An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for getdata ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1645-1 Rating: moderate References: #1186251 Cross-References: CVE-2021-20204 CVSS scores: CVE-2021-20204 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-20204 (SUSE): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: getdata was updated to 0.11.0, fixing bugs and a security issue: - CVE-2021-20204: Fixed a use after free in _GD_Supports() in encoding.c (boo#1186251) for all relevant changes see: https://github.com/ketiltrout/getdata/releases/tag/v0.11.0 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1645=1 Package List: - openSUSE Leap 15.2 (x86_64): getdata-0.11.0-lp152.4.3.1 getdata-debuginfo-0.11.0-lp152.4.3.1 getdata-debugsource-0.11.0-lp152.4.3.1 getdata-devel-0.11.0-lp152.4.3.1 getdata-doc-0.11.0-lp152.4.3.1 libf95getdata7-0.11.0-lp152.4.3.1 libf95getdata7-debuginfo-0.11.0-lp152.4.3.1 libfgetdata6-0.11.0-lp152.4.3.1 libfgetdata6-debuginfo-0.11.0-lp152.4.3.1 libgetdata++7-0.11.0-lp152.4.3.1 libgetdata++7-debuginfo-0.11.0-lp152.4.3.1 libgetdata8-0.11.0-lp152.4.3.1 libgetdata8-debuginfo-0.11.0-lp152.4.3.1 perl-getdata-0.11.0-lp152.4.3.1 perl-getdata-debuginfo-0.11.0-lp152.4.3.1 python-getdata-0.11.0-lp152.4.3.1 python-getdata-debuginfo-0.11.0-lp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2021-20204.html https://bugzilla.suse.com/1186251 . The Debian team has issued a critical update for fetchdata to patch the serious vulnerability identified as CVE-2023-42501.. getdata update, openSUSE security, software vulnerabilities, patch instructions. . LinuxSecurity.com Team
0.11.0, fix use after free, CVE-2021-20204. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-3b8bb26909 2021-11-25 01:04:40.275950 --------------------------------------------------------------------------------Name : getdata Product : Fedora 33 Version : 0.11.0 Release : 1.fc33 URL : Summary : Library for reading and writing dirfile data Description : The GetData Project is the reference implementation of the Dirfile Standards, a filesystem-based database format for time-ordered binary data. The Dirfile database format is designed to provide a fast, simple format for storing and reading data. --------------------------------------------------------------------------------Update Information: 0.11.0, fix use after free, CVE-2021-20204 --------------------------------------------------------------------------------ChangeLog: * Tue Nov 16 2021 Gwyn Ciesla - 0.11.0-1 - 0.11.0 - Spec cleanup. * Thu Jul 22 2021 Fedora Release Engineering - 0.10.0-16 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild * Tue Jan 26 2021 Fedora Release Engineering - 0.10.0-15 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1917635 - Memory corruption (use after free) in getdata v0.10.0 https://bugzilla.redhat.com/show_bug.cgi?id=1917635 [ 2 ] Bug #1956350 - CVE-2021-20204 getdata: Use after free in _GD_Supports() in encoding.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1956350 [ 3 ] Bug #2023520 - getdata-0.11.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2023520 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-3b8bb26909' at the command line. For moreinformation, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
0.11.0, fix use after free, CVE-2021-20204. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-e2b64c614b 2021-11-25 01:04:01.087647 --------------------------------------------------------------------------------Name : getdata Product : Fedora 35 Version : 0.11.0 Release : 1.fc35 URL : Summary : Library for reading and writing dirfile data Description : The GetData Project is the reference implementation of the Dirfile Standards, a filesystem-based database format for time-ordered binary data. The Dirfile database format is designed to provide a fast, simple format for storing and reading data. --------------------------------------------------------------------------------Update Information: 0.11.0, fix use after free, CVE-2021-20204 --------------------------------------------------------------------------------ChangeLog: * Tue Nov 16 2021 Gwyn Ciesla - 0.11.0-1 - 0.11.0 - Spec cleanup. --------------------------------------------------------------------------------References: [ 1 ] Bug #1917635 - Memory corruption (use after free) in getdata v0.10.0 https://bugzilla.redhat.com/show_bug.cgi?id=1917635 [ 2 ] Bug #1956350 - CVE-2021-20204 getdata: Use after free in _GD_Supports() in encoding.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1956350 [ 3 ] Bug #2023520 - getdata-0.11.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2023520 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-e2b64c614b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
0.11.0, fix use after free, CVE-2021-20204. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-197545a753 2021-11-25 00:57:41.647579 --------------------------------------------------------------------------------Name : getdata Product : Fedora 34 Version : 0.11.0 Release : 1.fc34 URL : Summary : Library for reading and writing dirfile data Description : The GetData Project is the reference implementation of the Dirfile Standards, a filesystem-based database format for time-ordered binary data. The Dirfile database format is designed to provide a fast, simple format for storing and reading data. --------------------------------------------------------------------------------Update Information: 0.11.0, fix use after free, CVE-2021-20204 --------------------------------------------------------------------------------ChangeLog: * Tue Nov 16 2021 Gwyn Ciesla - 0.11.0-1 - 0.11.0 - Spec cleanup. * Thu Jul 22 2021 Fedora Release Engineering - 0.10.0-16 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1917635 - Memory corruption (use after free) in getdata v0.10.0 https://bugzilla.redhat.com/show_bug.cgi?id=1917635 [ 2 ] Bug #1956350 - CVE-2021-20204 getdata: Use after free in _GD_Supports() in encoding.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1956350 [ 3 ] Bug #2023520 - getdata-0.11.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2023520 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-197545a753' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signedwith the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.