FAPI PolicyPCR not instatiating correctly (CVE-2020-24455). Note that all TPM object created with a PolicyPCR with the currentPcrs and currentPcrsAndBank options have been created with an incorrect policy that omits PCR checks. All such objects have to be recreated. . MGASA-2020-0417 - Updated tpm2-tss packages fix a security vulnerability Publication date: 13 Nov 2020 URL: https://advisories.mageia.org/MGASA-2020-0417.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-24455 FAPI PolicyPCR not instatiating correctly (CVE-2020-24455). Note that all TPM object created with a PolicyPCR with the currentPcrsand currentPcrsAndBank options have been created with an incorrect policy that omits PCR checks. All such objects have to be recreated. The tpm2-tss package has been updated to version 2.4.3, which includes a fix for this issue and several other changes. See the upstream release announcements for details. References: - https://bugs.mageia.org/show_bug.cgi?id=27412 - https://github.com/tpm2-software/tpm2-tss/releases/tag/2.4.3 - https://github.com/tpm2-software/tpm2-tss/releases - https://lists.fedoraproject.org/archives/list/
Low: selinux-policy enhancement update. Date: Tue, 14 Feb 2012 10:20:17 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Low: selinux-policy on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Low: selinux-policy enhancement update Issue date: 2012-02-13 The selinux-policy packages contain the rules that govern how confined processes run on the system. This update fixes the following bug: * An incorrect SELinux policy prevented the qpidd service from starting. These selinux-policy packages contain updated SELinux rules, which allow the qpidd service to be started correctly. * With SELinux in enforcing mode, the ssh-keygen utility was prevented from access to various applications and thus could not be used to generate SSH keys for these programs. With this update, the "ssh_keygen_t" SELinux domain type has been implemented as unconfined, which ensures the ssh-keygen utility to work correctly. All users of selinux-policy are advised to upgrade to these updated packages, which fix these bugs. SL6.x SRPMS: selinux-policy-3.7.19-126.el6_2.6.src.rpm i386: selinux-policy-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-doc-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-minimum-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-mls-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-targeted-3.7.19-126.el6_2.6.noarch.rpm x86_64: selinux-policy-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-doc-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-minimum-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-mls-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-targeted-3.7.19-126.el6_2.6.noarch.rpm . The recent SELinux policy modification addresses service initiation problems and enhances SSH key creation within Scientific Linux operating systems.. scientific linux selinux enhancement, selinux policy update, security patch. . Severity: Low. LinuxSecurity.com Team
In DSA-1603-1, Debian released an update to the BIND 9 domain name server, which introduced UDP source port randomization to mitigate the threat of DNS cache poisoning attacks (identified by the Common Vulnerabilities and Exposures project as CVE-2008-1447). - ------------------------------------------------------------------------Debian Security Advisory DSA-1617-1
