Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
iwd 2.22: Fix issue with handling the Affinities property. Fix issue with handling ConnectedAccessPoint signal when roaming.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-5d6c951b0b 2024-09-23 00:15:17.969906 -------------------------------------------------------------------------------- Name : iwd Product : Fedora 41 Version : 2.22 Release : 1.fc41 URL : https://archive.kernel.org/oldwiki/iwd.wiki.kernel.org/ Summary : Wireless daemon for Linux Description : The daemon and utilities for controlling and configuring the Wi-Fi network hardware. -------------------------------------------------------------------------------- Update Information: iwd 2.22: Fix issue with handling the Affinities property. Fix issue with handling ConnectedAccessPoint signal when roaming. -------------------------------------------------------------------------------- ChangeLog: * Sat Sep 14 2024 Peter Robinson - 2.22-1 - Update to 2.22 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2311767 - iwd-2.22 is available https://bugzilla.redhat.com/show_bug.cgi?id=2311767 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-5d6c951b0b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The update for the shadow suite issued as DSA-3793-1 introduced a regression in su signal handling. If su receives a signal like SIGTERM, it is not propagated to the child. Updated packages are now available to correct this issue. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3793-2
USN-3276-1 introduced a regression in su.. =========================================================================Ubuntu Security Notice USN-3276-2 May 17, 2017 shadow regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: USN-3276-1 introduced a regression in su. Software Description: - shadow: system login tools Details: USN-3276-1 intended to fix a vulnerability in su. The solution introduced a regression in su signal handling. This update modifies the security fix. We apologize for the inconvenience. Original advisory details: Sebastian Krahmer discovered integer overflows in shadow utilities. A local attacker could possibly cause them to crash or potentially gain privileges via crafted input. (CVE-2016-6252) Tobias Stöckmann discovered a race condition in su. A local attacker could cause su to send SIGKILL to other processes with root privileges. (CVE-2017-2616) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: login 1:4.2-3.2ubuntu1.17.04.2 passwd 1:4.2-3.2ubuntu1.17.04.2 uidmap 1:4.2-3.2ubuntu1.17.04.2 Ubuntu 16.10: login 1:4.2-3.2ubuntu1.16.10.2 passwd 1:4.2-3.2ubuntu1.16.10.2 uidmap 1:4.2-3.2ubuntu1.16.10.2 Ubuntu 16.04 LTS: login 1:4.2-3.1ubuntu5.3 passwd 1:4.2-3.1ubuntu5.3 uidmap 1:4.2-3.1ubuntu5.3 Ubuntu 14.04 LTS: login 1:4.1.5.1-1ubuntu9.5 passwd 1:4.1.5.1-1ubuntu9.5 uidmap 1:4.1.5.1-1ubuntu9.5 In general, a standard system update will make allthe necessary changes. References: https://ubuntu.com/security/notices/USN-3276-2 https://ubuntu.com/security/notices/USN-3276-1 https://bugs.launchpad.net/ubuntu/+source/shadow/+bug/1690820 Package Information: https://launchpad.net/ubuntu/+source/shadow/1:4.2-3.2ubuntu1.17.04.2 https://launchpad.net/ubuntu/+source/shadow/1:4.2-3.2ubuntu1.16.10.2 https://launchpad.net/ubuntu/+source/shadow/1:4.2-3.1ubuntu5.3 https://launchpad.net/ubuntu/+source/shadow/1:4.1.5.1-1ubuntu9.5 . Ubuntu Advisory: USN-3276-3 resolves a hidden regression in su signal processing impacting various versions.. shadow security, Ubuntu advisory, su issue, local privilege attack, Ubuntu update. . Severity: Medium. LinuxSecurity.com Team
