libXpm 3.5.17, fixes CVE-2023-43788, CVE-2023-43789, CVE-2023-43786. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-c4cf6646b9 2023-11-03 18:20:20.952126 -------------------------------------------------------------------------------- Name : libXpm Product : Fedora 39 Version : 3.5.17 Release : 1.fc39 URL : https://www.x.org/wiki/ Summary : X.Org X11 libXpm runtime library Description : X.Org X11 libXpm runtime library -------------------------------------------------------------------------------- Update Information: libXpm 3.5.17, fixes CVE-2023-43788, CVE-2023-43789, CVE-2023-43786 -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 5 2023 Peter Hutterer - 3.5.17-1 - libXpm 3.5.17 * Wed Sep 6 2023 Benjamin Tissoires - 3.5.15-5 - SPDX migration -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-c4cf6646b9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for [PUT CVEs HERE]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-591b7f5047 2023-10-15 01:42:32.629376 -------------------------------------------------------------------------------- Name : libXpm Product : Fedora 38 Version : 3.5.17 Release : 1.fc38 URL : https://www.x.org/wiki/ Summary : X.Org X11 libXpm runtime library Description : X.Org X11 libXpm runtime library -------------------------------------------------------------------------------- Update Information: Security fix for [PUT CVEs HERE] -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 5 2023 Peter Hutterer - 3.5.17-1 - libXpm 3.5.17 * Wed Sep 6 2023 Benjamin Tissoires - 3.5.15-5 - SPDX migration * Thu Jul 20 2023 Fedora Release Engineering - 3.5.15-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2242248 - CVE-2023-43788 libXpm: out of bounds read in XpmCreateXpmImageFromBuffer() https://bugzilla.redhat.com/show_bug.cgi?id=2242248 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-591b7f5047' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
An update for libXpm is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: libXpm security update Advisory ID: RHSA-2023:0379-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0379 Issue date: 2023-01-23 CVE Names: CVE-2022-4883 CVE-2022-44617 CVE-2022-46285 ==================================================================== 1. Summary: An update for libXpm is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: X.Org X11 libXpm runtime library. Security Fix(es): * libXpm: compression commands depend on $PATH (CVE-2022-4883) * libXpm: Runaway loop on width of 0 and enormous height (CVE-2022-44617) * libXpm: Infinite loop on unclosed comments (CVE-2022-46285) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2160092 - CVE-2022-46285 libXpm: Infinite loop on unclosed comments 2160193 -CVE-2022-44617 libXpm: Runaway loop on width of 0 and enormous height 2160213 - CVE-2022-4883 libXpm: compression commands depend on $PATH 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: libXpm-3.5.12-9.el8_7.src.rpm aarch64: libXpm-3.5.12-9.el8_7.aarch64.rpm libXpm-debuginfo-3.5.12-9.el8_7.aarch64.rpm libXpm-debugsource-3.5.12-9.el8_7.aarch64.rpm libXpm-devel-3.5.12-9.el8_7.aarch64.rpm libXpm-devel-debuginfo-3.5.12-9.el8_7.aarch64.rpm ppc64le: libXpm-3.5.12-9.el8_7.ppc64le.rpm libXpm-debuginfo-3.5.12-9.el8_7.ppc64le.rpm libXpm-debugsource-3.5.12-9.el8_7.ppc64le.rpm libXpm-devel-3.5.12-9.el8_7.ppc64le.rpm libXpm-devel-debuginfo-3.5.12-9.el8_7.ppc64le.rpm s390x: libXpm-3.5.12-9.el8_7.s390x.rpm libXpm-debuginfo-3.5.12-9.el8_7.s390x.rpm libXpm-debugsource-3.5.12-9.el8_7.s390x.rpm libXpm-devel-3.5.12-9.el8_7.s390x.rpm libXpm-devel-debuginfo-3.5.12-9.el8_7.s390x.rpm x86_64: libXpm-3.5.12-9.el8_7.i686.rpm libXpm-3.5.12-9.el8_7.x86_64.rpm libXpm-debuginfo-3.5.12-9.el8_7.i686.rpm libXpm-debuginfo-3.5.12-9.el8_7.x86_64.rpm libXpm-debugsource-3.5.12-9.el8_7.i686.rpm libXpm-debugsource-3.5.12-9.el8_7.x86_64.rpm libXpm-devel-3.5.12-9.el8_7.i686.rpm libXpm-devel-3.5.12-9.el8_7.x86_64.rpm libXpm-devel-debuginfo-3.5.12-9.el8_7.i686.rpm libXpm-devel-debuginfo-3.5.12-9.el8_7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-4883 https://access.redhat.com/security/cve/CVE-2022-44617 https://access.redhat.com/security/cve/CVE-2022-46285 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY88LetzjgjWX9erEAQiDbBAAhyCWDlAIdwW5KlQYUTb+9Yc/cFoTEnmr HOkXrUQUu4qgvN/Lb0UYGuLNr7LTRPv7FjkIUX3XBzcYvbQPABF+UTm6u5Mc3pXw O41h6s6tF6fY9V3h5bOYOkDEN3QLIPGE1jQuwZ6l79MAUPKnHDigA5UO6nvNt5Y/ 2lTpDK+UiK2x/SE/YDY8bCMgqfooFRx1h93TosK1BVHCd7RPnjNEQHWGm0KLfihH VsGXjEY781waCxOJioAvI7vJJChHv9MCSA8hEx9M49c4XLiPp6ow7Lr29dpKAT8J EDQ5mGVHPqEe7HnUuWZegF7eigWYSAFE3p1+jlPN7BJMUdUhxIxsyf3JjB51cM0v wxLDWcUy8xS5mKYHN3LghvDCCEeB1koybE/zGovUWWhk77kZ+tCo3GA2tOj9nK5I Lf5kFnliczzLoYN6MX0YqC8aGsz6fnZoww/uQ5q8CT02ujIHMZzMjQV0WeLe+oGC e0do4xFOKKs6Qyp2toD/7dqBmXI21RF67ykNXzhkCdREOKuCbpKcA2zuhqL+TejS jR4p2z1+SpoGz2Q995bbCNZfD8pPCeDRpvX69KISy/1bk7NNB6iuYERfFQpoffXv M5x1uXmcD9uwYCdHnH9BULUf7el07Sn1+sx7bGf5m7Z8nK/GrKsR6lgUjawPTGhF NzDIrORAie4=V0et -----END PGP SIGNATURE----- -- RHSA-announce mailing list
