An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for guile ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1659-1 Rating: low References: #1004221 Cross-References: CVE-2016-8605 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP5 SUSE Linux Enterprise Workstation Extension 12-SP4 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for guile fixes the following issues: - CVE-2016-8605: Fixed thread-unsafe umask modification (bsc#1004221). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2020-1659=1 - SUSE Linux Enterprise Workstation Extension 12-SP4: zypper in -t patch SUSE-SLE-WE-12-SP4-2020-1659=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-1659=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2020-1659=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): guile1-1.8.8-16.4.39 guile1-debuginfo-1.8.8-16.4.39 guile1-debugsource-1.8.8-16.4.39 libguile-srfi-srfi-1-v-3-3-1.8.8-16.4.39 libguile-srfi-srfi-1-v-3-3-debuginfo-1.8.8-16.4.39 libguile-srfi-srfi-13-14-v-3-3-1.8.8-16.4.39 libguile-srfi-srfi-13-14-v-3-3-debuginfo-1.8.8-16.4.39 libguile-srfi-srfi-4-v-3-3-1.8.8-16.4.39 libguile-srfi-srfi-4-v-3-3-debuginfo-1.8.8-16.4.39 libguile-srfi-srfi-60-v-2-2-1.8.8-16.4.39 libguile-srfi-srfi-60-v-2-2-debuginfo-1.8.8-16.4.39 libguile17-1.8.8-16.4.39 libguile17-debuginfo-1.8.8-16.4.39 libguilereadline-v-17-17-1.8.8-16.4.39 libguilereadline-v-17-17-debuginfo-1.8.8-16.4.39 - SUSE Linux Enterprise Workstation Extension 12-SP4 (x86_64): guile1-1.8.8-16.4.39 guile1-debuginfo-1.8.8-16.4.39 guile1-debugsource-1.8.8-16.4.39 libguile-srfi-srfi-1-v-3-3-1.8.8-16.4.39 libguile-srfi-srfi-1-v-3-3-debuginfo-1.8.8-16.4.39 libguile-srfi-srfi-13-14-v-3-3-1.8.8-16.4.39 libguile-srfi-srfi-13-14-v-3-3-debuginfo-1.8.8-16.4.39 libguile-srfi-srfi-4-v-3-3-1.8.8-16.4.39 libguile-srfi-srfi-4-v-3-3-debuginfo-1.8.8-16.4.39 libguile-srfi-srfi-60-v-2-2-1.8.8-16.4.39 libguile-srfi-srfi-60-v-2-2-debuginfo-1.8.8-16.4.39 libguile17-1.8.8-16.4.39 libguile17-debuginfo-1.8.8-16.4.39 libguilereadline-v-17-17-1.8.8-16.4.39 libguilereadline-v-17-17-debuginfo-1.8.8-16.4.39 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): guile1-1.8.8-16.4.39 guile1-debuginfo-1.8.8-16.4.39 guile1-debugsource-1.8.8-16.4.39 libguile-srfi-srfi-1-v-3-3-1.8.8-16.4.39 libguile-srfi-srfi-1-v-3-3-debuginfo-1.8.8-16.4.39 libguile-srfi-srfi-13-14-v-3-3-1.8.8-16.4.39 libguile-srfi-srfi-13-14-v-3-3-debuginfo-1.8.8-16.4.39 libguile-srfi-srfi-4-v-3-3-1.8.8-16.4.39 libguile-srfi-srfi-4-v-3-3-debuginfo-1.8.8-16.4.39 libguile-srfi-srfi-60-v-2-2-1.8.8-16.4.39 libguile-srfi-srfi-60-v-2-2-debuginfo-1.8.8-16.4.39 libguile1-devel-1.8.8-16.4.39 libguile17-1.8.8-16.4.39 libguile17-debuginfo-1.8.8-16.4.39 libguilereadline-v-17-17-1.8.8-16.4.39 libguilereadline-v-17-17-debuginfo-1.8.8-16.4.39 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64ppc64le s390x x86_64): guile1-1.8.8-16.4.39 guile1-debuginfo-1.8.8-16.4.39 guile1-debugsource-1.8.8-16.4.39 libguile-srfi-srfi-1-v-3-3-1.8.8-16.4.39 libguile-srfi-srfi-1-v-3-3-debuginfo-1.8.8-16.4.39 libguile-srfi-srfi-13-14-v-3-3-1.8.8-16.4.39 libguile-srfi-srfi-13-14-v-3-3-debuginfo-1.8.8-16.4.39 libguile-srfi-srfi-4-v-3-3-1.8.8-16.4.39 libguile-srfi-srfi-4-v-3-3-debuginfo-1.8.8-16.4.39 libguile-srfi-srfi-60-v-2-2-1.8.8-16.4.39 libguile-srfi-srfi-60-v-2-2-debuginfo-1.8.8-16.4.39 libguile1-devel-1.8.8-16.4.39 libguile17-1.8.8-16.4.39 libguile17-debuginfo-1.8.8-16.4.39 libguilereadline-v-17-17-1.8.8-16.4.39 libguilereadline-v-17-17-debuginfo-1.8.8-16.4.39 References: https://www.suse.com/security/cve/CVE-2016-8605.html https://bugzilla.suse.com/1004221 _______________________________________________ sle-security-updates mailing list
