The container suse/ltss/sle15.4/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/ltss/sle15.4/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2024:243-1 Container Tags : suse/ltss/sle15.4/bci-base:15.4 , suse/ltss/sle15.4/bci-base:15.4.2.8 , suse/ltss/sle15.4/sle15:15.4 , suse/ltss/sle15.4/sle15:15.4.2.8 Container Release : 2.8 Severity : important Type : security References : 1211188 1211190 1212475 1217000 1218126 1218186 1218209 1218475 CVE-2023-1667 CVE-2023-2283 CVE-2023-48795 CVE-2023-6004 CVE-2023-6918 CVE-2024-22365 ----------------------------------------------------------------- The container suse/ltss/sle15.4/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:136-1 Released: Thu Jan 18 09:53:47 2024 Summary: Security update for pam Type: security Severity: moderate References: 1217000,1218475,CVE-2024-22365 This update for pam fixes the following issues: - CVE-2024-22365: Fixed a local denial of service during PAM login due to a missing check during path manipulation (bsc#1218475). - Check localtime_r() return value to fix crashing (bsc#1217000) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:139-1 Released: Thu Jan 18 11:33:54 2024 Summary: Recommended update for go1.21 Type: recommended Severity: moderate References: 1212475 This update for go1.21 fixes the following issues: go1.21.6 (released 2024-01-09) includes fixes to the compiler, the runtime, and the crypto/tls, maps, and runtime/pprof packages. (bsc#1212475) * x/build,os/signal: TestDetectNohup and TestNohup fail on replacement darwin LUCI builders * runtime: ReadMemStats fatal error: mappedReady and other memstats arenot equal * cmd/compile: linux/s390x: inlining bug in s390x * maps: maps.Clone reference semantics when cloning a map with large value types * runtime: excessive memory use between 1.21.0 -> 1.21.1 * cmd/compile: max/min builtin broken when used with string(byte) conversions * runtime/pprof: incorrect function names for generics functions * crypto: upgrade to BoringCrypto fips-20220613 and enable TLS 1.3 * runtime: race condition raised with parallel tests, panic(nil) and -race ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:140-1 Released: Thu Jan 18 11:34:58 2024 Summary: Security update for libssh Type: security Severity: important References: 1211188,1211190,1218126,1218186,1218209,CVE-2023-1667,CVE-2023-2283,CVE-2023-48795,CVE-2023-6004,CVE-2023-6918 This update for libssh fixes the following issues: Security fixes: - CVE-2023-6004: Fixed command injection using proxycommand (bsc#1218209) - CVE-2023-48795: Fixed potential downgrade attack using strict kex (bsc#1218126) - CVE-2023-6918: Fixed missing checks for return values of MD functions (bsc#1218186) - CVE-2023-1667: Fixed NULL dereference during rekeying with algorithm guessing (bsc#1211188) - CVE-2023-2283: Fixed possible authorization bypass in pki_verify_data_signature under low-memory conditions (bsc#1211190) Other fixes: - Update to version 0.9.8 - Allow @ in usernames when parsing from URI composes - Update to version 0.9.7 - Fix several memory leaks in GSSAPI handling code The following package changes have been done: - container-suseconnect-2.4.0-150000.4.48.1 updated - libssh-config-0.9.8-150400.3.3.1 updated - libssh4-0.9.8-150400.3.3.1 updated - pam-1.3.0-150000.6.66.1 updated . SUSE Container Advisory provides significant security updates addressing critical vulnerabilities in SystemD and OpenSSL features.. SUSE Container Security, PAM fix, LibSSH vulnerabilities, SystemD issues. . Severity: Critical. LinuxSecurity.com Team
- Updated to latest upstream (65.0.2) - Disabled Mozilla Crashreporter to get Wayland crashes by ABRT. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-7ad9201e59 2019-03-06 06:57:11.061648 --------------------------------------------------------------------------------Name : firefox Product : Fedora 29 Version : 65.0.2 Release : 1.fc29 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. --------------------------------------------------------------------------------Update Information: - Updated to latest upstream (65.0.2) - Disabled Mozilla Crashreporter to get Wayland crashes by ABRT --------------------------------------------------------------------------------ChangeLog: * Fri Mar 1 2019 Martin Stransky - 65.0.2-1 - Updated to 65.0.2 - Disabled PGO+LTO for Fedora 30 - Disabled Mozilla Crashreporter to get Wayland crashes by ABRT - Disabled s390x builds due to https://pagure.io/fedora-infrastructure/issue/7581 * Thu Feb 28 2019 Martin Stransky - 65.0.1-2 - Enable ARBT for Fedora 29 and later to catch wayland crashes. - Disable system libvpx for Fedora 30 and later. * Wed Feb 20 2019 Martin Stransky - 65.0.1-1 - Disabled s390x/f28 builds due to https://pagure.io/fedora-infrastructure/issue/7581 * Fri Feb 15 2019 Jan Horak - 65.0.1-1 - Update to 65.0.1 * Mon Feb 4 2019 Martin Stransky - 65.0-4 - Added fix for mozbz#1522780 * Thu Jan 31 2019 Fedora Release Engineering - 65.