Updated stunnel packages are now available for Red Hat Linux 7.1, 7.2, 7.3,and 8.0 systems. These updates address problems stemming from improper useof non-reentrant functions in signal handlers.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated stunnel packages available Advisory ID: RHSA-2003:296-01 Issue date: 2003-11-24 Updated on: 2003-11-24 Product: Red Hat Linux Keywords: stunnel signal Cross references: RHSA-2003:297 Obsoletes: RHSA-2003:221 CVE Names: CAN-2002-1563 CAN-2003-0740 - --------------------------------------------------------------------- 1. Topic: Updated stunnel packages are now available for Red Hat Linux 7.1, 7.2, 7.3, and 8.0 systems. These updates address problems stemming from improper use of non-reentrant functions in signal handlers. 2. Relevant releases/architectures: Red Hat Linux 7.1 - i386 Red Hat Linux 7.2 - i386, ia64 Red Hat Linux 7.3 - i386 Red Hat Linux 8.0 - i386 3. Problem description: Stunnel is a wrapper for network connections. It can be used to tunnel an unencrypted network connection over an encrypted connection (encrypted using SSL or TLS) or to provide an encrypted means of connecting to services that do not natively support encryption. A previous advisory provided updated packages to address re-entrancy problems in stunnel's signal-handling routines. These updates did not address other bugs that were found by Steve Grubb, and introduced an additional bug, which was fixed in stunnel 3.26. All users should upgrade to these errata packages, which address these issues by updating stunnel to version 3.26. NOTE: After upgrading, any instances of stunnel configured to run in daemon mode should be restarted, and any active network connections that are currently being serviced by stunnel should be terminated and reestablished. 4. Solution: Before applying thisupdate, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. If up2date fails to connect to Red Hat Network due to SSL Certificate Errors, you need to install a version of the up2date client with an updated certificate. The latest version of up2date is available from the Red Hat FTP site and may also be downloaded directly from the RHN website: 5. RPMs required: Red Hat Linux 7.1: SRPMS: i386: Red Hat Linux 7.2: SRPMS: i386: ia64: Red Hat Linux 7.3: SRPMS: i386: Red Hat Linux 8.0: SRPMS: i386: 6. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- cfd2b7c9519812d58a945d4b5e189fdd 7.1/en/os/SRPMS/stunnel-3.26-1.7.1.src.rpm f05723a19a2990ce17ded0ce817890b5 7.1/en/os/i386/stunnel-3.26-1.7.1.i386.rpm f1c75122248f440e96adff582de64520 7.2/en/os/SRPMS/stunnel-3.26-1.7.3.src.rpm e307840b930fc50e4bb2b61a0578af5a 7.2/en/os/i386/stunnel-3.26-1.7.3.i386.rpm cd223922c7a690d7dfcfdd2e49c49e24 7.2/en/os/ia64/stunnel-3.26-1.7.3.ia64.rpm f1c75122248f440e96adff582de64520 7.3/en/os/SRPMS/stunnel-3.26-1.7.3.src.rpm e307840b930fc50e4bb2b61a0578af5a 7.3/en/os/i386/stunnel-3.26-1.7.3.i386.rpm 071ab6a4091737a4292e631bd74909758.0/en/os/SRPMS/stunnel-3.26-1.8.0.src.rpm d3718eebbd8b921de713c4914da22dec 8.0/en/os/i386/stunnel-3.26-1.8.0.