An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for csync2 =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F Announcement ID: openSUSE-SU-2021:0853-1 Rating: moderate References: #1147137 #1147139 Cross-References: CVE-2019-15522 CVE-2019-15523 CVSS scores: CVE-2019-15522 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N= /S:U/C:H/I:H/A:H CVE-2019-15522 (SUSE): 3.5 CVSS:3.0/AV:A/AC:L/PR:L/UI:N= /S:U/C:N/I:L/A:N CVE-2019-15523 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N= /S:U/C:N/I:L/A:N CVE-2019-15523 (SUSE): 2.6 CVSS:3.0/AV:A/AC:H/PR:L/UI:N= /S:U/C:N/I:L/A:N Affected Products: openSUSE Leap 15.2 =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F An update that fixes two vulnerabilities is now available. Description: This update for csync2 fixes the following issues: - CVE-2019-15522: Fixed an issue where daemon fails to enforce TLS (bsc#1147137) - CVE-2019-15523: Fixed an incorrect TLS handshake error handling (bsc#1147139) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended instal= lation methods like YaST online=5Fupdate or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-853=3D1 Package List: - openSUSE Leap 15.2 (x86=5F64): csync2-2.0+git.1461714863.10636a4-lp152.5.3.1 csync2-debuginfo-2.0+git.1461714863.10636a4-lp152.5.3.1 csync2-debugsource-2.0+git.1461714863.10636a4-lp152.5.3.1 References: https://www.suse.com/security/cve/CVE-2019-15522.html https://www.suse.com/security/cve/CVE-2019-15523.html https://bugzilla.suse.com/1147137 https://bugzilla.suse.com/1147139 . An update for Debian has been released, targeting potential weaknesses in the application ksync with elevated importance. Explore the enhancements.. openSUSE Update, csync2 Vulnerabilities, Security Advisory. . LinuxSecurity.com Team
USN-6844-1 caused the cupsd daemon to never start. ========================================================================== Ubuntu Security Notice USN-6844-2 June 28, 2024 cups regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: USN-6844-1 caused the cupsd daemon to never start Software Description: - cups: Common UNIX Printing System(tm) Details: USN-6844-1 fixed vulnerabilities in the CUPS package. The update lead to the discovery of a regression in CUPS with regards to how the cupsd daemon handles Listen configuration directive. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Rory McNamara discovered that when starting the cupsd server with a Listen configuration item, the cupsd process fails to validate if bind call passed. An attacker could possibly trick cupsd to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS cups 2.4.7-1.2ubuntu7.2 cups-daemon 2.4.7-1.2ubuntu7.2 Ubuntu 23.10 cups 2.4.6-0ubuntu3.2 cups-daemon 2.4.6-0ubuntu3.2 Ubuntu 22.04 LTS cups 2.4.1op1-1ubuntu4.10 cups-daemon 2.4.1op1-1ubuntu4.10 Ubuntu 20.04 LTS cups 2.3.1-9ubuntu1.8 cups-daemon 2.3.1-9ubuntu1.8 Ubuntu 18.04 LTS cups 2.2.7-1ubuntu2.10+esm5 Available with Ubuntu Pro cups-daemon 2.2.7-1ubuntu2.10+esm5 Available with Ubuntu Pro Ubuntu 16.04 LTS cups 2.1.3-4ubuntu0.11+esm7 Available with Ubuntu Pro cups-daemon 2.1.3-4ubuntu0.11+esm7 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6844-2 https://ubuntu.com/security/notices/USN-6844-1 https://bugs.launchpad.net/ubuntu/+source/cups/+bug/2070315 Package Information: https://launchpad.net/ubuntu/+source/cups/2.4.7-1.2ubuntu7.2 https://launchpad.net/ubuntu/+source/cups/2.4.6-0ubuntu3.2 https://launchpad.net/ubuntu/+source/cups/2.4.1op1-1ubuntu4.10 https://launchpad.net/ubuntu/+source/cups/2.3.1-9ubuntu1.8 . A patch addresses a bug impacting the cupsd service in CUPS throughout several Ubuntu versions post USN-6844-1.. CUPS Daemon Issues, Ubuntu Security Updates, Common Unix Printing System. . Severity: Important. LinuxSecurity.com Team