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Thu Jan 31 2019 Jan Grulich - 65.0-2 - Re-enable PipeWire support * Mon Jan 28 2019 Martin Stransky - 65.0-1 - Update to 65.0 build 2 * Wed Jan 16 2019 Martin Stransky - 64.0.2-2 - Rebuild * Thu Jan 10 2019 Jan Horak -64.0.2-1 - Update to 64.0.2 * Mon Jan 7 2019 Jan Horak - 64.0-7 - Pipewire patch rebased (thanks to Tomas Popela) - Enabled PGO on some arches. * Fri Jan 4 2019 Carmen Bianca Bakker - 64.0-6 - Changed locale detector to handle Esperanto (rhbz#1656900) * Fri Dec 21 2018 Martin Stransky - 64.0-5 - Test PGO build. * Wed Dec 12 2018 Martin Stransky - 64.0-4 - Use gcc on all platforms for official release. * Wed Dec 12 2018 Martin Stransky - 64.0-3 - Updated PGO build setup. * Tue Dec 4 2018 Martin Stransky - 64.0-2 - Updated to Firefox 64 (Build 3) - Built with Clang on some arches. * Mon Nov 26 2018 Martin Stransky - 63.0.3-3 - [Wayland] Fixed issues with Sway compositor and wl_keyboard setup (mozbz#1507475). * Wed Nov 21 2018 Martin Stransky - 63.0.3-2 - [Wayland] Fixed mozbz#1507475 - crash when display changes (rhbz#1646151). * Thu Nov 15 2018 Martin Stransky - 63.0.3-1 - Updated to latest upstream (63.0.3) * Tue Nov 13 2018 Martin Stransky - 63.0.1-6 - Added an option to build with clang/llvm. - Fixed debug builds. - Fixed warnings at Wayland clipboard code. * Tue Nov 6 2018 Martin Stransky - 63.0.1-5 - Added fix for mozbz#1502457- disable Contextual Feature Recommender/shield studies by default. * Mon Nov 5 2018 Martin Stransky - 63.0.1-4 - Added clipboard fix (mozbz#1504689) * Fri Nov 2 2018 Dan Horak - 63.0.1-3 - Added fixes for ppc64le * Thu Nov 1 2018 Martin Stransky - 63.0.1-2 - Fixed typo on man page (rhbz#1643766) * Thu Nov 1 2018 Martin Stransky - 63.0.1-1 - Updated to latest upstream (63.0.1 build 4) * Tue Oct 23 2018 Martin Stransky - 63.0-2 - Updated to latest upstream (63.0 build 2) * Thu Oct 18 2018 Martin Stransky - 63.0-1 - Updated to latest upstream (63.0) - Updated PipeWire patch * Tue Oct 9 2018 Martin Stransky - 62.0.3-4 - Added fix for mozbz#1447775 - wrong dropspace sizing. * Tue Oct 9 2018 Martin Stransky - 62.0.3-3 - Added fix for mozbz#1493081 - popups incorrectly placed and sized. *Mon Oct 8 2018 Martin Stransky - 62.0.3-2 - Added pipewire patch (mozbz#1496359) - Added Wayland patches from Firefox 63 - Enable Wayland backed by default on Fedora 30 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-7ad9201e59' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-2376-1 October 09, 2014 linux vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: - linux: Linux kernel Details: Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's magicmouse HID driver. A physically proximate attacker could exploit this flaw to cause a denial of service (system crash) or possibly execute arbitrary code via specially crafted devices. (CVE-2014-3181) Ben Hawkes reported some off by one errors for report descriptors in the Linux kernel's HID stack. A physically proximate attacker could exploit these flaws to cause a denial of service (out-of-bounds write) via a specially crafted device. (CVE-2014-3184) Several bounds check flaws allowing for buffer overflows were discovered in the Linux kernel's Whiteheat USB serial driver. A physically proximate attacker could exploit these flaws to cause a denial of service (system crash) via a specially crafted device. (CVE-2014-3185) Steven Vittitoe reported a buffer overflow in the Linux kernel's PicoLCD HID device driver. A physically proximate attacker could exploit this flaw to cause a denial of service (system crash) or possibly execute arbitrary code via a specially craft device. (CVE-2014-3186) A flaw was discovered in the Linux kernel's UDF filesystem (used on some CD-ROMs and DVDs) when processing indirect ICBs. An attacker who can cause CD, DVD or image file with a specially crafted inode to be mounted can cause a denial of service (infinite loop or stack consumption). (CVE-2014-6410) James Eckersall discovered a buffer overflow in the Ceph filesystem in the Linux kernel. A remote attacker could exploit this flaw tocause a denial of service (memory consumption and panic) or possibly have other unspecified impact via a long unencrypted auth ticket. (CVE-2014-6416) James Eckersall discovered a flaw in the handling of memory allocation failures in the Ceph filesystem. A remote attacker could exploit this flaw to cause a denial of service (system crash) or possibly have unspecified other impact. (CVE-2014-6417) James Eckersall discovered a flaw in how the Ceph filesystem validates auth replies. A remote attacker could exploit this flaw to cause a denial of service (system crash) or possibly have other unspecified impact. (CVE-2014-6418) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: linux-image-3.2.0-70-generic 3.2.0-70.105 linux-image-3.2.0-70-generic-pae 3.2.0-70.105 linux-image-3.2.0-70-highbank 3.2.0-70.105 linux-image-3.2.0-70-omap 3.2.0-70.105 linux-image-3.2.0-70-powerpc-smp 3.2.0-70.105 linux-image-3.2.0-70-powerpc64-smp 3.2.0-70.105 linux-image-3.2.0-70-virtual 3.2.0-70.105 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-2376-1 CVE-2014-3181, CVE-2014-3184, CVE-2014-3185, CVE-2014-3186, CVE-2014-6410, CVE-2014-6416, CVE-2014-6417, CVE-2014-6418 Package Information: https://launchpad.net/ubuntu/+source/linux/3.2.0-70.105 . Multiplesecurity issues fixed in Ubuntu 12.04 LTS kernel to avert potential system crashes and exploits.. Kernel Security Issues, Ubuntu Kernel Updates, Denial of Service Fixes. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.