Update to upstream release 3.2.5. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c395d8fef4 2024-07-18 04:05:28.192702 -------------------------------------------------------------------------------- Name : freeradius Product : Fedora 39 Version : 3.2.5 Release : 1.fc39 URL : http://www.freeradius.org/ Summary : High-performance and highly configurable free RADIUS server Description : The FreeRADIUS Server Project is a high performance and highly configurable GPL'd free RADIUS server. The server is similar in some respects to Livingston's 2.0 server. While FreeRADIUS started as a variant of the Cistron RADIUS server, they don't share a lot in common any more. It now has many more features than Cistron or Livingston, and is much more configurable. FreeRADIUS is an Internet authentication daemon, which implements the RADIUS protocol, as defined in RFC 2865 (and others). It allows Network Access Servers (NAS boxes) to perform authentication for dial-up users. There are also RADIUS clients available for Web servers, firewalls, Unix logins, and more. Using RADIUS allows authentication and authorization for a network to be centralized, and minimizes the amount of re-configuration which has to be done when adding or deleting new users. -------------------------------------------------------------------------------- Update Information: Update to upstream release 3.2.5 -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 9 2024 Antonio Torres - 3.2.5-1 - Update to upstream release 3.2.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2296625 - CVE-2024-3596 freeradius: forgery attack [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2296625 -------------------------------------------------------------------------------- This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c395d8fef4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Security fixes for CVE-2022-37966, CVE-2022-37967 and CVE-2022-38023. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7f9021ead1 2022-12-21 01:17:10.825705 --------------------------------------------------------------------------------Name : samba Product : Fedora 36 Version : 4.16.8 Release : 0.fc36 URL : Summary : Server and Client software to interoperate with Windows machines Description : Samba is the standard Windows interoperability suite of programs for Linux and Unix. --------------------------------------------------------------------------------Update Information: Security fixes for CVE-2022-37966, CVE-2022-37967 and CVE-2022-38023 --------------------------------------------------------------------------------ChangeLog: * Fri Dec 16 2022 Guenther Deschner - 4.16.8-0 - resolves: #2154303, #2154304 - Security fixes for CVE-2022-37966 - resolves: #2154320, #2154322 - Security fixes for CVE-2022-37967 - resolves: #2154362, #2154363 - Security fixes for CVE-2022-38023 --------------------------------------------------------------------------------References: [ 1 ] Bug #2154303 - CVE-2022-37966 samba: Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability. https://bugzilla.redhat.com/show_bug.cgi?id=2154303 [ 2 ] Bug #2154320 - CVE-2022-37967 samba: Kerberos constrained delegation ticket forgery possible against Samba AD DC https://bugzilla.redhat.com/show_bug.cgi?id=2154320 [ 3 ] Bug #2154362 - CVE-2022-38023 samba: RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided https://bugzilla.redhat.com/show_bug.cgi?id=2154362 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-7f9021ead1' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
gnupg2 is updated to 2.2.18 and fix security vulnerability: Web of Trust forgeries using collisions in SHA-1 signatures (CVE-2019-14855) * Note that this change removes all SHA-1 based key signature newer than 2019-01-19 from the web-of-trust. This includes all key signature created . MGASA-2019-0348 - Updated gnupg2 packages fix security vulnerability Publication date: 30 Nov 2019 URL: https://advisories.mageia.org/MGASA-2019-0348.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-14855 gnupg2 is updated to 2.2.18 and fix security vulnerability: Web of Trust forgeries using collisions in SHA-1 signatures (CVE-2019-14855) * Note that this change removes all SHA-1 based key signature newer than 2019-01-19 from the web-of-trust. This includes all key signature created with dsa1024 keys. The new option --allow-weak-key-signatues can be used to override the new and safer behaviour. For other fixes in this update, see the gnupg-announce reference. References: - https://bugs.mageia.org/show_bug.cgi?id=25749 - https://lists.gnupg.org/pipermail/gnupg-announce/2019q4/000442.html - https://www.cve.org/CVERecord?id=CVE-2019-14855 SRPMS: - 7/core/gnupg2-2.2.18-1.mga7 . Update MGASA-2019-0349 addresses vulnerabilities in openssl regarding certificate validation. The amendments enhance cryptographic security by disabling weak ciphers and algorithms.. gnupg2 security, Mageia security update, SHA-1 collision, Web of Trust, security advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.