Security fix for CVE-2016-8605. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-990e2012ea 2017-01-12 01:45:35.654643 -------------------------------------------------------------------------------- Name : compat-guile18 Product : Fedora 24 Version : 1.8.8 Release : 14.fc24 URL : http://www.gnu.org/software/guile/ Summary : A GNU implementation of Scheme for application extensibility Description : GUILE (GNU's Ubiquitous Intelligent Language for Extension) is a library implementation of the Scheme programming language, written in C. GUILE provides a machine-independent execution platform that can be linked in as a library during the building of extensible programs. Install the compat-guile18 package if you'd like to add extensibility to programs that you are developing. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-8605 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1383966 - CVE-2016-8605 guile: Thread-unsafe umask modification https://bugzilla.redhat.com/show_bug.cgi?id=1383966 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade compat-guile18' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to the latest stable release, which fixes CVE-2016-8605 and CVE-2016-8606.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-a47bf58beb 2016-10-21 17:21:55.671017 -------------------------------------------------------------------------------- Name : guile Product : Fedora 23 Version : 2.0.13 Release : 1.fc23 URL : http://www.gnu.org/software/guile/ Summary : A GNU implementation of Scheme for application extensibility Description : GUILE (GNU's Ubiquitous Intelligent Language for Extension) is a library implementation of the Scheme programming language, written in C. GUILE provides a machine-independent execution platform that can be linked in as a library during the building of extensible programs. Install the guile package if you'd like to add extensibility to programs that you are developing. -------------------------------------------------------------------------------- Update Information: Update to the latest stable release, which fixes CVE-2016-8605 and CVE-2016-8606. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1383966 - CVE-2016-8605 guile: Thread-unsafe umask modification https://bugzilla.redhat.com/show_bug.cgi?id=1383966 [ 2 ] Bug #1383972 - CVE-2016-8606 guile: REPL server vulnerable to HTTP inter-protocol attacks https://bugzilla.redhat.com/show_bug.cgi?id=1383972 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update guile' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to the latest stable release, which fixes CVE-2016-8605 and CVE-2016-8606.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-0aab71f552 2016-10-16 18:50:00.470003 -------------------------------------------------------------------------------- Name : guile Product : Fedora 25 Version : 2.0.13 Release : 1.fc25 URL : http://www.gnu.org/software/guile/ Summary : A GNU implementation of Scheme for application extensibility Description : GUILE (GNU's Ubiquitous Intelligent Language for Extension) is a library implementation of the Scheme programming language, written in C. GUILE provides a machine-independent execution platform that can be linked in as a library during the building of extensible programs. Install the guile package if you'd like to add extensibility to programs that you are developing. -------------------------------------------------------------------------------- Update Information: Update to the latest stable release, which fixes CVE-2016-8605 and CVE-2016-8606. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1383966 - CVE-2016-8605 guile: Thread-unsafe umask modification https://bugzilla.redhat.com/show_bug.cgi?id=1383966 [ 2 ] Bug #1383972 - CVE-2016-8606 guile: REPL server vulnerable to HTTP inter-protocol attacks https://bugzilla.redhat.com/show_bug.cgi?id=1383972 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update guile' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.