An update that solves three vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for sudo ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0225-1 Rating: important References: #1180684 #1180685 #1180687 #1181090 Cross-References: CVE-2021-23239 CVE-2021-23240 CVE-2021-3156 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that solves three vulnerabilities and has one errata is now available. Description: This update for sudo fixes the following issues: - A Heap-based buffer overflow in sudo could be exploited to allow a user to gain root privileges [bsc#1181090,CVE-2021-3156] - It was possible for a user to test for the existence of a directory due to a Race Condition in `sudoedit` [bsc#1180684,CVE-2021-23239] - A Possible Symlink Attack vector existed in `sudoedit` if SELinux was running in permissive mode [bsc#1180685, CVE-2021-23240] - It was possible for a User to enable Debug Settings not Intended for them [bsc#1180687] Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-225=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-225=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): sudo-debuginfo-1.8.27-4.6.1 sudo-debugsource-1.8.27-4.6.1 sudo-devel-1.8.27-4.6.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390xx86_64): sudo-1.8.27-4.6.1 sudo-debuginfo-1.8.27-4.6.1 sudo-debugsource-1.8.27-4.6.1 References: https://www.suse.com/security/cve/CVE-2021-23239.html https://www.suse.com/security/cve/CVE-2021-23240.html https://www.suse.com/security/cve/CVE-2021-3156.html https://bugzilla.suse.com/1180684 https://bugzilla.suse.com/1180685 https://bugzilla.suse.com/1180687 https://bugzilla.suse.com/1181090 . Red Hat Security Patch addresses various vulnerabilities in OpenSSH, bolstering system integrity and reliability.. SUSE Linux Enterprise, sudo security, important updates, system integrity. . Severity: Important. LinuxSecurity.com Team
Fix to directory traversal attacks (CVE-2017-17042).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-ca05b30e86 2017-12-12 13:48:05.815813 --------------------------------------------------------------------------------Name : rubygem-yard Product : Fedora 25 Version : 0.8.7.6 Release : 4.fc25 URL : https://yardoc.org/ Summary : Documentation tool for consistent and usable documentation in Ruby Description : YARD is a documentation generation tool for the Ruby programming language. It enables the user to generate consistent, usable documentation that can be exported to a number of formats very easily, and also supports extending for custom Ruby constructs such as custom class level definitions. --------------------------------------------------------------------------------Update Information: Fix to directory traversal attacks (CVE-2017-17042). --------------------------------------------------------------------------------References: [ 1 ] Bug #1519065 - CVE-2017-17042 rubygem-yard: (lib/yard/core_ext/file.rb) is vulnerable to directory traversal attacks https://bugzilla.redhat.com/show_bug.cgi?id=1519065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade rubygem-yard' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.