The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-7869 http://linux.oracle.com/errata/ELSA-2024-7869.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-8.0-8.0.10-1.0.1.el9_4.x86_64.rpm aspnetcore-runtime-dbg-8.0-8.0.10-1.0.1.el9_4.x86_64.rpm aspnetcore-targeting-pack-8.0-8.0.10-1.0.1.el9_4.x86_64.rpm dotnet-apphost-pack-8.0-8.0.10-1.0.1.el9_4.x86_64.rpm dotnet-host-8.0.10-1.0.1.el9_4.x86_64.rpm dotnet-hostfxr-8.0-8.0.10-1.0.1.el9_4.x86_64.rpm dotnet-runtime-8.0-8.0.10-1.0.1.el9_4.x86_64.rpm dotnet-runtime-dbg-8.0-8.0.10-1.0.1.el9_4.x86_64.rpm dotnet-sdk-8.0-8.0.110-1.0.1.el9_4.x86_64.rpm dotnet-sdk-dbg-8.0-8.0.110-1.0.1.el9_4.x86_64.rpm dotnet-targeting-pack-8.0-8.0.10-1.0.1.el9_4.x86_64.rpm dotnet-templates-8.0-8.0.110-1.0.1.el9_4.x86_64.rpm netstandard-targeting-pack-2.1-8.0.110-1.0.1.el9_4.x86_64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.110-1.0.1.el9_4.x86_64.rpm aarch64: aspnetcore-runtime-8.0-8.0.10-1.0.1.el9_4.aarch64.rpm aspnetcore-runtime-dbg-8.0-8.0.10-1.0.1.el9_4.aarch64.rpm aspnetcore-targeting-pack-8.0-8.0.10-1.0.1.el9_4.aarch64.rpm dotnet-apphost-pack-8.0-8.0.10-1.0.1.el9_4.aarch64.rpm dotnet-host-8.0.10-1.0.1.el9_4.aarch64.rpm dotnet-hostfxr-8.0-8.0.10-1.0.1.el9_4.aarch64.rpm dotnet-runtime-8.0-8.0.10-1.0.1.el9_4.aarch64.rpm dotnet-runtime-dbg-8.0-8.0.10-1.0.1.el9_4.aarch64.rpm dotnet-sdk-8.0-8.0.110-1.0.1.el9_4.aarch64.rpm dotnet-sdk-dbg-8.0-8.0.110-1.0.1.el9_4.aarch64.rpm dotnet-targeting-pack-8.0-8.0.10-1.0.1.el9_4.aarch64.rpm dotnet-templates-8.0-8.0.110-1.0.1.el9_4.aarch64.rpm netstandard-targeting-pack-2.1-8.0.110-1.0.1.el9_4.aarch64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.110-1.0.1.el9_4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//dotnet8.0-8.0.110-1.0.1.el9_4.src.rpm Related CVEs: CVE-2024-38229 CVE-2024-43483 CVE-2024-43484 CVE-2024-43485 Description ofchanges: [8.0.110-1.0.1] - Add support for Oracle Linux [8.0.110-1] - Update to .NET SDK 8.0.110 and Runtime 8.0.10 - Resolves: RHEL-60800 [8.0.109-1] - Update to .NET SDK 8.0.109 and Runtime 8.0.9 - Resolves: RHEL-56679 _______________________________________________ El-errata mailing list
Git could be made to run programs as your login if it explored a specially crafted repository.. =========================================================================Ubuntu Security Notice USN-3243-1 March 23, 2017 git vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Git could be made to run programs as your login if it explored a specially crafted repository. Software Description: - git: fast, scalable, distributed revision control system Details: It was discovered that Git incorrectly sanitized branch names in the PS1 variable when configured to display the repository status in the shell prompt. If a user were tricked into exploring a malicious repository, a remote attacker could use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: git 1:1.9.1-1ubuntu0.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3243-1 CVE-2014-9938 Package Information: https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4 . Update Ubuntu 14.04 LTS to secure against Git vulnerabilities that permit code execution from harmful repositories.. Git Vulnerability, Ubuntu Security Update, Code Execution Risk. . LinuxSecurity.com Team
