Update NTFS-3G to 2021.8.22 to fix multiple CVEs ---- New upstream development version 1.45.7. ---- Upstream patch to work with qemu 6.1 (RHBZ#1998820). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-4dd269a76c 2021-09-07 19:06:12.617794 --------------------------------------------------------------------------------Name : partclone Product : Fedora 35 Version : 0.3.17 Release : 4.fc35 URL : https://partclone.org/ Summary : Utility to clone and restore a partition Description : Partclone provides utilities to clone and restore used blocks on a partition and is designed for higher compatibility of the file system by using existing libraries, e.g. e2fslibs is used to read and write the ext2 partition. --------------------------------------------------------------------------------Update Information: Update NTFS-3G to 2021.8.22 to fix multiple CVEs ---- New upstream development version 1.45.7. ---- Upstream patch to work with qemu 6.1 (RHBZ#1998820) --------------------------------------------------------------------------------ChangeLog: * Thu Sep 2 2021 Robert Scheck 0.3.17-4 - Rebuilt for ntfs-3g 2021.8.22 (#2000495) --------------------------------------------------------------------------------References: [ 1 ] Bug #1998820 - libguestfs breaks with qemu 6.1 with error "Backing file specified without backing format" https://bugzilla.redhat.com/show_bug.cgi?id=1998820 [ 2 ] Bug #1999788 - ntfs-3g: Multiple buffer overflows in all versions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1999788 [ 3 ] Bug #1999869 - ntfs-3g-2021.8.22 is available https://bugzilla.redhat.com/show_bug.cgi?id=1999869 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-4dd269a76c' at the command line. For moreinformation, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update NTFS-3G to 2021.8.22 to fix multiple CVEs. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-38d1b07839 2021-09-07 16:26:35.652642 --------------------------------------------------------------------------------Name : partclone Product : Fedora 33 Version : 0.3.17 Release : 4.fc33 URL : https://partclone.org/ Summary : Utility to clone and restore a partition Description : Partclone provides utilities to clone and restore used blocks on a partition and is designed for higher compatibility of the file system by using existing libraries, e.g. e2fslibs is used to read and write the ext2 partition. --------------------------------------------------------------------------------Update Information: Update NTFS-3G to 2021.8.22 to fix multiple CVEs --------------------------------------------------------------------------------ChangeLog: * Thu Sep 2 2021 Robert Scheck 0.3.17-4 - Rebuilt for ntfs-3g 2021.8.22 (#2000495) * Thu Jul 22 2021 Fedora Release Engineering - 0.3.17-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild * Tue Jan 26 2021 Fedora Release Engineering - 0.3.17-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1999788 - ntfs-3g: Multiple buffer overflows in all versions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1999788 [ 2 ] Bug #1999869 - ntfs-3g-2021.8.22 is available https://bugzilla.redhat.com/show_bug.cgi?id=1999869 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-38d1b07839' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signedwith the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update NTFS-3G to 2021.8.22 to fix multiple CVEs ---- New upstream development version 1.45.7. ---- Upstream patch to work with qemu 6.1 (RHBZ#1998820). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-c0235d9d79 2021-09-04 19:31:30.714719 --------------------------------------------------------------------------------Name : partclone Product : Fedora 34 Version : 0.3.17 Release : 4.fc34 URL : https://partclone.org/ Summary : Utility to clone and restore a partition Description : Partclone provides utilities to clone and restore used blocks on a partition and is designed for higher compatibility of the file system by using existing libraries, e.g. e2fslibs is used to read and write the ext2 partition. --------------------------------------------------------------------------------Update Information: Update NTFS-3G to 2021.8.22 to fix multiple CVEs ---- New upstream development version 1.45.7. ---- Upstream patch to work with qemu 6.1 (RHBZ#1998820) --------------------------------------------------------------------------------ChangeLog: * Thu Sep 2 2021 Robert Scheck 0.3.17-4 - Rebuilt for ntfs-3g 2021.8.22 (#2000495) * Thu Jul 22 2021 Fedora Release Engineering - 0.3.17-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1998820 - libguestfs breaks with qemu 6.1 with error "Backing file specified without backing format" https://bugzilla.redhat.com/show_bug.cgi?id=1998820 [ 2 ] Bug #1999788 - ntfs-3g: Multiple buffer overflows in all versions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1999788 [ 3 ] Bug #1999869 - ntfs-3g-2021.8.22 is available https://bugzilla.redhat.com/show_bug.cgi?id=1999869 --------------------------------------------------------------------------------This update can be installedwith the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-c0235d9d79' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
It was discovered that partclone, an utility to backup partitions, was prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. This could allow remote attackers to cause a 'Denial of Service attack' in the context . Hash: SHA256 Package : partclone Version : 0.2.48-1+deb7u1 CVE ID : CVE-2017-6596 Debian Bug : 857966 It was discovered that partclone, an utility to backup partitions, was prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. This could allow remote attackers to cause a 'Denial of Service attack' in the context of the user running the affected application via a crafted partition image. For Debian 7 "Wheezy", these problems have been fixed in version 0.2.48-1+deb7u1. We recommend that you upgrade your partclone packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A crucial security patch for Partclone in Debian LTS has been released. Upgrade without delay to prevent potential Denial of Service vulnerabilities.. partclone update, Debian security, buffer overflow fix, Denial of Service, partition backup utility. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.