Use RPM macros for python and cmake build directory ---- Ensure stb_image contains the latest CVE patches. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-23c0bd9a45 2023-11-08 01:38:49.724824 -------------------------------------------------------------------------------- Name : mlpack Product : Fedora 38 Version : 4.2.1 Release : 5.fc38 URL : https://www.mlpack.org/ Summary : Fast, header-only C++ machine learning library Description : mlpack is a C++ machine learning library with emphasis on scalability, speed, and ease-of-use. Its aim is to make machine learning possible for novice users by means of a simple, consistent API, while simultaneously exploiting C++ language features to provide maximum performance and maximum flexibility for expert users. mlpack outperforms competing machine learning libraries by large margins. -------------------------------------------------------------------------------- Update Information: Use RPM macros for python and cmake build directory ---- Ensure stb_image contains the latest CVE patches -------------------------------------------------------------------------------- ChangeLog: * Mon Oct 30 2023 Benson Muite - 4.2.1-5 - Use RPM macros for python and cmake build directory * Fri Oct 27 2023 Benjamin A. Beasley - 4.2.1-4 - Ensure stb_image contains the latest CVE patches * Wed Oct 25 2023 Benjamin A. Beasley - 4.2.1-3 - Ensure stb_image contains the latest CVE patches -------------------------------------------------------------------------------- References: [ 1 ] Bug #2246895 - Rebuild for static stb_image CVE vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2246895 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-23c0bd9a45' at the command line. For moreinformation, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to LLVM 17.0.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-67f0f8d186 2023-11-03 18:20:20.952539 -------------------------------------------------------------------------------- Name : libcxx Product : Fedora 39 Version : 17.0.2 Release : 1.fc39 URL : https://libcxx.llvm.org/ Summary : C++ standard library targeting C++11 Description : libc++ is a new implementation of the C++ standard library, targeting C++11. -------------------------------------------------------------------------------- Update Information: Update to LLVM 17.0.2 -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 4 2023 Tulio Magno Quites Machado Filho - 17.0.2-1 - Update to LLVM 17.0.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2225597 - CVE-2023-29941 llvm: sparse-buffer-rewrite pass crashes with Segmentation fault [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2225597 [ 2 ] Bug #2241873 - llvm-17.0.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2241873 [ 3 ] Bug #2242208 - libcxx-17.0.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2242208 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-67f0f8d186' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
This update of skopeo fixes the following issues: rebuild the package with the go 1.21 security release (bsc#1212475).. # Security update for skopeo Announcement ID: SUSE-SU-2023:3561-1 Rating: important References: * #1212475 Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that has one security fix can now be installed. ## Description: This update of skopeo fixes the following issues: * rebuild the package with the go 1.21 security release (bsc#1212475). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3561=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3561=1 * Basesystem Module 15-SP4 zypper in -tpatch SUSE-SLE-Module-Basesystem-15-SP4-2023-3561=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-3561=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-3561=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-3561=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-3561=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-3561=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-3561=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-3561=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-3561=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2023-3561=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * skopeo-debuginfo-1.12.0-150300.11.5.1 * skopeo-1.12.0-150300.11.5.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * skopeo-debuginfo-1.12.0-150300.11.5.1 * skopeo-1.12.0-150300.11.5.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * skopeo-debuginfo-1.12.0-150300.11.5.1 * skopeo-1.12.0-150300.11.5.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * skopeo-debuginfo-1.12.0-150300.11.5.1 * skopeo-1.12.0-150300.11.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (aarch64 x86_64) * skopeo-debuginfo-1.12.0-150300.11.5.1 * skopeo-1.12.0-150300.11.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * skopeo-debuginfo-1.12.0-150300.11.5.1 * skopeo-1.12.0-150300.11.5.1 * SUSE Linux Enterprise Server 15 SP3LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * skopeo-debuginfo-1.12.0-150300.11.5.1 * skopeo-1.12.0-150300.11.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * skopeo-debuginfo-1.12.0-150300.11.5.1 * skopeo-1.12.0-150300.11.5.1 * SUSE Manager Proxy 4.2 (x86_64) * skopeo-debuginfo-1.12.0-150300.11.5.1 * skopeo-1.12.0-150300.11.5.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * skopeo-debuginfo-1.12.0-150300.11.5.1 * skopeo-1.12.0-150300.11.5.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * skopeo-debuginfo-1.12.0-150300.11.5.1 * skopeo-1.12.0-150300.11.5.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * skopeo-debuginfo-1.12.0-150300.11.5.1 * skopeo-1.12.0-150300.11.5.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1212475 . Critical security patch for Skopeo targeting concerns linked to package recompilation following the Go 1.21 security update.. Skopeo Update, Security Fixes, Package Maintenance, openSUSE Security. . Severity: Important. LinuxSecurity.com Team
Update to devscripts-2.18.4, see for details.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-1ce5098a2d 2018-09-21 05:19:39.106935 --------------------------------------------------------------------------------Name : devscripts Product : Fedora 29 Version : 2.18.4 Release : 1.fc29 URL : https://packages.debian.org/sid/devscripts Summary : Scripts for Debian Package maintainers Description : Scripts to make the life of a Debian Package maintainer easier. --------------------------------------------------------------------------------Update Information: Update to devscripts-2.18.4, see for details. --------------------------------------------------------------------------------References: [ 1 ] Bug #1597581 - CVE-2018-13043 devscripts: grep-excuses uses YAML:Syck unsafely [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1597581 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-1ce5098a2d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.