Security fix for CVE-2023-6237 (openssl: Excessive time spent checking invalid RSA public keys). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-9cc95d56ce 2024-10-15 00:15:42.652984 -------------------------------------------------------------------------------- Name : edk2 Product : Fedora 41 Version : 20240813 Release : 2.fc41 URL : http://www.tianocore.org Summary : UEFI firmware for 64-bit virtual machines Description : EDK II is a modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications. This package contains sample 64-bit UEFI firmware builds for QEMU and KVM. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-6237 (openssl: Excessive time spent checking invalid RSA public keys) -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 11 2024 Paolo Bonzini - 20240813-2 - add openssl fix for CVE-2023-6237 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2258502 - CVE-2023-6237 openssl: Excessive time spent checking invalid RSA public keys https://bugzilla.redhat.com/show_bug.cgi?id=2258502 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-9cc95d56ce' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
GPSd could return the wrong time.. =========================================================================Ubuntu Security Notice USN-5035-1 August 10, 2021 gpsd vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.04 - Ubuntu 20.04 LTS Summary: GPSd could return the wrong time. Software Description: - gpsd: Global Positioning System Details: It was discovered that GPSd incorrectly handled certain leap second events which would result in the time jumping back 1024 weeks on 2021-10-31. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: gpsd 3.22-2ubuntu1.2 libgps28 3.22-2ubuntu1.2 Ubuntu 20.04 LTS: gpsd 3.20-8ubuntu0.4 libgps26 3.20-8ubuntu0.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5035-1 https://bugs.launchpad.net/ubuntu/+source/gpsd/+bug/1938730 Package Information: https://launchpad.net/ubuntu/+source/gpsd/3.22-2ubuntu1.2 https://launchpad.net/ubuntu/+source/gpsd/3.20-8ubuntu0.4 . A flaw in the GPS daemon on Ubuntu could lead to incorrect time readings. Please update your system to maintain precise time accuracy.. gpsd Vulnerability, Timing Issue, Ubuntu System Update, Software Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.