Critical evasion in suricata (CVE-2021-35063) References: - https://bugs.mageia.org/show_bug.cgi?id=29012 - https://lists.fedoraproject.org/archives/list/
Various security, performance, accuracy and stability issues have been fixed, including a critical evasion assigned CVE-2021-35063.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-a8ebb71068 2021-07-10 01:12:57.152147 --------------------------------------------------------------------------------Name : suricata Product : Fedora 34 Version : 6.0.3 Release : 1.fc34 URL : Summary : Intrusion Detection System Description : The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field. This new Engine supports Multi-threading, Automatic Protocol Detection (IP, TCP, UDP, ICMP, HTTP, TLS, FTP and SMB! ), Gzip Decompression, Fast IP Matching, and GeoIP identification. --------------------------------------------------------------------------------Update Information: Various security, performance, accuracy and stability issues have been fixed, including a critical evasion assigned CVE-2021-35063. --------------------------------------------------------------------------------ChangeLog: * Thu Jul 1 2021 Steve Grubb 6.0.3-1 - New security and bugfix release - Fix logrotation location (#1966955) * Fri Jun 4 2021 Python Maint - 6.0.2-2 - Rebuilt for Python 3.10 --------------------------------------------------------------------------------References: [ 1 ] Bug #1980454 - CVE-2021-35063 suricata: critical evasion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1980454 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-a8ebb71068' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes three vulnerabilities is now available.. openSUSE Security Update: ClamAV: 0.97.5 update ______________________________________________________________________________ Announcement ID: openSUSE-SU-2012:0833-1 Rating: important References: #767574 Cross-References: CVE-2012-1457 CVE-2012-1458 CVE-2012-1459 Affected Products: openSUSE 12.1 openSUSE 11.4 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update addresses possible evasion cases in some archive formats and stability issues in portions of the bytecode engine. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 12.1: zypper in -t patch openSUSE-2012-362 - openSUSE 11.4: zypper in -t patch openSUSE-2012-362 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 12.1 (i586 x86_64): clamav-0.97.5-4.1 clamav-debuginfo-0.97.5-4.1 clamav-debugsource-0.97.5-4.1 - openSUSE 12.1 (noarch): clamav-db-0.97.5-4.1 - openSUSE 11.4 (i586 x86_64): clamav-0.97.5-10.1 clamav-debuginfo-0.97.5-10.1 clamav-debugsource-0.97.5-10.1 - openSUSE 11.4 (noarch): clamav-db-0.97.5-10.1 References: https://www.suse.com/security/cve/CVE-2012-1457.html https://www.suse.com/security/cve/CVE-2012-1458.html https://www.suse.com/security/cve/CVE-2012-1459.html -- . The latest ClamAV patch targets significant security flaws in Fedora, enhancing its overall resilience and protection.. openSUSE Security Update, ClamAV Patch, System Evasion Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.