Security fix for CVE-2023-5535, CVE-2023-5441 ---- patchlevel 1984 ---- The newest upstream commit. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-1976197889 2023-11-03 18:20:20.955902 -------------------------------------------------------------------------------- Name : vim Product : Fedora 39 Version : 9.0.2048 Release : 1.fc39 URL : https://www.vim.org/ Summary : The VIM editor Description : VIM (VIsual editor iMproved) is an updated and improved version of the vi editor. Vi was the first real screen-based editor for UNIX, and is still very popular. VIM improves on vi by adding new features: multiple windows, multi-level undo, block highlighting and more. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-5535, CVE-2023-5441 ---- patchlevel 1984 ---- The newest upstream commit -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 18 2023 Zdenek Dohnal - 2:9.0.2048-1 - patchlevel 2048 * Thu Oct 5 2023 Remi Collet - 2:9.0.1984-2 - rebuild for new libsodium * Thu Oct 5 2023 Zdenek Dohnal - 2:9.0.1984-1 - patchlevel 1984 * Mon Oct 2 2023 Zdenek Dohnal - 2:9.0.1968-1 - patchlevel 1968 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2242141 - CVE-2023-5344 vim: Heap-based Buffer Overflow in trunc_string() https://bugzilla.redhat.com/show_bug.cgi?id=2242141 [ 2 ] Bug #2242926 - CVE-2023-5441 vim: NULL pointer dereference in screen_line() in src/screen.c https://bugzilla.redhat.com/show_bug.cgi?id=2242926 [ 3 ] Bug #2244101 - CVE-2023-5535 vim: use after free https://bugzilla.redhat.com/show_bug.cgi?id=2244101 -------------------------------------------------------------------------------- This update can be installed with the "dnf"update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1976197889' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
This update includes the fix for a memory consumption denial of service issue in the handling of request header lines (CVE CAN-2004-0942).. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-421 2004-11-12 --------------------------------------------------------------------- Product : Fedora Core 3 Name : httpd Version : 2.0.52 Release : 3.1 Summary : Apache HTTP Server Description : Apache is a powerful, full-featured, efficient, and freely-available Web server. Apache is also the most popular Web server on the Internet. --------------------------------------------------------------------- Update Information: This update includes the fix for a memory consumption denial of service issue in the handling of request header lines (CVE CAN-2004-0942). --------------------------------------------------------------------- * Thu Nov 11 2004 Joe Orton 2.0.52-3.1 - add fix for memory consumption DoS, CAN-2004-0942 --------------------------------------------------------------------- This update can be downloaded from: 7716c1d14e0ae69a891f2a329523dc96 SRPMS/httpd-2.0.52-3.1.src.rpm ec3154ccfa6ac70331c830836dcc4871 x86_64/httpd-2.0.52-3.1.x86_64.rpm 31fa689b0a81efdd0e004be836637bc9 x86_64/httpd-devel-2.0.52-3.1.x86_64.rpm c1d9035ad988c68b8ddae0c85c71ee02 x86_64/httpd-manual-2.0.52-3.1.x86_64.rpm 39c126e3f817d373daca7c441cb44caa x86_64/mod_ssl-2.0.52-3.1.x86_64.rpm ceb684bb374754185bcdd4d859b11204 x86_64/httpd-suexec-2.0.52-3.1.x86_64.rpm 5b3aedb582d98588a052741f907b191c x86_64/debug/httpd-debuginfo-2.0.52-3.1.x86_64.rpm de542c36d54e33026de4ab41c5e1853f i386/httpd-2.0.52-3.1.i386.rpm d1e862ee15033b0a8a4f0e61e09a58eb i386/httpd-devel-2.0.52-3.1.i386.rpm ec0ffcc129a05b97d8e83656bc49efff i386/httpd-manual-2.0.52-3.1.i386.rpm 5c55333c780b4fe78449044c95d93ed3 i386/mod_ssl-2.0.52-3.1.i386.rpm bf1ffd0c0cf005de92d3efeb81c9228e i386/httpd-suexec-2.0.52-3.1.i386.rpm 4e2f66cc48e668b74dedcfb9f9c12e66 i386/debug/httpd-debuginfo-2.0.52-3.1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Memory overflow vulnerability patch for Apache HTTPD 2.0.52 on Fedora, enhancing request header processing. Discover the details!. Apache Server Security,Fedora Update,Memory Consumption Fix,HTTPD Update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.