The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-0672-1 https://linux.oracle.com/errata/ELSA-2022-0672-1.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: ruby-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.i686.rpm ruby-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.x86_64.rpm ruby-devel-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.i686.rpm ruby-devel-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.x86_64.rpm ruby-doc-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-abrt-0.3.0-4.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-abrt-doc-0.3.0-4.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-bigdecimal-1.3.4-109.0.1.module+el8.5.0+20513+af7be134.i686.rpm rubygem-bigdecimal-1.3.4-109.0.1.module+el8.5.0+20513+af7be134.x86_64.rpm rubygem-bson-4.3.0-2.module+el8.3.0+7756+e45777e9.x86_64.rpm rubygem-bson-doc-4.3.0-2.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-bundler-1.16.1-4.module+el8.5.0+20497+d0a7b862.noarch.rpm rubygem-bundler-doc-1.16.1-4.module+el8.5.0+20497+d0a7b862.noarch.rpm rubygem-did_you_mean-1.2.0-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-io-console-0.4.6-109.0.1.module+el8.5.0+20513+af7be134.i686.rpm rubygem-io-console-0.4.6-109.0.1.module+el8.5.0+20513+af7be134.x86_64.rpm rubygem-json-2.1.0-109.0.1.module+el8.5.0+20513+af7be134.i686.rpm rubygem-json-2.1.0-109.0.1.module+el8.5.0+20513+af7be134.x86_64.rpm rubygem-minitest-5.10.3-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-mongo-2.5.1-2.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-mongo-doc-2.5.1-2.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-mysql2-0.4.10-4.module+el8.3.0+7756+e45777e9.x86_64.rpm rubygem-mysql2-doc-0.4.10-4.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-net-telnet-0.1.1-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-openssl-2.1.2-109.0.1.module+el8.5.0+20513+af7be134.i686.rpm rubygem-openssl-2.1.2-109.0.1.module+el8.5.0+20513+af7be134.x86_64.rpm rubygem-pg-1.0.0-2.module+el8.3.0+7756+e45777e9.x86_64.rpm rubygem-pg-doc-1.0.0-2.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-power_assert-1.1.1-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-psych-3.0.2-109.0.1.module+el8.5.0+20513+af7be134.i686.rpm rubygem-psych-3.0.2-109.0.1.module+el8.5.0+20513+af7be134.x86_64.rpm rubygem-rake-12.3.3-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-rdoc-6.0.1.1-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygems-2.7.6.3-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygems-devel-2.7.6.3-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-test-unit-3.2.7-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-xmlrpc-0.3.0-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm ruby-irb-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm ruby-libs-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.i686.rpm ruby-libs-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.x86_64.rpm aarch64: ruby-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.aarch64.rpm ruby-devel-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.aarch64.rpm ruby-doc-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-abrt-0.3.0-4.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-abrt-doc-0.3.0-4.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-bigdecimal-1.3.4-109.0.1.module+el8.5.0+20513+af7be134.aarch64.rpm rubygem-bson-4.3.0-2.module+el8.3.0+7756+e45777e9.aarch64.rpm rubygem-bson-doc-4.3.0-2.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-bundler-1.16.1-4.module+el8.5.0+20497+d0a7b862.noarch.rpm rubygem-bundler-doc-1.16.1-4.module+el8.5.0+20497+d0a7b862.noarch.rpm rubygem-did_you_mean-1.2.0-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-io-console-0.4.6-109.0.1.module+el8.5.0+20513+af7be134.aarch64.rpm rubygem-json-2.1.0-109.0.1.module+el8.5.0+20513+af7be134.aarch64.rpm rubygem-minitest-5.10.3-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-mongo-2.5.1-2.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-mongo-doc-2.5.1-2.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-mysql2-0.4.10-4.module+el8.3.0+7756+e45777e9.aarch64.rpm rubygem-mysql2-doc-0.4.10-4.