Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Update to 9.16.33 (#2342784) Security Fixes: DNS-over-HTTPS flooding fixes. (CVE-2024-12705) Limit additional section processing for large RDATA sets. (CVE-2024-11187) New Features:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-3551f3ba1b 2025-02-12 01:35:52.622127+00:00 -------------------------------------------------------------------------------- Name : bind Product : Fedora 41 Version : 9.18.33 Release : 1.fc41 URL : https://www.isc.org/bind/ Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly. -------------------------------------------------------------------------------- Update Information: Update to 9.16.33 (#2342784) Security Fixes: DNS-over-HTTPS flooding fixes. (CVE-2024-12705) Limit additional section processing for large RDATA sets. (CVE-2024-11187) New Features: Add a new option to configure the maximum number of outgoing queries per client request. Bug Fixes: Fix nsupdate hang when processing a large update. Fix possible assertion failure when reloading server while processing update policy rules. [GL #5006] Fix dnssec-signzone signing non-DNSKEY RRsets with revoked keys. Fix improper handling of unknown directives in resolv.conf. Upstream Release Notes -------------------------------------------------------------------------------- ChangeLog: * Sun Feb 2 2025 Petr MenÅ¡Ãk - 32:9.18.33-1 - Update to 9.16.33 (rhbz#2342784) * Fri Jan 17 2025 Petr MenÅ¡Ãk - 32:9.18.32-4 - Add sysusers named user creation (rhbz#2105415) * Thu Dec 12 2024 Petr MenÅ¡Ãk - 32:9.18.32-1 - Update to 9.18.32 (#2331675) - RemoveCHANGES file from package - Disable DLZ plugins, they are not shipped with bind anymore - Add new root key 38696 into package files too * Thu Dec 12 2024 Petr MenÅ¡Ãk - 32:9.18.31-3 - Disable temporarily PDF generation on all platforms * Wed Dec 4 2024 Petr MenÅ¡Ãk - 32:9.18.31-2 - Add nsupdate TLS support (FREEIPA-11706) - Include a test for nsupdate changes * Thu Nov 14 2024 Petr MenÅ¡Ãk - 32:9.18.31-1 - Update to 9.18.31 (#2319214) * Thu Nov 14 2024 Petr MenÅ¡Ãk - 32:9.18.30-3 - Bump obsoleted license version (rhbz#2308102) * Tue Oct 8 2024 Petr MenÅ¡Ãk - 32:9.18.30-2 - Make OpenSSL engine support optional -------------------------------------------------------------------------------- References: [ 1 ] Bug #2319214 - bind-9.18.31 is available https://bugzilla.redhat.com/show_bug.cgi?id=2319214 [ 2 ] Bug #2331675 - bind-9.18.32 is available https://bugzilla.redhat.com/show_bug.cgi?id=2331675 [ 3 ] Bug #2342784 - bind-9.18.33 is available https://bugzilla.redhat.com/show_bug.cgi?id=2342784 [ 4 ] Bug #2342883 - CVE-2024-12705 bind: DNS-over-HTTPS implementation suffers from multiple issues under heavy query load [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2342883 [ 5 ] Bug #2342891 - CVE-2024-11187 bind: Many records in the additional section cause CPU exhaustion [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2342891 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3551f3ba1b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . The latest update for BIND 9.16.33 in Fedora 41 resolves DNS flooding vulnerabilities and improves overall security, as stated in advisory FEDORA-2025-3551f3ba1b.. dns flooding fix,binding updates,fedora advisories,service security updates,bind fixes. . LinuxSecurity.com Team
Update to latest upstream. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-aebaa73b1f 2024-10-15 15:21:19.794709 -------------------------------------------------------------------------------- Name : pdns-recursor Product : Fedora 41 Version : 5.1.2 Release : 1.fc41 URL : https://www.powerdns.com/ Summary : Modern, advanced and high performance recursing/non authoritative name server Description : PowerDNS Recursor is a non authoritative/recursing DNS server. Use this package if you need a dns cache for your network. -------------------------------------------------------------------------------- Update Information: Update to latest upstream -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 3 2024 Sander Hoentjen - 5.1.2-1 - Update to 5.1.2 - fixes #2299449 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2295543 - pdns-recursor-5.1.