The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-7005 http://linux.oracle.com/errata/ELSA-2026-7005.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: git-lfs-3.6.1-8.el10_1.x86_64.rpm aarch64: git-lfs-3.6.1-8.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/git-lfs-3.6.1-8.el10_1.src.rpm Related CVEs: CVE-2026-25679 Description of changes: [3.6.1-8] - Rebuild with new Golang _______________________________________________ El-errata mailing list
rpki-client 7.5 untrusted input: - Fail repository synchronisation after 15min runtime. - Limit the number of repositories per TAL. - Don't allow `DOCTYPE` definitions in RRDP XML files. - Fix detection of HTTP redirect loops. * Limit the number of concurrent `rsync` processes. * Fix `CRLF` in TAL files.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-c9852f0be4 2021-11-18 01:13:15.271873 --------------------------------------------------------------------------------Name : rpki-client Product : Fedora 35 Version : 7.5 Release : 1.fc35 URL : https://www.rpki-client.org/ Summary : RPKI validator to support BGP Origin Validation Description : The OpenBSD rpki-client is a free, easy-to-use implementation of the Resource Public Key Infrastructure (RPKI) for Relying Parties (RP) to facilitate validation of the Route Origin of a BGP announcement. The program queries the RPKI repository system, downloads and validates Route Origin Authorisations (ROAs) and finally outputs Validated ROA Payloads (VRPs) in the configuration format of OpenBGPD, BIRD, and also as CSV or JSON objects for consumption by other routing stacks. --------------------------------------------------------------------------------Update Information: rpki-client 7.5 =============== * Make rpki-client more resilient regarding untrusted input: - Fail repository synchronisation after 15min runtime. - Limit the number of repositories per TAL. - Don't allow `DOCTYPE` definitions in RRDP XML files. - Fix detection of HTTP redirect loops. * Limit the number of concurrent `rsync` processes. * Fix `CRLF` in TAL files. --------------------------------------------------------------------------------ChangeLog: * Tue Nov 9 2021 Robert Scheck 7.5-1 - Upgrade to 7.5 (#2021523) --------------------------------------------------------------------------------References: [ 1 ] Bug #2021523 -rpki-client-7.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2021523 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-c9852f0be4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Updated golang packages fix security vulnerability: An integer overflow vulnerability was found in the Go crypto/x509 and golang.org/x/crypto/cryptobyte libraries on 32-bit architectures. A remote attacker could exploit this by supplying a crafted x.509 certificate, or . MGASA-2020-0173 - Updated golang packages fix security vulnerability Publication date: 15 Apr 2020 URL: https://advisories.mageia.org/MGASA-2020-0173.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-7919 Updated golang packages fix security vulnerability: An integer overflow vulnerability was found in the Go crypto/x509 and golang.org/x/crypto/cryptobyte libraries on 32-bit architectures. A remote attacker could exploit this by supplying a crafted x.509 certificate, or other ASN.1 structure, as either a client or server to crash vulnerable Go applications (CVE-2020-7919). References: - https://bugs.mageia.org/show_bug.cgi?id=26465 - https://lists.fedoraproject.org/archives/list/
python: Information Disclosure due to urlsplit improper NFKC normalization (CVE-2019-9636) SL7 x86_64 python-2.7.5-77.el7_6.x86_64.rpm python-debuginfo-2.7.5-77.el7_6.i686.rpm python-debuginfo-2.7.5-77.el7_6.x86_64.rpm python-libs-2.7.5-77.el7_6.i686.rpm python-libs-2.7.5-77.el7_6.x86_64.rpm python-debug-2.7.5-77.el7_6.x86_64.rpm python-devel-2.7.5-77.el7_6.x86_6 [More...]. Synopsis: Important: python security update Advisory ID: SLSA-2019:0710-1 Issue Date: 2019-04-08 CVE Numbers: CVE-2019-9636 -- Security Fix(es): * python: Information Disclosure due to urlsplit improper NFKC normalization (CVE-2019-9636) -- SL7 x86_64 python-2.7.5-77.el7_6.x86_64.rpm python-debuginfo-2.7.5-77.el7_6.i686.rpm python-debuginfo-2.7.5-77.el7_6.x86_64.rpm python-libs-2.7.5-77.el7_6.i686.rpm python-libs-2.7.5-77.el7_6.x86_64.rpm python-debug-2.7.5-77.el7_6.x86_64.rpm python-devel-2.7.5-77.el7_6.x86_64.rpm python-test-2.7.5-77.el7_6.x86_64.rpm python-tools-2.7.5-77.el7_6.x86_64.rpm tkinter-2.7.5-77.el7_6.x86_64.rpm python-2.7.5-77.el7_6.src.rpm - Scientific Linux Development Team . Important Python security update for SL7 x86_64 addressing potential exposure risk issues to enhance system safety. python security update, information disclosure, SL7 x86_64, python maintenance. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.