Fixes for GStreamer-SA-2023-0010 (ZDI-CAN-22299) and GStreamer-SA-2023-0009 (ZDI-CAN-22226) (CVE-2023-44429). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-1661e0af22 2023-11-19 01:23:27.465329 -------------------------------------------------------------------------------- Name : gstreamer1-doc Product : Fedora 39 Version : 1.22.7 Release : 1.fc39 URL : https://gstreamer.freedesktop.org/ Summary : GStreamer documentation Description : GStreamer documentation. -------------------------------------------------------------------------------- Update Information: Fixes for GStreamer-SA-2023-0010 (ZDI-CAN-22299) and GStreamer-SA-2023-0009 (ZDI-CAN-22226) (CVE-2023-44429) -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 14 2023 Gwyn Ciesla - 1.22.7-1 - 1.22.7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2249492 - gst-devtools-1.22.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=2249492 [ 2 ] Bug #2249493 - python-gstreamer1-1.22.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=2249493 [ 3 ] Bug #2249522 - gstreamer1-1.22.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=2249522 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1661e0af22' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves two vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for documentation-suse-openstack-cloud, kibana, openstack-keystone, openstack-monasca-notification ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1654-1 Rating: important References: #1186868 #1189390 #1197204 Cross-References: CVE-2021-22141 CVE-2021-38155 CVSS scores: CVE-2021-22141 (SUSE): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVE-2021-38155 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: HPE Helion Openstack 8 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud Crowbar 8 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for documentation-suse-openstack-cloud, kibana, openstack-keystone, openstack-monasca-notification fixes the following issues: - CVE-2021-22141: Fixed URL redirection flaw (bsc#1186868). - CVE-2021-38155: Fixed information disclosure during account locking (bsc#1189390). The following non-security bugs were fixed: - Fix smtp server authentication (bsc#1197204) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2022-1654=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2022-1654=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2022-1654=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (noarch): documentation-suse-openstack-cloud-deployment-8.20211112-1.38.1 documentation-suse-openstack-cloud-supplement-8.20211112-1.38.1 documentation-suse-openstack-cloud-upstream-admin-8.20211112-1.38.1 documentation-suse-openstack-cloud-upstream-user-8.20211112-1.38.1 openstack-keystone-12.0.4~dev11-5.36.1 openstack-keystone-doc-12.0.4~dev11-5.36.1 openstack-monasca-notification-1.10.2~dev4-3.9.1 python-keystone-12.0.4~dev11-5.36.1 python-monasca-notification-1.10.2~dev4-3.9.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): kibana-4.6.6-3.12.1 kibana-debuginfo-4.6.6-3.12.1 - SUSE OpenStack Cloud 8 (x86_64): kibana-4.6.6-3.12.1 kibana-debuginfo-4.6.6-3.12.1 - SUSE OpenStack Cloud 8 (noarch): documentation-suse-openstack-cloud-installation-8.20211112-1.38.1 documentation-suse-openstack-cloud-operations-8.20211112-1.38.1 documentation-suse-openstack-cloud-opsconsole-8.20211112-1.38.1 documentation-suse-openstack-cloud-planning-8.20211112-1.38.1 documentation-suse-openstack-cloud-security-8.20211112-1.38.1 documentation-suse-openstack-cloud-supplement-8.20211112-1.38.1 documentation-suse-openstack-cloud-upstream-admin-8.20211112-1.38.1 documentation-suse-openstack-cloud-upstream-user-8.20211112-1.38.1 documentation-suse-openstack-cloud-user-8.20211112-1.38.1 openstack-keystone-12.0.4~dev11-5.36.1 openstack-keystone-doc-12.0.4~dev11-5.36.1 openstack-monasca-notification-1.10.2~dev4-3.9.1 python-keystone-12.0.4~dev11-5.36.1 python-monasca-notification-1.10.2~dev4-3.9.1 venv-openstack-keystone-x86_64-12.0.4~dev11-11.45.1 venv-openstack-monasca-x86_64-2.2.2~dev1-11.45.1 - HPE Helion Openstack 8 (noarch): documentation-hpe-helion-openstack-installation-8.20211112-1.38.1 documentation-hpe-helion-openstack-operations-8.20211112-1.38.1 documentation-hpe-helion-openstack-opsconsole-8.20211112-1.38.1 documentation-hpe-helion-openstack-planning-8.20211112-1.38.1 documentation-hpe-helion-openstack-security-8.20211112-1.38.1 documentation-hpe-helion-openstack-user-8.20211112-1.38.1 openstack-keystone-12.0.4~dev11-5.36.1 openstack-keystone-doc-12.0.4~dev11-5.36.1 openstack-monasca-notification-1.10.2~dev4-3.9.1 python-keystone-12.0.4~dev11-5.36.1 python-monasca-notification-1.10.2~dev4-3.9.1 venv-openstack-keystone-x86_64-12.0.4~dev11-11.45.1 venv-openstack-monasca-x86_64-2.2.2~dev1-11.45.1 - HPE Helion Openstack 8 (x86_64): kibana-4.6.6-3.12.1 kibana-debuginfo-4.6.6-3.12.1 References: https://www.suse.com/security/cve/CVE-2021-22141.html https://www.suse.com/security/cve/CVE-2021-38155.html https://bugzilla.suse.com/1186868 https://bugzilla.suse.com/1189390 https://bugzilla.suse.com/1197204 . SUSE Security Patch resolves critical concerns in OpenStack documentation, enhancing security and reliability for end users.. SUSE Security Update, OpenStack Documentation, Security Fixes. . Severity: Important. LinuxSecurity.com Team