Update SELinux policy to current rawhide to fix many policy problems . ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-271 2006-04-11 ---------------------------------------------------------------------Product : Fedora Core 5 Name : libsepol Version : 1.12.4 Release : 1.fc5 Summary : SELinux binary policy manipulation library Description : Security-enhanced Linux is a feature of the Linux® kernel and a number of utilities with enhanced security functionality designed to add mandatory access controls to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve the security of the Flask operating system. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of Type Enforcement®, Role-based Access Control, and Multi-level Security. libsepol provides an API for the manipulation of SELinux binary policies. It is used by checkpolicy (the policy compiler) and similar tools, as well as by programs like load_policy that need to perform specific transformations on binary policies such as customizing policy boolean settings. ---------------------------------------------------------------------Update Information: Update SELinux policy to current rawhide to fix many policy problems ---------------------------------------------------------------------* Mon Apr 3 2006 Dan Walsh 1.12.4-1.fc5 - Bump for FC5 * Wed Mar 29 2006 Dan Walsh 1.12.4-1 - Upgrade to latest from NSA * Generalize test for bitmap overflow in ebitmap_set_bit. * Mon Mar 27 2006 Dan Walsh 1.12.3-1 - Upgrade to latest from NSA * Fixed attr_convert_callback and expand_convert_type_set typemap bug. * Fri Mar 24 2006 Dan Walsh 1.12.2-1 - Upgrade to latest from NSA * Fixed avrule_block_write num_decls endian bug. *Fri Mar 17 2006 Dan Walsh 1.12.1-1 - Upgrade to latest from NSA * Fixed sepol_module_package_write buffer overflow bug. ---------------------------------------------------------------------This update can be downloaded from: 898a86aaf531753c3d2df49cc685dc1c641f7a9b SRPMS/libsepol-1.12.4-1.fc5.src.rpm e0d976643374b7d6694f253f49697aa3cc669227 ppc/libsepol-1.12.4-1.fc5.ppc.rpm 0c0f1dfc42c5116b941937cda3e5ba0136292fd1 ppc/libsepol-devel-1.12.4-1.fc5.ppc.rpm 776bf940200ef1292c97d3f3d41025af96cd2b79 ppc/debug/libsepol-debuginfo-1.12.4-1.fc5.ppc.rpm 47cbad1912e07a8e949e6004d3d4023622f39fb6 x86_64/libsepol-1.12.4-1.fc5.x86_64.rpm 71fb2d5115076ec520e81752fdf430bcba345453 x86_64/libsepol-devel-1.12.4-1.fc5.x86_64.rpm b3d84eef5157ba7a92588b8a7aa7c5d18dc3b410 x86_64/debug/libsepol-debuginfo-1.12.4-1.fc5.x86_64.rpm eb81ee7b91bfb2540764e97bdd3571ffb874c69c i386/libsepol-1.12.4-1.fc5.i386.rpm 4f621a495943eb4ed5919d393d0a30962028bbb1 i386/libsepol-devel-1.12.4-1.fc5.i386.rpm 47e0e367adad01bbcbc51914fd0ca12f205432f2 i386/debug/libsepol-debuginfo-1.12.4-1.fc5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-247 2006-04-03 ---------------------------------------------------------------------Product : Fedora Core 5 Name : selinux-policy Version : 2.2.25 Release : 3.fc5 Summary : SELinux policy configuration Description : SELinux Reference Policy - modular. --------------------------------------------------------------------- ---------------------------------------------------------------------This update can be downloaded from: dcbfaa8f1e69eacfe37da49004fd6898a62311d4 SRPMS/selinux-policy-2.2.25-3.fc5.src.rpm 911639245d8a3044976ec1c32989f394ace52593 ppc/selinux-policy-2.2.25-3.fc5.noarch.rpm e0333457aa9785b5e678dd2293ca991d1ae3b34f ppc/selinux-policy-targeted-2.2.25-3.fc5.noarch.rpm 186c6f5772a3fd00212a5518fbaac4218faca01b ppc/selinux-policy-mls-2.2.25-3.fc5.noarch.rpm 96ad10776cde18547e3250619ccf793ed6e7d9ee ppc/selinux-policy-strict-2.2.25-3.fc5.noarch.rpm 911639245d8a3044976ec1c32989f394ace52593 x86_64/selinux-policy-2.2.25-3.fc5.noarch.rpm e0333457aa9785b5e678dd2293ca991d1ae3b34f x86_64/selinux-policy-targeted-2.2.25-3.fc5.noarch.rpm 186c6f5772a3fd00212a5518fbaac4218faca01b x86_64/selinux-policy-mls-2.2.25-3.fc5.noarch.rpm 96ad10776cde18547e3250619ccf793ed6e7d9ee x86_64/selinux-policy-strict-2.2.25-3.fc5.noarch.rpm 911639245d8a3044976ec1c32989f394ace52593 i386/selinux-policy-2.2.25-3.fc5.noarch.rpm e0333457aa9785b5e678dd2293ca991d1ae3b34f i386/selinux-policy-targeted-2.2.25-3.fc5.noarch.rpm 186c6f5772a3fd00212a5518fbaac4218faca01b i386/selinux-policy-mls-2.2.25-3.fc5.noarch.rpm 96ad10776cde18547e3250619ccf793ed6e7d9ee i386/selinux-policy-strict-2.2.25-3.fc5.noarch.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at. ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.