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-net-telnet-0.1.1-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-openssl-2.1.2-109.0.1.module+el8.5.0+20513+af7be134.aarch64.rpm rubygem-pg-1.0.0-2.module+el8.3.0+7756+e45777e9.aarch64.rpm rubygem-pg-doc-1.0.0-2.module+el8.3.0+7756+e45777e9.noarch.rpm rubygem-power_assert-1.1.1-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-psych-3.0.2-109.0.1.module+el8.5.0+20513+af7be134.aarch64.rpm rubygem-rake-12.3.3-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-rdoc-6.0.1.1-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygems-2.7.6.3-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygems-devel-2.7.6.3-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-test-unit-3.2.7-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm rubygem-xmlrpc-0.3.0-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm ruby-irb-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.noarch.rpm ruby-libs-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/ruby-2.5.9-109.0.1.module+el8.5.0+20513+af7be134.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates/rubygem-abrt-0.3.0-4.module+el8.3.0+7756+e45777e9.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates/rubygem-bson-4.3.0-2.module+el8.3.0+7756+e45777e9.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates/rubygem-bundler-1.16.1-4.module+el8.5.0+20497+d0a7b862.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates/rubygem-mongo-2.5.1-2.module+el8.3.0+7756+e45777e9.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates/rubygem-mysql2-0.4.10-4.module+el8.3.0+7756+e45777e9.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates/rubygem-pg-1.0.0-2.module+el8.3.0+7756+e45777e9.src.rpm Related CVEs: CVE-2021-31799 CVE-2021-31810 CVE-2021-32066 Description of changes: ruby [2.5.9-109.0.1] - Rebuild with a dependency containing fix for Orabug: 33921593 [2.5.9-109] - Properly fix command injection vulnerability in Rdoc. Related: CVE-2021-31799 [2.5.9-108] - Fix command injection vulnerability in RDoc. Resolves: CVE-2021-31799 - Fix StartTLS stripping vulnerability in Net::IMAP Resolves: CVE-2021-32066 - Fix FTP PASV command response can cause Net::FTP to connect to arbitraryhost. Resolves: CVE-2021-31810 _______________________________________________ El-errata mailing list
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for curl ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:14585-1 Rating: moderate References: #1179398 #1179399 Cross-References: CVE-2020-8284 CVE-2020-8285 Affected Products: SUSE Linux Enterprise Server 11-SECURITY ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for curl fixes the following issues: - CVE-2020-8284: Fixed an issue where a malicious FTP server could make curl connect to a different IP (bsc#1179398). - CVE-2020-8285: Fixed an FTP wildcard stack overflow (bsc#1179399). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SECURITY: zypper in -t patch secsp3-curl-14585=1 Package List: - SUSE Linux Enterprise Server 11-SECURITY (i586 ia64 ppc64 s390x x86_64): curl-openssl1-7.37.0-70.57.1 libcurl4-openssl1-7.37.0-70.57.1 - SUSE Linux Enterprise Server 11-SECURITY (ppc64 s390x x86_64): libcurl4-openssl1-32bit-7.37.0-70.57.1 - SUSE Linux Enterprise Server 11-SECURITY (ia64): libcurl4-openssl1-x86-7.37.0-70.57.1 References: https://www.suse.com/security/cve/CVE-2020-8284.html https://www.suse.com/security/cve/CVE-2020-8285.html https://bugzilla.suse.com/1179398 https://bugzilla.suse.com/1179399 . SUSE Security Patch for wget addresses moderate vulnerabilities: CVE-2020-8286 and CVE-2020-8287 pertaining to HTTP risks.. Suse Security Update,curl fix,FTP Threats,curl vulnerabilities. . Severity: Important. LinuxSecurity.com Team
