Forbid shell metasymbols in username/hostname. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-37627e432e 2024-01-23 01:21:28.284261 -------------------------------------------------------------------------------- Name : openssh Product : Fedora 38 Version : 9.0p1 Release : 18.fc38 URL : https://www.openssh.org/portable.html Summary : An open source implementation of SSH protocol version 2 Description : SSH (Secure SHell) is a program for logging into and executing commands on a remote machine. SSH is intended to replace rlogin and rsh, and to provide secure encrypted communications between two untrusted hosts over an insecure network. X11 connections and arbitrary TCP/IP ports can also be forwarded over the secure channel. OpenSSH is OpenBSD's version of the last free version of SSH, bringing it up to date in terms of security and features. This package includes the core files necessary for both the OpenSSH client and server. To make this package useful, you should also install openssh-clients, openssh-server, or both. -------------------------------------------------------------------------------- Update Information: Forbid shell metasymbols in username/hostname -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 10 2024 Dmitry Belyavskiy - 9.0p1-18 - Forbid shell metasymbols in username/hostname Resolves: CVE-2023-51385 - Fix Terrapin attack Resolves: CVE-2023-48795 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-37627e432e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update for gegl04 is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: gegl04 security update Advisory ID: RHSA-2022:0178-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:0178 Issue date: 2022-01-19 CVE Names: CVE-2021-45463 ==================================================================== 1. Summary: An update for gegl04 is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder EUS (v. 8.4) - ppc64le, x86_64 Red Hat Enterprise Linux AppStream EUS (v.8.4) - ppc64le, x86_64 3. Description: GEGL (Generic Graphics Library) is a graph-based image processing framework. Security Fix(es): * gegl: shell expansion via a crafted pathname (CVE-2021-45463) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2035383 - CVE-2021-45463 gegl: shell expansion via a crafted pathname 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.8.4): Source: gegl04-0.4.4-6.el8_4.1.src.rpm ppc64le: gegl04-0.4.4-6.el8_4.1.ppc64le.rpm gegl04-debuginfo-0.4.4-6.el8_4.1.ppc64le.rpm gegl04-debugsource-0.4.4-6.el8_4.1.ppc64le.rpm gegl04-tools-debuginfo-0.4.4-6.el8_4.1.ppc64le.rpm x86_64: gegl04-0.4.4-6.el8_4.1.i686.rpm gegl04-0.4.4-6.el8_4.1.x86_64.rpm gegl04-debuginfo-0.4.4-6.el8_4.1.i686.rpm gegl04-debuginfo-0.4.4-6.el8_4.1.x86_64.rpm gegl04-debugsource-0.4.4-6.el8_4.1.i686.rpm gegl04-debugsource-0.4.4-6.el8_4.1.x86_64.rpm gegl04-tools-debuginfo-0.4.4-6.el8_4.1.i686.rpm gegl04-tools-debuginfo-0.4.4-6.el8_4.1.x86_64.rpm Red Hat CodeReady Linux Builder EUS (v. 8.4): ppc64le: gegl04-debuginfo-0.4.4-6.el8_4.1.ppc64le.rpm gegl04-debugsource-0.4.4-6.el8_4.1.ppc64le.rpm gegl04-devel-0.4.4-6.el8_4.1.ppc64le.rpm gegl04-tools-debuginfo-0.4.4-6.el8_4.1.ppc64le.rpm x86_64: gegl04-debuginfo-0.4.4-6.el8_4.1.i686.rpm gegl04-debuginfo-0.4.4-6.el8_4.1.x86_64.rpm gegl04-debugsource-0.4.4-6.el8_4.1.i686.rpm gegl04-debugsource-0.4.4-6.el8_4.1.x86_64.rpm gegl04-devel-0.4.4-6.el8_4.1.i686.rpm gegl04-devel-0.4.4-6.el8_4.1.x86_64.rpm gegl04-tools-debuginfo-0.4.4-6.el8_4.1.i686.rpm gegl04-tools-debuginfo-0.4.4-6.el8_4.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-45463 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYegFbNzjgjWX9erEAQi0LQ/+KapC1EXi+mef4abubYSEB7+q+CIpyUf4 +GOBMEqfb9AbsFCWlsKEeMDqImsEf0xyINfvuiIQbiJFco+QvA6e9slOgIOGi4qh 8J7xngoiS+2T80D0wv7jOq/QSbWluM5/mPG384WEzMFrtZhjIkzITjGunnEhv4W+ zpO4t0UpxZYXoqMgMrf3PF81ab8hNWNytOdYBwya+corPPzO5T/7pZ/TSeL6BYVE 6J5uxCiVeNJhz5ntRJugDPpll2WbY2BHgt9WNpLWBqXaZOUFIaqd+wAlWLNUGYB0 8OwbcUXMgYMnv0Y/AzngEZW3/m+WGR8BApEjV7Yh8AocNSBea8YGfwEYo9jDZnFH Or2ZIsH00EDsdDLHyf7CwiKrQiHcZjA4M2Yo8BzyC0f2GpvN7mgNnobSOUfzszgj GLgpa01OHvJdBgX6z6dXMgYxwJu1yhXHGYEhPxyhP/7sAzAzo1a+YwvPg1ysP0UE oUO+cMN7/risCZgzfy4o4gqMMdfi4OLLEmTaLSKULJ0Vcodu5dUrL/eFdifM1xoe