Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Two issues were discovered in librabbitmq, a C-language client library used to communicate with RabbitMQ servers using the Advanced Message Queuing Protocol (AMQP). CVE-2026-44235 A size_t underflow in AMQP frame length computation could have. Debian LTS Advisory DLA-4658-1
Moderate: librabbitmq security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:6482", "synopsis": "Moderate: librabbitmq security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for librabbitmq.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The librabbitmq packages provide an Advanced Message Queuing Protocol (AMQP) client library that allows you to communicate with AMQP servers using protocol version 0-9-1.\n\nSecurity Fix(es):\n\n* rabbitmq-c/librabbitmq: Insecure credentials submission (CVE-2023-35789)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 9.3 Release Notes linked from the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2215762", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2215762", "description": ""}], "cves": [{"name": "CVE-2023-35789", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35789", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "cvss3BaseScore": "5.1", "cwe": null}], "references": [], "publishedAt": "2026-06-25T12:03:37.665962Z", "rpms": {"Rocky Linux 9": {"nvras": ["librabbitmq-0:0.11.0-7.el9.aarch64.rpm", "librabbitmq-0:0.11.0-7.el9.i686.rpm", "librabbitmq-0:0.11.0-7.el9.ppc64le.rpm", "librabbitmq-0:0.11.0-7.el9.s390x.rpm", "librabbitmq-0:0.11.0-7.el9.src.rpm", "librabbitmq-0:0.11.0-7.el9.x86_64.rpm", "librabbitmq-debuginfo-0:0.11.0-7.el9.aarch64.rpm", "librabbitmq-debuginfo-0:0.11.0-7.el9.i686.rpm", "librabbitmq-debuginfo-0:0.11.0-7.el9.ppc64le.rpm","librabbitmq-debuginfo-0:0.11.0-7.el9.s390x.rpm", "librabbitmq-debuginfo-0:0.11.0-7.el9.x86_64.rpm", "librabbitmq-debugsource-0:0.11.0-7.el9.aarch64.rpm", "librabbitmq-debugsource-0:0.11.0-7.el9.i686.rpm", "librabbitmq-debugsource-0:0.11.0-7.el9.ppc64le.rpm", "librabbitmq-debugsource-0:0.11.0-7.el9.s390x.rpm", "librabbitmq-debugsource-0:0.11.0-7.el9.x86_64.rpm", "librabbitmq-devel-0:0.11.0-7.el9.aarch64.rpm", "librabbitmq-devel-0:0.11.0-7.el9.i686.rpm", "librabbitmq-devel-0:0.11.0-7.el9.ppc64le.rpm", "librabbitmq-devel-0:0.11.0-7.el9.s390x.rpm", "librabbitmq-devel-0:0.11.0-7.el9.x86_64.rpm", "librabbitmq-tools-0:0.11.0-7.el9.aarch64.rpm", "librabbitmq-tools-0:0.11.0-7.el9.ppc64le.rpm", "librabbitmq-tools-0:0.11.0-7.el9.s390x.rpm", "librabbitmq-tools-0:0.11.0-7.el9.x86_64.rpm", "librabbitmq-tools-debuginfo-0:0.11.0-7.el9.aarch64.rpm", "librabbitmq-tools-debuginfo-0:0.11.0-7.el9.ppc64le.rpm", "librabbitmq-tools-debuginfo-0:0.11.0-7.el9.s390x.rpm", "librabbitmq-tools-debuginfo-0:0.11.0-7.el9.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Discover the librabbitmq security update for Rocky Linux 9 addressing moderate risks and insecure credentials.. Rocky Linux librabbitmq security update CVE-2023-35789 credentials. . Severity: moderate. LinuxSecurity.com Team
Two security vulnberabilities were discovered in librabbitmq, an AMQP client library, which could result in denial of service or potentially the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in version 0.15.0-1+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6343-1
An issue has been found in librabbitmq, a AMQP client library and tools written in C. The issue is related to credential visibility when . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4096-1
