An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for bubblewrap ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1826-1 Rating: important References: #1136958 Cross-References: CVE-2019-12439 Affected Products: SUSE Linux Enterprise Module for Desktop Applications 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for bubblewrap fixes the following issues: Security issue fixed: - CVE-2019-12439: Fixed insecure use of /tmp (bsc#1136958). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Desktop Applications 15: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-2019-1826=1 Package List: - SUSE Linux Enterprise Module for Desktop Applications 15 (aarch64 ppc64le s390x x86_64): bubblewrap-0.2.0-3.3.1 bubblewrap-debuginfo-0.2.0-3.3.1 bubblewrap-debugsource-0.2.0-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-12439.html https://bugzilla.suse.com/1136958 _______________________________________________ sle-security-updates mailing list
insecure use of /tmp in mktexlsr. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-7292 2015-05-01 11:26:55 -------------------------------------------------------------------------------- Name : texlive Product : Fedora 21 Version : 2014 Release : 7.1.20140525_r34255.fc21 URL : https://tug.org/texlive/ Summary : TeX formatting system Description : The TeX Live software distribution offers a complete TeX system for a variety of Unix, Macintosh, Windows and other platforms. It encompasses programs for editing, typesetting, previewing and printing of TeX documents in many different languages, and a large collection of TeX macros and font libraries. The distribution includes extensive general documentation about TeX, as well as the documentation for the included software packages. -------------------------------------------------------------------------------- Update Information: insecure use of /tmp in mktexlsr -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 29 2015 Than Ngo - 4:2014-7.1.20140525_r34255 - Resolves: bz#1181169, insecure use of /tmp in mktexlsr * Wed Mar 4 2015 Ville Skyttä - 4:2014-7.20140525_r34255 - Install rpm macros in %{_rpmconfidir}/macros.d where available (#1074287) * Mon Jan 26 2015 David Tardon - 4:2014-6.20140525_r34255 - rebuild for ICU 54.1 * Fri Jan 23 2015 Marek Kasik - 4:2014-5.20140525_r34255 - Rebuild (poppler-0.30.0) * Sat Dec 27 2014 Kevin Fenzi - 4:2014-4.20140525_r34255 * Drop scriptlet that touches /home. Fixes bugs: #1128240 #1047361 #1073518 #1054338 * Thu Nov 27 2014 Marek Kasik - 4:2014-3.20140525_r34255 - Rebuild (poppler-0.28.1) * Tue Aug 26 2014 David Tardon - 4:2014-2.20140525_r34255 - rebuild for ICU 53.1 * Mon Aug 18 2014 Fedora Release Engineering - 4:2014-1.20140525_r34255.1 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1181167 - texlive: insecure use of /tmp in mktexlsr https://bugzilla.redhat.com/show_bug.cgi?id=1181167 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update texlive' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
insecure use of /tmp in mktexlsr. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-7564 2015-05-06 05:56:18 -------------------------------------------------------------------------------- Name : texlive Product : Fedora 22 Version : 2014 Release : 8.20140525_r34255.fc22 URL : https://tug.org/texlive/ Summary : TeX formatting system Description : The TeX Live software distribution offers a complete TeX system for a variety of Unix, Macintosh, Windows and other platforms. It encompasses programs for editing, typesetting, previewing and printing of TeX documents in many different languages, and a large collection of TeX macros and font libraries. The distribution includes extensive general documentation about TeX, as well as the documentation for the included software packages. -------------------------------------------------------------------------------- Update Information: insecure use of /tmp in mktexlsr -------------------------------------------------------------------------------- References: [ 1 ] Bug #1181167 - texlive: insecure use of /tmp in mktexlsr https://bugzilla.redhat.com/show_bug.cgi?id=1181167 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update texlive' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.