Security fix for CVE-2021-31800 - #1957428, #1957427 - fix path traversal in smbserver.py ---- Updated to new upstream release 0.9.22. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-888ccfd5b6 2021-05-16 02:06:09.511375 --------------------------------------------------------------------------------Name : python-impacket Product : Fedora 33 Version : 0.9.22 Release : 3.fc33 URL : https://github.com/fortra/impacket Summary : Collection of Python classes providing access to network packets Description : Impacket is a collection of Python classes focused on providing access to network packets. Impacket allows Python developers to craft and decode network packets in simple and consistent manner. It is highly effective when used in conjunction with a packet capture utility or package such as Pcapy. Packets can be constructed from scratch, as well as parsed from raw data. Furthermore, the object oriented API makes it simple to work with deep protocol hierarchies. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-31800 - #1957428, #1957427 - fix path traversal in smbserver.py ---- Updated to new upstream release 0.9.22 --------------------------------------------------------------------------------ChangeLog: * Fri May 7 2021 Michal Ambroz - 0.9.22-3 - fix CVE-2021-31800 - #1957428, #1957427 during 0.9.22 lifecycle * Sun May 2 2021 Michal Ambroz - 0.9.22-2 - fix dependencies for EPEL7 as of #1893859 * Wed Apr 14 2021 Michal Ambroz - 0.9.22-1 - Updated to new upstream release 0.9.22 - modernize specfile with bconds - upstream patch for python39 compatibility (needed for FC34+) * Wed Jan 27 2021 Fedora Release Engineering - 0.9.21-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1957426 - CVE-2021-31800 python-impacket: Multiple path traversal vulnerabilities in smbserver.py https://bugzilla.redhat.com/show_bug.cgi?id=1957426 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-888ccfd5b6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2021-31800 - #1957428, #1957427 - fix path traversal in smbserver.py ---- Updated to new upstream release 0.9.22. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-52dfb60726 2021-05-16 02:01:05.994424 --------------------------------------------------------------------------------Name : python-impacket Product : Fedora 34 Version : 0.9.22 Release : 3.fc34 URL : https://github.com/fortra/impacket Summary : Collection of Python classes providing access to network packets Description : Impacket is a collection of Python classes focused on providing access to network packets. Impacket allows Python developers to craft and decode network packets in simple and consistent manner. It is highly effective when used in conjunction with a packet capture utility or package such as Pcapy. Packets can be constructed from scratch, as well as parsed from raw data. Furthermore, the object oriented API makes it simple to work with deep protocol hierarchies. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-31800 - #1957428, #1957427 - fix path traversal in smbserver.py ---- Updated to new upstream release 0.9.22 --------------------------------------------------------------------------------ChangeLog: * Fri May 7 2021 Michal Ambroz - 0.9.22-3 - fix CVE-2021-31800 - #1957428, #1957427 during 0.9.22 lifecycle * Sun May 2 2021 Michal Ambroz - 0.9.22-2 - fix dependencies for EPEL7 as of #1893859 * Wed Apr 14 2021 Michal Ambroz - 0.9.22-1 - Updated to new upstream release 0.9.22 - modernize specfile with bconds - upstream patch for python39 compatibility (needed for FC34+) * Wed Jan 27 2021 Fedora Release Engineering - 0.9.21-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1957426 - CVE-2021-31800 python-impacket: Multiple path traversal vulnerabilities in smbserver.py https://bugzilla.redhat.com/show_bug.cgi?id=1957426 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-52dfb60726' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Red Hat OpenShift Container Platform release 4.5.16 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: OpenShift Container Platform 4.5.16 security update Advisory ID: RHSA-2020:4320-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2020:4320 Issue date: 2020-10-26 CVE Names: CVE-2020-14336 ==================================================================== 1. Summary: Red Hat OpenShift Container Platform release 4.5.16 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Security Fix(es): * openshift: Restricted SCC allows pods to craft custom network packets (CVE-2020-14336) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For OpenShift Container Platform 4.5 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errataupdate: https://docs.redhat.com/en/documentation/openshift_container_platform/4.5/html/release_notes/ocp-4-5-release-notes Details on how to access this content are available at - -cli.html. 4. Bugs fixed (https://bugzilla.redhat.com/): 1856529 - CVE-2020-14336 ose-machine-config-operator-container: openshift: restricted SCC allows pods to craft custom network packets [openshift-4] 1858981 - CVE-2020-14336 openshift: restricted SCC allows pods to craft custom network packets 5. References: https://access.redhat.com/security/cve/CVE-2020-14336 https://access.redhat.com/security/updates/classification/#low 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX5bghtzjgjWX9erEAQgpAQ/+PDKD81hbLiUf9C7EPfyPnFmCkxQF1e2/ ecpKivZjK2Ekgb6T0Ryj99o3H+pZ3rNcltSSZ3BiMqSQ2TEWAPBETKmWSvXokfBi Mdh/CJhbRg8xbjk3AkdhLsZO5tPjASx+ZIE+vf2GDrj5pQcPLhdTbNNl3O6C8bmQ v7VrQud+kVruREusBmVWg1HTa4bG7LAUv3kQg8aoGtnJseSd/IhbAXqshR5tL2r5 WGQ0C/GWByabVUPhQbJcNe9xP7M+H5yZWTUbAWOzSderQaFyS25uOdJo3TO3lKnR dg2c6LXj5+SVSQgSQlaUka+du2k4KYwQZfBPsnEf5c7c5XmY1LoDgFkoFhbetHRN rECJlAwBnubrpd68MVEP9uU9ujCmUhBBqfJ8YpOu6Qr78JMtHpIFXZ+gJ1WgR/AU FcTAvu9ou93es66gCfxI31RjnLaiL4DWtfMoZQ6H+7tR/O0wMHs5cgm0zWICvL3x jHOdeqy118Sn9ZbfPr975d3AbDBDdz+qQrTd99Rg8068xxPjtMED0Uptsn5GAGRJ mFlWBOpyRSL1QOjM4I80UhL1IrDBtkGf7x2XTb8dmAD0lg71qLOQcosQmGmNcwSA l7beFbrjvWV+KQScXD80MbB7PzUFdMbr55ycqwyNmHLqhZP82hSS1/CaTiQ/coxW ShBj5Z9Ua1E=Kg/D -----END PGP SIGNATURE----- -- RHSA-announce mailing list
It was discovered that insufficient sanitising of received network packets in the game server of Teeworlds, an online multi-player platform 2D shooter, could result in denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4763-1
Get the latest Linux and open source security news straight to your inbox.