Brief introduction CVE-2021-3563 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3714-1
Stunnel was not properly verifying TLS certificates, possibly allowing an integrity/confidentiality compromise.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202105-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: stunnel: Improper certificate validation Date: May 26, 2021 Bugs: #772146 ID: 202105-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Stunnel was not properly verifying TLS certificates, possibly allowing an integrity/confidentiality compromise. Background ========= The stunnel program is designed to work as an SSL/TLS encryption wrapper between a client and a local or remote server. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/stunnel < 5.58 > = 5.58 Description ========== It was discovered that stunnel did not correctly verified the client certificate when options "redirect" and "verifyChain" are used. Impact ===== A remote attacker could send a specially crafted certificate, possibly resulting in a breach of integrity or confidentiality. Workaround ========= There is no known workaround at this time. Resolution ========= All stunnel users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/stunnel-5.58" References ========= [ 1 ] CVE-2021-20230 https://nvd.nist.gov/vuln/detail/CVE-2021-20230 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202105-02 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Update to new release. 2.17.8+ include the security fix for CVE-2020-13614 axel: TLS implementation lacks hostname verification leading to possible confidentiality breach. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-5214bd8f14 2021-05-05 01:20:25.877561 --------------------------------------------------------------------------------Name : axel Product : Fedora 34 Version : 2.17.10 Release : 1.fc34 URL : https://github.com/axel-download-accelerator/axel Summary : Light command line download accelerator for Linux and Unix Description : Axel tries to accelerate HTTP/FTP downloading process by using multiple connections for one file. It can use multiple mirrors for a download. Axel has no dependencies and is lightweight, so it might be useful as a wget clone on byte-critical systems. --------------------------------------------------------------------------------Update Information: Update to new release. 2.17.8+ include the security fix for CVE-2020-13614 axel: TLS implementation lacks hostname verification leading to possible confidentiality breach --------------------------------------------------------------------------------ChangeLog: * Mon Apr 26 2021 Frantisek Zatloukal - 2.17.10-1 - Updated to axel-2.17.10 --------------------------------------------------------------------------------References: [ 1 ] Bug #1848468 - CVE-2020-13614 axel: TLS implementation lacks hostname verification leading to possible confidentiality breach [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1848468 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-5214bd8f14' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed withthe Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to new release. 2.17.8+ include the security fix for CVE-2020-13614 axel: TLS implementation lacks hostname verification leading to possible confidentiality breach. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-90b4716992 2021-05-05 00:52:51.707432 --------------------------------------------------------------------------------Name : axel Product : Fedora 33 Version : 2.17.10 Release : 1.fc33 URL : https://github.com/axel-download-accelerator/axel Summary : Light command line download accelerator for Linux and Unix Description : Axel tries to accelerate HTTP/FTP downloading process by using multiple connections for one file. It can use multiple mirrors for a download. Axel has no dependencies and is lightweight, so it might be useful as a wget clone on byte-critical systems. --------------------------------------------------------------------------------Update Information: Update to new release. 2.17.8+ include the security fix for CVE-2020-13614 axel: TLS implementation lacks hostname verification leading to possible confidentiality breach --------------------------------------------------------------------------------ChangeLog: * Mon Apr 26 2021 Frantisek Zatloukal - 2.17.10-1 - Updated to axel-2.17.10 * Tue Jan 26 2021 Fedora Release Engineering - 2.16-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1848468 - CVE-2020-13614 axel: TLS implementation lacks hostname verification leading to possible confidentiality breach [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1848468 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-90b4716992' at the command line. For more information,refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several security issues were fixed in libcaca.. =========================================================================Ubuntu Security Notice USN-3860-1 January 15, 2019 libcaca vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in libcaca. Software Description: - libcaca: text mode graphics utilities Details: It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-20544) It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-20545, CVE-2018-20548, CVE-2018-20459) It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to access sensitive information. (CVE-2018-20546, CVE-2018-20547) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10: caca-utils 0.99.beta19-2ubuntu0.18.10.1 libcaca0 0.99.beta19-2ubuntu0.18.10.1 Ubuntu 18.04 LTS: caca-utils 0.99.beta19-2ubuntu0.18.04.1 libcaca0 0.99.beta19-2ubuntu0.18.04.1 Ubuntu 16.04 LTS: caca-utils 0.99.beta19-2ubuntu0.16.04.1 libcaca0 0.99.beta19-2ubuntu0.16.04.1 Ubuntu 14.04 LTS: caca-utils 0.99.beta18-1ubuntu5.1 libcaca0 0.99.beta18-1ubuntu5.1 In general, a standard system update will make all thenecessary changes. References: https://ubuntu.com/security/notices/USN-3860-1 CVE-2018-20544, CVE-2018-20545, CVE-2018-20546, CVE-2018-20547, CVE-2018-20548, CVE-2018-20549 Package Information: https://launchpad.net/ubuntu/+source/libcaca/0.99.beta19-2ubuntu0.18.10.1 https://launchpad.net/ubuntu/+source/libcaca/0.99.beta19-2ubuntu0.18.04.1 https://launchpad.net/ubuntu/+source/libcaca/0.99.beta19-2ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/libcaca/0.99.beta18-1ubuntu5.1 . Ubuntu addresses libcaca security flaws impacting various versions; ensure updates are applied promptly to mitigate exploit risks.. Libcaca Update, Ubuntu Security Notices, Denial of Service, Code Execution, Confidentiality Breach. . Severity: Critical. LinuxSecurity.com Team
