An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for freetds ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1417-2 Rating: moderate References: #1141132 Cross-References: CVE-2019-13508 Affected Products: SUSE Linux Enterprise Module for Server Applications 15-SP2 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for freetds to 1.1.36 fixes the following issues: Security issue fixed: - CVE-2019-13508: Fixed a heap overflow that could have been caused by malicious servers sending UDT types over protocol version 5.0 (bsc#1141132). Non-security issues fixed: - Enabled Kerberos support - Version update to 1.1.36: * Default TDS protocol version is now "auto" * Improved UTF-8 performances * TDS Pool Server is enabled * MARS support is enabled * NTLMv2 is enabled * See NEWS and ChangeLog for a complete list of changes Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP2: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP2-2020-1417=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP2-2020-1417=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP1-2020-1417=1 Package List: - SUSE LinuxEnterprise Module for Server Applications 15-SP2 (aarch64 ppc64le s390x x86_64): freetds-debuginfo-1.1.36-3.3.1 freetds-debugsource-1.1.36-3.3.1 libct4-1.1.36-3.3.1 libct4-debuginfo-1.1.36-3.3.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2 (aarch64 ppc64le s390x x86_64): freetds-debuginfo-1.1.36-3.3.1 freetds-debugsource-1.1.36-3.3.1 libsybdb5-1.1.36-3.3.1 libsybdb5-debuginfo-1.1.36-3.3.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1 (aarch64 ppc64le s390x x86_64): freetds-debuginfo-1.1.36-3.3.1 freetds-debugsource-1.1.36-3.3.1 libsybdb5-1.1.36-3.3.1 libsybdb5-debuginfo-1.1.36-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-13508.html https://bugzilla.suse.com/1141132 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for freetds ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0741-1 Rating: moderate References: #1141132 Cross-References: CVE-2019-13508 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for freetds to 1.1.36 fixes the following issues: Security issue fixed: - CVE-2019-13508: Fixed a heap overflow that could have been caused by malicious servers sending UDT types over protocol version 5.0 (bsc#1141132). Non-security issues fixed: - Enabled Kerberos support - Version update to 1.1.36: * Default TDS protocol version is now "auto" * Improved UTF-8 performances * TDS Pool Server is enabled * MARS support is enabled * NTLMv2 is enabled * See NEWS and ChangeLog for a complete list of changes This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-741=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): freetds-config-1.1.36-lp151.3.3.1 freetds-debuginfo-1.1.36-lp151.3.3.1 freetds-debugsource-1.1.36-lp151.3.3.1 freetds-devel-1.1.36-lp151.3.3.1 freetds-doc-1.1.36-lp151.3.3.1 freetds-tools-1.1.36-lp151.3.3.1 freetds-tools-debuginfo-1.1.36-lp151.3.3.1 libct4-1.1.36-lp151.3.3.1 libct4-debuginfo-1.1.36-lp151.3.3.1 libsybdb5-1.1.36-lp151.3.3.1 libsybdb5-debuginfo-1.1.36-lp151.3.3.1 libtdsodbc0-1.1.36-lp151.3.3.1 libtdsodbc0-debuginfo-1.1.36-lp151.3.3.1 References: https://www.suse.com/security/cve/CVE-2019-13508.html https://bugzilla.suse.com/1141132 -- . Ubuntu Security Patch tackles a buffer overflow vulnerability in libevent, enhancing overall system safety and data protection measures.. openSUSE Update, freetds Security, heap Overflow Fix, openSUSE Patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for freetds ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1417-1 Rating: moderate References: #1141132 Cross-References: CVE-2019-13508 Affected Products: SUSE Linux Enterprise Module for Server Applications 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for freetds to 1.1.36 fixes the following issues: Security issue fixed: - CVE-2019-13508: Fixed a heap overflow that could have been caused by malicious servers sending UDT types over protocol version 5.0 (bsc#1141132). Non-security issues fixed: - Enabled Kerberos support - Version update to 1.1.36: * Default TDS protocol version is now "auto" * Improved UTF-8 performances * TDS Pool Server is enabled * MARS support is enabled * NTLMv2 is enabled * See NEWS and ChangeLog for a complete list of changes Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP1: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP1-2020-1417=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15-SP1 (aarch64 ppc64le s390x x86_64): freetds-debuginfo-1.1.36-3.3.1 freetds-debugsource-1.1.36-3.3.1 libct4-1.1.36-3.3.1 libct4-debuginfo-1.1.36-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-13508.html https://bugzilla.suse.com/1141132 _______________________________________________ sle-security-updates mailinglist
