backport fix for PEAP client (CVE-2023-52160). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-a95bdde55b 2024-02-27 01:07:18.072526 -------------------------------------------------------------------------------- Name : wpa_supplicant Product : Fedora 39 Version : 2.10 Release : 9.fc39 URL : http://w1.fi/wpa_supplicant/ Summary : WPA/WPA2/IEEE 802.1X Supplicant Description : wpa_supplicant is a WPA Supplicant for Linux, BSD and Windows with support for WPA and WPA2 (IEEE 802.11i / RSN). Supplicant is the IEEE 802.1X/WPA component that is used in the client stations. It implements key negotiation with a WPA Authenticator and it controls the roaming and IEEE 802.11 authentication/association of the wlan driver. -------------------------------------------------------------------------------- Update Information: backport fix for PEAP client (CVE-2023-52160) -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 22 2024 Davide Caratti - 1:2.10-9 - Backport fix for PEAP client (CVE-2023-52160) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2264594 - TRIAGE CVE-2023-52160 wpa_supplicant: potential authorization bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2264594 [ 2 ] Bug #2265479 - unpatched CVE-2023-52160 in Fedora 38 & 39 https://bugzilla.redhat.com/show_bug.cgi?id=2265479 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a95bdde55b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Projectcan be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
- update to the latest upstream release. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-645497fb95 2022-09-12 17:36:48.816207 --------------------------------------------------------------------------------Name : nghttp2 Product : Fedora 37 Version : 1.49.0 Release : 1.fc37 URL : https://nghttp2.org/ Summary : Experimental HTTP/2 client, server and proxy Description : This package contains the HTTP/2 client, server and proxy programs. --------------------------------------------------------------------------------Update Information: - update to the latest upstream release --------------------------------------------------------------------------------ChangeLog: * Tue Aug 23 2022 Kamil Dudka 1.49.0-1 - update to the latest upstream release --------------------------------------------------------------------------------References: [ 1 ] Bug #2120533 - nghttp2-1.49.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2120533 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-645497fb95' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2021:3494-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:3494 Issue date: 2021-09-13 CVE Names: CVE-2021-38493 ==================================================================== 1. Summary: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64le, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 78.14.0. Security Fix(es): * Mozilla: Memory safety bugs fixed in Firefox 92, Firefox ESR 78.14 and Firefox ESR 91.1 (CVE-2021-38493) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Thunderbird must be restarted for theupdate to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2002119 - CVE-2021-38493 Mozilla: Memory safety bugs fixed in Firefox 92, Firefox ESR 78.14 and Firefox ESR 91.1 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: thunderbird-78.14.0-1.el7_9.src.rpm x86_64: thunderbird-78.14.0-1.el7_9.x86_64.rpm thunderbird-debuginfo-78.14.0-1.el7_9.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): Source: thunderbird-78.14.0-1.el7_9.src.rpm ppc64le: thunderbird-78.14.0-1.el7_9.ppc64le.rpm thunderbird-debuginfo-78.14.0-1.el7_9.ppc64le.rpm x86_64: thunderbird-78.14.0-1.el7_9.x86_64.rpm thunderbird-debuginfo-78.14.0-1.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: thunderbird-78.14.0-1.el7_9.src.rpm x86_64: thunderbird-78.14.0-1.el7_9.x86_64.rpm thunderbird-debuginfo-78.14.0-1.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-38493 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYT8AF9zjgjWX9erEAQj04w//V073qpbygU+F4P8yR2InkY3GszK3BFS3 qbXSsujD4qOzT+j10KGuSL3/bR25AwC8uA4Py7dXt4c8NGZWkBlrJZkhRU7qH2e1 MpVSO/5PzrwL46C5ucvlWzxkgxE13EzzvpU+glVtEAu8m+4vVcRgXbsK9j/jpQIA FD329FK52ErF8G7YVW23JN4grEHMK5GG/8EnvBBB9aYRWSIfS09/VX0iDNQmFlXi zI3S5eANaqbeFNlXC1C2DuY56igL652bR56VABCwi9393hpAdT7iehxLXtn1OKGf LTysa1CjxjlQwnXxBcpkLlCW3ZNZt730NTlCd1AYQPjTuX1AHdzDwNxqRHifEd8f UiqHXGO+PBc4NG39fpaHiaG2tM6ro21FbzjcvTyIGdV1xKwB9JwPFQLtE5WJENqF gyr8CfYMNZpaRl8xBbhRvhFPMHlvkz8HO5X2nlreukhDC3mFFpcICKBnC+R6wxeK o6/1umUSfz6/7NMRKldJa2qycV8UVS5/dgYx95SksrrYWW4wg8p3DMyEtE9paDN0 xqjFGECaH1TydEFeq6Q/ajOyFWYWyAu//6XaORMzr3BkQ/8KijTx8zdUIGiIYmDK +p03bTFMlvCzxb7cl0Rl3XafNR05yIZiPjiqTYM1xFEKn6SEILRqwvqoS9lg8uWd T8hvEmbXZFE=gCNH -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.