This update for dbus-1 fixes the following issues: CVE-2023-34969: Fixed a possible dbus-daemon crash by an unprivileged users (bsc#1212126).. # Security update for dbus-1 Announcement ID: SUSE-SU-2023:2877-1 Rating: moderate References: * #1212126 Cross-References: * CVE-2023-34969 CVSS scores: * CVE-2023-34969 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-34969 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.3 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for dbus-1 fixes the following issues: * CVE-2023-34969: Fixed a possible dbus-daemon crash by an unprivileged users (bsc#1212126). ## Patch Instructions: To install this SUSE Moderate update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2023-2877=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-2877=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-2877=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-2877=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-2877=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-2877=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-2877=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-2877=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-2877=1 ## Package List: * openSUSE Leap Micro 5.3 (aarch64 x86_64) * dbus-1-1.12.2-150400.18.8.1 * dbus-1-debuginfo-1.12.2-150400.18.8.1 * dbus-1-x11-1.12.2-150400.18.8.1 * dbus-1-x11-debugsource-1.12.2-150400.18.8.1 * dbus-1-debugsource-1.12.2-150400.18.8.1 * libdbus-1-3-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-1.12.2-150400.18.8.1 * dbus-1-x11-debuginfo-1.12.2-150400.18.8.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * dbus-1-1.12.2-150400.18.8.1 * dbus-1-debuginfo-1.12.2-150400.18.8.1 * dbus-1-x11-1.12.2-150400.18.8.1 * dbus-1-x11-debugsource-1.12.2-150400.18.8.1 * dbus-1-debugsource-1.12.2-150400.18.8.1 * libdbus-1-3-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-1.12.2-150400.18.8.1 * dbus-1-devel-1.12.2-150400.18.8.1 * dbus-1-x11-debuginfo-1.12.2-150400.18.8.1 * openSUSE Leap 15.4 (x86_64) * libdbus-1-3-32bit-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-32bit-1.12.2-150400.18.8.1 * dbus-1-devel-32bit-1.12.2-150400.18.8.1 * dbus-1-32bit-debuginfo-1.12.2-150400.18.8.1 * openSUSE Leap 15.4 (noarch) * dbus-1-devel-doc-1.12.2-150400.18.8.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * dbus-1-1.12.2-150400.18.8.1 * dbus-1-debuginfo-1.12.2-150400.18.8.1 * dbus-1-x11-1.12.2-150400.18.8.1 * dbus-1-x11-debugsource-1.12.2-150400.18.8.1 *dbus-1-debugsource-1.12.2-150400.18.8.1 * libdbus-1-3-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-1.12.2-150400.18.8.1 * dbus-1-devel-1.12.2-150400.18.8.1 * dbus-1-x11-debuginfo-1.12.2-150400.18.8.1 * openSUSE Leap 15.5 (x86_64) * libdbus-1-3-32bit-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-32bit-1.12.2-150400.18.8.1 * dbus-1-devel-32bit-1.12.2-150400.18.8.1 * dbus-1-32bit-debuginfo-1.12.2-150400.18.8.1 * openSUSE Leap 15.5 (noarch) * dbus-1-devel-doc-1.12.2-150400.18.8.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * dbus-1-1.12.2-150400.18.8.1 * dbus-1-debuginfo-1.12.2-150400.18.8.1 * dbus-1-x11-1.12.2-150400.18.8.1 * dbus-1-x11-debugsource-1.12.2-150400.18.8.1 * dbus-1-debugsource-1.12.2-150400.18.8.1 * libdbus-1-3-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-1.12.2-150400.18.8.1 * dbus-1-x11-debuginfo-1.12.2-150400.18.8.