Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Version 1.4.1 Update bundled Composer to 2.9.7 Version 1.4.0 New features! Prompt to install missing system dependencies. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3f4283f831 2026-04-23 01:08:14.063017+00:00 -------------------------------------------------------------------------------- Name : pie Product : Fedora 43 Version : 1.4.1 Release : 1.fc43 URL : https://github.com/php/pie Summary : PHP Installer for Extensions Description : PIE (PHP Installer for Extensions). PIE can install an extension to any installed PHP version. A list of extensions that support PIE can be found on https://packagist.org/extensions. Documentation: /usr/share/doc/pie/docs/usage.md -------------------------------------------------------------------------------- Update Information: Version 1.4.1 Update bundled Composer to 2.9.7 Version 1.4.0 New features! Prompt to install missing system dependencies Prompt to install build toolchain Support pre-packaged-binary for download-url-method Support INSTALL_ROOT environment variable to override destination For more information, see Upstream annoucenement -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 14 2026 Remi Collet - 1.4.1-1 - update to 1.4.1 * Wed Apr 8 2026 Remi Collet - 1.4.0-1 - update to 1.4.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3f4283f831' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
It was discovered that there was an issue in the opendmarc DMARC email filter system. A call to "db_stop" was missing from the post-installation script which meant that, under some configurations, the script would hang indefinitely. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3550-1
The update for mariadb-10.3 released as DLA-3114 introduced a bug in the mariadb-server-10.3 package, that could cause installation failures when installing or updating plugin packages. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3114-2
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in . MGASA-2022-0294 - Updated nodejs packages fix security vulnerability Publication date: 25 Aug 2022 URL: https://advisories.mageia.org/MGASA-2022-0294.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-43616, CVE-2022-32212, CVE-2022-32213, CVE-2022-32214, CVE-2022-32215, CVE-2022-32222 The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differsfrom package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. (CVE-2021-43616) DNS rebinding in --inspect via invalid IP addresses (CVE-2022-32212) HTTP Request Smuggling - Flawed Parsing of Transfer-Encoding (CVE-2022-32213) HTTP Request Smuggling - Improper Delimiting of Header Fields (CVE-2022-32214) HTTP Request Smuggling - Incorrect Parsing of Multi-line Transfer-Encoding (CVE-2022-32215) Attempt to read openssl.cnf from /home/iojs/build/ upon startup (CVE-2022-32222) References: - https://bugs.mageia.org/show_bug.cgi?id=30078 - https://nodejs.org/en/blog/vulnerability/july-2022-security-releases/ - https://github.com/nodejs/node/releases/tag/v14.19.0 - https://github.com/nodejs/node/releases/tag/v14.19.1 - https://github.com/nodejs/node/releases/tag/v14.19.2 - https://github.com/nodejs/node/releases/tag/v14.19.3 - https://github.com/nodejs/node/releases/tag/v14.20.0 - https://www.cve.org/CVERecord?id=CVE-2021-43616 - https://www.cve.org/CVERecord?id=CVE-2022-32212 - https://www.cve.org/CVERecord?id=CVE-2022-32213 -https://www.cve.org/CVERecord?id=CVE-2022-32214 - https://www.cve.org/CVERecord?id=CVE-2022-32215 - https://www.cve.org/CVERecord?id=CVE-2022-32222 SRPMS: - 8/core/nodejs-14.20.0-1.1.mga8 . Mageia has announced security note MGASA-2022-0294, addressing various vulnerabilities in nodejs packages to enhance system security.. nodejs Security Updates, Mageia Nodejs Vulnerabilities, Npm Package Threats. . LinuxSecurity.com Team
