This update for bind fixes the following issues: Update to release 9.16.44:. # Security update for bind Announcement ID: SUSE-SU-2023:3821-1 Rating: important References: * #1215472 Cross-References: * CVE-2023-3341 CVSS scores: * CVE-2023-3341 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-3341 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for bind fixes the following issues: Update to release 9.16.44: * CVE-2023-3341: Fixed stack exhaustion flaw in control channel code may cause named to terminate unexpectedly (bsc#1215472). Update to release 9.16.43 * Processing already-queued queries received over TCP could cause an assertion failure, when the server was reconfigured at the same time or the cache was being flushed. This has been fixed. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2023-3821=1 openSUSE-SLE-15.5-2023-3821=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-3821=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2023-3821=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * bind-debuginfo-9.16.44-150500.8.12.2 * bind-utils-9.16.44-150500.8.12.2 * bind-debugsource-9.16.44-150500.8.12.2 *bind-9.16.44-150500.8.12.2 * bind-utils-debuginfo-9.16.44-150500.8.12.2 * openSUSE Leap 15.5 (noarch) * bind-doc-9.16.44-150500.8.12.2 * python3-bind-9.16.44-150500.8.12.2 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * bind-debugsource-9.16.44-150500.8.12.2 * bind-utils-debuginfo-9.16.44-150500.8.12.2 * bind-utils-9.16.44-150500.8.12.2 * bind-debuginfo-9.16.44-150500.8.12.2 * Basesystem Module 15-SP5 (noarch) * python3-bind-9.16.44-150500.8.12.2 * Server Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * bind-debugsource-9.16.44-150500.8.12.2 * bind-9.16.44-150500.8.12.2 * bind-debuginfo-9.16.44-150500.8.12.2 * Server Applications Module 15-SP5 (noarch) * bind-doc-9.16.44-150500.8.12.2 ## References: * https://www.suse.com/security/cve/CVE-2023-3341.html * https://bugzilla.suse.com/show_bug.cgi?id=1215472 . Critical openSUSE notice 2023:4821-2 for bind addresses a heap overflow vulnerability and additional patches.. OpenSUSE Advisory,Bind Security Update,System Patch,Important Update. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for sqlite3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:14771-1 Rating: important References: #1160439 Cross-References: CVE-2019-20218 CVSS scores: CVE-2019-20218 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2019-20218 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for sqlite3 fixes the following issues: - CVE-2019-20218: Fixed a stack unwinding flaw in the selectExpander after a parsing error. (bsc#1160439) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-sqlite3-14771=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-sqlite3-14771=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-sqlite3-14771=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (i586 ppc64 s390x x86_64): libsqlite3-0-3.7.6.3-1.4.7.15.1 sqlite3-3.7.6.3-1.4.7.15.1 - SUSE Linux Enterprise Server 11-SP4-LTSS (ppc64 s390x x86_64): libsqlite3-0-32bit-3.7.6.3-1.4.7.15.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): libsqlite3-0-3.7.6.3-1.4.7.15.1 sqlite3-3.7.6.3-1.4.7.15.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390xx86_64): sqlite3-debuginfo-3.7.6.3-1.4.7.15.1 References: https://www.suse.com/security/cve/CVE-2019-20218.html https://bugzilla.suse.com/1160439 . A critical update for sqlite3 has been released to rectify significant vulnerabilities affecting SUSE, tagged with Announcement ID: SUSE-SU-2021:14771-2.. SUSE Security Update, sqlite3 Patch, Important Security Fix. . Severity: Important. LinuxSecurity.com Team
Update to 88.0.4324.182. Fixes CVE-2021-21149 CVE-2021-21150 CVE-2021-21151 CVE-2021-21152 CVE-2021-21153 CVE-2021-21154 CVE-2021-21155 CVE-2021-21156 CVE-2021-21157. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-aa764a8531 2021-02-28 17:25:31.286237 --------------------------------------------------------------------------------Name : chromium Product : Fedora 33 Version : 88.0.4324.182 Release : 1.fc33 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser Description : Chromium is an open-source web browser, powered by WebKit (Blink). --------------------------------------------------------------------------------Update Information: Update to 88.0.4324.182. Fixes CVE-2021-21149 CVE-2021-21150 CVE-2021-21151 CVE-2021-21152 CVE-2021-21153 CVE-2021-21154 CVE-2021-21155 CVE-2021-21156 CVE-2021-21157 --------------------------------------------------------------------------------ChangeLog: * Wed Feb 17 2021 Tom Callaway - 88.0.4234.182-1 - update to 88.0.4234.182 --------------------------------------------------------------------------------References: [ 1 ] Bug #1929523 - CVE-2021-21149 chromium-browser: Stack overflow in Data Transfer https://bugzilla.redhat.com/show_bug.cgi?id=1929523 [ 2 ] Bug #1929524 - CVE-2021-21150 chromium-browser: Use after free in Downloads https://bugzilla.redhat.com/show_bug.cgi?id=1929524 [ 3 ] Bug #1929525 - CVE-2021-21151 chromium-browser: Use after free in Payments https://bugzilla.redhat.com/show_bug.cgi?id=1929525 [ 4 ] Bug #1929526 - CVE-2021-21152 chromium-browser: Heap buffer overflow in Media https://bugzilla.redhat.com/show_bug.cgi?id=1929526 [ 5 ] Bug #1929527 - CVE-2021-21153 chromium-browser: Stack overflow in GPU Process https://bugzilla.redhat.com/show_bug.cgi?id=1929527 [ 6 ] Bug #1929528 - CVE-2021-21154 chromium-browser: Heap bufferoverflow in Tab Strip https://bugzilla.redhat.com/show_bug.cgi?id=1929528 [ 7 ] Bug #1929529 - CVE-2021-21155 chromium-browser: Heap buffer overflow in Tab Strip https://bugzilla.redhat.com/show_bug.cgi?id=1929529 [ 8 ] Bug #1929530 - CVE-2021-21156 chromium-browser: Heap buffer overflow in V8 https://bugzilla.redhat.com/show_bug.cgi?id=1929530 [ 9 ] Bug #1929531 - CVE-2021-21157 chromium-browser: Use after free in Web Sockets https://bugzilla.redhat.com/show_bug.cgi?id=1929531 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-aa764a8531' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Important: netpbm security update. Date: Tue, 13 Dec 2011 08:14:57 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: FASTBUGS for SL 5x i386, x86_64 now available MIME-Version: 1.0 The following FASTBUGS have been uploaded to i386: acpid-1.0.4-12.el5.i386.rpm gtk2-2.10.4-21.el5_7.7.i386.rpm gtk2-devel-2.10.4-21.el5_7.7.i386.rpm sos-1.7-9.54.el5_7.1.noarch.rpm x86_64: acpid-1.0.4-12.el5.x86_64.rpm gtk2-2.10.4-21.el5_7.7.i386.rpm gtk2-2.10.4-21.el5_7.7.x86_64.rpm gtk2-devel-2.10.4-21.el5_7.7.i386.rpm gtk2-devel-2.10.4-21.el5_7.7.x86_64.rpm sos-1.7-9.54.el5_7.1.noarch.rpm Date: Tue, 13 Dec 2011 11:08:42 -0600 Reply-To:
Get the latest Linux and open source security news straight to your inbox.