Fedora 33 Fixed 1984005 Fedora 34 - Fixed CVE-2021-36770 - Ensure that UTF-16 decode always includes a trailing NUL. - Replace non-ASCII apostrophes w/ \x27, which were introduced in #155 - Addressed: find_encoding returns Internal encoding `Unicode` is no longer a valid encoding name.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-44c65203cc 2021-08-25 20:03:26.599277 --------------------------------------------------------------------------------Name : perl-Encode Product : Fedora 33 Version : 3.08 Release : 459.fc33 URL : https://metacpan.org/dist/Encode Summary : Character encodings in Perl Description : The Encode module provides the interface between Perl strings and the rest of the system. Perl strings are sequences of characters. --------------------------------------------------------------------------------Update Information: Fedora 33 Fixed 1984005 Fedora 34 - Fixed CVE-2021-36770 - Ensure that UTF-16 decode always includes a trailing NUL. - Replace non-ASCII apostrophes w/ \x27, which were introduced in #155 - Addressed: find_encoding returns Internal encoding `Unicode` is no longer a valid encoding name. --------------------------------------------------------------------------------ChangeLog: * Mon Aug 9 2021 Jitka Plesnikova - 4:3.08-459 - Fix CVE-2021-36770 - mitigate @INC pollution when loading ConfigLocal --------------------------------------------------------------------------------References: [ 1 ] Bug #1991539 - CVE-2021-36770 perl-Encode: bug in local configuration loading allows arbitrary Perl code execution placed under the current working directory [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1991539 [ 2 ] Bug #1991658 - perl-Encode-3.12 is available https://bugzilla.redhat.com/show_bug.cgi?id=1991658 --------------------------------------------------------------------------------This update can be installed withthe "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-44c65203cc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fedora 33 Fixed 1984005 Fedora 34 - Fixed CVE-2021-36770 - Ensure that UTF-16 decode always includes a trailing NUL. - Replace non-ASCII apostrophes w/ \x27, which were introduced in #155 - Addressed: find_encoding returns Internal encoding `Unicode` is no longer a valid encoding name.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-92e07de1dd 2021-08-13 01:20:44.629632 --------------------------------------------------------------------------------Name : perl-Encode Product : Fedora 34 Version : 3.12 Release : 460.fc34 URL : https://metacpan.org/dist/Encode Summary : Character encodings in Perl Description : The Encode module provides the interface between Perl strings and the rest of the system. Perl strings are sequences of characters. --------------------------------------------------------------------------------Update Information: Fedora 33 Fixed 1984005 Fedora 34 - Fixed CVE-2021-36770 - Ensure that UTF-16 decode always includes a trailing NUL. - Replace non-ASCII apostrophes w/ \x27, which were introduced in #155 - Addressed: find_encoding returns Internal encoding `Unicode` is no longer a valid encoding name. --------------------------------------------------------------------------------ChangeLog: * Mon Aug 9 2021 Jitka Plesnikova - 4:3.12-460 - 3.12 bump --------------------------------------------------------------------------------References: [ 1 ] Bug #1991539 - CVE-2021-36770 perl-Encode: bug in local configuration loading allows arbitrary Perl code execution placed under the current working directory [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1991539 [ 2 ] Bug #1991658 - perl-Encode-3.12 is available https://bugzilla.redhat.com/show_bug.cgi?id=1991658 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2021-92e07de1dd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Some security issues are found on oniguruma. This new rpm should fix these issues. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-5409bb5e68 2019-07-31 01:48:17.829137 --------------------------------------------------------------------------------Name : oniguruma Product : Fedora 29 Version : 6.9.1 Release : 2.fc29 URL : https://github.com/kkos/oniguruma/ Summary : Regular expressions library Description : Oniguruma is a regular expressions library. The characteristics of this library is that different character encoding for every regular expression object can be specified. (supported APIs: GNU regex, POSIX and Oniguruma native) --------------------------------------------------------------------------------Update Information: Some security issues are found on oniguruma. This new rpm should fix these issues --------------------------------------------------------------------------------ChangeLog: * Fri Jul 12 2019 Mamoru TASAKA - 6.9.1-2 - patch for CVE-2019-13225 based on the upstream and backported into 6.9.1 (#1728966) - NON-upstream patch for CVE-2019-13224 (#1728971) * Wed Dec 12 2018 Mamoru TASAKA - 6.9.1-1 - 6.9.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1728971 - CVE-2019-13224 oniguruma: use-after-free in onig_new_deluxe() in regext.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1728971 [ 2 ] Bug #1728966 - CVE-2019-13225 oniguruma: null-pointer dereference in match_at() in regexec.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1728966 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-5409bb5e68' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.