Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
New libnotify packages are available for Slackware 15.0 and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] libnotify (SSA:2023-283-02) New libnotify packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/libnotify-0.8.3-i586-1_slack15.0.txz: Upgraded. This release contains a critical stability/minor security update which affects Electron applications that utilize Portal notifications (eg, through Flatpak). It is highly recommended that all users of libnotify 0.8.x update to this release. (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libnotify-0.8.3-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/libnotify-0.8.3-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/libnotify-0.8.3-i586-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/libnotify-0.8.3-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: 9fa17d1faa882d2d14bfa2dfe009f079 libnotify-0.8.3-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 6a9a601e6f4053e166ce2029e990c6b7 libnotify-0.8.3-x86_64-1_slack15.0.txz Slackware -current package: 4b31ada4e25abe2d29d892a4a169150c l/libnotify-0.8.3-i586-1.txz Slackware x86_64 -current package: 9411aff6ff3a6857d567d1a9731a30e6 l/libnotify-0.8.3-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg libnotify-0.8.3-i586-1_slack15.0.txz +-----+ . Updated libnotify versions for Slackware 15.0 and current tackle significant security vulnerabilities affecting Electron application notifications.. Libnotify Update, Slackware Security, Electron App Fix, Package Upgrade, Security Update. . Severity: Critical. LinuxSecurity.com Team
Fix for the empty notification message issue. ---- Fix for crash on empty notification message.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-c942ed0424 2016-10-02 23:33:08.604399 -------------------------------------------------------------------------------- Name : systemd Product : Fedora 24 Version : 229 Release : 15.fc24 URL : https://https:// Summary : A System and Service Manager Description : systemd is a system and service manager for Linux, compatible with SysV and LSB init scripts. systemd provides aggressive parallelization capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, keeps track of processes using Linux cgroups, supports snapshotting and restoring of the system state, maintains mount and automount points and implements an elaborate transactional dependency-based service control logic. -------------------------------------------------------------------------------- Update Information: Fix for the empty notification message issue. ---- Fix for crash on empty notification message. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1380286 - CVE-2016-7795 CVE-2016-7796 systemd: Assertion failure when PID 1 receives a zero-length message over notify socket https://bugzilla.redhat.com/show_bug.cgi?id=1380286 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update systemd' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.