31.0.5 release RHBZ#2364462 RHBZ#2366729 RHBZ#2366735. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d636dbcc45 2025-06-04 02:09:45.732933+00:00 -------------------------------------------------------------------------------- Name : nextcloud Product : Fedora 42 Version : 31.0.5 Release : 1.fc42 URL : http://nextcloud.com Summary : Private file sync and share server Description : NextCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your devices and enables basic editing right on the web. NextCloud is extendable via a simple but powerful API for applications and plugins. -------------------------------------------------------------------------------- Update Information: 31.0.5 release RHBZ#2364462 RHBZ#2366729 RHBZ#2366735 -------------------------------------------------------------------------------- ChangeLog: * Mon May 26 2025 Andrew Bauer - 31.0.5-1 - 31.0.5 release RHBZ#2364462 RHBZ#2366729 RHBZ#2366735 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2364462 - nextcloud-31.0.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2364462 [ 2 ] Bug #2366729 - CVE-2025-48050 nextcloud: DOMPurify Path Traversal Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2366729 [ 3 ] Bug #2366735 - CVE-2025-48050 nextcloud: DOMPurify Path Traversal Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2366735 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d636dbcc45' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to version 1.26.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.26.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-fa2d7b25d9 2023-11-18 01:32:59.408277 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 37 Version : 1.26.0 Release : 1.fc37 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.26.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.26.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 9 2023 Fabio Valentini - 1.26.0-1 - Update to version 1.26.0; Fixes RHBZ#2248507 * Thu Nov 9 2023 Fabio Valentini - 1.25.0-2 - Ignore some test timeouts on s390x * Thu Nov 9 2023 Fabio Valentini - 1.25.0-1 - Update to version 1.25.0; Fixes RHBZ#2242032 * Thu Nov 9 2023 Fabio Valentini - 1.24.0-1 - Update to version 1.24.0; Fixes RHBZ#2237824 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2248412 - syncthing: golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2248412 -------------------------------------------------------------------------------- This update can be installed with the "dnf"update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-fa2d7b25d9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 20.0.11; Fixes one high severity and multiple low severity CVEs. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-9b421b78af 2021-07-22 01:13:10.976131 --------------------------------------------------------------------------------Name : nextcloud Product : Fedora 34 Version : 20.0.11 Release : 1.fc34 URL : http://nextcloud.com Summary : Private file sync and share server Description : NextCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your devices and enables basic editing right on the web. NextCloud is extendable via a simple but powerful API for applications and plugins. --------------------------------------------------------------------------------Update Information: Update to 20.0.11; Fixes one high severity and multiple low severity CVEs --------------------------------------------------------------------------------ChangeLog: * Mon Jul 12 2021 Christopher Engelhard 20.0.11-1 - Update to 20.0.11; Fixes RHBZ#1981503; Fixes RHBZ#1981505 --------------------------------------------------------------------------------References: [ 1 ] Bug #1981503 - CVE-2021-32688 nextcloud: Improper permission check permits tokens to change their own permissions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1981503 [ 2 ] Bug #1981505 - CVE-2021-32680 nextcloud: Improper audit logging for expiration date events [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1981505 [ 3 ] Bug #1981817 - CVE-2021-32678 nextcloud: ratelimit not applied on OCS API responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1981817 [ 4 ] Bug #1981819 - CVE-2021-32679 nextcloud: filenames not escaped by default in controllers using DownloadResponse [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1981819 [ 5 ] Bug #1981821 - CVE-2021-32703 nextcloud: lack of ratelimit on shareinfo endpoint [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1981821 [ 6 ] Bug #1981824 - CVE-2021-32705 nextcloud: lack of ratelimit on public DAV endpoint [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1981824 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-9b421b78af' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to Nextcloud 18.0.9, fixes CVE-2020-81-39, CVE-2020-8173, CVE-2020-8183, CVE-2020-8223, CVE-2020-8154, CVE-2020-8155. Updating the Mail & Groupfolders apps from within Nextcloud also fixes CVE-2020-8153, CVE-2020-8156. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-c9863904de 2020-10-19 16:56:49.452478 --------------------------------------------------------------------------------Name : nextcloud Product : Fedora 32 Version : 18.0.9 Release : 1.fc32 URL : http://nextcloud.com Summary : Private file sync and share server Description : NextCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your devices and enables basic editing right on the web. NextCloud is extendable via a simple but powerful API for applications and plugins. --------------------------------------------------------------------------------Update Information: Update to Nextcloud 18.0.9, fixes CVE-2020-81-39, CVE-2020-8173, CVE-2020-8183, CVE-2020-8223, CVE-2020-8154, CVE-2020-8155. Updating the Mail & Groupfolders apps from within Nextcloud also fixes CVE-2020-8153, CVE-2020-8156 --------------------------------------------------------------------------------ChangeLog: * Sun Oct 11 2020 Christopher Engelhard - 18.0.9-1 - Update to Nextcloud 18.0.9 --------------------------------------------------------------------------------References: [ 1 ] Bug #1838275 - CVE-2020-8153 CVE-2020-8154 CVE-2020-8155 CVE-2020-8156 nextcloud: multiple vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1838275 [ 2 ] Bug #1838535 - CVE-2020-8139 nextcloud: hide-download shares to be downloadable when appending /download to the URL [fedora-31] https://bugzilla.redhat.com/show_bug.cgi?id=1838535 [ 3 ] Bug #1873704 - Please update to 18.0.8 on Fedora32 https://bugzilla.redhat.com/show_bug.cgi?id=1873704 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-c9863904de' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-701 2006-06-12 ---------------------------------------------------------------------Product : Fedora Core 4 Name : rsync Version : 2.6.8 Release : 1.FC4.1 Summary : A program for synchronizing files over a network. Description : Rsync uses a reliable algorithm to bring remote and host files into sync very quickly. Rsync is fast because it just sends the differences in the files over the network instead of sending the complete files. Rsync is often used as a very powerful mirroring process or just as a more capable replacement for the rcp command. A technical report which describes the rsync algorithm is included in this package. ---------------------------------------------------------------------* Mon Jun 12 2006 Jay Fenlason 2.6.8-1.FC4.1 - Add my xattrs_bug patch to fix a bug where xattrs don't get sent correctly. - Add BuildRequires to make sure libattr-devel and libacl-devel are avaliable - replace --with... with --enable... so they actually work - Add make, autoconf and gcc to BuildRequires ---------------------------------------------------------------------This update can be downloaded from: 7d53cbe51e170993f68418b65d8162edd949b3df SRPMS/rsync-2.6.8-1.FC4.1.src.rpm 7d53cbe51e170993f68418b65d8162edd949b3df noarch/rsync-2.6.8-1.FC4.1.src.rpm f2477bfde62ff935d65877de4cefcaaff1d00038 ppc/rsync-2.6.8-1.FC4.1.ppc.rpm bba627409b462e1cfe57c33bc1e54a0e21123db4 ppc/debug/rsync-debuginfo-2.6.8-1.FC4.1.ppc.rpm 33a25a41d610f3028e4becba12ddd89f33da96a1 x86_64/rsync-2.6.8-1.FC4.1.x86_64.rpm b0f8cd707063d2e89e6ccfcd6c0bd1743417739f x86_64/debug/rsync-debuginfo-2.6.8-1.FC4.1.x86_64.rpm 348e84d7b28e6eb7d52b022d4f27c9befbc780ea i386/rsync-2.6.8-1.FC4.1.i386.rpm b938a11177fc4a055c2637c719046dfe30e02c41 i386/debug/rsync-debuginfo-2.6.8-1.FC4.1.i386.rpm This update can be installed with the 'yum' update program. Use 'yumupdate package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.