A vulnerability has been discovered in Stellarium, which can lead to arbitrary file writes.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202407-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Stellarium: Arbitrary File Write Date: July 05, 2024 Bugs: #905300 ID: 202407-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Stellarium, which can lead to arbitrary file writes. Background ========== Stellarium is a free open source planetarium for your computer. It shows a realistic sky in 3D, just like what you see with the naked eye, binoculars or a telescope. Affected packages ================= Package Vulnerable Unaffected ------------------------ ------------ ------------ sci-astronomy/stellarium < 23.1 > = 23.1 Description =========== A vulnerability has been discovered in Stellarium. Please review the CVE identifier referenced below for details. Impact ====== Attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal. Workaround ========== There is no known workaround at this time. Resolution ========== All Stellarium users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sci-astronomy/stellarium-23.1" References ========== [ 1 ] CVE-2023-28371 https://nvd.nist.gov/vuln/detail/CVE-2023-28371 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202407-18 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security ofour users' machines is of utmost importance to us. Any security concerns should be addressed to
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for stellarium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0097-1 Rating: important References: #1209285 Cross-References: CVE-2023-28371 CVSS scores: CVE-2023-28371 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for stellarium fixes the following issues: - CVE-2023-28371: Fixed arbitrary file write issue. (boo#1209285) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-97=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 ppc64le s390x x86_64): stellarium-0.21.2-bp154.2.3.1 References: https://www.suse.com/security/cve/CVE-2023-28371.html https://bugzilla.suse.com/1209285 . New openSUSE patch addresses arbitrary file write vulnerability in Stellarium, bolstering overall system security. Find out further details.. openSUSE Security, Stellarium Update, Arbitrary File Fix. . Severity: Important. LinuxSecurity.com Team
Attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal. (CVE-2023-28371) References: - https://bugs.mageia.org/show_bug.cgi?id=31742 . MGASA-2023-0129 - Updated stellarium packages fix security vulnerability Publication date: 06 Apr 2023 URL: https://advisories.mageia.org/MGASA-2023-0129.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-28371 Attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal. (CVE-2023-28371) References: - https://bugs.mageia.org/show_bug.cgi?id=31742 - https://lists.fedoraproject.org/archives/list/
Patches for CVE-2023-28371. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-2cf272ad72 2023-03-29 02:35:46.540915 --------------------------------------------------------------------------------Name : stellarium Product : Fedora 37 Version : 1.2 Release : 9.fc37 URL : http://stellarium.org/ Summary : Photo-realistic nightsky renderer Description : Stellarium is a real-time 3D photo-realistic nightsky renderer. It can generate images of the sky as seen through the Earth's atmosphere with more than one hundred thousand stars from the Hipparcos Catalogue, constellations, planets, major satellites and nebulas. --------------------------------------------------------------------------------Update Information: Patches for CVE-2023-28371 --------------------------------------------------------------------------------ChangeLog: * Mon Mar 20 2023 Gwyn Ciesla - 1.2-9 - Patches for CVE-2023-28371 * Sun Mar 12 2023 Neal Gompa - 1.2-8 - Kill TELESCOPECONTROL support on F38 due to libindi 2 incompatibility * Thu Mar 2 2023 Mamoru TASAKA - 1.2-7 - F-39: kill USE_PLUGIN_TELESCOPECONTROL support due to libindi 2 incompatibility * Wed Mar 1 2023 Gwyn Ciesla - 1.2-6 - migrated to SPDX license * Sun Feb 26 2023 Gwyn Ciesla - 1.2-5 - libindi rebuild. --------------------------------------------------------------------------------References: [ 1 ] Bug #2180112 - CVE-2023-28371 stellarium: arbitrary file write [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2180112 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-2cf272ad72' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. Moredetails on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Patches for CVE-2023-28371. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-57f5e7c000 2023-03-29 00:16:08.313725 --------------------------------------------------------------------------------Name : stellarium Product : Fedora 38 Version : 1.2 Release : 9.fc38 URL : http://stellarium.org/ Summary : Photo-realistic nightsky renderer Description : Stellarium is a real-time 3D photo-realistic nightsky renderer. It can generate images of the sky as seen through the Earth's atmosphere with more than one hundred thousand stars from the Hipparcos Catalogue, constellations, planets, major satellites and nebulas. --------------------------------------------------------------------------------Update Information: Patches for CVE-2023-28371 --------------------------------------------------------------------------------ChangeLog: * Mon Mar 20 2023 Gwyn Ciesla - 1.2-9 - Patches for CVE-2023-28371 --------------------------------------------------------------------------------References: [ 1 ] Bug #2180112 - CVE-2023-28371 stellarium: arbitrary file write [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2180112 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-57f5e7c000' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-a5e10b188a 2023-03-14 00:16:44.047436 --------------------------------------------------------------------------------Name : stellarium Product : Fedora 38 Version : 1.2 Release : 8.fc38 URL : http://stellarium.org/ Summary : Photo-realistic nightsky renderer Description : Stellarium is a real-time 3D photo-realistic nightsky renderer. It can generate images of the sky as seen through the Earth's atmosphere with more than one hundred thousand stars from the Hipparcos Catalogue, constellations, planets, major satellites and nebulas. --------------------------------------------------------------------------------Update Information: FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 12 2023 Neal Gompa - 1.2-8 - Kill TELESCOPECONTROL support on F38 due to libindi 2 incompatibility * Thu Mar 2 2023 Mamoru TASAKA - 1.2-7 - F-39: kill USE_PLUGIN_TELESCOPECONTROL support due to libindi 2 incompatibility * Wed Mar 1 2023 Gwyn Ciesla - 1.2-6 - migrated to SPDX license * Sun Feb 26 2023 Gwyn Ciesla - 1.2-5 - libindirebuild. --------------------------------------------------------------------------------References: [ 1 ] Bug #1944122 - notcurses-2.3.17 is available https://bugzilla.redhat.com/show_bug.cgi?id=1944122 [ 2 ] Bug #2022640 - notcurses-2.4.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2022640 [ 3 ] Bug #2028587 - notcurses-3.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2028587 [ 4 ] Bug #2045133 - notcurses: FTBFS in Fedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045133 [ 5 ] Bug #2053373 - notcurses-3.0.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2053373 [ 6 ] Bug #2172934 - CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2172934 [ 7 ] Bug #2173846 - ffmpeg-6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2173846 [ 8 ] Bug #2174875 - k3b-22.12.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2174875 [ 9 ] Bug #2176135 - mlt-7.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2176135 [ 10 ] Bug #2176519 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176519 [ 11 ] Bug #2176520 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176520 [ 12 ] Bug #2177300 - retroarch-1.15.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177300 [ 13 ]Bug #2177550 - nv-codec-headers-12.0.16.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a5e10b188a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.