[New upstream release](https://github.com/coreos/coreos-installer/releases/tag/v0.10.1) fixing CVE-2021-20319.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-23fed0cab4 2021-10-29 22:48:33.392309 --------------------------------------------------------------------------------Name : rust-coreos-installer Product : Fedora 35 Version : 0.10.1 Release : 1.fc35 URL : Summary : Installer for Fedora CoreOS and RHEL CoreOS Description : coreos-installer installs Fedora CoreOS or RHEL CoreOS to bare-metal machines (or, occasionally, to virtual machines). --------------------------------------------------------------------------------Update Information: [New upstream release](https://github.com/coreos/coreos-installer/releases/tag/v0.10.1) fixing CVE-2021-20319. --------------------------------------------------------------------------------ChangeLog: * Mon Oct 11 2021 Benjamin Gilbert - 0.10.1-1 - New release * Tue Sep 14 2021 Sahana Prasad - 0.10.0-3 - Rebuilt with OpenSSL 3.0.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #2011862 - CVE-2021-20319 coreos-installer: incorrect signature verification on gzip-compressed install images https://bugzilla.redhat.com/show_bug.cgi?id=2011862 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-23fed0cab4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes 7 vulnerabilities is now available.. openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1831-1 Rating: important References: #1178375 Cross-References: CVE-2020-16004 CVE-2020-16005 CVE-2020-16006 CVE-2020-16007 CVE-2020-16008 CVE-2020-16009 CVE-2020-16011 Affected Products: openSUSE Leap 15.2 openSUSE Leap 15.1 openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: This update for chromium fixes the following issues: - Update to 86.0.4240.183 boo#1178375 - CVE-2020-16004: Use after free in user interface. - CVE-2020-16005: Insufficient policy enforcement in ANGLE. - CVE-2020-16006: Inappropriate implementation in V8 - CVE-2020-16007: Insufficient data validation in installer. - CVE-2020-16008: Stack buffer overflow in WebRTC. - CVE-2020-16009: Inappropriate implementation in V8. - CVE-2020-16011: Heap buffer overflow in UI on Windows. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1831=1 - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-1831=1 - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-1831=1 Package List: - openSUSE Leap 15.2 (x86_64): chromedriver-86.0.4240.183-lp152.2.45.1 chromedriver-debuginfo-86.0.4240.183-lp152.2.45.1 chromium-86.0.4240.183-lp152.2.45.1 chromium-debuginfo-86.0.4240.183-lp152.2.45.1 - openSUSE Leap 15.1 (x86_64): chromedriver-86.0.4240.183-lp151.2.150.1 chromedriver-debuginfo-86.0.4240.183-lp151.2.150.1 chromium-86.0.4240.183-lp151.2.150.1 chromium-debuginfo-86.0.4240.183-lp151.2.150.1 - openSUSE Backports SLE-15-SP1 (aarch64 x86_64): chromedriver-86.0.4240.183-bp151.3.119.1 chromium-86.0.4240.183-bp151.3.119.1 References: https://www.suse.com/security/cve/CVE-2020-16004.html https://www.suse.com/security/cve/CVE-2020-16005.html https://www.suse.com/security/cve/CVE-2020-16006.html https://www.suse.com/security/cve/CVE-2020-16007.html https://www.suse.com/security/cve/CVE-2020-16008.html https://www.suse.com/security/cve/CVE-2020-16009.html https://www.suse.com/security/cve/CVE-2020-16011.html https://bugzilla.suse.com/1178375 -- . Addresses significant vulnerabilities in Chromium for openSUSE, with crucial security patches set to be launched shortly.. openSUSE Security Update, Chromium Patch, Risk Management. . Severity: Important. LinuxSecurity.com Team
Security flaws have been found in the SYSLINUX installer when running setuid root.. - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200302-06 - --------------------------------------------------------------------- PACKAGE : syslinux SUMMARY : security issues in installer DATE : 2003-02-17 14:40 UTC EXPLOIT : local - --------------------------------------------------------------------- From syslinux changelog: "Security flaws have been found in the SYSLINUX installer when running setuid root. Rewrite the SYSLINUX installer so it uses mtools instead. It therefore now requires mtools (specifically mcopy and mattrib) to exist on your system, but it will not require root privileges and SHOULD NOT be setuid." SOLUTION It is recommended that all Gentoo Linux users who are running sys-apps/syslinux upgrade to syslinux-2.02 as follows: emerge sync emerge -u syslinux emerge clean - ---------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.