An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for tor ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1513-1 Rating: moderate References: #1192658 Cross-References: CVE-2021-22929 Affected Products: openSUSE Leap 15.2 openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for tor fixes the following issues: tor 0.4.6.8: * Improving reporting of general overload state for DNS timeout errors by relays * Regenerate fallback directories for October 2021 * Bug fixes for onion services * CVE-2021-22929: do not log v2 onion services access attempt warnings on disk excessively (TROVE-2021-008, boo#1192658) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1513=1 - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2021-1513=1 Package List: - openSUSE Leap 15.2 (x86_64): tor-0.4.6.8-lp152.2.18.1 tor-debuginfo-0.4.6.8-lp152.2.18.1 tor-debugsource-0.4.6.8-lp152.2.18.1 - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): tor-0.4.6.8-bp153.2.9.1 References: https://www.suse.com/security/cve/CVE-2021-22929.html https://bugzilla.suse.com/1192658 . Updates in openSUSE have remedied a tor vulnerability, enhancing log handling and optimizing service performance.. OpenSUSE Security Update, Tor Vulnerability Fixes, Software Patch. . LinuxSecurity.com Team
The container suse/sles12sp5 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sles12sp5 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2021:84-1 Container Tags : suse/sles12sp5:6.5.151 , suse/sles12sp5:latest Container Release : 6.5.151 Severity : important Type : security References : 1082318 1088639 1112438 1125689 1134616 1146182 1146184 1176201 1181358 962914 964140 966514 CVE-2016-1544 CVE-2018-1000168 CVE-2019-9511 CVE-2019-9513 CVE-2020-11080 ----------------------------------------------------------------- The container suse/sles12sp5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:796-1 Released: Tue Mar 16 10:28:14 2021 Summary: Recommended update for zlib Type: recommended Severity: moderate References: 1176201 This update for zlib fixes the following issues: - Fixed hw compression on z15 (bsc#1176201) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:932-1 Released: Wed Mar 24 12:13:01 2021 Summary: Security update for nghttp2 Type: security Severity: important References: 1082318,1088639,1112438,1125689,1134616,1146182,1146184,1181358,962914,964140,966514,CVE-2016-1544,CVE-2018-1000168,CVE-2019-9511,CVE-2019-9513,CVE-2020-11080 This update for nghttp2 fixes the following issues: Security issues fixed: - CVE-2020-11080: HTTP/2 Large Settings Frame DoS (bsc#1181358). - CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service (bsc#1146184). - CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#1146182). -CVE-2018-1000168: Fixed ALTSVC frame client side denial of service (bsc#1088639). - CVE-2016-1544: Fixed out of memory due to unlimited incoming HTTP header fields (bsc#966514). Bug fixes and enhancements: - Packages must not mark license files as %doc (bsc#1082318) - Typo in description of libnghttp2_asio1 (bsc#962914) - Fixed mistake in spec file (bsc#1125689) - Fixed build issue with boost 1.70.0 (bsc#1134616) - Fixed build issue with GCC 6 (bsc#964140) - Feature: Add W&S module (FATE#326776, bsc#1112438) . The security patch for SUSE/SLES12SP5 addresses urgent vulnerabilities, enhancing the nghttp2 service alongside zlib performance flaws.. SUSE Updates, DoS Security Fixes, SLES12SP5 Patches. . Severity: Important. LinuxSecurity.com Team
New upstream release (#1934336), include user ssh-agent.service (#1761817). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-f68a5a75ba 2021-03-23 00:15:16.316555 --------------------------------------------------------------------------------Name : kde-settings Product : Fedora 34 Version : 34.0 Release : 9.fc34 URL : https://pagure.io/fedora-kde/kde-settings Summary : Config files for kde Description : Config files for kde. --------------------------------------------------------------------------------Update Information: New upstream release (#1934336), include user ssh-agent.service (#1761817) --------------------------------------------------------------------------------ChangeLog: * Sat Mar 6 2021 Rex Dieter - 34.0-9 - drop ssh-agent.service, moved to openssh-clients (yay) * Tue Mar 2 2021 Rex Dieter - 34.0-8 - ssh-agent.service improvements * Mon Mar 1 2021 Rex Dieter - 34.0-7 - ssh-agent.service: drop After=plasma-core.target * Mon Mar 1 2021 Rex Dieter - 34.0-6 - ssh-agent.sh: only set SSH_AUTH_SOCK if not already * Sun Feb 28 2021 Rex Dieter - 34.0-5 - ssh-agent.service improvements --------------------------------------------------------------------------------References: [ 1 ] Bug #1935055 - CVE-2021-28041 openssh: double-free memory corruption may lead to arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=1935055 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-f68a5a75ba' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.