Upstream details at : https://access.redhat.com/errata/RHSA-2021:3798. CentOS Errata and Security Advisory 2021:3798 Moderate Upstream details at : https://access.redhat.com/errata/RHSA-2021:3798 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: a9775c264bc9077729880ff223db6978a0ee4aae22b8fbdf9d5c6d935f6518a3 openssl-1.0.2k-22.el7_9.x86_64.rpm bf4623f90ace835b85614e7e022ffcb2427a5b8235c7dedd511d580ac0c878aa openssl-devel-1.0.2k-22.el7_9.i686.rpm 3f51b4953396f40f83ef6281561e6aa2bd69daf5e98921e1562160c40eb64061 openssl-devel-1.0.2k-22.el7_9.x86_64.rpm 4d49a5d533e4c753cbeaf06a490dca1f72f5462a8fa7f3c634484c68241ddc7c openssl-libs-1.0.2k-22.el7_9.i686.rpm b3004d122d0a738cbff817b9531b9787dcd2e46f3ed06c59e99fd50749720806 openssl-libs-1.0.2k-22.el7_9.x86_64.rpm 60601627ced255e03b49d78f605f8c7726747b2eb27ab5531b5296d0afd1b2ce openssl-perl-1.0.2k-22.el7_9.x86_64.rpm d8d9646b9eb2ea7556c1afe53b0eacb8fcacd861d66fc82fd1bcecaf2c47e41a openssl-static-1.0.2k-22.el7_9.i686.rpm 2130f82985059fdc1825e34c818c10ce54691d99d56fb5b663cd8452c750913e openssl-static-1.0.2k-22.el7_9.x86_64.rpm Source: 1465729173440314b8a461c413b59c9e3263b07e83dc095051c77d2c3894bce5 openssl-1.0.2k-22.el7_9.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for python ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:2189-1 Rating: important References: #1176262 Cross-References: CVE-2019-20916 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python fixes the following issues: - Fixed a directory traversal in _download_http_url() (bsc#1176262 CVE-2019-20916) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-2189=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): libpython2_7-1_0-2.7.17-lp151.10.29.1 libpython2_7-1_0-debuginfo-2.7.17-lp151.10.29.1 python-2.7.17-lp151.10.29.1 python-base-2.7.17-lp151.10.29.1 python-base-debuginfo-2.7.17-lp151.10.29.1 python-base-debugsource-2.7.17-lp151.10.29.1 python-curses-2.7.17-lp151.10.29.1 python-curses-debuginfo-2.7.17-lp151.10.29.1 python-debuginfo-2.7.17-lp151.10.29.1 python-debugsource-2.7.17-lp151.10.29.1 python-demo-2.7.17-lp151.10.29.1 python-devel-2.7.17-lp151.10.29.1 python-gdbm-2.7.17-lp151.10.29.1 python-gdbm-debuginfo-2.7.17-lp151.10.29.1 python-idle-2.7.17-lp151.10.29.1 python-tk-2.7.17-lp151.10.29.1 python-tk-debuginfo-2.7.17-lp151.10.29.1 python-xml-2.7.17-lp151.10.29.1 python-xml-debuginfo-2.7.17-lp151.10.29.1 - openSUSE Leap 15.1(x86_64): libpython2_7-1_0-32bit-2.7.17-lp151.10.29.1 libpython2_7-1_0-32bit-debuginfo-2.7.17-lp151.10.29.1 python-32bit-2.7.17-lp151.10.29.1 python-32bit-debuginfo-2.7.17-lp151.10.29.1 python-base-32bit-2.7.17-lp151.10.29.1 python-base-32bit-debuginfo-2.7.17-lp151.10.29.1 - openSUSE Leap 15.1 (noarch): python-doc-2.7.17-lp151.10.29.1 python-doc-pdf-2.7.17-lp151.10.29.1 References: https://www.suse.com/security/cve/CVE-2019-20916.html https://bugzilla.suse.com/1176262 _______________________________________________ openSUSE Security Announce mailing list --
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-3444-1 October 10, 2017 linux, linux-aws, linux-gke, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-gke: Linux kernel for Google Container Engine (GKE) systems - linux-kvm: Linux kernel for cloud environments - linux-raspi2: Linux kernel for Raspberry Pi 2 - linux-snapdragon: Linux kernel for Snapdragon processors Details: Jan H. Schönherr discovered that the Xen subsystem did not properly handle block IO merges correctly in some situations. An attacker in a guest vm could use this to cause a denial of service (host crash) or possibly gain administrative privileges in the host. (CVE-2017-12134) Andrey Konovalov discovered that a divide-by-zero error existed in the TCP stack implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash). (CVE-2017-14106) Otto Ebeling discovered that the memory manager in the Linux kernel did not properly check the effective UID in some situations. A local attacker could use this to expose sensitive information. (CVE-2017-14140) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: linux-image-4.4.0-1008-kvm 4.4.0-1008.13 linux-image-4.4.0-1032-gke 4.4.0-1032.32 linux-image-4.4.0-1038-aws 4.4.0-1038.47 linux-image-4.4.0-1075-raspi2 4.4.0-1075.83 linux-image-4.4.0-1077-snapdragon 4.4.0-1077.82 linux-image-4.4.0-97-generic 4.4.0-97.120 linux-image-4.4.0-97-generic-lpae 4.4.0-97.120 linux-image-4.4.0-97-lowlatency 4.4.0-97.120 linux-image-4.4.0-97-powerpc-e500mc 4.4.0-97.120 linux-image-4.4.0-97-powerpc-smp 4.4.0-97.120 linux-image-4.4.0-97-powerpc64-emb 4.4.0-97.120 linux-image-4.4.0-97-powerpc64-smp 4.4.0-97.120 linux-image-aws 4.4.0.1038.40 linux-image-generic 4.4.0.97.102 linux-image-generic-lpae 4.4.0.97.102 linux-image-gke 4.4.0.1032.33 linux-image-kvm 4.4.0.1008.8 linux-image-lowlatency 4.4.0.97.102 linux-image-powerpc-e500mc 4.4.0.97.102 linux-image-powerpc-smp 4.4.0.97.102 linux-image-powerpc64-emb 4.4.0.97.102 linux-image-powerpc64-smp 4.4.0.97.102 linux-image-raspi2 4.4.0.1075.75 linux-image-snapdragon 4.4.0.1077.69 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-3444-1 CVE-2017-12134, CVE-2017-14106, CVE-2017-14140 Package Information: https://launchpad.net/ubuntu/+source/linux/4.4.0-97.120 https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1038.47 https://launchpad.net/ubuntu/+source/linux-gke/4.4.0-1032.32 https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1008.13 https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1075.83 https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1077.82 . System patches in Fedora target significant vulnerabilities according to FSA-2023-001, maintainingoverall security.. Ubuntu Kernel Updates, Security Fixes, Denial of Service, Linux Kernel, Security Advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.