An update that solves various issues can now be installed.. openSUSE security update: security update for putty ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20851-1 Rating: important Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves various issues can now be installed. Description: This update for putty fixes the following issues: Changes in putty: - Update to release 0.84 * Fixed a remotely triggerable double-free in RSA key exchange. * Fixed a remotely triggerable crash (assertion failure - program termination) in NIST ECDSA signature verification. * Fixed marking of Telnet and Rlogin session data with a trust sigil after you authenticated to a proxy (possibly allowing a server to spoof a repeat proxy password prompt). * New ability to run a specified command before starting the connection, e.g. to perform wake-on-LAN or a port knock. * Display 'pre-edit text', showing the progress of using multiple keystrokes to compose a single Unicode character. * Improved support for to running the GUI tools on Wayland (fixed startup issues and tuned performance). * Configuring a SSH certificate authority used to fail unless you manually made a config directory, now fixed. * Fixed a spurious "Network error: Socket is not connected" when authenticating to some HTTP proxies. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-281=1 Package List: - openSUSE Leap 16.0: putty-0.84-bp160.1.1 . This important advisory details a security update for openSUSE's putty fixing critical issues like remote crashes and authentication bugs.. openSUSE putty update important issues remote crash. .Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-1569 https://linux.oracle.com/errata/ELSA-2023-1569.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: gnutls-3.6.16-6.el8_7.i686.rpm gnutls-3.6.16-6.el8_7.x86_64.rpm gnutls-c++-3.6.16-6.el8_7.i686.rpm gnutls-c++-3.6.16-6.el8_7.x86_64.rpm gnutls-dane-3.6.16-6.el8_7.i686.rpm gnutls-dane-3.6.16-6.el8_7.x86_64.rpm gnutls-devel-3.6.16-6.el8_7.i686.rpm gnutls-devel-3.6.16-6.el8_7.x86_64.rpm gnutls-utils-3.6.16-6.el8_7.x86_64.rpm aarch64: gnutls-3.6.16-6.el8_7.aarch64.rpm gnutls-c++-3.6.16-6.el8_7.aarch64.rpm gnutls-dane-3.6.16-6.el8_7.aarch64.rpm gnutls-devel-3.6.16-6.el8_7.aarch64.rpm gnutls-utils-3.6.16-6.el8_7.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//gnutls-3.6.16-6.el8_7.src.rpm Related CVEs: CVE-2023-0361 Description of changes: [3.6.16-6] - Fix x86_64 CPU feature detection when AVX is not available (#2131152) - Fix timing side-channel in TLS RSA key exchange (#2162598) _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.