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * dbus-1-1.12.2-150400.18.8.1 * dbus-1-debuginfo-1.12.2-150400.18.8.1 * dbus-1-x11-1.12.2-150400.18.8.1 * dbus-1-x11-debugsource-1.12.2-150400.18.8.1 * dbus-1-debugsource-1.12.2-150400.18.8.1 * libdbus-1-3-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-1.12.2-150400.18.8.1 * dbus-1-x11-debuginfo-1.12.2-150400.18.8.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * dbus-1-1.12.2-150400.18.8.1 * dbus-1-debuginfo-1.12.2-150400.18.8.1 * dbus-1-x11-1.12.2-150400.18.8.1 * dbus-1-x11-debugsource-1.12.2-150400.18.8.1 * dbus-1-debugsource-1.12.2-150400.18.8.1 * libdbus-1-3-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-1.12.2-150400.18.8.1 * dbus-1-x11-debuginfo-1.12.2-150400.18.8.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * dbus-1-1.12.2-150400.18.8.1 * dbus-1-debuginfo-1.12.2-150400.18.8.1 * dbus-1-x11-1.12.2-150400.18.8.1 * dbus-1-x11-debugsource-1.12.2-150400.18.8.1 * dbus-1-debugsource-1.12.2-150400.18.8.1 *libdbus-1-3-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-1.12.2-150400.18.8.1 * dbus-1-x11-debuginfo-1.12.2-150400.18.8.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * dbus-1-1.12.2-150400.18.8.1 * dbus-1-debuginfo-1.12.2-150400.18.8.1 * dbus-1-x11-1.12.2-150400.18.8.1 * dbus-1-x11-debugsource-1.12.2-150400.18.8.1 * dbus-1-debugsource-1.12.2-150400.18.8.1 * libdbus-1-3-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-1.12.2-150400.18.8.1 * dbus-1-devel-1.12.2-150400.18.8.1 * dbus-1-x11-debuginfo-1.12.2-150400.18.8.1 * Basesystem Module 15-SP4 (x86_64) * libdbus-1-3-32bit-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-32bit-1.12.2-150400.18.8.1 * dbus-1-32bit-debuginfo-1.12.2-150400.18.8.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * dbus-1-1.12.2-150400.18.8.1 * dbus-1-debuginfo-1.12.2-150400.18.8.1 * dbus-1-x11-1.12.2-150400.18.8.1 * dbus-1-x11-debugsource-1.12.2-150400.18.8.1 * dbus-1-debugsource-1.12.2-150400.18.8.1 * libdbus-1-3-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-1.12.2-150400.18.8.1 * dbus-1-devel-1.12.2-150400.18.8.1 * dbus-1-x11-debuginfo-1.12.2-150400.18.8.1 * Basesystem Module 15-SP5 (x86_64) * libdbus-1-3-32bit-debuginfo-1.12.2-150400.18.8.1 * libdbus-1-3-32bit-1.12.2-150400.18.8.1 * dbus-1-32bit-debuginfo-1.12.2-150400.18.8.1 ## References: * https://www.suse.com/security/cve/CVE-2023-34969.html * https://bugzilla.suse.com/show_bug.cgi?id=1212126 . Important security patch resolves dbus-1 vulnerabilities, tackling daemon stability problems across numerous openSUSE releases.. dbus-1 Update, openSUSE Security, daemon Fix. . LinuxSecurity.com Team
Updated sysklogd packages.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-033 2005-01-19 ---------------------------------------------------------------------Product : Fedora Core 3 Name : sysklogd Version : 1.4.1 Release : 26_FC3 Summary : System logging and kernel message trapping daemons. Description : The sysklogd package contains two system utilities (syslogd and klogd) which provide support for system logging. Syslogd and klogd run as daemons (background processes) and log system messages to different places, like sendmail logs, security logs, error logs, etc. ---------------------------------------------------------------------Update Information: Updated sysklogd packages. ---------------------------------------------------------------------* Fri Jan 14 2005 