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2295543 [ 2 ] Bug #2299449 - pdns-recursor-5.1.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2299449 [ 3 ] Bug #2316319 - CVE-2024-25590 pdns-recursor: Crafted responses can lead to a denial of service due to cache inefficiencies in the Recursor [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2316319 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-aebaa73b1f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ce2936b568 2024-05-26 01:25:15.719720 -------------------------------------------------------------------------------- Name : rust-ybaas Product : Fedora 40 Version : 0.0.17 Release : 3.fc40 URL : Summary : Yubibomb as a service Description : Don't you love when you accidentally tap your Yubikey when you have your IRC client in focus and you send 987947 into Libera? Want to be able to have that experience without having to reach all the way over to your laptop's USB port? Don't want the complexity of installing and using the yubibomb CLI tool? Now you can use yubibomb as a service! -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+(denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 0.0.17-3 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ce2936b568' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update for axis fixes the following issues: CVE-2023-51441: Fixed SSRF when untrusted input is passed to the service admin HTTP API (bsc#1218605).. # Security update for axis Announcement ID: SUSE-SU-2024:0852-1 Rating: moderate References: * bsc#1218605 Cross-References: * CVE-2023-51441 CVSS scores: * CVE-2023-51441 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2023-51441 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for axis fixes the following issues: * CVE-2023-51441: Fixed SSRF when untrusted input is passed to the service admin HTTP API (bsc#1218605). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-852=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-852=1 ## Package List: * openSUSE Leap 15.5 (noarch) * axis-1.4-150200.13.9.1 * axis-manual-1.4-150200.13.9.1 * Basesystem Module 15-SP5 (noarch) * axis-1.4-150200.13.9.1 ## References: * https://www.suse.com/security/cve/CVE-2023-51441.html * https://bugzilla.suse.com/show_bug.cgi?id=1218605 . Mitigate SSRF vulnerability within the axis package on openSUSE, bolstering defenses against unauthorized data inputs. Proceed with the installation of suggested updates immediately.. openSUSE Update, Axis Security Fix, SSRF Issue Resolution, Security Patch. . LinuxSecurity.com Team
* bsc#1219243 Cross-References: * CVE-2024-0727 . # Security update for openssl-1_0_0 Announcement ID: SUSE-SU-2024:0814-1 Rating: moderate References: * bsc#1219243 Cross-References: * CVE-2024-0727 CVSS scores: * CVE-2024-0727 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2024-0727 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for openssl-1_0_0 fixes the following issues: * CVE-2024-0727: Denial of service when processing a maliciously formatted PKCS12 file (bsc#1219243). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-814=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-814=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-814=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-814=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * openssl-1_0_0-debugsource-1.0.2p-3.90.1 * openssl-1_0_0-debuginfo-1.0.2p-3.90.1 * libopenssl-1_0_0-devel-1.0.2p-3.90.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (s390x x86_64) * libopenssl-1_0_0-devel-32bit-1.0.2p-3.90.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * libopenssl1_0_0-hmac-1.0.2p-3.90.1 *libopenssl-1_0_0-devel-1.0.2p-3.90.1 * openssl-1_0_0-debuginfo-1.0.2p-3.90.1 * libopenssl1_0_0-debuginfo-1.0.2p-3.90.1 * openssl-1_0_0-1.0.2p-3.90.1 * libopenssl1_0_0-1.0.2p-3.90.1 * openssl-1_0_0-debugsource-1.0.2p-3.90.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * openssl-1_0_0-doc-1.0.2p-3.90.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * libopenssl1_0_0-32bit-1.0.2p-3.90.1 * libopenssl1_0_0-hmac-32bit-1.0.2p-3.90.1 * libopenssl1_0_0-debuginfo-32bit-1.0.2p-3.90.