An update that fixes 5 vulnerabilities is now available. . SUSE Security Update: Security update for samba ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2318-1 Rating: important References: #1095048 #1095056 #1095057 #1103411 #1103414 Cross-References: CVE-2018-10858 CVE-2018-10918 CVE-2018-10919 CVE-2018-1139 CVE-2018-1140 Affected Products: SUSE Linux Enterprise Module for Basesystem 15 SUSE Linux Enterprise High Availability 15 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for samba fixes the following issues: The following security vulnerabilities were fixed: - CVE-2018-1139: Disable NTLMv1 auth if smb.conf doesn't allow it; (bsc#1095048) - CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes; (bsc#1095056) - CVE-2018-10919: Confidential attribute disclosure via substring search; (bsc#1095057) - CVE-2018-10858: smbc_urlencode helper function is a subject to buffer overflow; (bsc#1103411) - CVE-2018-10918: Fix NULL ptr dereference in DsCrackNames on a user without a SPN; (bsc#1103414) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-1555=1 - SUSE Linux Enterprise High Availability 15: zypper in -t patch SUSE-SLE-Product-HA-15-2018-1555=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): libdcerpc-binding0-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc-binding0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc-samr-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc-samr0-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc-samr0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc0-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-krb5pac-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-krb5pac0-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-krb5pac0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-nbt-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-nbt0-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-nbt0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-standard-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-standard0-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-standard0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr0-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libnetapi-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libnetapi0-4.7.8+git.86.94b6d10f7dd-4.15.1 libnetapi0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-credentials-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-credentials0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-credentials0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-errors-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-errors0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-errors0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-hostconfig-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-hostconfig0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-hostconfig0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-passdb-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-passdb0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-passdb0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-policy-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-policy0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-util-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-util0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-util0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamdb-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamdb0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamdb0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbclient-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbclient0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbclient0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbconf-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbconf0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbconf0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbldap-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbldap2-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbldap2-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libtevent-util-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libtevent-util0-4.7.8+git.86.94b6d10f7dd-4.15.1 libtevent-util0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libwbclient-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libwbclient0-4.7.8+git.86.94b6d10f7dd-4.15.1 libwbclient0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-client-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-client-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-core-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-debugsource-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-libs-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-libs-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-winbind-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-winbind-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 - SUSE Linux Enterprise High Availability 15 (aarch64 ppc64le s390x x86_64): ctdb-4.7.8+git.86.94b6d10f7dd-4.15.1 ctdb-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-debugsource-4.7.8+git.86.94b6d10f7dd-4.15.1 References: https://www.suse.com/security/cve/CVE-2018-10858.html https://www.suse.com/security/cve/CVE-2018-10918.html https://www.suse.com/security/cve/CVE-2018-10919.html https://www.suse.com/security/cve/CVE-2018-1139.html https://www.suse.com/security/cve/CVE-2018-1140.html https://bugzilla.suse.com/1095048 https://bugzilla.suse.com/1095056 https://bugzilla.suse.com/1095057 https://bugzilla.suse.com/1103411 https://bugzilla.suse.com/1103414 . Crucial SUSE Security Patch for Samba tackling several vulnerabilities and offering essential update guidelines.. SUSE Security, Samba Patch, System Security Update, Linux vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.