- Update to 1.2.23 - CVE-46169 Release notes: . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-d4085a681f 2023-01-13 01:20:10.116824 --------------------------------------------------------------------------------Name : cacti-spine Product : Fedora 36 Version : 1.2.23 Release : 1.fc36 URL : Summary : Threaded poller for Cacti written in C Description : Spine is a supplemental poller for Cacti that makes use of pthreads to achieve excellent performance. --------------------------------------------------------------------------------Update Information: - Update to 1.2.23 - CVE-46169 Release notes: --------------------------------------------------------------------------------ChangeLog: * Wed Jan 4 2023 Morten Stevens - 1.2.23-1 - Update to 1.2.23 * Tue Dec 13 2022 Florian Weimer - 1.2.22-2 - Port configure script to C99 --------------------------------------------------------------------------------References: [ 1 ] Bug #2151572 - CVE-2022-46169 cacti: unauthenticated command injection https://bugzilla.redhat.com/show_bug.cgi?id=2151572 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-d4085a681f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-urllib3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0486-1 Rating: moderate References: #1177211 Cross-References: CVE-2020-26116 CVSS scores: CVE-2020-26116 (NVD) : 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N CVE-2020-26116 (SUSE): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N Affected Products: SUSE OpenStack Cloud 7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-urllib3 fixes the following issues: - CVE-2020-26116: Raise ValueError if method contains control characters and thus prevent CRLF injection into URLs (bsc#1177211). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2021-486=1 Package List: - SUSE OpenStack Cloud 7 (noarch): python-urllib3-1.16-3.15.1 References: https://www.suse.com/security/cve/CVE-2020-26116.html https://bugzilla.suse.com/1177211 . New patch released for python-urllib3 mitigating control character injection threats. Resolve security issue in line with SUSE advisory.. SUSE Update, Python Urllib3, Security Patch, Moderate Risk, Control Characters Fix. . LinuxSecurity.com Team
Tavis Ormandy discovered that the patch applied to fix CVE-2014-6271 released in DSA-3032-1 for bash, the GNU Bourne-Again Shell, was incomplete and could still allow some characters to be injected into another environment (CVE-2014-7169). With this update prefix and suffix . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3035-1
Get the latest Linux and open source security news straight to your inbox.