- Update starship to version 0.56.0. - Update shadow-rs crate to version 0.6.3. - Update urlencoding crate to version 1.3.3. - Update versions crate to version 3.0.2. - Rebuild starship with crossbeam-deque 0.8.1 / 0.7.4 for CVE-2021-32810.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-64e9e98eb4 2021-08-15 01:09:28.221864 --------------------------------------------------------------------------------Name : rust-versions Product : Fedora 34 Version : 3.0.2 Release : 1.fc34 URL : Summary : Library for parsing and comparing software version numbers Description : Library for parsing and comparing software version numbers. --------------------------------------------------------------------------------Update Information: - Update starship to version 0.56.0. - Update shadow-rs crate to version 0.6.3. - Update urlencoding crate to version 1.3.3. - Update versions crate to version 3.0.2. - Rebuild starship with crossbeam-deque 0.8.1 / 0.7.4 for CVE-2021-32810. --------------------------------------------------------------------------------ChangeLog: * Sun Aug 1 2021 Fabio Valentini 3.0.2-1 - Update to version 3.0.2; Fixes RHBZ#1988865 * Fri Jul 23 2021 Fedora Release Engineering - 3.0.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1974127 - rust-starship-0.56.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1974127 [ 2 ] Bug #1988865 - rust-versions-3.0.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1988865 [ 3 ] Bug #1988867 - rust-shadow-rs-0.6.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1988867 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2021-64e9e98eb4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fix of #1876738 and #1876689. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-5460fcf6bd 2020-09-25 16:31:57.897781 --------------------------------------------------------------------------------Name : zeromq Product : Fedora 33 Version : 4.3.3 Release : 1.fc33 URL : https://zeromq.org Summary : Software library for fast, message-based applications Description : The 0MQ lightweight messaging kernel is a library which extends the standard socket interfaces with features traditionally provided by specialized messaging middle-ware products. 0MQ sockets provide an abstraction of asynchronous message queues, multiple messaging patterns, message filtering (subscriptions), seamless access to multiple transport protocols and more. This package contains the ZeroMQ shared library. --------------------------------------------------------------------------------Update Information: Fix of #1876738 and #1876689 --------------------------------------------------------------------------------ChangeLog: * Tue Sep 15 2020 Denis Arnaud - 4.3.3-1 - Upstream upgrade - Fixes #1876738 and #1876689 --------------------------------------------------------------------------------References: [ 1 ] Bug #1876689 - CVE-2020-15166 zeromq: unauthenticated clients causing denial-of-service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1876689 [ 2 ] Bug #1876738 - zeromq-4.3.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1876738 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-5460fcf6bd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used bythe Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2019-13132. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-d20ce4d5a1 2019-09-28 00:00:59.189385 --------------------------------------------------------------------------------Name : zeromq Product : Fedora 31 Version : 4.3.2 Release : 1.fc31 URL : https://zeromq.org Summary : Software library for fast, message-based applications Description : The 0MQ lightweight messaging kernel is a library which extends the standard socket interfaces with features traditionally provided by specialized messaging middle-ware products. 0MQ sockets provide an abstraction of asynchronous message queues, multiple messaging patterns, message filtering (subscriptions), seamless access to multiple transport protocols and more. This package contains the ZeroMQ shared library. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-13132 --------------------------------------------------------------------------------References: [ 1 ] Bug #1727055 - CVE-2019-13132 zeromq: stack-overflow on any server protected by encryption/authentication https://bugzilla.redhat.com/show_bug.cgi?id=1727055 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-d20ce4d5a1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Latest stable releases of libmspack and cabextract, includes security fixes for CVE-2018-14680, CVE-2018-14681, CVE-2018-14682, CVE-2018-18584, CVE-2018-18585. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-cb337fb199 2018-11-13 02:25:35.636330 --------------------------------------------------------------------------------Name : libmspack Product : Fedora 28 Version : 0.9.1 Release : 0.1.alpha.fc28 URL : https://www.cabextract.org.uk/libmspack/ Summary : Library for CAB and related files compression and decompression Description : The purpose of libmspack is to provide both compression and decompression of some loosely related file formats used by Microsoft. --------------------------------------------------------------------------------Update Information: Latest stable releases of libmspack and cabextract, includes security fixes for CVE-2018-14680, CVE-2018-14681, CVE-2018-14682, CVE-2018-18584, CVE-2018-18585 --------------------------------------------------------------------------------ChangeLog: * Tue Nov 6 2018 Rex Dieter - 0.9.1-0.1.alpha - 0.9.1alpha - libmspack-0.8-0.1.alpha corrupts extracted cab files (#1647033) - examples no longer installed (by default) * Tue Oct 30 2018 Rex Dieter - 0.8-0.1.alpha - 0.8alpha - use %make_build %make_install %ldconfig_scriptlets %license - devel: use %{?_isa} to tighten dep on main pkg - drop deprecated Group: tag - %files: tighten to include library soname * Wed Aug 1 2018 Richard W.M. Jones - 0.7-0.1.alpha - New upstream version 0.7alpha. - No tarball was uploaded so temporarily use tarball from github. - Fixes CVE-2018-14679 libmspack: off-by-one error in the CHM PMGI/PMGL chunk number validity checks * Fri Jul 13 2018 Fedora Release Engineering - 0.6-0.3.alpha - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1644215 - CVE-2018-18585 libmspack: chmd_read_headers() fails to reject filenames containing NULL bytes https://bugzilla.redhat.com/show_bug.cgi?id=1644215 [ 2 ] Bug #1644214 - CVE-2018-18584 libmspack: Out-of-bounds write in mspack/cab.h https://bugzilla.redhat.com/show_bug.cgi?id=1644214 [ 3 ] Bug #1610941 - CVE-2018-14682 libmspack: off-by-one error in the TOLOWER() macro for CHM decompression https://bugzilla.redhat.com/show_bug.cgi?id=1610941 [ 4 ] Bug #1610934 - CVE-2018-14680 libmspack: off-by-one error in the CHM chunk number validity checks https://bugzilla.redhat.com/show_bug.cgi?id=1610934 [ 5 ] Bug #1610896 - CVE-2018-14681 libmspack: out-of-bounds write in kwajd_read_headers in mspack/kwajd.c https://bugzilla.redhat.com/show_bug.cgi?id=1610896 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-cb337fb199' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.