An update that solves one vulnerability and has one errata is now available. . openSUSE Security Update: Security update for go1.16 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1420-1 Rating: moderate References: #1182345 #1191468 Cross-References: CVE-2021-38297 CVSS scores: CVE-2021-38297 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for go1.16 fixes the following issues: Update to go1.16.9 - CVE-2021-38297: misc/wasm, cmd/link: do not let command line args overwrite global data (bsc#1191468) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1420=1 Package List: - openSUSE Leap 15.2 (x86_64): go1.16-1.16.9-lp152.14.1 go1.16-doc-1.16.9-lp152.14.1 go1.16-race-1.16.9-lp152.14.1 References: https://www.suse.com/security/cve/CVE-2021-38297.html https://bugzilla.suse.com/1182345 https://bugzilla.suse.com/1191468 . Security patch released for openSUSE Leap 15.2 resolving a moderate severity vulnerability in go1.16.. openSUSE update, go1.16 security, software patch, command line security. . LinuxSecurity.com Team
Several security issues were fixed in python-gnupg. =========================================================================Ubuntu Security Notice USN-3964-1 May 02, 2019 python-gnupg vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.04 - Ubuntu 18.10 - Ubuntu 18.04 LTS Summary: Several security issues were fixed in python-gnupg Software Description: - python-gnupg: Python wrapper for the GNU Privacy Guard Details: Marcus Brinkmann discovered that GnuPG before 2.2.8 improperly handled certain command line parameters. A remote attacker could use this to spoof the output of GnuPG and cause unsigned e-mail to appear signed. (CVE-2018-12020) It was discovered that python-gnupg incorrectly handled the GPG passphrase. A remote attacker could send a specially crafted passphrase that would allow them to control the output of encryption and decryption operations. (CVE-2019-6690) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: python-gnupg 0.4.3-1ubuntu1.19.04.1 python3-gnupg 0.4.3-1ubuntu1.19.04.1 Ubuntu 18.10: python-gnupg 0.4.1-1ubuntu1.18.10.1 python3-gnupg 0.4.1-1ubuntu1.18.10.1 Ubuntu 18.04 LTS: python-gnupg 0.4.1-1ubuntu1.18.04.1 python3-gnupg 0.4.1-1ubuntu1.18.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3964-1 CVE-2018-12020, CVE-2019-6690 Package Information: https://launchpad.net/ubuntu/+source/python-gnupg/0.4.3-1ubuntu1.19.04.1 https://launchpad.net/ubuntu/+source/python-gnupg/0.4.1-1ubuntu1.18.10.1 https://launchpad.net/ubuntu/+source/python-gnupg/0.4.1-1ubuntu1.18.04.1 . Security alert issued for Ubuntu concerningpython-gnupg, aiming to protect users from potential remote threats through command line vulnerabilities and passphrase weaknesses.. Ubuntu Security, python-gnupg Vulnerabilities, Remote Access Exploit. . Severity: Critical. LinuxSecurity.com Team
xl command line config handling stack overflow [XSA-137, CVE-2015-3259]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-11247 2015-07-10 16:32:04 -------------------------------------------------------------------------------- Name : xen Product : Fedora 21 Version : 4.4.2 Release : 7.fc21 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: xl command line config handling stack overflow [XSA-137, CVE-2015-3259] -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 7 2015 Michael Young - 4.4.2-7 - xl command line config handling stack overflow [XSA-137, CVE-2015-3259] * Thu Jun 11 2015 Michael Young - 4.4.2-6 - Heap overflow in QEMU PCNET controller, allowing guest-> host escape [XSA-135, CVE-2015-3209] (#1230537) - GNTTABOP_swap_grant_ref operation misbehavior [XSA-134, CVE-2015-4163] - vulnerability in the iret hypercall handler [XSA-136, CVE-2015-4164] * Tue Jun 2 2015 Michael Young - 4.4.2-5 - Potential unintended writes to host MSI message data field via qemu [XSA-128, CVE-2015-4103] (#1227627) - PCI MSI mask bits inadvertently exposed to guests [XSA-129, CVE-2015-4104] (#1227628) - Guest triggerable qemu MSI-X pass-through error messages [XSA-130, CVE-2015-4105] (#1227629) - Unmediated PCI register access in qemu [XSA-131, CVE-2015-4106] (#1227631) * Wed May 13 2015 Michael Young - 4.4.2-4 - Privilege escalation via emulated floppy disk drive [XSA-133, CVE-2015-3456] (#1221153) * Mon Apr 20 2015 Michael Young - 4.4.2-3 - Information leak through XEN_DOMCTL_gettscinfo [XSA-132, CVE-2015-3340] (#1214037) * Tue Mar 31 2015 Michael Young - 4.4.2-2 - Long latency MMIOmapping operations are not preemptible [XSA-125, CVE-2015-2752] (#1207741) - Unmediated PCI command register access in qemu [XSA-126, CVE-2015-2756] (#1307738) - Certain domctl operations may be abused to lock up the host [XSA-127, CVE-2015-2751] (#1207739) * Mon Mar 23 2015 Michael Young - 4.4.2-1 - update to xen-4.4.2 remove patches for fixes that are now included * Fri Mar 13 2015 Michael Young - 4.4.1-16 - Additional patch for XSA-98 on arm64 * Thu Mar 12 2015 Michael Young - 4.4.1-15 - HVM qemu unexpectedly enabling emulated VGA graphics backends [XSA-119, CVE-2015-2152] (#1201365) * Wed Mar 11 2015 Michael Young - 4.4.1-14 - Hypervisor memory corruption due to x86 emulator flaw [XSA-123, CVE-2015-2151] (#1200398) * Thu Mar 5 2015 Michael Young - 4.4.1-13 - enable building pngs from fig files which is working again - fix oxenstored.service preset preuninstall script - arm: vgic: incorrect rate limiting of guest triggered logging [XSA-118, CVE-2015-1563] (#1187153) - Information leak via internal x86 system device emulation [XSA-121, CVE-2015-2044] - Information leak through version information hypercall [XSA-122, CVE-2015-2045] * Tue Jan 6 2015 Michael Young - 4.4.1-12 - xen crash due to use after free on hvm guest teardown [XSA-116, CVE-2015-0361] (#1179221) * Tue Dec 16 2014 Michael Young - 4.4.1-11 - fix xendomains issue introduced by xl migrate --debug patch * Mon Dec 8 2014 Michael Young - 4.4.1-10 - p2m lock starvation [XSA-114, CVE-2014-9065] - fix build with --without xsm * Thu Nov 27 2014 Michael Young - 4.4.1-9 - Excessive checking in compatibility mode hypercall argument translation [XSA-111, CVE-2014-8866] - Insufficient bounding of "REP MOVS" to MMIO emulated inside the hypervisor [XSA-112, CVE-2014-8867] - fix segfaults and failures in xl migrate --debug (#1166461) * Thu Nov 20 2014 Michael Young - 4.4.1-8 - Guest effectable page reference leak in MMU_MACHPHYS_UPDATE handling [XSA-113, CVE-2014-9030] (#1166914) * Tue Nov 18 2014 Michael Young - 4.4.1-7 -Insufficient restrictions on certain MMU update hypercalls [XSA-109, CVE-2014-8594] (#1165205) - Missing privilege level checks in x86 emulation of far branches [XSA-110, CVE-2014-8595] (#1165204) - Add fix for CVE-2014-0150 to qemu-dm, though it probably isn't exploitable from xen (#1086776) -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update xen' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.