Update to 6.2.8, fixing CVE-2022-48257 and CVE-2022-48258 Unbundle cpp-httlib, fixing CVE-2023-26130. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-b745c97f4b 2024-05-02 01:55:56.608353 -------------------------------------------------------------------------------- Name : et Product : Fedora 40 Version : 6.2.8 Release : 1.fc40 URL : https://eternalterminal.dev/ Summary : Remote shell that survives IP roaming and disconnect Description : Eternal Terminal (ET) is a remote shell that automatically reconnects without interrupting the session. -------------------------------------------------------------------------------- Update Information: Update to 6.2.8, fixing CVE-2022-48257 and CVE-2022-48258 Unbundle cpp-httlib, fixing CVE-2023-26130 -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 30 2024 Michel Lind - 6.2.8-1 - Update to 6.2.8 (rhbz#2162155) - Temporarily rebundle catch2; the version in Fedora is too old * Fri Apr 26 2024 Michel Lind - 6.2.1-15 - Disable unwind on s390x * Fri Apr 26 2024 Michel Lind - 6.2.1-14 - Unbundle cpp-httplib (rhbz#2169585) - Eliminate almost all sed usage - Use find_package to find cxxopts - Use pkg_check_modules to find easylogging++ - Enable SELinux support - Enable unwind support * Thu Apr 25 2024 Michel Lind - 6.2.1-13 - Use SPDX license identifier -------------------------------------------------------------------------------- References: [ 1 ] Bug #2161247 - CVE-2022-48257 et: EternalTerminal: information exposure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2161247 [ 2 ] Bug #2161251 - CVE-2022-48258 et: MisterTea/EternalTerminal: information exposure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2161251 [ 3 ] Bug #2162155 - et-6.2.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2162155 [ 4 ]Bug #2169585 - Please try to use cpp-httplib-devel package https://bugzilla.redhat.com/show_bug.cgi?id=2169585 [ 5 ] Bug #2211077 - CVE-2023-26130 et: cpp-httplib: CRLF Injection [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2211077 [ 6 ] Bug #2211079 - CVE-2023-26130 et: cpp-httplib: CRLF Injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2211079 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-b745c97f4b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 6.2.8, fixing CVE-2022-48257 and CVE-2022-48258 Unbundle cpp-httlib, fixing CVE-2023-26130. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-bd9e67c117 2024-05-02 01:43:10.602183 -------------------------------------------------------------------------------- Name : et Product : Fedora 38 Version : 6.2.8 Release : 1.fc38 URL : https://eternalterminal.dev/ Summary : Remote shell that survives IP roaming and disconnect Description : Eternal Terminal (ET) is a remote shell that automatically reconnects without interrupting the session. -------------------------------------------------------------------------------- Update Information: Update to 6.2.8, fixing CVE-2022-48257 and CVE-2022-48258 Unbundle cpp-httlib, fixing CVE-2023-26130 -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 30 2024 Michel Lind - 6.2.8-1 - Update to 6.2.8 (rhbz#2162155) - Temporarily rebundle catch2; the version in Fedora is too old * Fri Apr 26 2024 Michel Lind - 6.2.1-15 - Disable unwind on s390x * Fri Apr 26 2024 Michel Lind - 6.2.1-14 - Unbundle cpp-httplib (rhbz#2169585) - Eliminate almost all sed usage - Use find_package to find cxxopts - Use pkg_check_modules to find easylogging++ - Enable SELinux support - Enable unwind support * Thu Apr 25 2024 Michel Lind - 6.2.1-13 - Use SPDX license identifier * Wed Jan 24 2024 Fedora Release Engineering - 6.2.1-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering - 6.2.1-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2161247 - CVE-2022-48257 et: EternalTerminal: information exposure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2161247 [ 2 ] Bug #2161251 -CVE-2022-48258 et: MisterTea/EternalTerminal: information exposure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2161251 [ 3 ] Bug #2162155 - et-6.2.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2162155 [ 4 ] Bug #2169585 - Please try to use cpp-httplib-devel package https://bugzilla.redhat.com/show_bug.cgi?id=2169585 [ 5 ] Bug #2211077 - CVE-2023-26130 et: cpp-httplib: CRLF Injection [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2211077 [ 6 ] Bug #2211079 - CVE-2023-26130 et: cpp-httplib: CRLF Injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2211079 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-bd9e67c117' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 6.2.8, fixing CVE-2022-48257 and CVE-2022-48258 Unbundle cpp-httlib, fixing CVE-2023-26130. