* bsc#1229783 Cross-References: * CVE-2023-49582 . # Security update for apr Announcement ID: SUSE-SU-2024:3428-1 Rating: moderate References: * bsc#1229783 Cross-References: * CVE-2023-49582 CVSS scores: * CVE-2023-49582 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2023-49582 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2023-49582 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP5 * Basesystem Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for apr fixes the following issues: * CVE-2023-49582: Fixed an unexpected lax shared memory permissions. (bsc#1229783) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-3428=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3428=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3428=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-3428=1 ## Package List: * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libapr1-1.6.3-150000.3.6.1 * libapr1-debuginfo-1.6.3-150000.3.6.1 * apr-debugsource-1.6.3-150000.3.6.1 *apr-devel-1.6.3-150000.3.6.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libapr1-1.6.3-150000.3.6.1 * libapr1-debuginfo-1.6.3-150000.3.6.1 * apr-debugsource-1.6.3-150000.3.6.1 * apr-devel-1.6.3-150000.3.6.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libapr1-1.6.3-150000.3.6.1 * libapr1-debuginfo-1.6.3-150000.3.6.1 * apr-debugsource-1.6.3-150000.3.6.1 * apr-devel-1.6.3-150000.3.6.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libapr1-1.6.3-150000.3.6.1 * libapr1-debuginfo-1.6.3-150000.3.6.1 * apr-debugsource-1.6.3-150000.3.6.1 * apr-devel-1.6.3-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-49582.html * https://bugzilla.suse.com/show_bug.cgi?id=1229783 . Follow these installation guidelines to apply the latest SUSE APR security patch, addressing vulnerabilities across various distributions for enhanced safety. SUSE Security Update, apr Security Advisory, openSUSE Patch, Shared Memory Permissions Fix. . LinuxSecurity.com Team
This update to the apr package fixes a security issue in the handling of shared memory permissions. SECURITY: CVE-2023-49582: Apache Portable Runtime (APR): Unexpected lax shared memory permissions (cve.mitre.org) Lax permissions set by the Apache Portable Runtime library on. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-b40491b84b 2024-09-04 02:22:40.987666 -------------------------------------------------------------------------------- Name : apr Product : Fedora 40 Version : 1.7.5 Release : 1.fc40 URL : https://apr.apache.org/ Summary : Apache Portable Runtime library Description : The mission of the Apache Portable Runtime (APR) is to provide a free library of C data structures and routines, forming a system portability layer to as many operating systems as possible, including Unices, MS Win32, BeOS and OS/2. -------------------------------------------------------------------------------- Update Information: This update to the apr package fixes a security issue in the handling of shared memory permissions. SECURITY: CVE-2023-49582: Apache Portable Runtime (APR): Unexpected lax shared memory permissions (cve.mitre.org) Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 28 2024 Joe Orton - 1.7.5-1 - update to 1.7.5 (#2307902) * Wed Jul 17 2024 Fedora Release Engineering - 1.7.3-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2308487 - CVE-2023-49582 apr: Lax permissions in Apache Portable Runtime shared memory [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2308487 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-b40491b84b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for Mesa ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:3117-1 Rating: moderate References: #1156015 Cross-References: CVE-2019-5068 CVSS scores: CVE-2019-5068 (NVD) : 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVE-2019-5068 (SUSE): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server 12-SP2-BCL ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for Mesa fixes the following issues: Security issue fixed: - CVE-2019-5068: Fixed exploitable shared memory permissions vulnerability (bsc#1156015). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-3117=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2021-3117=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (s390x): libxatracker-devel-1.0.0-104.9.49 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): Mesa-11.2.1-104.9.49 Mesa-32bit-11.2.1-104.9.49 Mesa-debuginfo-11.2.1-104.9.49 Mesa-debuginfo-32bit-11.2.1-104.9.49 Mesa-debugsource-11.2.1-104.9.49 Mesa-libEGL1-11.2.1-104.9.49 Mesa-libEGL1-32bit-11.2.1-104.9.49 Mesa-libEGL1-debuginfo-11.2.1-104.9.49 Mesa-libEGL1-debuginfo-32bit-11.2.1-104.9.49 Mesa-libGL1-11.2.1-104.9.49 Mesa-libGL1-32bit-11.2.1-104.9.49 Mesa-libGL1-debuginfo-11.2.1-104.9.49 Mesa-libGL1-debuginfo-32bit-11.2.1-104.9.49 Mesa-libGLESv2-2-11.2.1-104.9.49 Mesa-libGLESv2-2-debuginfo-11.2.1-104.9.49 Mesa-libglapi0-11.2.1-104.9.49 Mesa-libglapi0-32bit-11.2.1-104.9.49 Mesa-libglapi0-debuginfo-11.2.1-104.9.49 Mesa-libglapi0-debuginfo-32bit-11.2.1-104.9.49 libgbm1-11.2.1-104.9.49 libgbm1-32bit-11.2.1-104.9.49 libgbm1-debuginfo-11.2.1-104.9.49 libgbm1-debuginfo-32bit-11.2.1-104.9.49 libxatracker2-1.0.0-104.9.49 libxatracker2-debuginfo-1.0.0-104.9.49 References: https://www.suse.com/security/cve/CVE-2019-5068.html https://bugzilla.suse.com/1156015 . SUSE has issued a security update for the Mesa package, which tackles vulnerabilities assessed with a moderate severity rating. This update includes detailed installation guidelines.. Mesa Security Fix, SUSE Update, Shared Memory Permissions. . LinuxSecurity.com Team
This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server. Previously the segments were readable and writable for any local user. Now they are accessible only to the user who executed the x11vnc server.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-069c0c3950 2021-03-19 19:51:22.363525 --------------------------------------------------------------------------------Name : x11vnc Product : Fedora 34 Version : 0.9.16 Release : 6.fc34 URL : https://github.com/LibVNC/x11vnc Summary : VNC server for the current X11 session Description : What WinVNC is to Windows x11vnc is to X Window System, i.e. a server which serves the current X Window System desktop via RFB (VNC) protocol to the user. Based on the ideas of x0rfbserver and on LibVNCServer it has evolved into a versatile and productive while still easy to use program. --------------------------------------------------------------------------------Update Information: This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server. Previously the segments were readable and writable for any local user. Now they are accessible only to the user who executed the x11vnc server. --------------------------------------------------------------------------------ChangeLog: * Mon Mar 1 2021 Petr Pisar - 0.9.16-6 - Fix CVE-2020-29074 (insecure permissions on a shared memory) (bug #1933603) --------------------------------------------------------------------------------References: [ 1 ] Bug #1933602 - CVE-2020-29074 x11vnc: insecure permissions on shm https://bugzilla.redhat.com/show_bug.cgi?id=1933602 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-069c0c3950' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server. Previously the segments were readable and writable for any local user. Now they are accessible only to the user who executed the x11vnc server.