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from https://access.redhat.com/security/team/key You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: http://marc.theaimsgroup.com/?l=stunnel-users&m=105980139926784 http://marc.theaimsgroup.com/?l=stunnel-users&m=106221975232250 http://marc.theaimsgroup.com/?l=bugtraq&m=106260760211958 CVE -CVE-2002-1563 CVE -CVE-2003-0740 8. Contact: The Red Hat security contact is . More contact details at https://www.redhat.com/en/technologies/all-products Copyright 2003 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQE/wcV5XlSAg2UNWIIRAnw4AJ9u7klajUMumofqL1o9vU6/uhjTGACeIRIC ehS8TWOZF6fd+owIpBhNSwE=69GI -----END PGP SIGNATURE----- . The latest stunnel patches for Fedora tackle issues concerning signal handling. Users are encouraged to update to improve system security.. Signal Handling Update, Red Hat, Stunnel Packages, Security Advisory. . Severity: Critical. LinuxSecurity.com Team
Using older versions of procmail it was possible to make procmail crash by sending it signals. On systems where procmail is installed setuid this could be exploited to obtain unauthorized privileges.. -------------------------------------------------------------------------- Debian Security Advisory DSA 083-1
Procmail, an autonomous mail processor, as shipped in Red Hat Linux 5.2,6.2, 7, and 7.1, handles signals unsafely.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated procmail packages available for Red Hat Linux 5.2, 6.2, 7 and 7.1 Advisory ID: RHSA-2001:093-03 Issue date: 2001-07-03 Updated on: 2001-07-13 Product: Red Hat Linux Keywords: procmail Cross references: Obsoletes: --------------------------------------------------------------------- 1. Topic: Procmail, an autonomous mail processor, as shipped in Red Hat Linux 5.2, 6.2, 7, and 7.1, handles signals unsafely. 2. Relevant releases/architectures: Red Hat Linux 5.2 - alpha, i386, sparc Red Hat Linux 6.2 - alpha, i386, sparc Red Hat Linux 7.0 - alpha, i386 Red Hat Linux 7.1 - alpha, i386, ia64 3. Problem description: Procmail was not handling signals properly. This has been fixed in procmail 3.21. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Linux 5.2: SRPMS: alpha: i386: sparc: Red Hat Linux 6.2: SRPMS: alpha: i386: sparc: Red Hat Linux 7.0: SRPMS: alpha: i386: Red Hat Linux 7.1: SRPMS: alpha: i386: ia64: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- c07f1a3eb5360143ea51afa401ae6639 5.2/en/os/SRPMS/procmail-3.21-0.52.src.rpm 1bc3b9acbf67118fa21fa7cb7ca2c14b 5.2/en/os/alpha/procmail-3.21-0.52.alpha.rpm b4a99c68a9141f2448709afd0c84ff60 5.2/en/os/i386/procmail-3.21-0.52.i386.rpm 86fe4d853a65dea9d892dfc7042fd12e 5.2/en/os/sparc/procmail-3.21-0.52.sparc.rpm 82ece26660bcfdd51aeea2b906737e6b 6.2/en/os/SRPMS/procmail-3.21-0.62.src.rpm dde2aa93f0b6dc5379ea77112478f16f 6.2/en/os/alpha/procmail-3.21-0.62.alpha.rpm 07c080d1d6f09138203a68cac57b8ca8 6.2/en/os/i386/procmail-3.21-0.62.i386.rpm e1a7a7103705463fd89fb09c002c84a4 6.2/en/os/sparc/procmail-3.21-0.62.sparc.rpm aee4c233f3f81a090379f903113a8212 7.0/en/os/SRPMS/procmail-3.21-0.71.src.rpm 5d378a8ae5599cac04802e3de254804e 7.0/en/os/alpha/procmail-3.21-0.71.alpha.rpm 51ad4ad3241887e2eb631e1799c94972 7.0/en/os/i386/procmail-3.21-0.71.i386.rpm aee4c233f3f81a090379f903113a8212 7.1/en/os/SRPMS/procmail-3.21-0.71.src.rpm 5d378a8ae5599cac04802e3de254804e 7.1/en/os/alpha/procmail-3.21-0.71.alpha.rpm 51ad4ad3241887e2eb631e1799c94972 7.1/en/os/i386/procmail-3.21-0.71.i386.rpm f1e8da53ad57d95a2ad108f30bab476a 7.1/en/os/ia64/procmail-3.21-0.71.ia64.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000, 2001 Red Hat, Inc. `. Critical vulnerability in Procmail resolved through Red Hat update, fixing an issue with signal handling affecting versions 5.2, 6.2, 7, and 7.1 of Red Hat.. RedHat Procmail SignalHandling SecurityUpdate. . Severity: Critical.LinuxSecurity.com Team