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-94a155818c 2024-05-02 01:36:55.268644 -------------------------------------------------------------------------------- Name : et Product : Fedora 39 Version : 6.2.8 Release : 1.fc39 URL : https://eternalterminal.dev/ Summary : Remote shell that survives IP roaming and disconnect Description : Eternal Terminal (ET) is a remote shell that automatically reconnects without interrupting the session. -------------------------------------------------------------------------------- Update Information: Update to 6.2.8, fixing CVE-2022-48257 and CVE-2022-48258 Unbundle cpp-httlib, fixing CVE-2023-26130 -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 30 2024 Michel Lind - 6.2.8-1 - Update to 6.2.8 (rhbz#2162155) - Temporarily rebundle catch2; the version in Fedora is too old * Fri Apr 26 2024 Michel Lind - 6.2.1-15 - Disable unwind on s390x * Fri Apr 26 2024 Michel Lind - 6.2.1-14 - Unbundle cpp-httplib (rhbz#2169585) - Eliminate almost all sed usage - Use find_package to find cxxopts - Use pkg_check_modules to find easylogging++ - Enable SELinux support - Enable unwind support * Thu Apr 25 2024 Michel Lind - 6.2.1-13 - Use SPDX license identifier * Wed Jan 24 2024 Fedora Release Engineering - 6.2.1-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering - 6.2.1-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2161247 - CVE-2022-48257 et: EternalTerminal: information exposure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2161247 [ 2 ] Bug #2161251 -CVE-2022-48258 et: MisterTea/EternalTerminal: information exposure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2161251 [ 3 ] Bug #2162155 - et-6.2.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2162155 [ 4 ] Bug #2169585 - Please try to use cpp-httplib-devel package https://bugzilla.redhat.com/show_bug.cgi?id=2169585 [ 5 ] Bug #2211077 - CVE-2023-26130 et: cpp-httplib: CRLF Injection [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2211077 [ 6 ] Bug #2211079 - CVE-2023-26130 et: cpp-httplib: CRLF Injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2211079 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-94a155818c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security and stability improvements. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-185b91b741 2022-05-16 02:04:05.714549 --------------------------------------------------------------------------------Name : et Product : Fedora 35 Version : 6.2.1 Release : 2.fc35 URL : https://eternalterminal.dev/ Summary : Remote shell that survives IP roaming and disconnect Description : Eternal Terminal (ET) is a remote shell that automatically reconnects without interrupting the session. --------------------------------------------------------------------------------Update Information: Several security and stability improvements --------------------------------------------------------------------------------ChangeLog: * Sat May 7 2022 Michel Alexandre Salim 6.2.1-2 - Fix %cmake invocation to make it work on Rawhide * Sat May 7 2022 Michel Alexandre Salim 6.2.1-1 - Update to 6.2.1 * Sat May 7 2022 Michel Alexandre Salim 6.1.11-1 - Update to 6.1.11; Unbundle Catch2 (Benjamin A. Beasley ) --------------------------------------------------------------------------------References: [ 1 ] Bug #2029239 - [abrt] et: el::base::utils::abort(): et killed by SIGABRT https://bugzilla.redhat.com/show_bug.cgi?id=2029239 [ 2 ] Bug #2039118 - et-6.2.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2039118 [ 3 ] Bug #2045358 - et: FTBFS in Fedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045358 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-185b91b741' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several security and stability improvements. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e3a794b591 2022-05-16 01:07:38.483117 --------------------------------------------------------------------------------Name : et Product : Fedora 36 Version : 6.2.1 Release : 2.fc36 URL : https://eternalterminal.dev/ Summary : Remote shell that survives IP roaming and disconnect Description : Eternal Terminal (ET) is a remote shell that automatically reconnects without interrupting the session. --------------------------------------------------------------------------------Update Information: Several security and stability improvements --------------------------------------------------------------------------------ChangeLog: * Fri May 6 2022 Michel Alexandre Salim 6.2.1-2 - Fix %cmake invocation to make it work on Rawhide * Fri May 6 2022 Michel Alexandre Salim 6.2.1-1 - Update to 6.2.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #2029239 - [abrt] et: el::base::utils::abort(): et killed by SIGABRT https://bugzilla.redhat.com/show_bug.cgi?id=2029239 [ 2 ] Bug #2039118 - et-6.2.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2039118 [ 3 ] Bug #2045358 - et: FTBFS in Fedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045358 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-e3a794b591' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
