Force cabal upload to always use digest auth and never basic auth Note this only affects uploading of new source tarballs to Hackage by Haskell upstream package maintainers. It is safer to upload packages via the Hackage web interface.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-8206 2015-05-14 20:20:21 -------------------------------------------------------------------------------- Name : haskell-platform Product : Fedora 22 Version : 2014.2.0.0.2 Release : 4.fc22 URL : https://www.haskell.org/platform/ Summary : Standard Haskell distribution Description : Haskell Platform is a suite of stable and well used Haskell libraries and tools. It provides a good starting environment for Haskell development. -------------------------------------------------------------------------------- Update Information: Force cabal upload to always use digest auth and never basic auth Note this only affects uploading of new source tarballs to Hackage by Haskell upstream package maintainers. It is safer to upload packages via the Hackage web interface. -------------------------------------------------------------------------------- ChangeLog: * Wed May 13 2015 Jens Petersen - 2014.2.0.0.3-4 - bump cabal-install to 1.18.1.0 and allow newer versions -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update haskell-platform' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist
Pavuk contains a bug that can allow an attacker to run arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200407-19 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Pavuk: Digest authentication helper buffer overflow Date: July 26, 2004 ID: 200407-19 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Pavuk contains a bug that can allow an attacker to run arbitrary code. Background ========= Pavuk is web spider and website mirroring tool. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/pavuk = 0.9.28-r3 Description ========== Pavuk contains several buffer overflow vulnerabilities in the code handling digest authentication. Impact ===== An attacker could cause a buffer overflow, leading to arbitrary code execution with the rights of the user running Pavuk. Workaround ========= There is no known workaround at this time. All users are encouraged to upgrade to the latest available version of Pavuk. Resolution ========= All Pavuk users should upgrade to the latest version: # emerge sync # emerge -pv "> =net-misc/pavuk-0.9.28-r3" # emerge "> =net-misc/pavuk-0.9.28-r3" Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200407-19 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressedto
Get the latest Linux and open source security news straight to your inbox.