Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security issues were discovered in php-phpseclib, a PHP library for arbitrary-precision integer arithmetic, which could lead to Denial of Service. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3750-1
It was discovered that php-phpseclib, a PHP library for arbitrary-precision integer arithmetic, was vulnerable to the so-called Terrapin Attack. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3718-1
## 1.4.3 (12, Nov 2019) ### Security Improvements: - Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-1b95d7a131 2020-04-13 16:45:10.937085 --------------------------------------------------------------------------------Name : php-robrichards-xmlseclibs1 Product : Fedora 30 Version : 1.4.3 Release : 1.fc30 URL : https://github.com/robrichards/xmlseclibs Summary : A PHP library for XML Security (version 1) Description : xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. NOTE: php-mcrypt will not be automatically installed as a dependency of this package so it will need to be "manually" installed if it is required --specifically for the following XMLSecurityKey encryption types: - XMLSecurityKey::AES128_CBC - XMLSecurityKey::AES192_CBC - XMLSecurityKey::AES256_CBC - XMLSecurityKey::TRIPLEDES_CBC Autoloader: /usr/share/php/robrichards-xmlseclibs/autoload.php --------------------------------------------------------------------------------Update Information: ## 1.4.3 (12, Nov 2019) ### Security Improvements: - Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465). --------------------------------------------------------------------------------ChangeLog: * Sun Apr 5 2020 Shawn Iwinski - 1.4.3-1 - Update to 1.4.3 (RHBZ #1771533, CVE-2019-3465) - https://nvd.nist.gov/vuln/detail/CVE-2019-3465 * Thu Jan 30 2020 Fedora Release Engineering - 1.4.2-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Fri Jul 26 2019 Fedora Release Engineering - 1.4.2-8 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1771533 - php-robrichards-xmlseclibs1-1.4.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1771533 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-1b95d7a131' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
## 2.1.1 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01 ## 2.1.0 Backports changes from 3.0 branch. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-81f61cdceb 2019-11-15 03:20:21.101981 --------------------------------------------------------------------------------Name : php-robrichards-xmlseclibs Product : Fedora 29 Version : 2.1.1 Release : 1.fc29 URL : https://github.com/robrichards/xmlseclibs Summary : A PHP library for XML Security Description : xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. NOTE: php-mcrypt will not be automatically installed as a dependency of this package so it will need to be "manually" installed if it is required --specifically for the following XMLSecurityKey encryption types: - XMLSecurityKey::AES128_CBC - XMLSecurityKey::AES192_CBC - XMLSecurityKey::AES256_CBC - XMLSecurityKey::TRIPLEDES_CBC Autoloader: /usr/share/php/RobRichards/XMLSecLibs/autoload.php --------------------------------------------------------------------------------Update Information: ## 2.1.1 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01 ## 2.1.0 Backports changes from 3.0 branch --------------------------------------------------------------------------------ChangeLog: * Wed Nov 6 2019 Shawn Iwinski - 2.1.1-1 - Update to 2.1.1 (CVE-2019-3465) - https://simplesamlphp.org/security/201911-01 * Fri Jul 26 2019 Fedora Release Engineering - 2.0.1-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Sat Feb 2 2019 Fedora Release Engineering - 2.0.1-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-81f61cdceb' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
## 3.0.4 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-9a960c8a98 2019-11-15 03:00:50.375473 --------------------------------------------------------------------------------Name : php-robrichards-xmlseclibs3 Product : Fedora 31 Version : 3.0.4 Release : 1.fc31 URL : https://github.com/robrichards/xmlseclibs Summary : A PHP library for XML Security (version 3) Description : xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Autoloader: /usr/share/php/RobRichards/XMLSecLibs3/autoload.php --------------------------------------------------------------------------------Update Information: ## 3.0.4 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01 --------------------------------------------------------------------------------ChangeLog: * Wed Nov 6 2019 Shawn Iwinski - 3.0.4-1 - Update to 3.0.4 (RHBZ #1769353 / CVE-2019-3465) - https://simplesamlphp.org/security/201911-01 --------------------------------------------------------------------------------References: [ 1 ] Bug #1769353 - php-robrichards-xmlseclibs3-3.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1769353 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-9a960c8a98' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Dawid Golunski discovered that PHPMailer, a popular library to send email from PHP applications, allowed a remote attacker to execute code if they were able to provide a crafted Sender address. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3750-1
### v1.10.3 / v2.3.3 - This is a security release fixing an issue with signature validation. Please upgrade as soon as possible. - [201612-01](https://simplesamlphp.org/security/201612-01). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-5c32bae671 2016-12-12 20:33:39.179894 -------------------------------------------------------------------------------- Name : php-simplesamlphp-saml2_1 Product : Fedora 23 Version : 1.10.3 Release : 1.fc23 URL : https://github.com/simplesamlphp/saml2 Summary : SAML2 PHP library from SimpleSAMLphp (version 1) Description : A PHP library for SAML2 related functionality. Extracted from SimpleSAMLphp [1], used by OpenConext [2]. This library started as a collaboration between UNINETT [3] and SURFnet [4] but everyone is invited to contribute. Autoloader: /usr/share/php/SAML2_1/autoload.php [1] https://simplesamlphp.org/ [2] https://openconext.org/ [3] https://sikt.no/ [4] https://www.surf.nl -------------------------------------------------------------------------------- Update Information: ### v1.10.3 / v2.3.3 - This is a security release fixing an issue with signature validation. Please upgrade as soon as possible. - [201612-01](https://simplesamlphp.org/security/201612-01) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1401147 - php-simplesamlphp-saml2-2.3.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1401147 [ 2 ] Bug #1401148 - php-simplesamlphp-saml2_1-1.10.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1401148 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade php-simplesamlphp-saml2_1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signedwith the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
### v1.10.3 / v2.3.3 - This is a security release fixing an issue with signature validation. Please upgrade as soon as possible. - [201612-01](https://simplesamlphp.org/security/201612-01). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-5c32bae671 2016-12-12 20:33:39.179894 -------------------------------------------------------------------------------- Name : php-simplesamlphp-saml2 Product : Fedora 23 Version : 2.3.3 Release : 1.fc23 URL : https://github.com/simplesamlphp/saml2 Summary : SAML2 PHP library from SimpleSAMLphp Description : A PHP library for SAML2 related functionality. Extracted from SimpleSAMLphp [1], used by OpenConext [2]. This library started as a collaboration between UNINETT [3] and SURFnet [4] but everyone is invited to contribute. Autoloader: /usr/share/php/SAML2/autoload.php [1] https://simplesamlphp.org/ [2] https://openconext.org/ [3] https://sikt.no/ [4] https://www.surf.nl -------------------------------------------------------------------------------- Update Information: ### v1.10.3 / v2.3.3 - This is a security release fixing an issue with signature validation. Please upgrade as soon as possible. - [201612-01](https://simplesamlphp.org/security/201612-01) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1401147 - php-simplesamlphp-saml2-2.3.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1401147 [ 2 ] Bug #1401148 - php-simplesamlphp-saml2_1-1.10.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1401148 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade php-simplesamlphp-saml2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.