An update that contains security fixes can now be installed. . SUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1580-1 Rating: important References: #1183790 #1185021 #1185196 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for xen fixes the following issues: - A recent systemd update caused a regression in 'xenstored.service' systemd now fails to track units that use systemd-notify. (bsc#1183790) - Add a fix to delay between the call to 'systemd-notify' and the final exit of the wrapper script. (bsc#1185021, bsc#1185196) - Run xenstored in a separeately, which will make processing of large and/or concurrent batches of xenstore accesses more robust. (fate#323663) Special Instructions and Notes: Please reboot the system after installing this update. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-1580=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-1580=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 x86_64): xen-debugsource-4.12.4_10-3.42.1 xen-devel-4.12.4_10-3.42.1 - SUSE Linux Enterprise Server 12-SP5 (x86_64): xen-4.12.4_10-3.42.1 xen-debugsource-4.12.4_10-3.42.1 xen-doc-html-4.12.4_10-3.42.1 xen-libs-32bit-4.12.4_10-3.42.1 xen-libs-4.12.4_10-3.42.1 xen-libs-debuginfo-32bit-4.12.4_10-3.42.1 xen-libs-debuginfo-4.12.4_10-3.42.1 xen-tools-4.12.4_10-3.42.1 xen-tools-debuginfo-4.12.4_10-3.42.1 xen-tools-domU-4.12.4_10-3.42.1 xen-tools-domU-debuginfo-4.12.4_10-3.42.1 References: https://bugzilla.suse.com/1183790 https://bugzilla.suse.com/1185021 https://bugzilla.suse.com/1185196 . SUSE Security Patch for xen resolves process vulnerabilities. Apply updates via zypper patch or YaST. A reboot is advised.. SUSE Linux Enterprise, xen fixes, security updates, systemd regression. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is now available. now available.. openSUSE Security Update: Security update for util-linux ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:0590-1 Rating: important References: #1008965 #1012504 #1012632 #1019332 #1020077 #1023041 Cross-References: CVE-2017-2616 Affected Products: openSUSE Leap 42.1 ______________________________________________________________________________ An update that solves one vulnerability and has 5 fixes is now available. Description: This update for util-linux fixes the following issues: This security issue was fixed: - CVE-2017-2616: In su with PAM support it was possible for local users to send SIGKILL to selected other processes with root privileges (bsc#1023041). This non-security issues were fixed: - lscpu: Implement WSL detection and work around crash (bsc#1019332) - fstrim: De-duplicate btrfs sub-volumes for "fstrim -a" and bind mounts (bsc#1020077) - Fix regressions in safe loop re-use patch set for libmount (bsc#1012504) - Disable ro checks for mtab (bsc#1012632) - Ensure that the option "users,exec,dev,suid" work as expected on NFS mounts (bsc#1008965) This update was imported from the SUSE:SLE-12-SP1:Update update project. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.1: zypper in -t patch openSUSE-2017-305=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.1 (i586 x86_64): libblkid-devel-2.25-21.1 libblkid1-2.25-21.1 libblkid1-debuginfo-2.25-21.1 libmount-devel-2.25-21.1 libmount1-2.25-21.1 libmount1-debuginfo-2.25-21.1 libsmartcols-devel-2.25-21.1 libsmartcols1-2.25-21.1 libsmartcols1-debuginfo-2.25-21.1 libuuid-devel-2.25-21.1 libuuid1-2.25-21.1 libuuid1-debuginfo-2.25-21.1 python-libmount-2.25-21.1 python-libmount-debuginfo-2.25-21.1 python-libmount-debugsource-2.25-21.1 util-linux-2.25-21.1 util-linux-debuginfo-2.25-21.1 util-linux-debugsource-2.25-21.1 util-linux-systemd-2.25-21.1 util-linux-systemd-debuginfo-2.25-21.1 util-linux-systemd-debugsource-2.25-21.1 uuidd-2.25-21.1 uuidd-debuginfo-2.25-21.1 - openSUSE Leap 42.1 (noarch): util-linux-lang-2.25-21.1 - openSUSE Leap 42.1 (x86_64): libblkid-devel-32bit-2.25-21.1 libblkid1-32bit-2.25-21.1 libblkid1-debuginfo-32bit-2.25-21.1 libmount-devel-32bit-2.25-21.1 libmount1-32bit-2.25-21.1 libmount1-debuginfo-32bit-2.25-21.1 libuuid-devel-32bit-2.25-21.1 libuuid1-32bit-2.25-21.1 libuuid1-debuginfo-32bit-2.25-21.1 References: https://www.suse.com/security/cve/CVE-2017-2616.html https://bugzilla.suse.com/1008965 https://bugzilla.suse.com/1012504 https://bugzilla.suse.com/1012632 https://bugzilla.suse.com/1019332 https://bugzilla.suse.com/1020077 https://bugzilla.suse.com/1023041 . New update released for openSUSE; includes critical security patch for util-linux, enhancing overall system protection.. openSUSE security fix, util-linux update, system patch management. . Severity: Important. LinuxSecurity.com Team