Update to 1.1.20. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-b67929609d 2019-11-17 01:29:40.270718 --------------------------------------------------------------------------------Name : freetds Product : Fedora 31 Version : 1.1.20 Release : 1.fc31 URL : http://www.freetds.org/ Summary : Implementation of the TDS (Tabular DataStream) protocol Description : FreeTDS is a project to document and implement the TDS (Tabular DataStream) protocol. TDS is used by Sybase(TM) and Microsoft(TM) for client to database server communications. FreeTDS includes call level interfaces for DB-Lib, CT-Lib, and ODBC. --------------------------------------------------------------------------------Update Information: Update to 1.1.20 --------------------------------------------------------------------------------ChangeLog: * Thu Nov 7 2019 Dmitry Butskoy - 1.1.20-1 - update to 1.1.20 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-b67929609d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Updated freetds packages fix security vulnerability: Felix Wilhelm discovered that FreeTDS incorrectly handled certain types after a protocol downgrade. A remote attacker could use this issue to cause FreeTDS to crash, resulting in a denial of service, or possibly . MGASA-2019-0319 - Updated freetds packages fix security vulnerability Publication date: 07 Nov 2019 URL: https://advisories.mageia.org/MGASA-2019-0319.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-13508 Updated freetds packages fix security vulnerability: Felix Wilhelm discovered that FreeTDS incorrectly handled certain types after a protocol downgrade. A remote attacker could use this issue to cause FreeTDS to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2019-13508). References: - https://bugs.mageia.org/show_bug.cgi?id=25653 - https://ubuntu.com/security/notices/USN-4173-1 - https://www.cve.org/CVERecord?id=CVE-2019-13508 SRPMS: - 7/core/freetds-1.00.83-2.1.mga7 . Recent updates to FreeTDS packages fix a major security flaw that may allow denial of service attacks or unauthorized code execution. Learn more about this update. FreeTDS Security Update, Mageia Security Advisories, Remote Attacks Threat, Protocol Downgrade Issues. . LinuxSecurity.com Team
FreeTDS could be made to crash or run programs if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-4173-1 October 30, 2019 freetds vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 - Ubuntu 19.04 - Ubuntu 18.04 LTS Summary: FreeTDS could be made to crash or run programs if it received specially crafted network traffic. Software Description: - freetds: libraries for connecting to MS SQL and Sybase SQL servers Details: Felix Wilhelm discovered that FreeTDS incorrectly handled certain types after a protocol downgrade. A remote attacker could use this issue to cause FreeTDS to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: freetds-bin 1.1.6-1ubuntu0.1 libct4 1.1.6-1ubuntu0.1 libsybdb5 1.1.6-1ubuntu0.1 tdsodbc 1.1.6-1ubuntu0.1 Ubuntu 19.04: freetds-bin 1.00.104-1ubuntu0.1 libct4 1.00.104-1ubuntu0.1 libsybdb5 1.00.104-1ubuntu0.1 tdsodbc 1.00.104-1ubuntu0.1 Ubuntu 18.04 LTS: freetds-bin 1.00.82-2ubuntu0.1 libct4 1.00.82-2ubuntu0.1 libsybdb5 1.00.82-2ubuntu0.1 tdsodbc 1.00.82-2ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4173-1 CVE-2019-13508 Package Information: https://launchpad.net/ubuntu/+source/freetds/1.1.6-1ubuntu0.1 https://launchpad.net/ubuntu/+source/freetds/1.00.104-1ubuntu0.1 https://launchpad.net/ubuntu/+source/freetds/1.00.82-2ubuntu0.1 . A vulnerability in FreeTDS on Ubuntu impacts various releases, enabling remote system crashes or arbitrary code execution.. FreeTDS,Unity,RemoteCrash,SecurityPatch,NetworkExploit. . Severity: Critical. LinuxSecurity.com Team
Upgrade to 1.1.11. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-14d102033e 2019-07-18 20:32:30.992535 --------------------------------------------------------------------------------Name : freetds Product : Fedora 29 Version : 1.1.11 Release : 1.fc29 URL : http://www.freetds.org/ Summary : Implementation of the TDS (Tabular DataStream) protocol Description : FreeTDS is a project to document and implement the TDS (Tabular DataStream) protocol. TDS is used by Sybase(TM) and Microsoft(TM) for client to database server communications. FreeTDS includes call level interfaces for DB-Lib, CT-Lib, and ODBC. --------------------------------------------------------------------------------Update Information: Upgrade to 1.1.11 --------------------------------------------------------------------------------ChangeLog: * Tue Jul 9 2019 Dmitry Butskoy - 1.1.11-1 - Upgrade to 1.1.11 (#1728191) * Sun Feb 17 2019 Igor Gnatenko - 1.00.38-8 - Rebuild for readline 8.0 * Thu Jan 31 2019 Fedora Release Engineering - 1.00.38-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1728191 - Private bug https://bugzilla.redhat.com/show_bug.cgi?id=1728191 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-14d102033e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Upgrade to 1.1.11. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-f74072a45d 2019-07-18 17:55:37.801088 --------------------------------------------------------------------------------Name : freetds Product : Fedora 30 Version : 1.1.11 Release : 1.fc30 URL : http://www.freetds.org/ Summary : Implementation of the TDS (Tabular DataStream) protocol Description : FreeTDS is a project to document and implement the TDS (Tabular DataStream) protocol. TDS is used by Sybase(TM) and Microsoft(TM) for client to database server communications. FreeTDS includes call level interfaces for DB-Lib, CT-Lib, and ODBC. --------------------------------------------------------------------------------Update Information: Upgrade to 1.1.11 --------------------------------------------------------------------------------ChangeLog: * Tue Jul 9 2019 Dmitry Butskoy - 1.1.11-1 - Upgrade to 1.1.11 (#1728191) --------------------------------------------------------------------------------References: [ 1 ] Bug #1728191 - Private bug https://bugzilla.redhat.com/show_bug.cgi?id=1728191 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-f74072a45d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.