Rebuilt with rust-tar 0.4.45 for CVE-2026-33056. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-25285d56e4 2026-03-31 00:16:35.926034+00:00 -------------------------------------------------------------------------------- Name : stgit Product : Fedora 44 Version : 2.5.5 Release : 5.fc44 URL : https://stacked-git.github.io/ Summary : Stack-based patch management for Git Description : Stacked Git, StGit for short, is an application for managing Git commits as a stack of patches. With a patch stack workflow, multiple patches can be developed concurrently and efficiently, with each patch focused on a single concern, resulting in both a clean Git commit history and improved productivity. -------------------------------------------------------------------------------- Update Information: Rebuilt with rust-tar 0.4.45 for CVE-2026-33056 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 22 2026 Benjamin A. Beasley - 2.5.5-5 - Rebuilt with rust-tar 0.4.45 for CVE-2026-33056 - Fixes RHBZ#2449690 - Updated the License expression and wrote it one-term-per-line -------------------------------------------------------------------------------- References: [ 1 ] Bug #2449690 - CVE-2026-33056 stgit: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449690 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-25285d56e4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can befound at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fixes CVE-2025-58188, unretire package and update to 3.8.2.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-36b3527937 2025-12-22 01:05:58.831277+00:00 -------------------------------------------------------------------------------- Name : gobuster Product : Fedora 42 Version : 3.8.2 Release : 2.fc42 URL : https://github.com/OJ/gobuster Summary : Directory/File, DNS and VHost busting tool written in Go Description : Directory/File, DNS and VHost busting tool written in Go. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2025-58188, unretire package and update to 3.8.2. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 5 2025 Emir Akdag - 3.8.2-1 - Unretire package and update to 3.8.2 - Fix CVE-2025-58188 - Switch to modern go-vendor-tools packaging -------------------------------------------------------------------------------- References: [ 1 ] Bug #2418895 - Review Request: gobuster - Directory/File, DNS and VHost busting tool written in Go https://bugzilla.redhat.com/show_bug.cgi?id=2418895 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-36b3527937' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fixes CVE-2025-40909 - Clone dirhandles without fchdir. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f142899732 2025-07-13 02:56:45.883771+00:00 -------------------------------------------------------------------------------- Name : perl Product : Fedora 41 Version : 5.40.2 Release : 516.fc41 URL : https://www.perl.org/ Summary : Practical Extraction and Report Language Description : Perl is a high-level programming language with roots in C, sed, awk and shell scripting. Perl is good at handling processes and files, and is especially good at handling text. Perl's hallmarks are practicality and efficiency. While it is used to do a lot of different things, Perl's most common applications are system administration utilities and web programming. This is a metapackage with all the Perl bits and core modules that can be found in the upstream tarball from perl.org. If you need only a specific feature, you can install a specific package instead. E.g. to handle Perl scripts with /usr/bin/perl interpreter, install perl-interpreter package. See perl-interpreter description for more details on the Perl decomposition into packages. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2025-40909 - Clone dirhandles without fchdir -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 9 2025 Jitka Plesnikova - 4:5.40.2-516 - Fixes: CVE-2025-40909 - Clone dirhandles without fchdir -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369463 - CVE-2025-40909 perl: Perl threads have a working directory race condition where file operations may target unintended paths [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2369463 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f142899732' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
XFree86 creates a directory in /tmp with the name .X11-unix for the X sockets and sets the directory to mode 1777. If an attacker creates a symlink with that filename and points it to another directory (e.g. /root), the permissions of the target directory is set to 1777. . ______________________________________________________________________________ SuSE Security Announcement Package: xf86-3.3.3-5 Date: Sun Mar 28 12:26:39 CEST 1999 Affected: unix operating systems using xfree86 ______________________________________________________________________________ A security hole was discovered in the package mentioned above. Please update as soon as possible or disable the service if you are using this software on your SuSE Linux installation(s). Other Linux distributions or operating systems might be affected as well, please contact your vendor for information about this issue. Thanks to the people from bugtraq for providing the details of this vulnerability and especially the XFree86 programmers who made a fix ready over the weekend. Please note, that we provide this information on as "as-is" basis only. There is no warranty whatsoever and no liability for any direct, indirect or incidental damage arising from this information or the installation of the update package. ______________________________________________________________________________ 1. Problem Description XFree86 creates a directory in /tmp with the name .X11-unix for the X sockets and sets the directory to mode 1777. If an attacker creates a symlink with that filename and points it to another directory (e.g. /root), the permissions of the target directory is set to 1777. 2. Impact A local attacker may create files with any contents in any directory. 3. Solution Upgrade your XF86. As a temporary fix you can put these commands into /sbin/init.d/boot.local: /bin/rm -rf /tmp/.X11-unix mkdir -p -m 1777/tmp/.X11-unix ______________________________________________________________________________ Here are the md5 checksums of the upgrade packages, please verify these before installing the new packages: glibc archives (SuSE 6.0): d2bb4132bc487debea45288f8199e1e7 x8514-3.3.3.1-13.i386.rpm 5f5b6a53027d54cb9df4cafcb284d720 xagx-3.3.3.1-13.i386.rpm 0c651985aa39750ed787df42c9dc49f7 xfbdev-3.3.3.1-13.i386.rpm 7353be5812375a350c7499e4bb4f7781 xglint-3.3.3.1-13.i386.rpm 88182f0e22ed3f4f564d0f678dc37ffe xi128-3.3.3.1-13.i386.rpm 492ddd01dd10dcb83d2cbf5995b7396b xlkit-3.3.3.1-13.i386.rpm 5779042312519b30e214d8aa4b9c2313 xmach32-3.3.3.1-13.i386.rpm 9fee0e2a4bcf4fbaa91759bc004faf88 xmach64-3.3.3.1-13.i386.rpm 338041da9001b5e36c55f9ffa6209613 xmach8-3.3.3.1-13.i386.rpm 68124d6e36cc48396aad4e395cb9567b xmono-3.3.3.1-13.i386.rpm ea4c0301ee8f33339f5908d82a4b271d xp9k-3.3.3.1-13.i386.rpm d219a182a79723b258b28f87bc22ee68 xs3-3.3.3.1-13.i386.rpm d8ad0f9b0d57f887cc076e794a749738 xs3v-3.3.3.1-13.i386.rpm ff0c37343e5bd30261ab7f05604ea6e7 xsvga-3.3.3.1-13.i386.rpm e151bf1ed2d6c9824b2c521dcf2f7141 xvga16-3.3.3.1-13.i386.rpm 9099ebe5428098f8ffacd1ab691b5937 xw32-3.3.3.1-13.i386.rpm 5627fc4da2eab1f56a9e636374982ede xxprt-3.3.3.1-13.i386.rpm libc5 archives (SuSE
Get the latest Linux and open source security news straight to your inbox.