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * libopenssl1_0_0-hmac-1.0.2p-3.90.1 * libopenssl-1_0_0-devel-1.0.2p-3.90.1 * openssl-1_0_0-debuginfo-1.0.2p-3.90.1 * libopenssl1_0_0-debuginfo-1.0.2p-3.90.1 * openssl-1_0_0-1.0.2p-3.90.1 * libopenssl1_0_0-1.0.2p-3.90.1 * openssl-1_0_0-debugsource-1.0.2p-3.90.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * openssl-1_0_0-doc-1.0.2p-3.90.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * libopenssl1_0_0-32bit-1.0.2p-3.90.1 * libopenssl1_0_0-hmac-32bit-1.0.2p-3.90.1 * libopenssl1_0_0-debuginfo-32bit-1.0.2p-3.90.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * libopenssl1_0_0-hmac-1.0.2p-3.90.1 * libopenssl-1_0_0-devel-1.0.2p-3.90.1 * openssl-1_0_0-debuginfo-1.0.2p-3.90.1 * libopenssl1_0_0-debuginfo-1.0.2p-3.90.1 * openssl-1_0_0-1.0.2p-3.90.1 * libopenssl1_0_0-1.0.2p-3.90.1 * openssl-1_0_0-debugsource-1.0.2p-3.90.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * openssl-1_0_0-doc-1.0.2p-3.90.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * libopenssl1_0_0-32bit-1.0.2p-3.90.1 * libopenssl1_0_0-hmac-32bit-1.0.2p-3.90.1 * libopenssl1_0_0-debuginfo-32bit-1.0.2p-3.90.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0727.html * https://bugzilla.suse.com/show_bug.cgi?id=1219243 . Uncover the most recentsecurity patch for openssl-1_0_0 in SUSE, tackling a moderate denial of service vulnerability.. SUSE Linux, openssl security, service update, Linux patches, security measures. . LinuxSecurity.com Team
It was discovered that there was a potential authorisation bypass vulnerability in Apache Zookeeper, a co-ordination service for reliable distributed applications. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3624-1
The container suse/pcp was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/pcp ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2734-1 Container Tags : suse/pcp:5 , suse/pcp:5-17.81 , suse/pcp:5.2 , suse/pcp:5.2-17.81 , suse/pcp:5.2.5 , suse/pcp:5.2.5-17.81 Container Release : 17.81 Severity : important Type : security References : 1214054 CVE-2023-36054 ----------------------------------------------------------------- The container suse/pcp was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3363-1 Released: Fri Aug 18 14:54:16 2023 Summary: Security update for krb5 Type: security Severity: important References: 1214054,CVE-2023-36054 This update for krb5 fixes the following issues: - CVE-2023-36054: Fixed a DoS that could be triggered by an authenticated remote user. (bsc#1214054) The following package changes have been done: - krb5-1.19.2-150400.3.6.1 updated - container:bci-bci-init-15.4-15.4-29.36 updated . Alert regarding security patch for SUSE Container suse/pcp related to significant DoS vulnerability identified as CVE-2023-36054.. SUSE Container Update, Krb5, DoS Issue, Security Patch, Service Update. . Severity: Important. LinuxSecurity.com Team
- Update yubibomb to version 0.2.12. - Update ybaas to version 0.0.16.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-80ab942675 2023-05-19 01:23:33.798279 --------------------------------------------------------------------------------Name : rust-ybaas Product : Fedora 37 Version : 0.0.16 Release : 1.fc37 URL : Summary : Yubibomb as a service Description : Don't you love when you accidentally tap your Yubikey when you have your IRC client in focus and you send 987947 into Libera? Want to be able to have that experience without having to reach all the way over to your laptop's USB port? Don't want the complexity of installing and using the yubibomb CLI tool? Now you can use yubibomb as a service! --------------------------------------------------------------------------------Update Information: - Update yubibomb to version 0.2.12. - Update ybaas to version 0.0.16. --------------------------------------------------------------------------------ChangeLog: * Mon May 8 2023 Fabio Valentini - 0.0.16-1 - Update to version 0.0.16; Fixes RHBZ#2062063 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-80ab942675' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.