] Bug #1381671 - Fails to connect to Google, with legacy CAs disabled, or with ca-certificates version 2.10 https://bugzilla.redhat.com/show_bug.cgi?id=1381671 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade empathy' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
This updates KDE to 4.3.1, the latest upstream bugfix release. The main improvements are: * KDE 4.3 is now also available in Croatian. * A crash when editing toolbar setup has been fixed. * Support for transferring files through SSH using KIO::Fish has been fixed. * A number of bugs in KWin, KDE's window and compositing manager has been fixed. * A large number of bugs in KMail, KDE's email client are now gone. See https://kde.org/announcements/announce-4.3.1/ for more information. In addition, this update: * fixes a potential security issue (CVE-2009-2702) with certificate validation in the KIO KSSL code. It is believed that the affected code is not actually used (the code in Qt, for which a security update was already issued, is) and thus the issue is only potential, but KSSL is being patched just in case, * splits PolicyKit-kde out of kdebase-workspace again to avoid forcing it onto GNOME-based setups, where PolicyKit-gnome is desired instead (#519654).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-9427 2009-09-09 00:48:07 -------------------------------------------------------------------------------- Name : kdeplasma-addons Product : Fedora 10 Version : 4.3.1 Release : 1.fc10 URL : https://kde.org/ Summary : Additional plasmoids for KDE Description : Additional plasmoids for KDE. -------------------------------------------------------------------------------- Update Information: This updates KDE to 4.3.1, the latest upstream bugfix release. The main improvements are: * KDE 4.3 is now also available in Croatian. * A crash when editing toolbar setup has been fixed. * Support for transferring files through SSH using KIO::Fish has been fixed. * A number of bugs in KWin, KDE's window and compositing manager has been fixed. * A large number of bugs in KMail, KDE's email client are now gone. See https://kde.org/announcements/announce-4.3.1/ for more information. In addition, thisupdate: * fixes a potential security issue (CVE-2009-2702) with certificate validation in the KIO KSSL code. It is believed that the affected code is not actually used (the code in Qt, for which a security update was already issued, is) and thus the issue is only potential, but KSSL is being patched just in case, * splits PolicyKit-kde out of kdebase-workspace again to avoid forcing it onto GNOME-based setups, where PolicyKit-gnome is desired instead (#519654). -------------------------------------------------------------------------------- ChangeLog: * Fri Aug 28 2009 Than Ngo - 4.3.1-1 - 4.3.1 * Thu Aug 13 2009 Than Ngo - 4.3.0-9 - omit BR on kdeedu-devel/eigen2-devel for rhel * Fri Aug 7 2009 Ben Boeckel - 4.3.0-8 - Waited for newRepo task * Fri Aug 7 2009 Ben Boeckel - 4.3.0-7 - Rebuild for mising rawhide oxygen-icon-theme - Fix patch comments * Fri Aug 7 2009 Ben Boeckel - 4.3.0-6 - Add patch to fix kde#196809 * Tue Aug 4 2009 Than Ngo - 4.3.0-5 - respin * Mon Aug 3 2009 Rex Dieter - 4.3.0-4 - fix microblog post crasher (kdebug#202364) * Mon Aug 3 2009 Rex Dieter - 4.3.0-3 - -libs subpkg to sanitize multilib * Sun Aug 2 2009 Rex Dieter - 4.3.0-2 - fix to allow updating of status via microblog plasmoid * Thu Jul 30 2009 Than Ngo - 4.3.0-1 - 4.3.0 * Wed Jul 22 2009 Than Ngo - 4.2.98-1 - 4.3rc3 * Thu Jul 16 2009 Rex Dieter - 4.2.96-2 - BR: libXcomposite-devel (lancelot eye-candy) * Sun Jul 12 2009 Than Ngo - 4.2.96-1 - 4.3rc2 * Fri Jun 26 2009 Than Ngo - 4.2.95-1 - 4.3rc1 * Thu Jun 4 2009 Rex Dieter - 4.2.90-1 - KDE-4.3 beta2 (4.2.90) * Mon May 25 2009 Rex Dieter - 4.2.85-4 - BR: eigen2-devel soprano-devel * Tue May 19 2009 Kevin Kofler - 4.2.85-3 - BR kdeedu-devel (for Marble) * Sun May 17 2009 Kevin Kofler - 4.2.85-2 - Obsoletes/Provides: kde-plasma-weather * Wed May 13 2009 Lukáš Tinkl - 4.2.85-1 - KDE 4.3 beta 1 * Thu Apr 30 2009 Rex Dieter - 4.2.2-3 - disable contacts krunner by default * Wed Apr 1 2009 Rex Dieter - 4.2.2-2 - optimize scriptlets *Tue Mar 31 2009 Lukáš Tinkl - 4.2.2-1 - KDE 4.2.2 * Mon Mar 16 2009 Rex Dieter - 4.2.1-3 - make bball applet work, ship .svg instead of .svgz (kdebug#185568) - use new %_qt45 macro - spec housecleaning * Fri Mar 13 2009 Kevin Kofler - 4.2.1-2 - fix Lancelot rendering issues with Qt 4.5 (F11+ only, as the effect of that patch with 4.4.3 is unknown) * Fri Feb 27 2009 Than Ngo - 4.2.1-1 - 4.2.1 * Wed Feb 25 2009 Fedora Release Engineering - 4.2.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Thu Jan 22 2009 Than Ngo - 4.2.0-1 - 4.2.0 * Wed Jan 7 2009 Than Ngo - 4.1.96-1 - 4.2rc1 * Tue Dec 16 2008 Rex Dieter 4.1.85-2 - saner versioned Obsoletes * Fri Dec 12 2008 Than Ngo 4.1.85-1 - 4.2beta2 * Tue Dec 2 2008 Kevin Kofler 4.1.80-3 - BR plasma-devel - add Provides: kde-plasma-lancelot - fix file list - BR libkexiv2-devel > = 0.4.0 on F10+ * Thu Nov 20 2008 Than Ngo 4.1.80-2 - merged - add Obsoletes: kde-plasma-lancelot * Thu Nov 20 2008 Lorenzo Villani - 4.1.80-1 - 4.1.80 - BR cmake > = 2.6.2 - make install/fast * Wed Nov 12 2008 Than Ngo 4.1.3-1 - 4.1.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #520661 - CVE-2009-2702 kdelibs: kssl incorrect verification of SSL certificate with NUL in subjectAltName https://bugzilla.redhat.com/show_bug.cgi?id=520661 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update kdeplasma-addons' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailinglist
Get the latest Linux and open source security news straight to your inbox.