gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c (CVE-2020-12658). References: - https://bugs.mageia.org/show_bug.cgi?id=28019 . MGASA-2021-0081 - Updated gssproxy package fixes a security vulnerability Publication date: 11 Feb 2021 URL: https://advisories.mageia.org/MGASA-2021-0081.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-12658 gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c (CVE-2020-12658). References: - https://bugs.mageia.org/show_bug.cgi?id=28019 - https://lists.debian.org/debian-lts-announce/2021/01/msg00004.html - https://www.cve.org/CVERecord?id=CVE-2020-12658 SRPMS: - 7/core/gssproxy-0.8.2-2.1.mga7 . Mageia 2022-0092 introduces kernel patches to fix vulnerabilities, ensuring improved performance and safeguarding user data.. gssproxy Update, Mageia Security, gssproxy Issue. . LinuxSecurity.com Team
Updated subversion packages fix security vulnerabilities: Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer (CVE-2018-11782). . MGASA-2019-0243 - Updated subversion packages fix security vulnerabilities Publication date: 06 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0243.html Type: security Affected Mageia releases: 6, 7 CVE: CVE-2018-11782, CVE-2019-0203 Updated subversion packages fix security vulnerabilities: Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer (CVE-2018-11782). Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands (CVE-2019-0203). References: - https://bugs.mageia.org/show_bug.cgi?id=25230 - https://subversion.apache.org/security/CVE-2018-11782-advisory.txt - https://subversion.apache.org/security/CVE-2019-0203-advisory.txt - https://www.cve.org/CVERecord?id=CVE-2018-11782 - https://www.cve.org/CVERecord?id=CVE-2019-0203 SRPMS: - 7/core/subversion-1.10.6-1.mga7 - 6/core/subversion-1.9.12-1.mga6 . Recent updates to subversion packages address security flaws impacting server operations and commands in Mageia versions H-6 and H-7.. Subversion Security Update, Mageia Releases, Server Process Fixes, Protocol Command Issues. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.