Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --- See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-ea8f4e232d 2022-07-30 01:52:05.591840 --------------------------------------------------------------------------------Name : golang-github-evanphx-json-patch Product : Fedora 36 Version : 5.5.0 Release : 4.fc36 URL : https://github.com/evanphx/json-patch Summary : Go library to apply RFC6902 patches and create and apply RFC7386 patches Description : Jsonpatch is a library which provides functionallity for both applying RFC6902 JSON patches against documents, as well as for calculating & applying RFC7396 JSON merge patches. --------------------------------------------------------------------------------Update Information: Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Maxwell G 5.5.0-4 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-ea8f4e232d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
New ruby packages are available for Slackware 13.1, 13.37, 14.0, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] ruby (SSA:2013-075-01) New ruby packages are available for Slackware 13.1, 13.37, 14.0, and -current to fix security issues. Here are the details from the Slackware 14.0 ChangeLog: +--------------------------+ patches/packages/ruby-1.9.3_p392-i486-1_slack14.0.txz: Upgraded. This release includes security fixes about bundled JSON and REXML. For more information, see: https://www.cve.org/CVERecord?id=CVE-2013-0269 https://www.cve.org/CVERecord?id=CVE-2013-1821 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.1: Updated package for Slackware x86_64 13.1: Updated package for Slackware 13.37: Updated package for Slackware x86_64 13.37: Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.1 package: d8a92d0917f4107ebad92f0acc918f0a ruby-1.9.3_p392-i486-1_slack13.1.txz Slackware x86_64 13.1 package: b0c05ed98dec1b441e3c6b2b1c2ef448 ruby-1.9.3_p392-x86_64-1_slack13.1.txz Slackware 13.37 package: 668cbcb1d019be2d17d2e360e14ca71a ruby-1.9.3_p392-i486-1_slack13.37.txz Slackware x86_64 13.37 package: 3dd5f32e3a490c99b76849a3849d3d7e ruby-1.9.3_p392-x86_64-1_slack13.37.txz Slackware 14.0 package: 2243ed86da5940c91a4b1c6321613229 ruby-1.9.3_p392-i486-1_slack14.0.txz Slackware x86_64 14.0 package: bebd503e73b25925759c0911e7e8c805 ruby-1.9.3_p392-x86_64-1_slack14.0.txz Slackware -currentpackage: 75ef8411ec70de62ccc9d53343fe67c7 d/ruby-1.9.3_p392-i486-1.txz Slackware x86_64 -current package: 282f29edc2de41f8757f00234de97777 d/ruby-1.9.3_p392-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg ruby-1.9.3_p392-i486-1_slack14.0.txz +-----+ . Recent updates for Ruby packages in Slackware have been released to address urgent security vulnerabilities efficiently and quickly.. ruby package update, slackware security fix, software upgrades. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.