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-93911302d6 2021-03-10 00:41:43.224833 --------------------------------------------------------------------------------Name : x11vnc Product : Fedora 33 Version : 0.9.16 Release : 5.fc33 URL : https://github.com/LibVNC/x11vnc Summary : VNC server for the current X11 session Description : What WinVNC is to Windows x11vnc is to X Window System, i.e. a server which serves the current X Window System desktop via RFB (VNC) protocol to the user. Based on the ideas of x0rfbserver and on LibVNCServer it has evolved into a versatile and productive while still easy to use program. --------------------------------------------------------------------------------Update Information: This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server. Previously the segments were readable and writable for any local user. Now they are accessible only to the user who executed the x11vnc server. --------------------------------------------------------------------------------ChangeLog: * Mon Mar 1 2021 Petr Pisar - 0.9.16-5 - Fix CVE-2020-29074 (insecure permissions on a shared memory) (bug #1933603) --------------------------------------------------------------------------------References: [ 1 ] Bug #1933602 - CVE-2020-29074 x11vnc: insecure permissions on shm https://bugzilla.redhat.com/show_bug.cgi?id=1933602 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-93911302d6' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Mozilla: Missing bounds check on shared memory read in the parent process (CVE-2020-6796) * Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) SL6 x86_64 firefox-68.5.0-2.el6_10.x86_64.rpm firefox-debuginfo-68.5.0-2.el6_10.x86_64.rpm firefox-68.5.0-2.el6_10.i686.rpm firefox-debuginfo-68.5.0-2.el6_10.i686.rpm i386 firefox-68.5.0-2.el6_ [More...]. Synopsis: Important: firefox security update Advisory ID: SLSA-2020:0521-1 Issue Date: 2020-02-17 CVE Numbers: None -- Security Fix(es): * Mozilla: Missing bounds check on shared memory read in the parent process (CVE-2020-6796) * Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) -- SL6 x86_64 firefox-68.5.0-2.el6_10.x86_64.rpm firefox-debuginfo-68.5.0-2.el6_10.x86_64.rpm firefox-68.5.0-2.el6_10.i686.rpm firefox-debuginfo-68.5.0-2.el6_10.i686.rpm i386 firefox-68.5.0-2.el6_10.i686.rpm firefox-debuginfo-68.5.0-2.el6_10.i686.rpm - Scientific Linux Development Team . Urgent: Essential Firefox security patches for Scientific Linux addressing memory safety vulnerabilities and bounds checking problems.. Firefox Update, Mozilla Security, Scientific Linux Advisory, Memory Safety Fixes. . Severity: Important. LinuxSecurity.com Team
Mozilla: Missing bounds check on shared memory read in the parent process (CVE-2020-6796) * Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) * Mozilla: Incorrect parsing of template tag could result in JavaScript injection (CVE-2020-6798) SL7 x86_64 firefox-68.5.0-2.el7_7.x86_64.rpm firefox-debuginfo-68.5.0-2.el7_7.x86_64.rpm firefox-68.5.0- [More...]. Synopsis: Important: firefox security update Advisory ID: SLSA-2020:0520-1 Issue Date: 2020-02-17 CVE Numbers: None -- Security Fix(es): * Mozilla: Missing bounds check on shared memory read in the parent process (CVE-2020-6796) * Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) * Mozilla: Incorrect parsing of template tag could result in JavaScript injection (CVE-2020-6798) -- SL7 x86_64 firefox-68.5.0-2.el7_7.x86_64.rpm firefox-debuginfo-68.5.0-2.el7_7.x86_64.rpm firefox-68.5.0-2.el7_7.i686.rpm firefox-debuginfo-68.5.0-2.el7_7.i686.rpm - Scientific Linux Development Team . Important patch release for Firefox on Scientific Linux, targeting vulnerabilities related to memory integrity and script injection risks.. firefox security patch, scientific linux advisories, memory safety bugs. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for Mesa ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0146-1 Rating: moderate References: #1156015 Cross-References: CVE-2019-5068 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for Mesa fixes the following issues: Security issue fixed: - CVE-2019-5068: Fixed exploitable shared memory permissions vulnerability (bsc#1156015). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2020-146=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-146=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-146=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): Mesa-debugsource-18.3.2-14.3.2 Mesa-drivers-debugsource-18.3.2-14.3.2 Mesa-libGLESv1_CM1-18.3.2-14.3.2 Mesa-libGLESv1_CM1-debuginfo-18.3.2-14.3.2 Mesa-libGLESv2-2-32bit-18.3.2-14.3.2 Mesa-libGLESv2-2-debuginfo-32bit-18.3.2-14.3.2 Mesa-libd3d-18.3.2-14.3.2 Mesa-libd3d-debuginfo-18.3.2-14.3.2 Mesa-libva-18.3.2-14.3.2 Mesa-libva-debuginfo-18.3.2-14.3.2 libXvMC_nouveau-18.3.2-14.3.2 libXvMC_nouveau-debuginfo-18.3.2-14.3.2 libXvMC_r600-18.3.2-14.3.2 libXvMC_r600-debuginfo-18.3.2-14.3.2 libvdpau_nouveau-18.3.2-14.3.2 libvdpau_nouveau-debuginfo-18.3.2-14.3.2 libvdpau_r300-18.3.2-14.3.2 libvdpau_r300-debuginfo-18.3.2-14.3.2 libvdpau_r600-18.3.2-14.3.2 libvdpau_r600-debuginfo-18.3.2-14.3.2 libvdpau_radeonsi-18.3.2-14.3.2 libvdpau_radeonsi-debuginfo-18.3.2-14.3.2 libvulkan_intel-18.3.2-14.3.2 libvulkan_intel-debuginfo-18.3.2-14.3.2 libvulkan_radeon-18.3.2-14.3.2 libvulkan_radeon-debuginfo-18.3.2-14.3.2 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): Mesa-KHR-devel-18.3.2-14.3.2 Mesa-debugsource-18.3.2-14.3.2 Mesa-devel-18.3.2-14.3.2 Mesa-dri-devel-18.3.2-14.3.2 Mesa-libEGL-devel-18.3.2-14.3.2 Mesa-libGL-devel-18.3.2-14.3.2 Mesa-libGLESv1_CM-devel-18.3.2-14.3.2 Mesa-libGLESv1_CM1-18.3.2-14.3.2 Mesa-libGLESv1_CM1-debuginfo-18.3.2-14.3.2 Mesa-libGLESv2-devel-18.3.2-14.3.2 Mesa-libGLESv3-devel-18.3.2-14.3.2 Mesa-libglapi-devel-18.3.2-14.3.2 libOSMesa-devel-18.3.2-14.3.2 libOSMesa8-18.3.2-14.3.2 libOSMesa8-debuginfo-18.3.2-14.3.2 libgbm-devel-18.3.2-14.3.2 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le x86_64): libxatracker-devel-1.0.0-14.3.2 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 x86_64): Mesa-drivers-debugsource-18.3.2-14.3.2 Mesa-libd3d-devel-18.3.2-14.3.2 - SUSE Linux Enterprise Software Development Kit 12-SP5 (s390x x86_64): libOSMesa8-32bit-18.3.2-14.3.2 libOSMesa8-debuginfo-32bit-18.3.2-14.3.2 - SUSE Linux Enterprise Software Development Kit 12-SP5 (x86_64): Mesa-libVulkan-devel-18.3.2-14.3.2 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): Mesa-18.3.2-14.3.2 Mesa-debugsource-18.3.2-14.3.2 Mesa-dri-18.3.2-14.3.2 Mesa-dri-debuginfo-18.3.2-14.3.2 Mesa-drivers-debugsource-18.3.2-14.3.2 Mesa-libEGL1-18.3.2-14.3.2 Mesa-libEGL1-debuginfo-18.3.2-14.3.2 Mesa-libGL1-18.3.2-14.3.2 Mesa-libGL1-debuginfo-18.3.2-14.3.2 Mesa-libGLESv2-2-18.3.2-14.3.2 Mesa-libGLESv2-2-debuginfo-18.3.2-14.3.2 Mesa-libglapi0-18.3.2-14.3.2 Mesa-libglapi0-debuginfo-18.3.2-14.3.2 libgbm1-18.3.2-14.3.2 libgbm1-debuginfo-18.3.2-14.3.2 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le x86_64): libxatracker2-1.0.0-14.3.2 libxatracker2-debuginfo-1.0.0-14.3.2 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): Mesa-32bit-18.3.2-14.3.2 Mesa-dri-32bit-18.3.2-14.3.2 Mesa-dri-debuginfo-32bit-18.3.2-14.3.2 Mesa-libEGL1-32bit-18.3.2-14.3.2 Mesa-libEGL1-debuginfo-32bit-18.3.2-14.3.2 Mesa-libGL1-32bit-18.3.2-14.3.2 Mesa-libGL1-debuginfo-32bit-18.3.2-14.3.2 Mesa-libglapi0-32bit-18.3.2-14.3.2 Mesa-libglapi0-debuginfo-32bit-18.3.2-14.3.2 libgbm1-32bit-18.3.2-14.3.2 libgbm1-debuginfo-32bit-18.3.2-14.3.2 References: https://www.suse.com/security/cve/CVE-2019-5068.html https://bugzilla.suse.com/1156015 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.