Procmail, an autonomous mail processor, as shipped in Red Hat Linux 5.2, 6.2, 7, and 7.1, handles signals unsafely.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated procmail packages available for Red Hat Linux 5.2, 6.2, 7 and 7.1 Advisory ID: RHSA-2001:093-03 Issue date: 2001-07-03 Updated on: 2001-07-13 Product: Red Hat Linux Keywords: procmail Cross references: Obsoletes: --------------------------------------------------------------------- 1. Topic: Procmail, an autonomous mail processor, as shipped in Red Hat Linux 5.2, 6.2, 7, and 7.1, handles signals unsafely. 2. Relevant releases/architectures: Red Hat Linux 5.2 - alpha, i386, sparc Red Hat Linux 6.2 - alpha, i386, sparc Red Hat Linux 7.0 - alpha, i386 Red Hat Linux 7.1 - alpha, i386, ia64 3. Problem description: Procmail was not handling signals properly. This has been fixed in procmail 3.21. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Linux 5.2: SRPMS: alpha: i386: sparc: Red Hat Linux 6.2: SRPMS: alpha: i386: sparc: Red Hat Linux 7.0: SRPMS: alpha: i386: Red Hat Linux 7.1: SRPMS: alpha: i386: ia64: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- c07f1a3eb5360143ea51afa401ae6639 5.2/en/os/SRPMS/procmail-3.21-0.52.src.rpm 1bc3b9acbf67118fa21fa7cb7ca2c14b 5.2/en/os/alpha/procmail-3.21-0.52.alpha.rpm b4a99c68a9141f2448709afd0c84ff60 5.2/en/os/i386/procmail-3.21-0.52.i386.rpm 86fe4d853a65dea9d892dfc7042fd12e 5.2/en/os/sparc/procmail-3.21-0.52.sparc.rpm 82ece26660bcfdd51aeea2b906737e6b 6.2/en/os/SRPMS/procmail-3.21-0.62.src.rpm dde2aa93f0b6dc5379ea77112478f16f 6.2/en/os/alpha/procmail-3.21-0.62.alpha.rpm 07c080d1d6f09138203a68cac57b8ca8 6.2/en/os/i386/procmail-3.21-0.62.i386.rpm e1a7a7103705463fd89fb09c002c84a4 6.2/en/os/sparc/procmail-3.21-0.62.sparc.rpm aee4c233f3f81a090379f903113a8212 7.0/en/os/SRPMS/procmail-3.21-0.71.src.rpm 5d378a8ae5599cac04802e3de254804e 7.0/en/os/alpha/procmail-3.21-0.71.alpha.rpm 51ad4ad3241887e2eb631e1799c94972 7.0/en/os/i386/procmail-3.21-0.71.i386.rpm aee4c233f3f81a090379f903113a8212 7.1/en/os/SRPMS/procmail-3.21-0.71.src.rpm 5d378a8ae5599cac04802e3de254804e 7.1/en/os/alpha/procmail-3.21-0.71.alpha.rpm 51ad4ad3241887e2eb631e1799c94972 7.1/en/os/i386/procmail-3.21-0.71.i386.rpm f1e8da53ad57d95a2ad108f30bab476a 7.1/en/os/ia64/procmail-3.21-0.71.ia64.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000, 2001 Red Hat, Inc. `. Critical security alert for Red Hat: Upgrade procmail to resolve issues with incorrect signal management impacting multiple versions.. Red Hat Linux Update, Procmail Security Fix, Signal Handling Flaw. . Severity: Critical.LinuxSecurity.com Team
When joe dies to a signal instead of a normal exit it is vulnerable to a symlink attack.. - ------------------------------------------------------------------------ Debian Security Advisory
Get the latest Linux and open source security news straight to your inbox.