Add mingw subpackages.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-6746739d52 2022-03-26 14:56:28.650826 --------------------------------------------------------------------------------Name : svg2svgt Product : Fedora 36 Version : 0.9.6 Release : 14.fc36 URL : https://github.com/manisandro/svg2svgt Summary : SVG to SVG Tiny converter Description : Library and tools to convert SVG images to SVG Tiny, the subset of SVG implemented by QtSvg. --------------------------------------------------------------------------------Update Information: Add mingw subpackages. --------------------------------------------------------------------------------ChangeLog: * Thu Feb 24 2022 Sandro Mani - 0.9.6-14 - Make mingw subpackages noarch * Sat Feb 19 2022 Sandro Mani - 0.9.6-13 - Add mingw subpackage --------------------------------------------------------------------------------References: [ 1 ] Bug #2060171 - F36FailsToInstall: mingw64-freeimage, mingw32-freeimage https://bugzilla.redhat.com/show_bug.cgi?id=2060171 [ 2 ] Bug #2060172 - F36FailsToInstall: mingw32-gdal, mingw64-gdal https://bugzilla.redhat.com/show_bug.cgi?id=2060172 [ 3 ] Bug #2060174 - F36FailsToInstall: mingw32-opencv, mingw64-opencv https://bugzilla.redhat.com/show_bug.cgi?id=2060174 [ 4 ] Bug #2060175 - F36FailsToInstall: mingw32-poppler, mingw64-poppler https://bugzilla.redhat.com/show_bug.cgi?id=2060175 [ 5 ] Bug #2060176 - F36FailsToInstall: mingw32-python3-shapely, mingw64-python3-shapely https://bugzilla.redhat.com/show_bug.cgi?id=2060176 [ 6 ] Bug #2060177 - F36FailsToInstall: mingw32-qtspell-qt5, mingw64-qtspell-qt5 https://bugzilla.redhat.com/show_bug.cgi?id=2060177 [ 7 ] Bug #2060358 - F36FailsToInstall: mingw32-python3-pyproj, mingw64-python3-pyproj https://bugzilla.redhat.com/show_bug.cgi?id=2060358 [ 8 ] Bug #2060816 -F36FailsToInstall: mingw64-SDL2_image, mingw32-SDL2_image https://bugzilla.redhat.com/show_bug.cgi?id=2060816 [ 9 ] Bug #2060818 - F36FailsToInstall: mingw32-qt5-qtimageformats, mingw64-qt5-qtimageformats https://bugzilla.redhat.com/show_bug.cgi?id=2060818 [ 10 ] Bug #2060819 - F36FailsToInstall: mingw32-qt5-qtwebkit, mingw64-qt5-qtwebkit https://bugzilla.redhat.com/show_bug.cgi?id=2060819 [ 11 ] Bug #2060820 - F36FailsToInstall: mingw32-qt6-qtimageformats, mingw64-qt6-qtimageformats https://bugzilla.redhat.com/show_bug.cgi?id=2060820 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-6746739d52' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Zhuowei Zhang discovered a bug in the EAP authentication client code of strongSwan, an IKE/IPsec suite, that may allow to bypass the client and in some scenarios even the server authentication, or could lead to a denial-of-service attack. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5056-1
pip could be made to install different git revisions.. =========================================================================Ubuntu Security Notice USN-4961-1 May 19, 2021 python-pip vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: pip could be made to install different git revisions. Software Description: - python-pip: Python package installer Details: It was discovered that pip incorrectly handled unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: python3-pip 20.0.2-5ubuntu1.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4961-1 https://bugs.launchpad.net/ubuntu/+source/python-pip/+bug/1926957 Package Information: https://launchpad.net/ubuntu/+source/python-pip/20.0.2-5ubuntu1.5 . The Ubuntu Security Advisory USN-4961-1 pertains to a security flaw in python-pip, which could lead to possible execution of malicious code through git revision access.. python-pip vulnerability, remote attack exploit, ubuntu security notice. . LinuxSecurity.com Team
Update postgresql and libpq to the new upstream release.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-3286ac2acc 2021-02-26 01:07:35.019067 --------------------------------------------------------------------------------Name : postgresql Product : Fedora 33 Version : 12.6 Release : 1.fc33 URL : https://www.postgresql.org/ Summary : PostgreSQL client programs Description : PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you'll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package. --------------------------------------------------------------------------------Update Information: Update postgresql and libpq to the new upstream release. --------------------------------------------------------------------------------ChangeLog: * Tue Feb 16 2021 Honza Horak - 12.6-1 - Update to 12.6 * Wed Jan 13 2021 Honza Horak - 12.5-1 - Update to 12.5 Also fixes: CVE-2020-14349 CVE-2020-14350 CVE-2020-25695 CVE-2020-25696 CVE-2020-25694 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-3286ac2acc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.