An update that solves one vulnerability can now be installed.. # syncthing-2.1.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:10764-1 Rating: moderate Cross-References: * CVE-2020-11022 CVSS scores: * CVE-2020-11022 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the syncthing-2.1.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * syncthing 2.1.0-1.1 * syncthing-relaysrv 2.1.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2020-11022.html . Update for syncthing solves moderate vulnerability in openSUSE Tumbleweed, addresses CVE-2020-11022.. OpenSUSE Security Update, syncthing Vulnerability Fix, Moderate Linux Threat. . LinuxSecurity.com Team
Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-aa6e72c713 2024-11-06 03:51:37.801150 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 41 Version : 1.28.0 Release : 1.fc41 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0 -------------------------------------------------------------------------------- ChangeLog: * Mon Oct 28 2024 Fabio Valentini - 1.28.0-1 - Update to version 1.28.0; Fixes RHBZ#2319211 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2292676 - CVE-2024-24789 syncthing: golang: archive/zip: Incorrect handling of certain ZIP files [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292676 [ 2 ] Bug #2292720 - CVE-2024-24789 syncthing: golang: archive/zip: Incorrect handling of certain ZIP files [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292720 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-aa6e72c713' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-4fc7cdc194 2024-11-06 02:43:53.691855 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 39 Version : 1.28.0 Release : 1.fc39 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0 -------------------------------------------------------------------------------- ChangeLog: * Mon Oct 28 2024 Fabio Valentini - 1.28.0-1 - Update to version 1.28.0; Fixes RHBZ#2319211 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2292676 - CVE-2024-24789 syncthing: golang: archive/zip: Incorrect handling of certain ZIP files [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292676 [ 2 ] Bug #2292720 - CVE-2024-24789 syncthing: golang: archive/zip: Incorrect handling of certain ZIP files [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292720 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-4fc7cdc194' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-b93312a597 2024-02-21 01:38:35.302031 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 38 Version : 1.27.3 Release : 1.fc38 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 12 2024 Fabio Valentini - 1.27.3-1 - Update to version 1.27.3; Fixes RHBZ#2263121 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2257833 - CVE-2023-49295 syncthing: quic-go: memory exhaustion attack against QUIC's path validation mechanism [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257833 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2024-b93312a597' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c46536abe6 2024-02-21 01:31:44.025637 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 39 Version : 1.27.3 Release : 1.fc39 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 12 2024 Fabio Valentini - 1.27.3-1 - Update to version 1.27.3; Fixes RHBZ#2263121 * Sun Feb 11 2024 Maxwell G - 1.27.2-3 - Rebuild for golang 1.22.0 * Sat Jan 27 2024 Fedora Release Engineering - 1.27.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2257833 - CVE-2023-49295 syncthing: quic-go: memory exhaustion attack against QUIC's path validation mechanism [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257833 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c46536abe6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to version 1.26.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.26.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-0d46257314 2023-11-18 01:37:22.840201 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 39 Version : 1.26.0 Release : 1.fc39 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.26.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.26.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 9 2023 Fabio Valentini - 1.26.0-1 - Update to version 1.26.0; Fixes RHBZ#2248507 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2248412 - syncthing: golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2248412 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0d46257314' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key.More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to version 1.26.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.26.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-d58c8eeb7c 2023-11-18 01:25:52.283227 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 38 Version : 1.26.0 Release : 1.fc38 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.26.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.26.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 9 2023 Fabio Valentini - 1.26.0-1 - Update to version 1.26.0; Fixes RHBZ#2248507 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2248412 - syncthing: golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2248412 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-d58c8eeb7c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key.More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for syncthing ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0126-1 Rating: moderate References: #1212085 Cross-References: CVE-2022-46165 CVSS scores: CVE-2022-46165 (NVD) : 4.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N CVE-2022-46165 (SUSE): 4.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for syncthing fixes the following issues: - Update to 1.13.5 * This release fixes CVE-2022-46165 âCross-site Scripting (XSS) in Web GUIâ * Bugfixes: #8503: "syncthing cli config devices add" reflect error when using --addresses flag #8764: Ignore patterns creating during folder addition are not loaded #8778: Tests fail on Windows with Go 1.20 #8779: Test cleanup fails all model tests on Windows on Go 1.20 #8859: Incorrect handling of path for auto accepted folder * Other issues: #8799: "fatal error: checkptr: converted pointer straddles multiple allocations" in crypto tests - Update to 1.23.4 - Bugfixes: #8851: "Running global migration to fix encryption file sizes" on every start - Update to 1.23.3 * Bugfixes: #5408: Selection of time in versions GUI not possible without editing the string inside the textfield #8277: Mutual encrypted sharing doesn't work (both sides with password) #8556: Increased file size when sharing between encrypted devices #8599: Key generation at connect time is slow for encrypted connections * Enhancements: #7859: Allow sub-second watcher delay (use case: remote development) * Otherissues: #8828: cmd/stdiscosrv: TestDatabaseGetSet flake - Adding a desktop file for the Web UI - Update to 1.23.2 * Bugfixes: #8749: Relay listener does not restart sometimes * Enhancements: #8660: GUI editor for xattr filter patterns #8781: gui: Remove duplicate Spanish translation * Other issues: #8768: Update quic-go for Go 1.20 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-126=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): syncthing-1.23.5-bp155.2.3.1 syncthing-relaysrv-1.23.5-bp155.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-46165.html https://bugzilla.suse.com/1212085 . Follow these steps to deploy the Syncthing patch addressing the moderate severity XSS vulnerability and ensure your system's security during the process. openSUSE Update,syncthing Security,Cross-Site Scripting Fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.