Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Update to uriparser-0.9.8.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-410d4ecabe 2024-05-14 01:32:20.839827 -------------------------------------------------------------------------------- Name : uriparser Product : Fedora 38 Version : 0.9.8 Release : 1.fc38 URL : https://uriparser.github.io/ Summary : URI parsing library - RFC 3986 Description : Uriparser is a strictly RFC 3986 compliant URI parsing library written in C. uriparser is cross-platform, fast, supports Unicode and is licensed under the New BSD license. -------------------------------------------------------------------------------- Update Information: Update to uriparser-0.9.8. -------------------------------------------------------------------------------- ChangeLog: * Sun May 5 2024 Sandro Mani - 0.9.8-1 - Update to 0.9.8 * Sat Jan 27 2024 Fedora Release Engineering - 0.9.7-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Neal Gompa - 0.9.7-4 - Move cmake files to the devel subpackage * Sat Jul 22 2023 Fedora Release Engineering - 0.9.7-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2278811 - CVE-2024-34402 CVE-2024-34403 uriparser: various flaws [fedora-38] https://bugzilla.redhat.com/show_bug.cgi?id=2278811 [ 2 ] Bug #2278812 - CVE-2024-34402 CVE-2024-34403 uriparser: various flaws [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2278812 [ 3 ] Bug #2278813 - CVE-2024-34402 CVE-2024-34403 uriparser: various flaws [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2278813 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-410d4ecabe' at thecommand line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 0.29 - Fixes 'clipbrowse command execution with multi-line clipboard text including "| sh"'. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2843f37353 2024-04-19 21:20:20.799127 -------------------------------------------------------------------------------- Name : perl-Clipboard Product : Fedora 40 Version : 0.29 Release : 1.fc40 URL : https://metacpan.org/dist/Clipboard Summary : Copy and paste with any OS Description : Who doesn't remember the first time they learned to copy and paste, and generated an exponentially growing text document? Yes, that's right, clipboards are magical. -------------------------------------------------------------------------------- Update Information: Update to 0.29 - Fixes 'clipbrowse command execution with multi-line clipboard text including "| sh"' -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 10 2024 Xavier Bachelot - 0.29-1 - Update to 0.29 (RHBZ#2273832) - Fixes RHBZ#2257224 and RHBZ#2257225 - Convert License: to SPDX -------------------------------------------------------------------------------- References: [ 1 ] Bug #2257225 - perl-Clipboard: clipbrowse command execution with multi-line clipboard text including "| sh" [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257225 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2843f37353' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The 5.13.12 stable kernel update contains a number of important fixes across the tree.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-33819e6b09 2021-08-21 01:05:40.547355 --------------------------------------------------------------------------------Name : kernel Product : Fedora 34 Version : 5.13.12 Release : 200.fc34 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package --------------------------------------------------------------------------------Update Information: The 5.13.12 stable kernel update contains a number of important fixes across the tree. --------------------------------------------------------------------------------ChangeLog: * Wed Aug 18 2021 Justin M. Forbes [5.13.12-200] - kernel-5.13.12-0 (Justin M. Forbes) * Tue Aug 17 2021 Justin M. Forbes [5.13.11-0] - bpf: Fix integer overflow involving bucket_size (Tatsuhiko Yasumatsu) - kernel-5.13.10-0 (Justin M. Forbes) - Fix up backport of Dell XPS 9710 quirk (Justin M. Forbes) - ASoC: Intel: sof_sdw_max98373: remove useless inits (Pierre-Louis Bossart) - ASoC: Intel: update sof_pcm512x quirks (Pierre-Louis Bossart) - ASoC: SOF: Intel: Use DMI string to search for adl_mx98373_rt5682 variant (jairaj arava) - ASoC: Intel: sof_sdw: add quirk for Dell XPS 9710 (Pierre-Louis Bossart) - kernel-5.13.9-0 (Justin M. Forbes) - drm/i915/dp: Use max params for