Software Properties could be tricked into installing arbitrary PPA GPG keys.. =========================================================================Ubuntu Security Notice USN-1588-1 October 01, 2012 software-properties vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.04 LTS Summary: Software Properties could be tricked into installing arbitrary PPA GPG keys. Software Description: - software-properties: manage the repositories that you install software from Details: It was discovered that the apt-add-repository tool incorrectly validated PPA GPG keys when importing from a keyserver. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to install altered package repository GPG keys. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: python-software-properties 0.82.7.3 Ubuntu 11.10: python-software-properties 0.81.13.5 Ubuntu 11.04: python-software-properties 0.80.9.2 Ubuntu 10.04 LTS: python-software-properties 0.75.10.3 In general, a standard system update will make all the necessary changes. References: https://bugs.launchpad.net/ubuntu/+source/software-properties/+bug/1016643 Package Information: https://launchpad.net/ubuntu/+source/software-properties/0.82.7.3 https://launchpad.net/ubuntu/+source/software-properties/0.81.13.5 https://launchpad.net/ubuntu/+source/software-properties/0.80.9.2 https://launchpad.net/ubuntu/+source/software-properties/0.75.10.3 . Critical notice regarding Software Elements malfunction impacting several Ubuntu releases. Prompt system upgrade advised.. Software Properties,GPG Key,Ubuntu Security Warning. . LinuxSecurity.com Team
This update includes the latest release of Subversion 1.0, including the fix for a regression in the performance of repository browsing since version 1.0.8.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-422 2004-11-12 --------------------------------------------------------------------- Product : Fedora Core 2 Name : subversion Version : 1.0.9 Release : 1 Summary : Modern Version Control System designed to replace CVS Description : Subversion is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. Subversion only stores the differences between versions, instead of every complete file. Subversion is intended to be a compelling replacement for CVS. --------------------------------------------------------------------- Update Information: This update includes the latest release of Subversion 1.0, including the fix for a regression in the performance of repository browsing since version 1.0.8. --------------------------------------------------------------------- * Thu Oct 14 2004 Joe Orton 1.0.9-1 - update to 1.0.9 --------------------------------------------------------------------- This update can be downloaded from: d0d44cf011c662e0078f6f9cf9612d70 SRPMS/subversion-1.0.9-1.src.rpm 57edb8ba1f5ec715bde48e8af5e6824e x86_64/subversion-1.0.9-1.x86_64.rpm 1a872e77e522a970584f269a6599b137 x86_64/subversion-devel-1.0.9-1.x86_64.rpm 5368593535f1f3b62f87fa4f75d480dc x86_64/mod_dav_svn-1.0.9-1.x86_64.rpm 71c4c0f458fdcbc0bd2742fc8457c98c x86_64/subversion-perl-1.0.9-1.x86_64.rpm b8f29ffa334f7675f107344a02ba3c82 x86_64/debug/subversion-debuginfo-1.0.9-1.x86_64.rpm 76a6ef90b9cb95bf1ee8ecb1d5b980a9 i386/subversion-1.0.9-1.i386.rpm 91923b904979425c3c0da28033cc0942 i386/subversion-devel-1.0.9-1.i386.rpm de845cc828ce43bb370604b722c28f7c i386/mod_dav_svn-1.0.9-1.i386.rpm 30257ba356c6192c13e0be7a52903c2e i386/subversion-perl-1.0.9-1.i386.rpm f7a1844876f989fc87958532f518ba54 i386/debug/subversion-debuginfo-1.0.9-1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Recent Subversion enhancement for Fedora focusing on performance setbacks observed in repository navigation since the last update.. Subversion Update, Performance Fix, Repository Management. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.