- Update to 4.1.5 Release notes: /powerdns-authoritative-server-4-0-6-4-1-5-and-recursor-4-0-9-4-1-5-released/ PowerDNS Security Advisory 2018-03 (https://doc.powerdns.com/authoritative/index.html /security-advisories/powerdns-advisory-2018-03.html) (CVE-2018-10851) PowerDNS Security Advisory 2018-05 (-. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-5a1e2759aa 2018-11-16 03:41:37.813272 --------------------------------------------------------------------------------Name : pdns Product : Fedora 27 Version : 4.1.5 Release : 1.fc27 URL : https://www.powerdns.com/ Summary : A modern, advanced and high performance authoritative-only nameserver Description : The PowerDNS Nameserver is a modern, advanced and high performance authoritative-only nameserver. It is written from scratch and conforms to all relevant DNS standards documents. Furthermore, PowerDNS interfaces with almost any database. --------------------------------------------------------------------------------Update Information: - Update to 4.1.5 Release notes: /powerdns-authoritative-server-4-0-6-4-1-5-and-recursor-4-0-9-4-1-5-released/ PowerDNS Security Advisory 2018-03 (https://doc.powerdns.com/authoritative/index.html /security-advisories/powerdns-advisory-2018-03.html) (CVE-2018-10851) PowerDNS Security Advisory 2018-05 () (CVE-2018-14626) --------------------------------------------------------------------------------ChangeLog: * Tue Nov 6 2018 Morten Stevens - 4.1.5-1 - Update to 4.1.5 - PowerDNS Security Advisory 2018-03 (CVE-2018-10851) - PowerDNS Security Advisory 2018-05 (CVE-2018-14626) * Mon Oct 1 2018 Richard Shaw - 4.1.4-1.1 - Rebuild for yaml-cpp 0.6 due to CVE-2017-5950. * Wed Sep 19 2018 Morten Stevens - 4.1.4-1 - Update to 4.1.4 * Fri Jul 13 2018 Fedora Release Engineering - 4.1.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Fri May 25 2018 Morten Stevens -4.1.3-1 - Update to 4.1.3 * Wed May 16 2018 Morten Stevens - 4.1.2-1 - Update to 4.1.2 * Mon Mar 19 2018 Iryna Shcherbina - 4.1.1-3 - Update Python 2 dependency declarations to new packaging standards (See * Mon Feb 19 2018 Ruben Kerkhof - 4.1.1-2 - BuildRequire gcc-c++ (https://fedoraproject.org/wiki/Packaging:C_and_C%2B%2B#BuildRequire) * Fri Feb 16 2018 Morten Stevens - 4.1.1-1 - Update to 4.1.1 * Wed Feb 14 2018 Richard Shaw - 4.1.0-5 - Rebuild for yaml-cpp 0.6.0. * Fri Feb 9 2018 Igor Gnatenko - 4.1.0-4 - Escape macros in %changelog * Thu Feb 8 2018 Fedora Release Engineering - 4.1.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Thu Feb 1 2018 Morten Stevens - 4.1.0-2 - Rebuilt for Boost 1.66 * Thu Nov 30 2017 Morten Stevens - 4.1.0-1 - Update to 4.1.0 * Wed Nov 29 2017 Igor Gnatenko - 4.1.0-0.8.rc3 - Rebuild for protobuf 3.5 * Fri Nov 17 2017 Morten Stevens - 4.1.0-0.7.rc3 - Update to 4.1.0-rc3 * Mon Nov 13 2017 Igor Gnatenko - 4.1.0-0.6.rc2 - Rebuild for protobuf 3.4 * Mon Nov 6 2017 Morten Stevens - 4.1.0-0.5.rc2 - Update to 4.1.0-rc2 - Dropped support for backend opendbx and zeromq * Mon Oct 23 2017 Morten Stevens - 4.1.0-0.4.rc1 - Removed Fedora specific systemd patch * Sun Oct 15 2017 Morten Stevens - 4.1.0-0.3.rc1 - Added Fedora specific systemd patch - Added upstream patch to fix an issue with MariaDB 10.2 - Enabled upstream systemd (--enable-systemd) support * Thu Sep 21 2017 Morten Stevens - 4.1.0-0.2.rc1 - Switch to mariadb-connector-c-devel - Spec file improvements * Thu Aug 31 2017 Morten Stevens - 4.1.0-0.1.rc1 - Update to 4.1.0-rc1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1649028 - CVE-2018-14626 pdns: Packet cache pollution via crafted query https://bugzilla.redhat.com/show_bug.cgi?id=1649028 [ 2 ] Bug #1588185 - CVE-2018-10851 pdns: Memory leak while parsing malformed records https://bugzilla.redhat.com/show_bug.cgi?id=1588185 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-5a1e2759aa' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.. SUSE Security Update: Security update for rubygem-actionpack ______________________________________________________________________________ Announcement ID: SUSE-SU-2012:1012-1 Rating: important References: #765097 #766791 Cross-References: CVE-2012-2660 CVE-2012-2661 CVE-2012-2694 CVE-2012-2695 Affected Products: SUSE Linux Enterprise Software Development Kit 11 SP2 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update to rubygem-actionpack fixes two unsafe query generations with "IS NULL" in the WHERE clause. (CVE-2012-2660 , CVE-2012-2694 ) Indications: Everyone using rubygem-actionpack should update. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP2: zypper in -t patch sdksp2-rubygem-actionpack-2_3-6630 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ia64 ppc64 s390x x86_64): rubygem-actionpack-2_3-2.3.14-0.10.1 References: https://www.suse.com/security/cve/CVE-2012-2660.html https://www.suse.com/security/cve/CVE-2012-2661.html https://www.suse.com/security/cve/CVE-2012-2694.html https://www.suse.com/security/cve/CVE-2012-2695.html . SUSE has released an update for rubygem-actionview that remedies critical security concerns. Mitigate risks with efficient query handling.. rubygem-actionpack update, SUSE security alert, Linux patch management. . Severity: Important. LinuxSecurity.com Team
Fix a problem with extra rows inserted because of mistaken pre-execution of a query. See also https://bugs.mysql.com/. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-773 2005-08-22 ---------------------------------------------------------------------Product : Fedora Core 3 Name : MyODBC Version : 2.50.39 Release : 25.FC3.1 Summary : ODBC driver for MySQL. Description : An ODBC driver for MySQL, for use with unixODBC ---------------------------------------------------------------------Update Information: Fix a problem with extra rows inserted because of mistaken pre-execution of a query. See also https://bugs.mysql.com/ ---------------------------------------------------------------------* Wed Aug 17 2005 Tom Lane 2.50.39-25.FC3.1 - Back-port upstream fix for bug #165257. ---------------------------------------------------------------------This update can be downloaded from: d55c836932cf81735c695a9eec8c4dda SRPMS/MyODBC-2.50.39-25.FC3.1.src.rpm 1c7686d019cb72d3e0f26ebcd13b438b x86_64/MyODBC-2.50.39-25.FC3.1.x86_64.rpm 8e13509244241f4d100731348721cc20 x86_64/debug/MyODBC-debuginfo-2.50.39-25.FC3.1.x86_64.rpm 6416a810960c9d243d42d583424534dd i386/MyODBC-2.50.39-25.FC3.1.i386.rpm e96338e357dad0e3ca97ab683def9e7d i386/debug/MyODBC-debuginfo-2.50.39-25.FC3.1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.