Multiple vulnerabilites have been found in Synapse, the worst of which could result in information leaks.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202401-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Synapse: Multiple Vulnerabilities Date: January 07, 2024 Bugs: #914765, #916609 ID: 202401-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilites have been found in Synapse, the worst of which could result in information leaks. Background ========== Synapse is a Matrix homeserver written in Python/Twisted. Affected packages ================= Package Vulnerable Unaffected -------------- ------------ ------------ net-im/synapse < 1.96.0 > = 1.96.0 Description =========== Multiple vulnerabilities have been discovered in Synapse. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Synapse users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-im/synapse-1.96.0" References ========== [ 1 ] CVE-2023-41335 https://nvd.nist.gov/vuln/detail/CVE-2023-41335 [ 2 ] CVE-2023-42453 https://nvd.nist.gov/vuln/detail/CVE-2023-42453 [ 3 ] CVE-2023-43796 https://nvd.nist.gov/vuln/detail/CVE-2023-43796 [ 4 ] CVE-2023-45129 https://nvd.nist.gov/vuln/detail/CVE-2023-45129 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202401-12 Concerns? ========= Security is a primary focus ofGentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Update to latest Synapse release which fixes CVE-2018-12291 (0.31.1) and a second security bug in 0.31.2: https://github.com/matrix-org/synapse/releases/tag/v0.31.2 This update includes a new package which is a dependency introduced by synapse-0.31. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-6e759af8fb 2018-06-23 20:45:47.528690 --------------------------------------------------------------------------------Name : matrix-synapse Product : Fedora 28 Version : 0.31.2 Release : 1.fc28 URL : https://github.com/matrix-org/synapse Summary : A Matrix reference homeserver written in Python using Twisted Description : Matrix is an ambitious new ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix from the core development team at matrix.org, written in Python/Twisted. It is intended to showcase the concept of Matrix and let folks see the spec in the context of a coded base and let you run your own homeserver and generally help bootstrap the ecosystem. --------------------------------------------------------------------------------Update Information: Update to latest Synapse release which fixes CVE-2018-12291 (0.31.1) and a second security bug in 0.31.2: https://github.com/matrix-org/synapse/releases/tag/v0.31.2 This update includes a new package which is a dependency introduced by synapse-0.31 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 14 2018 Jeremy Cline - 0.31.2-1 - Update to v0.31.2 - https://github.com/matrix-org/synapse/releases/tag/v0.31.2 * Wed Jun 13 2018 Jeremy Cline - 0.31.1-3 - Bring back the pin for pynacl * Wed Jun 13 2018 Jeremy Cline - 0.31.1-2 - Stop using Python dependency generator * Wed Jun 13 2018 Jeremy Cline - 0.31.1-1 - Update to v0.31.1 - Fix CVE-2018-12291 * Thu May 24 2018 Jeremy Cline - 0.29.1-1 - Update to the latestupstream release. - Use the Python dependency generator. * Tue May 1 2018 Jeremy Cline - 0.28.1-1 - Update to the latest upstream release. --------------------------------------------------------------------------------References: [ 1 ] Bug #1590102 - CVE-2018-12291 matrix-synapse: Missing event filtering in handlers/federation.py [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1590102 [ 2 ] Bug #1578181 - matrix-synapse-0.31.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1578181 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-6e759af8fb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.