GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working . MGASA-2022-0457 - Updated emacs packages fix security vulnerability Publication date: 13 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0457.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-45939 GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working directory has contents that depend on untrusted input. (CVE-2022-45939) References: - https://bugs.mageia.org/show_bug.cgi?id=31211 - https://lists.suse.com/pipermail/sle-security-updates/2022-December/013180.html - - https://www.cve.org/CVERecord?id=CVE-2022-45939 SRPMS: - 8/core/emacs-27.1-1.2.mga8 . Fedora enhances gedit to address file handling vulnerability using input sanitization, bolstering overall safety.. Emacs Security,Mageia Update,Command Execution Risk,Shell Metacharacters,Software Vulnerability. . Severity: Critical. LinuxSecurity.com Team
An update that solves 11 vulnerabilities and has 9 fixes is now available. . SUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2922-1 Rating: important References: #1027519 #1137251 #1176189 #1179148 #1179246 #1180491 #1181989 #1183877 #1185682 #1186428 #1186429 #1186433 #1186434 #1188050 #1189373 #1189376 #1189378 #1189380 #1189381 #1189882 Cross-References: CVE-2021-0089 CVE-2021-28690 CVE-2021-28692 CVE-2021-28693 CVE-2021-28694 CVE-2021-28695 CVE-2021-28696 CVE-2021-28697 CVE-2021-28698 CVE-2021-28699 CVE-2021-28700 CVSS scores: CVE-2021-0089 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVE-2021-28694 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-28695 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-28696 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-28697 (SUSE): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-28698 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-28699 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-28700 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE MicroOS 5.0 SUSE Linux Enterprise Module for Server Applications 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that solves 11 vulnerabilities and has 9 fixes is now available. Description: This update for xen fixes the following issues: Update to Xen 4.13.3 general bug fix release(bsc#1027519). Security issues fixed: - CVE-2021-28693: xen/arm: Boot modules are not scrubbed (bsc#1186428) - CVE-2021-28692: xen: inappropriate x86 IOMMU timeout detection / handling (bsc#1186429) - CVE-2021-0089: xen: Speculative Code Store Bypass (bsc#1186433) - CVE-2021-28690: xen: x86: TSX Async Abort protections not restored after S3 (bsc#1186434) - CVE-2021-28694,CVE-2021-28695,CVE-2021-28696: IOMMU page mapping issues on x86 (XSA-378)(bsc#1189373). - CVE-2021-28697: grant table v2 status pages may remain accessible after de-allocation (XSA-379)(bsc#1189376). - CVE-2021-28698: long running loops in grant table handling (XSA-380)(bsc#1189378). - CVE-2021-28699: inadequate grant-v2 status frames array bounds check (XSA-382)(bsc#1189380). - CVE-2021-28700: No memory limit for dom0less domUs (XSA-383)(bsc#1189381). Other issues fixed: - Fixed "Panic on CPU 0: IO-APIC + timer doesn't work!" (bsc#1180491) - Fixed an issue with xencommons, where file format expecations by fillup did not allign (bsc#1185682) - Fixed shell macro expansion in the spec file, so that ExecStart= in xendomains-wait-disks.service is created correctly (bsc#1183877) - Upstream bug fixes (bsc#1027519) - Fixed Xen SLES11SP4 guest hangs on cluster (bsc#1188050). - xl monitoring process exits during xl save -p|-c keep the monitoring process running to cleanup the domU during shutdown (bsc#1176189). - Dom0 hangs when pinning CPUs for dom0 with HVM guest (bsc#1179246). - Prevent superpage allocation in the LAPIC and ACPI_INFO range (bsc#1189882). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE MicroOS 5.0: zypper in -t patch SUSE-SUSE-MicroOS-5.0-2021-2922=1 - SUSE Linux Enterprise Module for Server Applications 15-SP2: zypper in-t patch SUSE-SLE-Module-Server-Applications-15-SP2-2021-2922=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-2922=1 Package List: - SUSE MicroOS 5.0 (x86_64): xen-debugsource-4.13.3_02-3.34.1 xen-libs-4.13.3_02-3.34.1 xen-libs-debuginfo-4.13.3_02-3.34.1 - SUSE Linux Enterprise Module for Server Applications 15-SP2 (noarch): xen-tools-xendomains-wait-disk-4.13.3_02-3.34.1 - SUSE Linux Enterprise Module for Server Applications 15-SP2 (x86_64): xen-4.13.3_02-3.34.1 xen-debugsource-4.13.3_02-3.34.1 xen-devel-4.13.3_02-3.34.1 xen-tools-4.13.3_02-3.34.1 xen-tools-debuginfo-4.13.3_02-3.34.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (x86_64): xen-debugsource-4.13.3_02-3.34.1 xen-libs-4.13.3_02-3.34.1 xen-libs-debuginfo-4.13.3_02-3.34.1 xen-tools-domU-4.13.3_02-3.34.1 xen-tools-domU-debuginfo-4.13.3_02-3.34.1 References: https://www.suse.com/security/cve/CVE-2021-0089.html https://www.suse.com/security/cve/CVE-2021-28690.html https://www.suse.com/security/cve/CVE-2021-28692.html https://www.suse.com/security/cve/CVE-2021-28693.html https://www.suse.com/security/cve/CVE-2021-28694.html https://www.suse.com/security/cve/CVE-2021-28695.html https://www.suse.com/security/cve/CVE-2021-28696.html https://www.suse.com/security/cve/CVE-2021-28697.html https://www.suse.com/security/cve/CVE-2021-28698.html https://www.suse.com/security/cve/CVE-2021-28699.html https://www.suse.com/security/cve/CVE-2021-28700.html https://bugzilla.suse.com/1027519 https://bugzilla.suse.com/1137251 https://bugzilla.suse.com/1176189 https://bugzilla.suse.com/1179148 https://bugzilla.suse.com/1179246 https://bugzilla.suse.com/1180491 https://bugzilla.suse.com/1181989 https://bugzilla.suse.com/1183877 https://bugzilla.suse.com/1185682 https://bugzilla.suse.com/1186428 https://bugzilla.suse.com/1186429 https://bugzilla.suse.com/1186433 https://bugzilla.suse.com/1186434 https://bugzilla.suse.com/1188050 https://bugzilla.suse.com/1189373 https://bugzilla.suse.com/1189376 https://bugzilla.suse.com/1189378 https://bugzilla.suse.com/1189380 https://bugzilla.suse.com/1189381 https://bugzilla.suse.com/1189882 . The recent update from SUSE enhances Xen security by tackling critical vulnerabilities, delivering essential patches and upgrades for improved safeguarding.. SUSE Xen Security Update, Linux Security Patches, Bug Fix Releases, Threat Mitigation. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following problems: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2666-1
Get the latest Linux and open source security news straight to your inbox.