Update the sequoia-openpgp crate to version 1.21.1. Addresses RUSTSEC-2024-0345. Update the sequoia-keystore crate to version 0.5.1. Update the sequoia-gpg-agent crate to version 0.4.2. This update also includes rebuilds of all affected applications that are affected by RUSTSEC-2024-0345 and a regression in sequoia-openpgp 1.21.0.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-029752e60b 2024-07-09 01:41:25.580220 -------------------------------------------------------------------------------- Name : rust-sequoia-sq Product : Fedora 39 Version : 0.37.0 Release : 3.fc39 URL : Summary : Command-line frontends for Sequoia Description : Command-line frontends for Sequoia. -------------------------------------------------------------------------------- Update Information: Update the sequoia-openpgp crate to version 1.21.1. Addresses RUSTSEC-2024-0345. Update the sequoia-keystore crate to version 0.5.1. Update the sequoia-gpg-agent crate to version 0.4.2. This update also includes rebuilds of all affected applications that are affected by RUSTSEC-2024-0345 and a regression in sequoia-openpgp 1.21.0. -------------------------------------------------------------------------------- ChangeLog: * Sun Jun 30 2024 Fabio Valentini - 0.37.0-3 - Rebuild for sequoia-openpgp 1.21.1 * Wed Jun 26 2024 Fabio Valentini - 0.37.0-2 - Rebuild for sequoia-openpgp 1.21.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-029752e60b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
- Update the sequoia-openpgp crate to version 1.16.0. - Update the nettle crate to version 7.3.0. - Update the nettle-sys crate to version 2.2.0. - Update the buffered-reader crate to version 1.2.0. Version 1.16.0 of the sequoia-openpgp crate fixes some issues in parsing code, which could lead to attempted out-of- bounds accesses that result in crashes due to bounds checks which are included. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-1d0d71b6aa 2023-05-27 01:25:15.781100 --------------------------------------------------------------------------------Name : rust-sequoia-policy-config Product : Fedora 37 Version : 0.6.0 Release : 4.fc37 URL : Summary : Configure Sequoia using a configuration file Description : Configure Sequoia using a configuration file. --------------------------------------------------------------------------------Update Information: - Update the sequoia-openpgp crate to version 1.16.0. - Update the nettle crate to version 7.3.0. - Update the nettle-sys crate to version 2.2.0. - Update the buffered-reader crate to version 1.2.0. Version 1.16.0 of the sequoia-openpgp crate fixes some issues in parsing code, which could lead to attempted out-of-bounds accesses that result in crashes due to bounds checks which are included by default in Rust code. This update contains rebuilds of all applications that are based on sequoia-openpgp to address this issue. ---- Update to version 1.5.0. This release improves compatibility with the version of librnp that's bundled in recent versions of thunderbird. --------------------------------------------------------------------------------ChangeLog: * Thu May 18 2023 Fabio Valentini - 0.6.0-4 - Rebuild for sequoia-openpgp v1.16 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1d0d71b6aa'at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Recent updates for the `tokio`, `h2`, and `openssl` crates addressed some (potential or confirmed) security or soundness issues: - `tokio`: [RUSTSEC-2023-0005](https://rustsec.org/advisories/RUSTSEC-2023-0005.html) - `h2`: [RUSTSEC-2023-0034](https://rustsec.org/advisories/RUSTSEC-2023-0034.html) / [CVE-2023-26964](https://nvd.nist.gov/vuln/detail/CVE-2023-26964) - `openssl`:. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-37ae269843 2023-05-18 00:49:56.087782 --------------------------------------------------------------------------------Name : rust-sevctl Product : Fedora 37 Version : 0.3.2 Release : 4.fc37 URL : Summary : Administrative utility for AMD SEV Description : Administrative utility for AMD SEV. --------------------------------------------------------------------------------Update Information: Recent updates for the `tokio`, `h2`, and `openssl` crates addressed some (potential or confirmed) security or soundness issues: - `tokio`: [RUSTSEC-2023-0005](https://rustsec.org/advisories/RUSTSEC-2023-0005.html) -`h2`: [RUSTSEC-2023-0034](https://rustsec.org/advisories/RUSTSEC-2023-0034.html) / [CVE-2023-26964](https://nvd.nist.gov/vuln/detail/CVE-2023-26964) - `openssl`: [RUSTSEC-2023-0022](https://rustsec.org/advisories/RUSTSEC-2023-0022.html), [RUSTSEC-2023-0023](https://rustsec.org/advisories/RUSTSEC-2023-0023.html), [RUSTSEC-2023-0024](https://rustsec.org/advisories/RUSTSEC-2023-0024.html) This update contains rebuilds of all affected applications against the latest versions of these crates, which have addressed all linked issues. --------------------------------------------------------------------------------ChangeLog: * Wed May 3 2023 Fabio Valentini - 0.3.2-4 - Rebuild for openssl crate > = v0.10.48 (RUSTSEC-2023-{0022,0023,0024}) --------------------------------------------------------------------------------This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2023-37ae269843' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Recent updates for the `tokio`, `h2`, and `openssl` crates addressed some (potential or confirmed) security or soundness issues: - `tokio`: [RUSTSEC-2023-0005](https://rustsec.org/advisories/RUSTSEC-2023-0005.html) - `h2`: [RUSTSEC-2023-0034](https://rustsec.org/advisories/RUSTSEC-2023-0034.html) / [CVE-2023-26964](https://nvd.nist.gov/vuln/detail/CVE-2023-26964) - `openssl`:. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-37ae269843 2023-05-18 00:49:56.087782 --------------------------------------------------------------------------------Name : rust-gst-plugin-reqwest Product : Fedora 37 Version : 0.10.4 Release : 2.fc37 URL : Summary : GStreamer reqwest HTTP Source Plugin Description : GStreamer reqwest HTTP Source Plugin. --------------------------------------------------------------------------------Update Information: Recent updates for the `tokio`, `h2`, and `openssl` crates addressed some (potential or confirmed) security or soundness issues: - `tokio`: [RUSTSEC-2023-0005](https://rustsec.org/advisories/RUSTSEC-2023-0005.html) -`h2`: [RUSTSEC-2023-0034](https://rustsec.org/advisories/RUSTSEC-2023-0034.html) / [CVE-2023-26964](https://nvd.nist.gov/vuln/detail/CVE-2023-26964) - `openssl`: [RUSTSEC-2023-0022](https://rustsec.org/advisories/RUSTSEC-2023-0022.html), [RUSTSEC-2023-0023](https://rustsec.org/advisories/RUSTSEC-2023-0023.html), [RUSTSEC-2023-0024](https://rustsec.org/advisories/RUSTSEC-2023-0024.html) This update contains rebuilds of all affected applications against the latest versions of these crates, which have addressed all linked issues. --------------------------------------------------------------------------------ChangeLog: * Wed May 3 2023 Fabio Valentini - 0.10.4-2 - Rebuild with h2 > = v0.3.18 and tokio > = v1.24.2 (RUSTSEC-2023-{0005,0034}) --------------------------------------------------------------------------------This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-37ae269843' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- Update cranelift crates to version 0.77.0. - Update the wast crate to version 38.0.0. - Update the wat crate to version 1.0.40. - Update the wasmparser crate to version 0.80.1. - Update wasmtime crates to version 0.30.0. - Update the backtrace crate to version 0.3.61. - Update the addr2line crate to version 0.16.0. - Update the object crate to version 0.26.2. - Update the gimli crate to. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-68713440cb 2021-09-30 00:51:55.645575 --------------------------------------------------------------------------------Name : rust-cranelift-bforest Product : Fedora 35 Version : 0.77.0 Release : 1.fc35 URL : Summary : Forest of B+-trees Description : Forest of B+-trees. --------------------------------------------------------------------------------Update Information: - Update cranelift crates to version 0.77.0. - Update the wast crate to version 38.0.0. - Update the wat crate to version 1.0.40. - Update the wasmparser crate to version 0.80.1. - Update wasmtime crates to version 0.30.0. - Update the backtrace crate to version 0.3.61. - Update the addr2line crate to version 0.16.0. - Update the object crate to version 0.26.2. - Update the gimli crate to version 0.25.0. The cranelift and wasmtime package updates also include security fixes for CVE-2021-39216, CVE-2021-39218, and CVE-2021-39219. --------------------------------------------------------------------------------ChangeLog: * Wed Sep 22 2021 Olivier Lemasle - 0.77.0-1 - Update to upstream 0.77.0 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-68713440cb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key.More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.