Jason Vas Dias 1.4.1rh-26 - Final fixup of '@host' name checking code: remove possible - duplicates properly * Tue Jan 04 2005 Jason Vas Dias 1.4.1rh-25 - Fix bug 144084 - bad version of '@host' name checking code - used by mistake + memory corruption caused by free of - addrinfo node returned by getaddrinfo(). * Thu Dec 02 2004 Jason Vas Dias 1.4.1rh-24 - Allow kernel printk's to emit an odd number of continuous '%'s . - (#141545) * Thu Dec 02 2004 Jason Vas Dias 1.4.1rh-24 - Do not allow hostnames that resolve to the address of a local - interface to be used for forwarding, else syslogd gets into - an infinite loop sending messages to itself (as reported by - Chuck Mead ). * Wed Dec 01 2004 Jason Vas Dias 1.4.1rh-23 - Allow SIGALRM to interrupt system calls, as syslogd expects. - In Fedora Core, signal(SIGALRM,...) uses SA_RESTART; one is - required to use siginterrupt() to get interruptable system calls. - (#140983) * Wed Aug 25 2004 Jason Vas Dias 1.4.1rh-22 - Fix race condition where child sends SIGTERM before parent handles it - (#126223,#123906) * Mon Jun 28 2004 Bill Nottingham 1.4.1rh-21 - async logging for mail (#73306) * Sun Jun 20 2004 Florian La Roche - do not set bsd compat on sockets #123912 - fix empty log lines #125679 * Fri Jun 11 2004 Florian La Roche 1.4.1rh-18 - make the race for -HUP a little bit smaller * Wed Jun 09 2004 Bill Nottingham 1.4.1rh-17 - don't escape UTF-8 (#89292, #71170, #112519) * Mon May 03 2004 Bill Nottingham 1.4.1rh-16 - add Owl patch for crunch_list function, fixes potential crashes (#120453) * Wed Apr 07 2004 Bill Nottingham 1.4.1rh-15 - fix recvfrom() on 64-bit big-endian platforms (#120201) * Mon Mar 08 2004 Bill Nottingham 1.4.1rh-14 - rebuild (#117696) * Thu Feb 12 2004 Thomas Woerner 1.4.1rh-13 - make sysklogd pie * Fri Feb 07 2003 Tim Powers 1.4.1rh-12 - rebuild * Wed Jan 08 2003 Tim Powers 1.4.1rh-11 - bump release number * Fri Dec 20 2002 Elliot Lee 1.4.1rh-10 - _smp_mflags * Mon Jun 17 2002 Bill Nottingham 1.4.1rh-9 - don't forcibly strip binaries * Wed Apr 17 2002 Bill Nottingham 1.4.1rh-8 - revert loglevel setting to previous behavior (#63664) * Tue Mar 12 2002 Bill Nottingham 1.4.1rh-7 - don't *require* logrotate, but conflict with older versions - fix fd leak of System.map (#52901) - switch to -x for klogd by default; we have kksymoops - provide LSB facility * Wed Aug 15 2001 Bill Nottingham - enable LFS for log files * Tue Aug 14 2001 Bill Nottingham - fix comments in config file (#51678) * Fri Aug 03 2001 Bill Nottingham - require a specific version of logrotate (#50794) - fix %preun for the case when it's not running (#50123) * Sun Jul 08 2001 Bill Nottingham - merge with 1.4.1 * Wed Feb 07 2001 Bill Nottingham - i18n tweaks * Tue Jan 23 2001 Bill Nottingham - new translation stuff * Fri Jan 19 2001 Bill Nottingham - adapt /etc/sysconfig/syslog for specification of arbitrary options (#23171) - fix translation stringslightly (#24088) * Mon Dec 18 2000 Bill Nottingham - don't set owner/group on manpages on install - read /etc/sysconfig/syslog if present for some configuration paramters - fix build with new kernel headers * Tue Dec 12 2000 Bill Nottingham - start klogd with '-2' * Mon Dec 11 2000 Bill Nottingham - update to 1.4 * Fri Dec 01 2000 Bill Nottingham - rebuild because of broken fileutils * Fri Oct 13 2000 Bill Nottingham - don't log cron in two separate places (#18122) * Thu Sep 14 2000 Bill Nottingham - more fixes from
Get the latest Linux and open source security news straight to your inbox.