An update for librabbitmq is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: librabbitmq security update Advisory ID: RHSA-2020:4445-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4445 Issue date: 2020-11-03 CVE Names: CVE-2019-18609 ==================================================================== 1. Summary: An update for librabbitmq is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The librabbitmq packages provide an Advanced Message Queuing Protocol (AMQP) client library that allows you to communicate with AMQP serversusing protocol version 0-9-1. Security Fix(es): * librabbitmq: integer overflow in amqp_handle_input in amqp_connection.c leads to heap-based buffer overflow (CVE-2019-18609) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section. 4.Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1786646 - CVE-2019-18609 librabbitmq: integer overflow in amqp_handle_input in amqp_connection.c leads to heap-based buffer overflow 6. Package List: Red Hat Enterprise Linux BaseOS (v. 8): Source: librabbitmq-0.9.0-2.el8.src.rpm aarch64: librabbitmq-0.9.0-2.el8.aarch64.rpm librabbitmq-debuginfo-0.9.0-2.el8.aarch64.rpm librabbitmq-debugsource-0.9.0-2.el8.aarch64.rpm librabbitmq-tools-debuginfo-0.9.0-2.el8.aarch64.rpm ppc64le: librabbitmq-0.9.0-2.el8.ppc64le.rpm librabbitmq-debuginfo-0.9.0-2.el8.ppc64le.rpm librabbitmq-debugsource-0.9.0-2.el8.ppc64le.rpm librabbitmq-tools-debuginfo-0.9.0-2.el8.ppc64le.rpm s390x: librabbitmq-0.9.0-2.el8.s390x.rpm librabbitmq-debuginfo-0.9.0-2.el8.s390x.rpm librabbitmq-debugsource-0.9.0-2.el8.s390x.rpm librabbitmq-tools-debuginfo-0.9.0-2.el8.s390x.rpm x86_64: librabbitmq-0.9.0-2.el8.i686.rpm librabbitmq-0.9.0-2.el8.x86_64.rpm librabbitmq-debuginfo-0.9.0-2.el8.i686.rpm librabbitmq-debuginfo-0.9.0-2.el8.x86_64.rpm librabbitmq-debugsource-0.9.0-2.el8.i686.rpm librabbitmq-debugsource-0.9.0-2.el8.x86_64.rpm librabbitmq-tools-debuginfo-0.9.0-2.el8.i686.rpm librabbitmq-tools-debuginfo-0.9.0-2.el8.x86_64.rpm Red Hat CodeReady Linux Builder (v.8): aarch64: librabbitmq-debuginfo-0.9.0-2.el8.aarch64.rpm librabbitmq-debugsource-0.9.0-2.el8.aarch64.rpm librabbitmq-devel-0.9.0-2.el8.aarch64.rpm librabbitmq-tools-debuginfo-0.9.0-2.el8.aarch64.rpm ppc64le: librabbitmq-debuginfo-0.9.0-2.el8.ppc64le.rpm librabbitmq-debugsource-0.9.0-2.el8.ppc64le.rpm librabbitmq-devel-0.9.0-2.el8.ppc64le.rpm librabbitmq-tools-debuginfo-0.9.0-2.el8.ppc64le.rpm s390x: librabbitmq-debuginfo-0.9.0-2.el8.s390x.rpm librabbitmq-debugsource-0.9.0-2.el8.s390x.rpm librabbitmq-devel-0.9.0-2.el8.s390x.rpm librabbitmq-tools-debuginfo-0.9.0-2.el8.s390x.rpm x86_64: librabbitmq-debuginfo-0.9.0-2.el8.i686.rpm librabbitmq-debuginfo-0.9.0-2.el8.x86_64.rpm librabbitmq-debugsource-0.9.0-2.el8.i686.rpm librabbitmq-debugsource-0.9.0-2.el8.x86_64.rpm librabbitmq-devel-0.9.0-2.el8.i686.rpm librabbitmq-devel-0.9.0-2.el8.x86_64.rpm librabbitmq-tools-debuginfo-0.9.0-2.el8.i686.rpm librabbitmq-tools-debuginfo-0.9.0-2.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-18609 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.3_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX6IxYdzjgjWX9erEAQiApQ/9F7Nif9dVrMaBZkY1G4HGRVpPvB6xMj54 MKjSAu7mpIxyQjQaXlpi/4ABLYAPe3aZJSZf7gq6uPOWrLpd9t+1gGAz159c36Nd gsuwkqyfgcMlDr8dto1QJEgfVuNIqmd2AGigM9CT7pgwjIdC2HKXk9aa49YTMYMS bPhd7MTu9U9AFVC2xjlAWtKqQqMvT51CCuBseXgEEXj8dKUmjI3uYFiK4C23AktS g3a8AMwNx8ovtj/BGkg1I1vMsrz3TyqAdXwkudnKVMO6lgAPDkbK63jIR/WU+L4N VjnsEUHgHjjvXKqjo4x8R+qAr4ZBD+yvtm1s1UlCysMHbWhv5YrEKWpHWa6Zn+zk O3XRtZ6U7hCP7kifcZvPvQajdempNkd7iVthrqQbWivXixJ20+rQkkZkTTWwMmOu uQrO+YpJ5qrw2p8vTmJtecuFoUHVpVKmUEHotg70Jk5FqiMHkQ8iDO621Qw68pmk tU6agCsWeHoyE0cKOZoFShbkFilEAJv8QziFXXZkB14uhjiEPdeISfFRpUHk3yZM KsLW1q4L4sFiaNFOLW+YHwHgN6wx8YDGBiXKltdxpDO7JZabrbdT9ww1kAhDN7uG 9SIO14o5UbbQq4mHL2Dkv6S2JI9AaQLip7hc3dWNLNE8QSjx+1KJr6sJ8M6EyX7x mO9RTMllbuw=eb8i -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for