Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-632b468c59 2024-11-29 03:47:35.523146+00:00 -------------------------------------------------------------------------------- Name : rust-rustls Product : Fedora 40 Version : 0.23.17 Release : 1.fc40 URL : https://crates.io/crates/rustls Summary : Modern TLS library written in Rust Description : Rustls is a modern TLS library written in Rust. -------------------------------------------------------------------------------- Update Information: Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and rustls is the only dependent package of zlib-rs. -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 20 2024 Benjamin A. Beasley - 0.23.17-1 - Update to version 0.23.17; Fixes RHBZ#2326682 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2326413 - CVE-2024-11249 rust-zlib-rs: zlib-rs stack overflow during decompression with malicious input [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2326413 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-632b468c59' at the command line. For more information,refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-41e6e2fc74 2024-11-29 03:29:16.747934+00:00 -------------------------------------------------------------------------------- Name : rust-zlib-rs Product : Fedora 41 Version : 0.4.0 Release : 1.fc41 URL : https://crates.io/crates/zlib-rs Summary : Memory-safe zlib implementation written in rust Description : A memory-safe zlib implementation written in rust. -------------------------------------------------------------------------------- Update Information: Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and rustls is the only dependent package of zlib-rs. -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 20 2024 Benjamin A. Beasley - 0.4.0-1 - Update to version 0.4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2326414 - CVE-2024-11249 rust-zlib-rs: zlib-rs stack overflow during decompression with malicious input [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2326414 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-41e6e2fc74' at the command line. For more information, refer tothe dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ff98facbc6 2024-10-19 01:18:49.824560 -------------------------------------------------------------------------------- Name : rust-hyper-rustls Product : Fedora 39 Version : 0.27.3 Release : 1.fc39 URL : https://crates.io/crates/hyper-rustls Summary : Rustls+hyper integration for pure rust HTTPS Description : Rustls+hyper integration for pure rust HTTPS. -------------------------------------------------------------------------------- Update Information: Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3. Update the tower crate to version 0.5.1 and add a compat package for version 0.4. Update the tower-http crate to version 0.6.1 and add a compat package for version 0.5. -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 10 2024 Fabio Valentini - 0.27.3-1 - Update to version 0.27.3; Fixes RHBZ#2309673 * Fri Jul 19 2024 Fedora Release Engineering - 0.27.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2316020 - CVE-2024-47609 rust-tonic: Remotely exploitable DoS in Tonic `
Get the latest Linux and open source security news straight to your inbox.