older panels (Kai-Heng Feng) - pinctrl: tigerlake: Fix GPIO mapping for newer version of software (Andy Shevchenko) - kernel-5.13.8-0 (Justin M. Forbes) - Re-enable sermouse for x86 (rhbz 1974002) (Justin M. Forbes) - Revert CRYPTO_ECDH and CRYPTO_ECDA from builtin to module to fix fips (Justin M. Forbes) - drm/rockchip: remove existing generic drivers to take over the device (Javier Martinez Canillas) - powerpc/pseries: Fix regression while building external modules (Srikar Dronamraju) - kernel-5.13.7-0 (Justin M.Forbes) - kernel-5.13.6-0 (Justin M. Forbes) - kernel-5.13.5-0 (Justin M. Forbes) - iwlwifi Add support for ax201 in Samsung Galaxy Book Flex2 Alpha (Justin M. Forbes) - Revert "usb: renesas-xhci: Fix handling of unknown ROM state" (Justin M. Forbes) - RHEL configs need this too (Justin M. Forbes) - kernel-5.13.4-0 (Justin M. Forbes) - Config update for 5.13.4 (Justin M. Forbes) - kernel-5.13.3-0 (Justin M. Forbes) - Don't tag a release as [redhat] (Justin M. Forbes) - platform/x86: amd-pmc: Fix missing unlock on error in amd_pmc_send_cmd() (Yang Yingliang) --------------------------------------------------------------------------------References: [ 1 ] Bug #1983686 - CVE-2021-3653 kernel: SVM nested virtualization issue in KVM (AVIC support) https://bugzilla.redhat.com/show_bug.cgi?id=1983686 [ 2 ] Bug #1983988 - CVE-2021-3656 kernel: SVM nested virtualization issue in KVM (VMLOAD/VMSAVE) https://bugzilla.redhat.com/show_bug.cgi?id=1983988 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-33819e6b09' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to 6.2.2, fixes CVE-2020-5313, CVE-2020-5312, CVE-2020-5311, CVE-2020-5310.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-df444e464e 2020-01-31 01:59:12.858062 --------------------------------------------------------------------------------Name : python-pillow Product : Fedora 31 Version : 6.2.2 Release : 1.fc31 URL : Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library (PIL) This library provides extensive file format support, an efficient internal representation, and powerful image processing capabilities. There are four subpackages: tk (tk interface), qt (PIL image wrapper for Qt), devel (development) and doc (documentation). --------------------------------------------------------------------------------Update Information: Update to 6.2.2, fixes CVE-2020-5313, CVE-2020-5312, CVE-2020-5311, CVE-2020-5310. --------------------------------------------------------------------------------ChangeLog: * Fri Jan 17 2020 Sandro Mani - 6.2.2-1 - Update to 6.2.2 * Tue Nov 26 2019 Sandro Mani - 6.1.0-4 - Backport patches for CVE-2019-16865 --------------------------------------------------------------------------------References: [ 1 ] Bug #1789541 - CVE-2020-5310 CVE-2020-5311 CVE-2020-5312 CVE-2020-5313 python-pillow: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1789541 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-df444e464e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
https://www.mediawiki.org/wiki/MediaWiki_1.27. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-9299ce1c7d 2016-09-06 18:18:46.585861 -------------------------------------------------------------------------------- Name : mediawiki Product : Fedora 25 Version : 1.27.1 Release : 1.fc25 URL : https://www.mediawiki.org/wiki/MediaWiki Summary : A wiki engine Description : MediaWiki is the software used for Wikipedia and the other Wikimedia Foundation websites. Compared to other wikis, it has an excellent range of features and support for high-traffic websites using multiple servers This package supports wiki farms. Read the instructions for creating wiki instances under /usr/share/doc/mediawiki/README.RPM. Remember to remove the config dir after completing the configuration. -------------------------------------------------------------------------------- Update Information: https://www.mediawiki.org/wiki/MediaWiki_1.27 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1369613 - CVE-2016-6331 CVE-2016-6332 CVE-2016-6333 CVE-2016-6334 CVE-2016-6335 CVE-2016-6336 mediawiki: multiple flaws fixed in 1.27.1, 1.26.4 and 1.23.15 https://bugzilla.redhat.com/show_bug.cgi?id=1369613 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mediawiki' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist
Get the latest Linux and open source security news straight to your inbox.