- fix out of bounds read in FTP PWD response parser (CVE-2017-1000254). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-601b4c20a4 2017-10-16 15:51:47.721047 --------------------------------------------------------------------------------Name : curl Product : Fedora 26 Version : 7.53.1 Release : 11.fc26 URL : https://curl.se/ Summary : A utility for getting files from remote servers (FTP, HTTP, and others) Description : curl is a command line tool for transferring data with URL syntax, supporting FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3 and RTSP. curl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, cookies, user+password authentication (Basic, Digest, NTLM, Negotiate, kerberos...), file transfer resume, proxy tunneling and a busload of other useful tricks. --------------------------------------------------------------------------------Update Information: - fix out of bounds read in FTP PWD response parser (CVE-2017-1000254) --------------------------------------------------------------------------------References: [ 1 ] Bug #1498396 - CVE-2017-1000254 curl: FTP PWD response parser out of bounds read [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1498396 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade curl' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] curl (SSA:2017-279-01) New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/curl-7.56.0-i586-1_slack14.2.txz: Upgraded. This update fixes a security issue: libcurl may read outside of a heap allocated buffer when doing FTP. For more information, see: https://curl.se/docs/CVE-2017-1000254.html https://www.cve.org/CVERecord?id=CVE-2017-1000254 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 package: 880c7281862df00ffe344295bd422f7a curl-7.56.0-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 6025ce06e93ddf6520f5bc731ff0888d curl-7.56.0-x86_64-1_slack14.0.txz Slackware 14.1 package: 0d887113412626fcc3f4fefa72456a6c curl-7.56.0-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 1d99e50e4a8f0ea7efe4784fb0b68ac8 curl-7.56.0-x86_64-1_slack14.1.txz Slackware 14.2 package: 4130d13192b46d033d7d7931628733d5 curl-7.56.0-i586-1_slack14.2.txz Slackware x86_64 14.2 package: de3bf8673814b9a4f07b04de8719357a curl-7.56.0-x86_64-1_slack14.2.txz Slackware -currentpackage: 80d914f7e63eaef96538ae032227dfea n/curl-7.56.0-i586-1.txz Slackware x86_64 -current package: 19b32807404f534a5ce33cd0a3f31a01 n/curl-7.56.0-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg curl-7.56.0-i586-1_slack14.2.txz +-----+ . Recent curl upgrades for Slackware releases address a critical vulnerability related to FTP buffer handling, ensuring enhanced security measures.. curl Update, Slackware Security, Linux Package Management. . Severity: Critical. LinuxSecurity.com Team
Moderate: wget security update. Date: Mon, 3 Nov 2014 17:52:32 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: wget on SL6.x, SL7.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: wget security update Advisory ID: SLSA-2014:1764-1 Issue Date: 2014-10-30 CVE Numbers: CVE-2014-4877 -- A flaw was found in the way Wget handled symbolic links. A malicious FTP server could allow Wget running in the mirror mode (using the '-m' command line option) to write an arbitrary file to a location writable to by the user running Wget, possibly leading to code execution. (CVE-2014-4877) Note: This update changes the default value of the --retr-symlinks option. The file symbolic links are now traversed by default and pointed-to files are retrieved rather than creating a symbolic link locally. -- SL6 x86_64 wget-1.12-5.el6_6.1.x86_64.rpm wget-debuginfo-1.12-5.el6_6.1.x86_64.rpm i386 wget-1.12-5.el6_6.1.i686.rpm wget-debuginfo-1.12-5.el6_6.1.i686.rpm SL7 x86_64 wget-1.14-10.el7_0.1.x86_64.rpm wget-debuginfo-1.14-10.el7_0.1.x86_64.rpm - Scientific Linux Development Team . Patch released for curl tackling low-level vulnerabilities on Fedora OS versions 32 and 33.. Scientific Linux, wget security, moderate threats, software updates. . LinuxSecurity.com Team
New yum fixes problems when connecting to certain ftp servers.. Date: Thu, 24 Aug 2006 14:35:38 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for "mozilla to seamonkey" on SL 301,302,303,304,305,307 i386,x86_64 now available Comments: To:
New yum fixes problems when connecting to certain ftp servers.. Date: Thu, 24 Aug 2006 14:35:36 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for "yum" on SL 301,302,303,304,305,307 i386,x86_64 now available Comments: To:
Get the latest Linux and open source security news straight to your inbox.