librabbitmq is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: librabbitmq security update Advisory ID: RHSA-2020:3949-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:3949 Issue date: 2020-09-29 CVE Names: CVE-2019-18609 ==================================================================== 1. Summary: An update for librabbitmq is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The librabbitmq packages provide an Advanced Message Queuing Protocol (AMQP) client library that allows you to communicate with AMQP serversusing protocol version 0-9-1. Security Fix(es): * librabbitmq: integer overflow in amqp_handle_input in amqp_connection.c leads to heap-based buffer overflow (CVE-2019-18609) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other relatedinformation, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.9 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1786646 - CVE-2019-18609 librabbitmq: integer overflow in amqp_handle_input in amqp_connection.c leads to heap-based buffer overflow 6. Package List: Red Hat Enterprise Linux ComputeNode (v. 7): Source: librabbitmq-0.8.0-3.el7.src.rpm x86_64: librabbitmq-0.8.0-3.el7.i686.rpm librabbitmq-0.8.0-3.el7.x86_64.rpm librabbitmq-debuginfo-0.8.0-3.el7.i686.rpm librabbitmq-debuginfo-0.8.0-3.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: librabbitmq-debuginfo-0.8.0-3.el7.i686.rpm librabbitmq-debuginfo-0.8.0-3.el7.x86_64.rpm librabbitmq-devel-0.8.0-3.el7.i686.rpm librabbitmq-devel-0.8.0-3.el7.x86_64.rpm librabbitmq-examples-0.8.0-3.el7.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: librabbitmq-0.8.0-3.el7.src.rpm ppc64: librabbitmq-0.8.0-3.el7.ppc.rpm librabbitmq-0.8.0-3.el7.ppc64.rpm librabbitmq-debuginfo-0.8.0-3.el7.ppc.rpm librabbitmq-debuginfo-0.8.0-3.el7.ppc64.rpm ppc64le: librabbitmq-0.8.0-3.el7.ppc64le.rpm librabbitmq-debuginfo-0.8.0-3.el7.ppc64le.rpm s390x: librabbitmq-0.8.0-3.el7.s390.rpm librabbitmq-0.8.0-3.el7.s390x.rpm librabbitmq-debuginfo-0.8.0-3.el7.s390.rpm librabbitmq-debuginfo-0.8.0-3.el7.s390x.rpm x86_64: librabbitmq-0.8.0-3.el7.i686.rpm librabbitmq-0.8.0-3.el7.x86_64.rpm librabbitmq-debuginfo-0.8.0-3.el7.i686.rpm librabbitmq-debuginfo-0.8.0-3.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: librabbitmq-debuginfo-0.8.0-3.el7.ppc.rpm librabbitmq-debuginfo-0.8.0-3.el7.ppc64.rpm librabbitmq-devel-0.8.0-3.el7.ppc.rpm librabbitmq-devel-0.8.0-3.el7.ppc64.rpm librabbitmq-examples-0.8.0-3.el7.ppc64.rpm ppc64le: librabbitmq-debuginfo-0.8.0-3.el7.ppc64le.rpm librabbitmq-devel-0.8.0-3.el7.ppc64le.rpm librabbitmq-examples-0.8.0-3.el7.ppc64le.rpm s390x: librabbitmq-debuginfo-0.8.0-3.el7.s390.rpm librabbitmq-debuginfo-0.8.0-3.el7.s390x.rpm librabbitmq-devel-0.8.0-3.el7.s390.rpm librabbitmq-devel-0.8.0-3.el7.s390x.rpm librabbitmq-examples-0.8.0-3.el7.s390x.rpm x86_64: librabbitmq-debuginfo-0.8.0-3.el7.i686.rpm librabbitmq-debuginfo-0.8.0-3.el7.x86_64.rpm librabbitmq-devel-0.8.0-3.el7.i686.rpm librabbitmq-devel-0.8.0-3.el7.x86_64.rpm librabbitmq-examples-0.8.0-3.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: librabbitmq-0.8.0-3.el7.src.rpm x86_64: librabbitmq-0.8.0-3.el7.i686.rpm librabbitmq-0.8.0-3.el7.x86_64.rpm librabbitmq-debuginfo-0.8.0-3.el7.i686.rpm librabbitmq-debuginfo-0.8.0-3.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: librabbitmq-debuginfo-0.8.0-3.el7.i686.rpm librabbitmq-debuginfo-0.8.0-3.el7.x86_64.rpm librabbitmq-devel-0.8.0-3.el7.i686.rpm librabbitmq-devel-0.8.0-3.el7.x86_64.rpm librabbitmq-examples-0.8.0-3.