rsh would allow unintended modification of target directory permissions.. =========================================================================Ubuntu Security Notice USN-5327-1 March 15, 2022 netkit-rsh vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: rsh would allow unintended modification of target directory permissions. Software Description: - netkit-rsh: client programs for remote shell connections Details: Hiroyuki Yamamori discovered that rsh incorrectly handled certain filenames. If a user or automated system were tricked into connecting to a malicious rsh server, a remote attacker could possibly use this issue to modify directory permissions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: rsh-client 0.17-17ubuntu0.1 rsh-server 0.17-17ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5327-1 CVE-2019-7282 Package Information: https://launchpad.net/ubuntu/+source/netkit-rsh/0.17-17ubuntu0.1 . CVE-2023-XXXX exposes Netkit-rsh flaws leading to unauthorized directory access. Perform system updates on Ubuntu 18.04 LTS for remediation specifics.. Netkit-rsh, Ubuntu 18.04, Permissions Modification. . Severity: Critical. LinuxSecurity.com Team
Security and compatibility fixes. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-808fab651c 2021-11-13 01:12:46.668870 --------------------------------------------------------------------------------Name : et Product : Fedora 34 Version : 6.1.9 Release : 1.fc34 URL : https://eternalterminal.dev/ Summary : Remote shell that survives IP roaming and disconnect Description : Eternal Terminal (ET) is a remote shell that automatically reconnects without interrupting the session. --------------------------------------------------------------------------------Update Information: Security and compatibility fixes --------------------------------------------------------------------------------ChangeLog: * Thu Nov 4 2021 Michel Alexandre Salim - 6.1.9-1 - Update to 6.1.9 * Wed Nov 3 2021 Michel Alexandre Salim - 6.1.8-2.20211103git900348b - Red fixes --------------------------------------------------------------------------------References: [ 1 ] Bug #1987466 - et: FTBFS in Fedora rawhide/f35 https://bugzilla.redhat.com/show_bug.cgi?id=1987466 [ 2 ] Bug #2018917 - et: FTBFS with OpenSSL 3.0.0 https://bugzilla.redhat.com/show_bug.cgi?id=2018917 [ 3 ] Bug #2020039 - et-6.1.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2020039 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-808fab651c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security and compatibility fixes. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-532fcdde8a 2021-11-13 01:06:08.136624 --------------------------------------------------------------------------------Name : et Product : Fedora 35 Version : 6.1.9 Release : 1.fc35 URL : https://eternalterminal.dev/ Summary : Remote shell that survives IP roaming and disconnect Description : Eternal Terminal (ET) is a remote shell that automatically reconnects without interrupting the session. --------------------------------------------------------------------------------Update Information: Security and compatibility fixes --------------------------------------------------------------------------------ChangeLog: * Thu Nov 4 2021 Michel Alexandre Salim - 6.1.9-1 - Update to 6.1.9 * Wed Nov 3 2021 Michel Alexandre Salim - 6.1.8-2.20211103git900348b - Red fixes * Wed Jul 21 2021 Fedora Release Engineering - 6.1.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1987466 - et: FTBFS in Fedora rawhide/f35 https://bugzilla.redhat.com/show_bug.cgi?id=1987466 [ 2 ] Bug #2018917 - et: FTBFS with OpenSSL 3.0.0 https://bugzilla.redhat.com/show_bug.cgi?id=2018917 [ 3 ] Bug #2020039 - et-6.1.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2020039 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-532fcdde8a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.