ZeAbBEzfBQso8yzSNdCvNTQAJ9rOVPSwpD4635Q6dsZrbRB1IKfRxccg04qxnSYN 67wU/khj5clSfji0bS27EqTvZUzgvUV/oY42JOPnKPC48nDPu5YW4yvNe5AFIuNv b7j6NyXagVk=aGmB -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for bash ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1178-1 Rating: important References: #1130324 Cross-References: CVE-2019-9924 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for bash fixes the following issues: Security issue fixed: - CVE-2019-9924: Fixed a vulnerability in which shell did not prevent user BASH_CMDS allowing the user to execute any command with the permissions of the shell (bsc#1130324). This update was imported from the SUSE:SLE-12-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2019-1178=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): bash-4.3-83.15.1 bash-debuginfo-4.3-83.15.1 bash-debugsource-4.3-83.15.1 bash-devel-4.3-83.15.1 bash-loadables-4.3-83.15.1 bash-loadables-debuginfo-4.3-83.15.1 libreadline6-6.3-83.15.1 libreadline6-debuginfo-6.3-83.15.1 readline-devel-6.3-83.15.1 - openSUSE Leap 42.3 (x86_64): bash-debuginfo-32bit-4.3-83.15.1 libreadline6-32bit-6.3-83.15.1 libreadline6-debuginfo-32bit-6.3-83.15.1 readline-devel-32bit-6.3-83.15.1 - openSUSE Leap 42.3 (noarch): bash-doc-4.3-83.15.1 bash-lang-4.3-83.15.1 readline-doc-6.3-83.15.1 References: https://www.suse.com/security/cve/CVE-2019-9924.html https://bugzilla.suse.com/1130324 -- . Critical Security Patch Released for openSUSE addresses severevulnerability in Bash related to CVE-2019-9924, which allows unauthorized command execution.. openSUSE Security,Bash Update,Shell Command Execution,Critical Patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for ImageMagick ______________________________________________________________________________ Announcement ID: SUSE-SU-2016:1610-1 Rating: important References: #982178 Cross-References: CVE-2016-5118 Affected Products: SUSE OpenStack Cloud 5 SUSE Manager Proxy 2.1 SUSE Manager 2.1 SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Server 11-SP2-LTSS SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for ImageMagick fixes the following issues: - CVE-2016-5118: popen() shell vulnerability via filenames (bsc#982178) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 5: zypper in -t patch sleclo50sp3-ImageMagick-12618=1 - SUSE Manager Proxy 2.1: zypper in -t patch slemap21-ImageMagick-12618=1 - SUSE Manager 2.1: zypper in -t patch sleman21-ImageMagick-12618=1 - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-ImageMagick-12618=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-ImageMagick-12618=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-ImageMagick-12618=1 - SUSE Linux Enterprise Server 11-SP2-LTSS: zypper in -t patch slessp2-ImageMagick-12618=1 - SUSE Linux Enterprise Debuginfo11-SP4: zypper in -t patch dbgsp4-ImageMagick-12618=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE OpenStack Cloud 5 (x86_64): libMagickCore1-32bit-6.4.3.6-7.40.1 libMagickCore1-6.4.3.6-7.40.1 - SUSE Manager Proxy 2.1 (x86_64): libMagickCore1-32bit-6.4.3.6-7.40.1 libMagickCore1-6.4.3.6-7.40.1 - SUSE Manager 2.1 (s390x x86_64): libMagickCore1-32bit-6.4.3.6-7.40.1 libMagickCore1-6.4.3.6-7.40.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): ImageMagick-6.4.3.6-7.40.1 ImageMagick-devel-6.4.3.6-7.40.1 libMagick++-devel-6.4.3.6-7.40.1 libMagick++1-6.4.3.6-7.40.1 libMagickWand1-6.4.3.6-7.40.1 perl-PerlMagick-6.4.3.6-7.40.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (ppc64 s390x x86_64): libMagickWand1-32bit-6.4.3.6-7.40.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): libMagickCore1-6.4.3.6-7.40.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): libMagickCore1-32bit-6.4.3.6-7.40.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): libMagickCore1-6.4.3.6-7.40.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (s390x x86_64): libMagickCore1-32bit-6.4.3.6-7.40.1 - SUSE Linux Enterprise Server 11-SP2-LTSS (i586 s390x x86_64): libMagickCore1-6.4.3.6-7.40.1 - SUSE Linux Enterprise Server 11-SP2-LTSS (s390x x86_64): libMagickCore1-32bit-6.4.3.6-7.40.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): ImageMagick-debuginfo-6.4.3.6-7.40.1 ImageMagick-debugsource-6.4.3.6-7.40.1 References: https://www.suse.com/security/cve/CVE-2016-5118.html https://bugzilla.suse.com/982178 . SUSE has released a security update for ImageMagick addressing a severe shell vulnerability. Ensure you apply the necessary patches to safeguard your system.. SUSE ImageMagick Update, Shell VulnerabilityFix, Important SUSE Patch. . Severity: Important. LinuxSecurity.com Team
