Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Update to 0.3.5 to fix FTBFS and test failures. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-fc7c0ca5c5 2025-03-05 01:14:13.862674+00:00 -------------------------------------------------------------------------------- Name : fscrypt Product : Fedora 41 Version : 0.3.5 Release : 2.fc41 URL : https://github.com/google/fscrypt Summary : Go tool for managing Linux filesystem encryption Description : fscrypt is a high-level tool for the management of Linux filesystem encryption. This tool manages metadata, key generation, key wrapping, PAM integration, and provides a uniform interface for creating and modifying encrypted directories. -------------------------------------------------------------------------------- Update Information: Update to 0.3.5 to fix FTBFS and test failures -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2025 Neal Gompa - 0.3.5-2 - Backport fix for tests on non-x86 arches * Fri Feb 14 2025 Neal Gompa - 0.3.5-1 - Update to 0.3.5 - Add patch to fix building tests with Go 1.24 * Thu Jan 16 2025 Fedora Release Engineering - 0.3.4-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2325331 - fscrypt being built with vulnerable golang version 1.23rc1 https://bugzilla.redhat.com/show_bug.cgi?id=2325331 [ 2 ] Bug #2334787 - fscrypt 0.3.5 available https://bugzilla.redhat.com/show_bug.cgi?id=2334787 [ 3 ] Bug #2340182 - fscrypt: FTBFS in Fedora rawhide/f42 https://bugzilla.redhat.com/show_bug.cgi?id=2340182 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-fc7c0ca5c5' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --- See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-5ef0bd9a27 2022-07-30 01:52:05.591823 --------------------------------------------------------------------------------Name : age Product : Fedora 36 Version : 1.0.0 Release : 6.fc36 URL : https://github.com/FiloSottile/age Summary : Simple, modern and secure encryption tool Description : A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability. --------------------------------------------------------------------------------Update Information: Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Maxwell G 1.0.0-6 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-5ef0bd9a27' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list--
An updated gnupg2 package that fixes one security issue is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: gnupg2 security update Advisory ID: RHSA-2010:0603-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2010:0603.html Issue date: 2010-08-04 CVE Names: CVE-2010-2547 ==================================================================== 1. Summary: An updated gnupg2 package that fixes one security issue is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and creating digital signatures, compliant with the proposed OpenPGP Internet standard and the S/MIME standard. A use-after-free flaw was found in the way gpgsm, a Cryptographic Message Syntax (CMS) encryption and signing tool, handled X.509 certificates with a large number of Subject Alternate Names. A specially-crafted X.509 certificate could, when imported, cause gpgsm to crash or, possibly, execute arbitrary code. (CVE-2010-2547) All gnupg2 users should upgrade to this updated package, which contains a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your systemhave been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 618156 - CVE-2010-2547 GnuPG 2: use-after-free when importing certificate with many alternate names 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: gnupg2-2.0.10-3.el5_5.1.i386.rpm gnupg2-debuginfo-2.0.10-3.el5_5.1.i386.rpm x86_64: gnupg2-2.0.10-3.el5_5.1.x86_64.rpm gnupg2-debuginfo-2.0.10-3.el5_5.1.x86_64.rpm Red Hat Enterprise Linux (v. 5 server): Source: i386: gnupg2-2.0.10-3.el5_5.1.i386.rpm gnupg2-debuginfo-2.0.10-3.el5_5.1.i386.rpm ia64: gnupg2-2.0.10-3.el5_5.1.ia64.rpm gnupg2-debuginfo-2.0.10-3.el5_5.1.ia64.rpm ppc: gnupg2-2.0.10-3.el5_5.1.ppc.rpm gnupg2-debuginfo-2.0.10-3.el5_5.1.ppc.rpm s390x: gnupg2-2.0.10-3.el5_5.1.s390x.rpm gnupg2-debuginfo-2.0.10-3.el5_5.1.s390x.rpm x86_64: gnupg2-2.0.10-3.el5_5.1.x86_64.rpm gnupg2-debuginfo-2.0.10-3.el5_5.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2010-2547 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2010 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFMWeeeXlSAg2UNWIIRArjUAJ9gK8m3Yr8IdymQsathMcBlFmLsDACgspkq Tw2T0sJAGDP/5gFesM2Ne7Y=kxV+ -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.