Moderate: dbus security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:4498", "synopsis": "Moderate: dbus security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for dbus.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility.\n\nSecurity Fix(es):\n\n* dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered (CVE-2023-34969)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2213166", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2213166", "description": ""}], "cves": [{"name": "CVE-2023-34969", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-34969", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.2", "cwe": "CWE-617"}], "references": [], "publishedAt": "2023-08-24T04:20:17.019312Z", "rpms": {"Rocky Linux 8": {"nvras": ["dbus-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-1:1.12.8-24.el8_8.1.src.rpm", "dbus-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-common-1:1.12.8-24.el8_8.1.noarch.rpm", "dbus-daemon-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-daemon-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-daemon-debuginfo-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-daemon-debuginfo-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-debuginfo-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-debuginfo-1:1.12.8-24.el8_8.1.i686.rpm", "dbus-debuginfo-1:1.12.8-24.el8_8.1.x86_64.rpm","dbus-debugsource-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-debugsource-1:1.12.8-24.el8_8.1.i686.rpm", "dbus-debugsource-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-devel-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-devel-1:1.12.8-24.el8_8.1.i686.rpm", "dbus-devel-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-libs-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-libs-1:1.12.8-24.el8_8.1.i686.rpm", "dbus-libs-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-libs-debuginfo-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-libs-debuginfo-1:1.12.8-24.el8_8.1.i686.rpm", "dbus-libs-debuginfo-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-tools-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-tools-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-tools-debuginfo-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-tools-debuginfo-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-x11-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-x11-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-x11-debuginfo-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-x11-debuginfo-1:1.12.8-24.el8_8.1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. The recent update for Rocky Linux addressing dbus has fixed a notable security vulnerability stemming from an assertion failure. It is advisable to upgrade for enhanced system stability.. Rocky Linux Security, Dbus Updates, Assertion Issue, System Services. . LinuxSecurity.com Team
Upstream details at : https://access.redhat.com/errata/RHSA-2022:6160. CentOS Errata and Security Advisory 2022:6160 Important Upstream details at : https://access.redhat.com/errata/RHSA-2022:6160 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 3aa88d01f6198efa435e94380ac7bb30d03f89a522b7860137a566276cea51c9 libgudev1-219-78.el7_9.7.i686.rpm 126385b940d5f6f201b6b30130139b0125b1d44dc7842c59cc7cbba5a9a4404d libgudev1-219-78.el7_9.7.x86_64.rpm 80b9e73c5db5a194278ac3415303dcf5c49c780dae020e15b55a65a9e02f2a56 libgudev1-devel-219-78.el7_9.7.i686.rpm 0d7fa70d37741c62bde710cf842f10260cf261673a4a7408c061b0e28d2bc955 libgudev1-devel-219-78.el7_9.7.x86_64.rpm b3629bade8ef787d20012f38cc73971fd4d755469722b2aa65b093f247fe10cc systemd-219-78.el7_9.7.x86_64.rpm 5490d928d2dc55d285caa5eaf9606be884605bf43d81604819679bc307219d29 systemd-devel-219-78.el7_9.7.i686.rpm a450c1170181a3ff18ece403ab9cd454a3f2fbe440d5f9b595bd3f0de9b1dd08 systemd-devel-219-78.el7_9.7.x86_64.rpm 1aa7058dfddcf6000119e4d89f90da91d35b7562587f5a8c91a2db80781c6303 systemd-journal-gateway-219-78.el7_9.7.x86_64.rpm 43b09300e3cae57123f6afdd23ac7e88411c687be6f131ff215ea718f5933e1c systemd-libs-219-78.el7_9.7.i686.rpm a6d9b567ef1b06e195132a506e27e02e6e7b6768d0d22c13cd692ffbbc8acec3 systemd-libs-219-78.el7_9.7.x86_64.rpm c3df4151777a268106f45f068f7a6e09e974ef1222fd6ccbafd4fd2f7307e011 systemd-networkd-219-78.el7_9.7.x86_64.rpm eb5d1459a1ed3b55d3a45f58f61633509ffca8700fc3dc3f1935cde74eb204c0 systemd-python-219-78.el7_9.7.x86_64.rpm 6f7cd47756fa8dfb7b6cb88b9a65c779de1981cf1b2707b6326ba27ddea5138d systemd-resolved-219-78.el7_9.7.i686.rpm badc986837eca92a61c46a7beb9bd700e04af6d84681d4ca53417eb37b7eeac4 systemd-resolved-219-78.el7_9.7.x86_64.rpm 27d4858f1741f00448f919a33388f3a4ce77d65c758523ac1aaa6845fcf67c97 systemd-sysv-219-78.el7_9.7.x86_64.rpm Source: b07ae51e28f6512b5b388391ff1440568d6fcac8ecfa194c3f9f5b6211f434fc systemd-219-78.el7_9.7.src.rpm -- Johnny Hughes CentOSProject { https://www.centos.org/ } irc: hughesjr, #
Security fix for [CVE-2017-12173]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-88a1f4854d 2017-10-27 13:50:45.813641 --------------------------------------------------------------------------------Name : sssd Product : Fedora 25 Version : 1.15.3 Release : 5.fc25 URL : https://pagure.io/SSSD/sssd/ Summary : System Security Services Daemon Description : Provides a set of daemons to manage access to remote directories and authentication mechanisms. It provides an NSS and PAM interface toward the system and a plug-gable back-end system to connect to multiple different account sources. It is also the basis to provide client auditing and policy services for projects like FreeIPA. The sssd sub-package is a meta-package that contains the daemon as well as all the existing back ends. --------------------------------------------------------------------------------Update Information: Security fix for [CVE-2017-12173] --------------------------------------------------------------------------------References: [ 1 ] Bug #1498173 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database https://bugzilla.redhat.com/show_bug.cgi?id=1498173 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade sssd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2015-5292. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-202c127199 2015-10-11 16:01:25.357331 -------------------------------------------------------------------------------- Name : sssd Product : Fedora 23 Version : 1.13.1 Release : 2.fc23 URL : https://fedoraproject.org/wiki/Infrastructure/Fedorahosted-retirement Summary : System Security Services Daemon Description : Provides a set of daemons to manage access to remote directories and authentication mechanisms. It provides an NSS and PAM interface toward the system and a plug-gable back-end system to connect to multiple different account sources. It is also the basis to provide client auditing and policy services for projects like FreeIPA. The sssd sub-package is a meta-package that contains the daemon as well as all the existing back ends. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-5292 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1267580 - CVE-2015-5292 sssd: memory leak in the sssd_pac_plugin https://bugzilla.redhat.com/show_bug.cgi?id=1267580 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update sssd' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.