New imagemagick packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] imagemagick (SSA:2016-152-01) New imagemagick packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +--------------------------+ patches/packages/imagemagick-6.8.6_10-i486-3_slack14.1.txz: Rebuilt. Removed popen() support to prevent another shell vulnerability. This issue was discovered by Bob Friesenhahn, of the GraphicsMagick project. For more information, see: https://www.cve.org/CVERecord?id=CVE-2016-5118 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/imagemagick-6.7.7_10-i486-3_slack14.0.txz Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/imagemagick-6.7.7_10-x86_64-3_slack14.0.txz Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/imagemagick-6.8.6_10-i486-3_slack14.1.txz Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/imagemagick-6.8.6_10-x86_64-3_slack14.1.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 package: 8038f31b0d67731c68d018cd83156763 imagemagick-6.7.7_10-i486-3_slack14.0.txz Slackware x86_64 14.0 package: 0d9eb6efc627987cf1b99dab3e25d78b imagemagick-6.7.7_10-x86_64-3_slack14.0.txz Slackware 14.1package: e3f901a4083406da10c93ee5979c98e2 imagemagick-6.8.6_10-i486-3_slack14.1.txz Slackware x86_64 14.1 package: cb65d697fbcb85bcd1d4cb816273731b imagemagick-6.8.6_10-x86_64-3_slack14.1.txz Slackware -current package: 383e9ddac6637a4f847438716beaa256 xap/imagemagick-6.9.4_5-i586-1.txz Slackware x86_64 -current package: 0c723689026530a689a1520ee959eaa1 xap/imagemagick-6.9.4_5-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg imagemagick-6.8.6_10-i486-3_slack14.1.txz +-----+ . Updated ImageMagick bundles for Slackware have been released to rectify a significant shell vulnerability, safeguarding system integrity and enhancing security.. imagemagick update, shell issue, slackware packages. . Severity: Critical. LinuxSecurity.com Team
This update fixes CAN-2005-0638, a problem in the parsing of shell metacharacters in filenames. It also fixes bugs in handling of malformed TIFF and PBM/PNM/PPM issues.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-236 2005-03-18 ---------------------------------------------------------------------Product : Fedora Core 2 Name : xloadimage Version : 4.1 Release : 34.FC2 Summary : An X Window System based image viewer. Description : The xloadimage utility displays images in an X Window System window, loads images into the root window, or writes images into a file. Xloadimage supports many image types (including GIF, TIFF, JPEG, XPM, and XBM). ---------------------------------------------------------------------Update Information: This update fixes CAN-2005-0638, a problem in the parsing of shell metacharacters in filenames. It also fixes bugs in handling of malformed TIFF and PBM/PNM/PPM issues. ---------------------------------------------------------------------* Fri Mar 18 2005 Bill Nottingham - use system libjpeg - fix quoting in filenames (CAN-2005-0638) * Fri Jan 21 2005 Bill Nottingham 4.1-33 - fix bad use of format strings (#70867, #78481 ) * Wed Oct 13 2004 Bill Nottingham 4.1-32 - add patch for slideshow (#114689) * Tue Jun 15 2004 Elliot Lee - rebuilt ---------------------------------------------------------------------This update can be downloaded from: 2c177151565a8c1c109bc36769831c1a SRPMS/xloadimage-4.1-34.FC2.src.rpm 9d01327b4444c76a06cb1cc8560b5891 x86_64/xloadimage-4.1-34.FC2.x86_64.rpm c3c25132097e69c71172e1d509dfa836 x86_64/debug/xloadimage-debuginfo-4.1-34.FC2.x86_64.rpm ba9ab8fd596fefdf4284015b90c82d36 i386/xloadimage-4.1-34.FC2.i386.rpm f35200f3233a2e9ea5bd560dc589ee29 i386/debug/xloadimage-debuginfo-4.1-34.FC2.i386.rpm This update can also be installed with the Update Agent; you can launchthe Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.