Update to 3.3.0.1 and CVE-2022-25844. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-edf635cf39 2022-10-28 11:45:05.423013 --------------------------------------------------------------------------------Name : glances Product : Fedora 35 Version : 3.3.0.1 Release : 2.fc35 URL : https://nicolargo.github.io/glances/ Summary : A cross-platform curses-based monitoring tool Description : Glances is a cross-platform monitoring tool which aims to present a large amount of monitoring information through a curses or Web based interface. The information dynamically adapts depending on the size of the user interface It can also work in client/server mode. Remote monitoring could be done via terminal, Web interface or API (XML-RPC and RESTful). Stats can also be exported to files or external time/value databases. Glances is written in Python and uses libraries to grab information from your system. It is based on an open architecture where developers can add new plugins or exports modules. --------------------------------------------------------------------------------Update Information: Update to 3.3.0.1 and CVE-2022-25844 --------------------------------------------------------------------------------ChangeLog: * Thu Oct 20 2022 aekoroglu 3.3.0.1-2 - Rebuilt for ppc64le * Thu Oct 20 2022 aekoroglu 3.3.0.1-1 - Update to 3.3.0.1 and CVE-2022-25844 (#2082542) * Tue Aug 2 2022 aekoroglu 3.2.7-1 - update to 3.2.7 * Thu Jul 21 2022 Fedora Release Engineering 3.2.6.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2082542 - CVE-2022-25844 glances: angular: Regular Expression Denial of Service (ReDoS) in angular [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2082542 [ 2 ] Bug #2135228 - glances-3.3.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2135228 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-edf635cf39' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- Update to 1.2.11 Release notes: . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-c1745db1aa 2020-04-15 20:32:17.101762 --------------------------------------------------------------------------------Name : cacti Product : Fedora 31 Version : 1.2.11 Release : 1.fc31 URL : Summary : An rrd based graphing tool Description : Cacti is a complete frontend to RRDTool. It stores all of the necessary information to create graphs and populate them with data in a MySQL database. The frontend is completely PHP driven. --------------------------------------------------------------------------------Update Information: - Update to 1.2.11 Release notes: --------------------------------------------------------------------------------ChangeLog: * Tue Apr 7 2020 Morten Stevens - 1.2.11-1 - Update to 1.2.11 --------------------------------------------------------------------------------References: [ 1 ] Bug #1820976 - Cannot upgrade from 1.2.9 to 1.2.10. F31 https://bugzilla.redhat.com/show_bug.cgi?id=1820976 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-c1745db1aa' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
It was discovered that psensor, a server for monitoring hardware sensors remotely, was prone to a directory traversal vulnerability because the create_response function in server/server.c lacks a check for whether a file is under the webserver directory. . Package : psensor Version : 0.6.2.17-2+deb7u1 CVE ID : CVE-2014-10073 Debian Bug : 896195 It was discovered that psensor, a server for monitoring hardware sensors remotely, was prone to a directory traversal vulnerability because the create_response function in server/server.c lacks a check for whether a file is under the webserver directory. For Debian 7 "Wheezy", these problems have been fixed in version 0.6.2.17-2+deb7u1. We recommend that you upgrade your psensor packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Psensor security patch: addresses a critical directory traversal vulnerability in Debian LTS installations impacting remote hardware sensor surveillance.. Psensor Directory Traversal, Debian LTS Update, Remote Sensor Monitoring. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.