Update to 3.1.0 Fix CVE-2020-24455 FAPI PolicyPCR not instatiating correctly Note: that all TPM object created with a PolicyPCR with the currentPcrs and currentPcrsAndBank options have been created with an incorrect policy that ommits PCR checks. All these objects have to be recreated!. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-fa78f3ca9f 2021-05-24 01:00:24.873960 --------------------------------------------------------------------------------Name : tpm2-tss Product : Fedora 34 Version : 3.1.0 Release : 1.fc34 URL : https://github.com/tpm2-software/tpm2-tss Summary : TPM2.0 Software Stack Description : tpm2-tss is a software stack supporting Trusted Platform Module(TPM) 2.0 system APIs. It sits between TPM driver and applications, providing TPM2.0 specified APIs for applications to access TPM module through kernel TPM drivers. --------------------------------------------------------------------------------Update Information: Update to 3.1.0 Fix CVE-2020-24455 FAPI PolicyPCR not instatiating correctly Note: that all TPM object created with a PolicyPCR with the currentPcrs and currentPcrsAndBank options have been created with an incorrect policy that ommits PCR checks. All these objects have to be recreated! --------------------------------------------------------------------------------ChangeLog: * Mon May 17 2021 Peter Robinson - 3.1.0-1 - Update to 3.1.0 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-fa78f3ca9f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: flash-player to 11.2.202.346 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2014:0377-1 Rating: important References: #867808 Cross-References: CVE-2013-0504 CVE-2014-0503 Affected Products: openSUSE 13.1:NonFree openSUSE 12.3:NonFree ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: Adobe Flash Player was updated to version 11.2.202.346 to fix security issues: CVE-2014-0503: A vulnerability that could be used to bypass the same origin policy was fixed. CVE-2014-0504: A vulnerability that could be used to read the contents of the clipboard was fixed. More information can be found on: -08.html Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.1:NonFree: zypper in -t patch openSUSE-2014-212 - openSUSE 12.3:NonFree: zypper in -t patch openSUSE-2014-212 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.1:NonFree (i586 x86_64): flash-player-11.2.202.346-38.1 flash-player-gnome-11.2.202.346-38.1 flash-player-kde4-11.2.202.346-38.1 - openSUSE 12.3:NonFree (i586 x86_64): flash-player-11.2.202.346-2.64.1 flash-player-gnome-11.2.202.346-2.64.1 flash-player-kde4-11.2.202.346-2.64.1 References: https://www.suse.com/security/cve/CVE-2013-0504.html https://www.suse.com/security/cve/CVE-2014-0503.html -- . New update for openSUSE: flash-player version 11.2.202.346 has been released, fixing important security vulnerabilities. Upgrade now!. openSUSE Updates, Flash Player Security, Important Updates, Software Vulnerabilities. . Severity:Important. LinuxSecurity.com Team
This update fixes CVE-2008-0595.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2008-2070 2008-02-28 21:10:49 --------------------------------------------------------------------------------Name : dbus Product : Fedora 8 Version : 1.1.2 Release : 9.fc8 URL : https://https:// Summary : D-BUS message bus Description : D-BUS is a system for sending messages between applications. It is used both for the systemwide message bus service, and as a per-user-login-session messaging facility. --------------------------------------------------------------------------------ChangeLog: * Wed Feb 27 2008 David Zeuthen - 1.1.2-9.fc8 - CVE-2008-0595 * Thu Oct 25 2007 Bill Nottingham - 1.1.2-8 - have -libs obsolete older versions of the main package so that yum upgrades work --------------------------------------------------------------------------------References: [ 1 ] Bug #432419 - CVE-2008-0595 dbus security policy circumvention https://bugzilla.redhat.com/show_bug.cgi?id=432419 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update dbus' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.