Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : beust-jcommander Product : Fedora 40 Version : 1.82 Release : 9.fc40 URL : http://jcommander.org/ Summary : Java framework for parsing command line parameters Description : JCommander is a very small Java framework that makes it trivial to parse command line parameters (with annotations). -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 1.82-9 - Rebuilt for java-21-openjdk as system jdk * Fri Mar 1 2024 Jiri Vanek - 1.82-8 - bump of release for for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
A flaw was discovered in Netty, a Java NIO client/server socket framework. The HTTP/2 protocol implementation allowed a denial of service (server resource consumption) because request cancellation can reset many streams quickly. This problem is also known as Rapid Reset Attack. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3656-1
It was discovered that libstruts1.2-java, a Java framework for MVC applications, contains a bug in its multi-page validation code. This allows input validation to be bypassed, even if MPV is not used directly. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3536-1
Security fix for CVE-2015-3192. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-11184 2015-07-04 17:45:37 -------------------------------------------------------------------------------- Name : springframework Product : Fedora 21 Version : 3.2.14 Release : 1.fc21 URL : https://spring.io/projects/spring-framework/ Summary : Spring Java Application Framework Description : Spring is a layered Java/J2EE application framework, based on code published in Expert One-on-One J2EE Design and Development by Rod Johnson (Wrox, 2002). -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-3192 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2015 Michal Srb - 0:3.2.14-1 - Update to 3.2.14 - Resolves: CVE-2015-3192 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1239002 - CVE-2015-3192 Spring Framework: denial-of-service attack with XML input https://bugzilla.redhat.com/show_bug.cgi?id=1239002 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update springframework' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Make current version of frysk available to FC5 users.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-739 2006-06-21 ---------------------------------------------------------------------Product : Fedora Core 5 Name : glib-java Version : 0.2.5 Release : 0.FC5 Summary : Base Library for the Java-GNOME libraries Description : Glib-java is a base framework for the Java-GNOME libraries. Allowing the use of GNOME through Java. ---------------------------------------------------------------------Update Information: Make current version of frysk available to FC5 users. ---------------------------------------------------------------------* Wed Jun 14 2006 Stepan Kasal - 0.2.5-0 - New version. * Wed May 24 2006 Ben Konrath - 0.2.4-4 - Change mod time of all java source files for the src zip. * Thu May 18 2006 Ben Konrath - 0.2.4-3 - Ensure Config.java has the same mod time accross rebuilds (needed for multilib). * Wed May 10 2006 Ben Konrath - 0.2.4-2 - Add -X option when zipping up the sources. This is needed for multilib. * Fri Apr 28 2006 Stepan Kasal - 0.2.4-1 - New version. ---------------------------------------------------------------------This update can be downloaded from: 128970ad158a14120a875cd1e577ecb6c2cbbbd1 SRPMS/glib-java-0.2.5-0.FC5.src.rpm 128970ad158a14120a875cd1e577ecb6c2cbbbd1 noarch/glib-java-0.2.5-0.FC5.src.rpm ff8ea72a1c813c53f781b19118382d3f1f4cf84e ppc/glib-java-devel-0.2.5-0.FC5.ppc.rpm 0b4068ec1e26759702e4db8d78d15b6484eaac67 ppc/glib-java-0.2.5-0.FC5.ppc.rpm 23690a7cd2728f6f046dc445db18e30f79ded767 ppc/debug/glib-java-debuginfo-0.2.5-0.FC5.ppc.rpm cd5c04833a0098d8580b16004db61eb8667a3e3c x86_64/glib-java-devel-0.2.5-0.FC5.x86_64.rpm 4af58f42b6d0a7caac9fac10491ac4a5e4112256 x86_64/debug/glib-java-debuginfo-0.2.5-0.FC5.x86_64.rpm 5c34a90ff91c72dd1be02f1fa99e739e3fd3f6ef x86_64/glib-java-0.2.5-0.FC5.x86_64.rpm f8828b971ed6b24366a086d47d36e55aa9d6c9ec i386/glib-java-devel-0.2.5-0.FC5.i386.rpm 99d69bdb3b9ba86b30db7d874b6125ac44c82716 i386/glib-java-0.2.5-0.FC5.i386.rpm 3c24f8d9de804a948fab64452bcb7b6322279ae4 i386/debug/glib-java-debuginfo-0.2.5-0.FC5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.