- CVE-2015-5287: ignore crashes of abrt tools if DebugLevel = 0 - CVE-2015-5273: create own random temporary directory - make crashes of processes with locked memory not-reportable - detect xorg backtraces from journald - fix the coredumpctl integration tool. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-79c1758468 2015-11-28 18:54:20.794542 -------------------------------------------------------------------------------- Name : abrt Product : Fedora 23 Version : 2.7.1 Release : 1.fc23 URL : https://abrt.readthedocs.io/en/latest/ Summary : Automatic bug detection and reporting tool Description : abrt is a tool to help users to detect defects in applications and to create a bug report with all information needed by maintainer to fix it. It uses plugin system to extend its functionality. -------------------------------------------------------------------------------- Update Information: - CVE-2015-5287: ignore crashes of abrt tools if DebugLevel = 0 - CVE-2015-5273: create own random temporary directory - make crashes of processes with locked memory not-reportable - detect xorg backtraces from journald - fix the coredumpctl integration tool -------------------------------------------------------------------------------- References: [ 1 ] Bug #1262252 - CVE-2015-5273 abrt: Insecure temporary directory usage in abrt-action-install-debuginfo-to-abrt-cache https://bugzilla.redhat.com/show_bug.cgi?id=1262252 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update abrt' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
New netscape packages are available that fix a potential overflow due to improper input verification in netscape's JPEGprocessing code.. ` --------------------------------------------------------------------- Red Hat, Inc. Security Advisory Synopsis: New netscape packages available to fix JPEG problem Advisory ID: RHSA-2000:046-02 Issue date: 2000-07-28 Updated on: 2000-07-28 Product: Red Hat Linux Keywords: netscpae JPEG Cross references: N/A --------------------------------------------------------------------- 1. Topic: New netscape packages are available that fix a potential overflow due to improper input verification in netscape's JPEG processing code. It is recommended that users of netscape update to the fixed packages. Users of Red Hat Linux 6.0 and 6.1 should use the packages for Red Hat Linux 6.2. 2. Relevant releases/architectures: Red Hat Linux 5.2 - i386 Red Hat Linux 6.0 - i386 Red Hat Linux 6.1 - i386 Red Hat Linux 6.2 - i386, alpha 3. Problem description: Netscape's processing of JPEG comments trusted the length parameter for comment fields; by manipulating this value, it would be possible to cause netscape to read in an excessive amount of data, overwriting memory. Specially designed data could allow a remote site to execute arbitrary code as the user of netscape. This vulnerability is fixed in Netscape 4.74. 4. Solution: For each RPM for your particular architecture, run: rpm -Fvh [filename] where filename is the name of the RPM. 5. Bug IDs fixed ( for more info): 10165 - Netscape mail client does not compact folders anymore 13695 - Small glitch in German translation 14506 - Upgrade of netscape-common fails 14657 - /usr/lib/netscape/de_DE: cpio: unlinkfailed 6. RPMs required: Red Hat Linux 5.2: i386: sources: Red Hat Linux 6.2: alpha: i386: sources: 7. Verification: MD5 sum PackageName -------------------------------------------------------------------------- 2520f9f234010f483d14ec524898ad29 5.2/SRPMS/netscape-4.74-0.5.2.src.rpm 2dd30f35857c05304e54253e7564634b 5.2/i386/netscape-common-4.74-0.5.2.i386.rpm 765fc5c8be9638560544379a3c7e1004 5.2/i386/netscape-communicator-4.74-0.5.2.i386.rpm d6ecb766f5d979e2787f239fefcce8fd 5.2/i386/netscape-navigator-4.74-0.5.2.i386.rpm 64999688cbd3b6be723c72d94dcb0f72 6.2/SRPMS/netscape-4.74-0.6.2.src.rpm e75ad6a500fa4ac0ef919f65aa8871bd 6.2/SRPMS/netscape-alpha-4.74-1.src.rpm 2796178bd0f400800d1fb5fccd39880b 6.2/alpha/netscape-common-4.74-1.alpha.rpm 2f2260eb8030751838f9d14a4eca71ae 6.2/alpha/netscape-communicator-4.74-1.alpha.rpm db641b2f9b63c3f986dece1ecc482d32 6.2/alpha/netscape-navigator-4.74-1.alpha.rpm 2f2f1be58b481030eb2da12dcd9a6a54 6.2/i386/netscape-common-4.74-0.6.2.i386.rpm 6b2045ecf408024a64962705c6395a1f 6.2/i386/netscape-communicator-4.74-0.6.2.i386.rpm 03b93972ba0f114d4be9ef50a2a21fa5 6.2/i386/netscape-navigator-4.74-0.6.2.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000 Red Hat, Inc. `. Fix critical overflow in Netscape JPEG processing on Red Hat 6.2. Update to protect against potential attacks and exploit.. Netscape Patch, Red Hat Linux, JPEG Update, Critical Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.