libXfont 2.0.2. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-cbb8db2be6 2017-11-11 13:29:22.441320 --------------------------------------------------------------------------------Name : libXfont2 Product : Fedora 27 Version : 2.0.2 Release : 1.fc27 URL : https://www.x.org/wiki/ Summary : X.Org X11 libXfont2 runtime library Description : X.Org X11 libXfont2 runtime library --------------------------------------------------------------------------------Update Information: libXfont 2.0.2 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libXfont2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
libXfont 2.0.2. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-f44afd1f34 2017-10-25 21:34:15.278067 --------------------------------------------------------------------------------Name : libXfont2 Product : Fedora 26 Version : 2.0.2 Release : 1.fc26 URL : https://www.x.org/wiki/ Summary : X.Org X11 libXfont2 runtime library Description : X.Org X11 libXfont2 runtime library --------------------------------------------------------------------------------Update Information: libXfont 2.0.2 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libXfont2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2016-7951, CVE-2016-7952. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-e6ba110670 2016-10-10 17:40:40.897988 -------------------------------------------------------------------------------- Name : libXtst Product : Fedora 25 Version : 1.2.3 Release : 1.fc25 URL : https://www.x.org/wiki/ Summary : X.Org X11 libXtst runtime library Description : X.Org X11 libXtst runtime library -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-7951, CVE-2016-7952 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1381919 - CVE-2016-7951 libXtst: Insufficient validation of server responses result in Integer overflows https://bugzilla.redhat.com/show_bug.cgi?id=1381919 [ 2 ] Bug #1381922 - CVE-2016-7952 libXtst: Insufficient validation of server responses result in various data mishandlings https://bugzilla.redhat.com/show_bug.cgi?id=1381922 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libXtst' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-808 2005-08-25 ---------------------------------------------------------------------Product : Fedora Core 3 Name : openmotif Version : 2.2.3 Release : 9.FC3.1 Summary : Open Motif runtime libraries and executables. Description : This is the Open Motif 2.2.1 runtime environment. It includes the Motif shared libraries, needed to run applications which are dynamically linked against Motif, and the Motif Window Manager "mwm". ---------------------------------------------------------------------* Mon Apr 4 2005 Thomas Woerner 2.2.3-9.FC3.1 - fixed possible libXpm overflows (#151642) - Upstream Fix: Multiscreen mode - Upstream Fix: Crash when restarting by a session manager (motifzone#1193) - Upstream Fix: Crash when duplicating a window menu containing f.circle_up (motifzone#1202) - fixed divide by zero error in ComputeVizCount() (#144420) - Xpmcreate: define LONG64 on 64 bit architectures (#143689) * Mon Nov 29 2004 Thomas Woerner 2.2.3-6.FC3.2 - allow to write XPM files with absolute path names again (#140815) ---------------------------------------------------------------------This update can be downloaded from: 44ad7dbba8941c741784859be3e05d39 SRPMS/openmotif-2.2.3-9.FC3.1.src.rpm 3fab42d7c700d11826559ca0cee95838 x86_64/openmotif-2.2.3-9.FC3.1.x86_64.rpm 11916783c2c51b82c33b32666fe88ed2 x86_64/openmotif-devel-2.2.3-9.FC3.1.x86_64.rpm ffcbc472795a9694d436706834c1d511 x86_64/debug/openmotif-debuginfo-2.2.3-9.FC3.1.x86_64.rpm 0ca7af9e3064663b28900c7cb2796366 x86_64/openmotif-2.2.3-9.FC3.1.i386.rpm 0ca7af9e3064663b28900c7cb2796366 i386/openmotif-2.2.3-9.FC3.1.i386.rpm 1b1b00ad520f23423cbb55b3a66ad96b i386/openmotif-devel-2.2.3-9.FC3.1.i386.rpm 1e872b3ed5934d59d159c6a650822ca7 i386/debug/openmotif-debuginfo-2.2.3-9.FC3.1.i386.rpm This update can also be installed with theUpdate Agent; you can launch the Update Agent with the 'up2date' command. ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.