Update to 3.6.5. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-a042f795b2 2018-04-09 19:08:06.183607 --------------------------------------------------------------------------------Name : python3-docs Product : Fedora 27 Version : 3.6.5 Release : 1.fc27 URL : https://www.python.org/ Summary : Documentation for the Python 3 programming language Description : The python3-docs package contains documentation on the Python 3 programming language and interpreter. Install the python3-docs package if you'd like to use the documentation for the Python 3 language. --------------------------------------------------------------------------------Update Information: Update to 3.6.5 --------------------------------------------------------------------------------References: [ 1 ] Bug #1548683 - Filter bogus rpmlint errors/warnings https://bugzilla.redhat.com/show_bug.cgi?id=1548683 [ 2 ] Bug #1560103 - Invalid content of C header file /usr/include/python3.6m/pyconfig.h https://bugzilla.redhat.com/show_bug.cgi?id=1560103 [ 3 ] Bug #1560295 - /usr/lib/debug/usr/lib64/libpython3.6m.so.1.0-3.6.4-20.fc28.x86_64.debug-gdb.py has wrong shebang https://bugzilla.redhat.com/show_bug.cgi?id=1560295 [ 4 ] Bug #1563462 - CVE-2018-1060 CVE-2018-1061 python3: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1563462 [ 5 ] Bug #1546990 - pathfix.py leaves bunch of ~ suffixed files around https://bugzilla.redhat.com/show_bug.cgi?id=1546990 [ 6 ] Bug #1531253 - %py_byte_compile() macro works for Python 3 only https://bugzilla.redhat.com/show_bug.cgi?id=1531253 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade python3-docs' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to Firefox 3.0.10 fixing one security issue: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ Depending packages rebuilt against new Firefox are also included in this update. Additional bugs fixed in other packages: - totem: Fix YouTube plugin following web site changes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-4078 2009-04-28 00:41:54 -------------------------------------------------------------------------------- Name : yelp Product : Fedora 9 Version : 2.22.1 Release : 12.fc9 URL : Summary : A system documentation reader from the Gnome project Description : Yelp is the Gnome 2 help/documentation browser. It is designed to help you browse all the documentation on your system in one central tool. -------------------------------------------------------------------------------- Update Information: Update to Firefox 3.0.10 fixing one security issue: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-3.0/ Depending packages rebuilt against new Firefox are also included in this update. Additional bugs fixed in other packages: - totem: Fix YouTube plugin following web site changes -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 27 2009 Christopher Aillon - 2.22.1-12 - Rebuild against newer gecko * Tue Apr 21 2009 Christopher Aillon - 2.22.1-11 - Rebuild against newer gecko * Fri Mar 27 2009 Christopher Aillon - 2.22.1-10 - Rebuild against newer gecko * Fri Mar 6 2009 Jan Horak - 2.22.1-9 - Rebuild against newer gecko * Wed Feb 4 2009 Christopher Aillon - 2.22.1-8 - Rebuild against newer gecko * Wed Dec 17 2008 Christopher Aillon - 2.22.1-7 - Rebuild against newer gecko * Wed Nov 12 2008 Christopher Aillon - 2.22.1-6 - Rebuild against newer gecko * Wed Sep 24 2008 Christopher Aillon - 2.22.1-5 - Rebuild against newer gecko * Wed Jul 16 2008 Christopher Aillon -2.22.1-4 - Rebuild against newer gecko * Wed Jun 18 2008 Martin Stransky - 2.22.1-3 - rebuild against xulrunner * Mon May 19 2008 Matthew Barnes - 2.22.1-2 - Require docbook-dtds (RH bug #447209). -------------------------------------------------------------------------------- References: [ 1 ] Bug #497447 - CVE-2009-1313 Firefox crash in nsTextFrame::ClearTextRun() https://bugzilla.redhat.com/show_bug.cgi?id=497447 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update yelp' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.