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-18609 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.9_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX3OjkdzjgjWX9erEAQhqoQ//bDEmtr09kB3tNsueySxTvQzx/IMTckmP 9bfpjsvzPb0ra6bjQ5U4k3fzx/Iz0tq4IkQ0r6RqiqhytKBttaCGKcLirAaojXJx iHlrH6LjOE3C5rsqshEv//ymN5xaBM2QhmnrfWhubiXSP1Vro3jITSREyACv24eq hHCIE6Z1qpoIkPw4VgRN5wVwWTJ7KdF1FkEVaUQekd0Ld06949NdAJU10LVYV0DR CmsASNpK6WO4dz/kFsSRT64jcS+lz3EjZCtNoXiNPYrvI6cJTl3QkD0AY0Z6gR6q qbP/+Y3TJ7XP1LnTJ3ebBqAXphs+Vki1jvuZNBEm89WATWtKJQxOb7OmGPOEA0MB y1UazrhsaIzZdKi7S1rPe4phU/tRhYNvgUfyH+CwyKUd7S+EiULKDZJdpB47uV+9 1L6RsH29n37k4MTXIvbQloanz4MBnEIJwKCJIoD1mOM4joRhvP/j0zIYXLU+/Wfi rYNJi9ChknOV7BWV/Iupu9Nt6EG30bC4oLPM1q6QpRpn5JVQYF8umGzDp2voIY9t puLdA00MjMqyUVX1IUPjw/2VWwP/wOSAkWiwTJXcX2UL7urtRBbIGC7tT3eUzeqo Qpl/eKUDSgUFCyr/hhpCrND37boIVmFkW+3If7cNn83FmbmA5sA/yoi6h2Xk4TM/ +YEy/bdXFuI=/PRZ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
RabbitMQ could be made to execute arbitrary code if it received a specially crafted input.. =========================================================================Ubuntu Security Notice USN-4214-2 December 11, 2019 librabbitmq vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: RabbitMQ could be made to execute arbitrary code if it received a specially crafted input. Software Description: - librabbitmq: Command-line utilities for interacting with AMQP servers Details: USN-4214-1 fixed a vulnerability in RabbitMQ. This update provides the corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: It was discovered that RabbitMQ incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: amqp-tools 0.8.0-1ubuntu0.18.04.2 librabbitmq4 0.8.0-1ubuntu0.18.04.2 Ubuntu 16.04 LTS: amqp-tools 0.7.1-1ubuntu0.2 librabbitmq-dev 0.7.1-1ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4214-2 https://ubuntu.com/security/notices/USN-4214-1 CVE-2019-18609 Package Information: https://launchpad.net/ubuntu/+source/librabbitmq/0.8.0-1ubuntu0.18.04.2 https://launchpad.net/ubuntu/+source/librabbitmq/0.7.1-1ubuntu0.2 . Ubuntu Security Advisory USN-4214-3 highlights a critical vulnerability in librabbitmq impacting various releases.. RabbitMQ, Ubuntu Security Notice, Code Execution, Input Handling. . Severity: Important. LinuxSecurity.com Team
**Added:** * amqp_ssl_socket_get_context can be used to get the current OpenSSL CTX* associated with a connection. **Changed:** * openssl: missing OpenSSL config is ignored as an OpenSSL init error (#523) * AMQP_DEFAULT_MAX_CHANNELS is now set to 2047 to follow current default channel limit in the RabbitMQ broker. (#513) **Fixed:** * add additional input. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-dd7c8f5435 2019-12-10 03:03:41.437135 --------------------------------------------------------------------------------Name : librabbitmq Product : Fedora 30 Version : 0.10.0 Release : 1.fc30 URL : https://github.com/alanxz/rabbitmq-c Summary : Client library for AMQP Description : This is a C-language AMQP client library for use with AMQP servers speaking protocol versions 0-9-1. --------------------------------------------------------------------------------Update Information: **Added:** * amqp_ssl_socket_get_context can be used to get the current OpenSSL CTX* associated with a connection. **Changed:** * openssl: missing OpenSSL config is ignored as an OpenSSL init error (#523) * AMQP_DEFAULT_MAX_CHANNELS is now set to 2047 to follow current default channel limit in the RabbitMQ broker. (#513) **Fixed:** * add additional input validation to prevent integer overflow when parsing a frame header. This addresses **CVE-2019-18609**. --------------------------------------------------------------------------------ChangeLog: * Mon Dec 2 2019 Remi Collet - 0.10.0-1 - update to 0.10.0 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-dd7c8f5435' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.