Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
This update for emacs fixes the following issues: CVE-2024-30203: Fixed treating inline MIME contents as trusted (bsc#1222053) CVE-2024-30204: Fixed LaTeX preview enabled by default for e-mail. # Security update for emacs Announcement ID: SUSE-SU-2024:1294-1 Rating: moderate References: * bsc#1222050 * bsc#1222052 * bsc#1222053 Cross-References: * CVE-2024-30203 * CVE-2024-30204 * CVE-2024-30205 CVSS scores: * CVE-2024-30203 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-30204 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-30205 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP5 * Desktop Applications Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for emacs fixes the following issues: * CVE-2024-30203: Fixed treating inline MIME contents as trusted (bsc#1222053) * CVE-2024-30204: Fixed LaTeX preview enabled by default for e-mail attachments (bsc#1222052) * CVE-2024-30205: Fixed Org mode considering contents of remote files as trusted (bsc#1222050) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-1294=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-1294=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-1294=1 * Desktop Applications Module 15-SP5 zypper in -t patchSUSE-SLE-Module-Desktop-Applications-15-SP5-2024-1294=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * emacs-x11-27.2-150400.3.11.1 * etags-27.2-150400.3.11.1 * emacs-x11-debuginfo-27.2-150400.3.11.1 * emacs-debugsource-27.2-150400.3.11.1 * etags-debuginfo-27.2-150400.3.11.1 * emacs-27.2-150400.3.11.1 * emacs-debuginfo-27.2-150400.3.11.1 * emacs-nox-27.2-150400.3.11.1 * emacs-nox-debuginfo-27.2-150400.3.11.1 * openSUSE Leap 15.4 (noarch) * emacs-el-27.2-150400.3.11.1 * emacs-info-27.2-150400.3.11.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * emacs-x11-27.2-150400.3.11.1 * etags-27.2-150400.3.11.1 * emacs-x11-debuginfo-27.2-150400.3.11.1 * emacs-debugsource-27.2-150400.3.11.1 * etags-debuginfo-27.2-150400.3.11.1 * emacs-27.2-150400.3.11.1 * emacs-debuginfo-27.2-150400.3.11.1 * emacs-nox-27.2-150400.3.11.1 * emacs-nox-debuginfo-27.2-150400.3.11.1 * openSUSE Leap 15.5 (noarch) * emacs-el-27.2-150400.3.11.1 * emacs-info-27.2-150400.3.11.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * etags-27.2-150400.3.11.1 * emacs-debugsource-27.2-150400.3.11.1 * etags-debuginfo-27.2-150400.3.11.1 * emacs-27.2-150400.3.11.1 * emacs-debuginfo-27.2-150400.3.11.1 * emacs-nox-27.2-150400.3.11.1 * emacs-nox-debuginfo-27.2-150400.3.11.1 * Basesystem Module 15-SP5 (noarch) * emacs-el-27.2-150400.3.11.1 * emacs-info-27.2-150400.3.11.1 * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * emacs-x11-27.2-150400.3.11.1 * emacs-debugsource-27.2-150400.3.11.1 * emacs-debuginfo-27.2-150400.3.11.1 * emacs-x11-debuginfo-27.2-150400.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2024-30203.html * https://www.suse.com/security/cve/CVE-2024-30204.html * https://www.suse.com/security/cve/CVE-2024-30205.html * https://bugzilla.suse.com/show_bug.cgi?id=1222050 *https://bugzilla.suse.com/show_bug.cgi?id=1222052 * https://bugzilla.suse.com/show_bug.cgi?id=1222053 . This emacs upgrade addresses several security concerns related to embedded MIME and LaTeX rendering configurations, classified as moderate.. emacs trust issues, openSUSE security patch, emacs content fix. . LinuxSecurity.com Team
An update that fixes 5 vulnerabilities is now available. . openSUSE Security Update: Security update for nextcloud-desktop ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0171-1 Rating: important References: #1205798 #1205799 #1205800 #1205801 #1207976 Cross-References: CVE-2022-39331 CVE-2022-39332 CVE-2022-39333 CVE-2022-39334 CVE-2023-23942 CVSS scores: CVE-2022-39331 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2022-39332 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2022-39333 (NVD) : 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2022-39334 (NVD) : 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N CVE-2023-23942 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for nextcloud-desktop fixes the following issues: Update ot 3.8.0 - Resize WebView widget once the loginpage rendered - Feature/secure file drop - Check German translation for wrong wording - L10n: Correct word - Fix displaying of file details button for local syncfileitem activities - Improve config upgrade warning dialog - Only accept folder setup page if overrideLocalDir is set - Update CHANGELOG. - Prevent ShareModel crash from accessing bad pointers - Bugfix/init value for pointers - Log to stdout when built in Debug config - Clean up account creation and deletion code - L10n: Added dot to end of sentence - L10n: Fixed grammar - Fix "Create new folder" menu entries in settings not working correctly on macOS - Ci/clang tidy checks initvariables - Fix share dialog infinite loading - Fix edit locally job not finding the user account: wrong user id - Skip e2e encrypted files with empty filename in metadata - Use new connect syntax - Fix avatars not showing up in settings dialog account actions until clicked on - Always discover blacklisted folders to avoid data loss when modifying selectivesync list. - Fix infinite loading in the share dialog when public link shares are disabled on the server - With cfapi when dehydrating files add missing flag - Fix text labels in Sync Status component - Display 'Search globally' as the last sharees list element - Fix display of 2FA notification. - Bugfix/do not restore virtual files - Show server name in tray main window - Add Ubuntu Lunar - Debian build classification 'beta' cannot override 'release'. - Update changelog - Follow shouldNotify flag to hide notifications when needed - Bugfix/stop after creating config file - E2EE cut extra zeroes from derypted byte array. - When local sync folder is overriden, respect this choice - Feature/e2ee fixes - This update also fixes security issues: - (boo#1205798, CVE-2022-39331) - Arbitrary HyperText Markup Language injection in notifications - (boo#1205799, CVE-2022-39332) - Arbitrary HyperText Markup Language injection in user status and information - (boo#1205800, CVE-2022-39333) - Arbitrary HyperText Markup Language injection in desktop client application - (boo#1205801, CVE-2022-39334) - Client incorrectly trusts invalid TLS certificates - (boo#1207976, CVE-2023-23942) - missing sanitisation on qml labels leading to javascript injection Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for yourproduct: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-171=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 x86_64): libnextcloudsync-devel-3.8.0-bp155.2.3.1 libnextcloudsync0-3.8.0-bp155.2.3.1 nextcloud-desktop-3.8.0-bp155.2.3.1 nextcloud-desktop-dolphin-3.8.0-bp155.2.3.1 - openSUSE Backports SLE-15-SP5 (noarch): caja-extension-nextcloud-3.8.0-bp155.2.3.1 cloudproviders-extension-nextcloud-3.8.0-bp155.2.3.1 nautilus-extension-nextcloud-3.8.0-bp155.2.3.1 nemo-extension-nextcloud-3.8.0-bp155.2.3.1 nextcloud-desktop-doc-3.8.0-bp155.2.3.1 nextcloud-desktop-lang-3.8.0-bp155.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-39331.html https://www.suse.com/security/cve/CVE-2022-39332.html https://www.suse.com/security/cve/CVE-2022-39333.html https://www.suse.com/security/cve/CVE-2022-39334.html https://www.suse.com/security/cve/CVE-2023-23942.html https://bugzilla.suse.com/1205798 https://bugzilla.suse.com/1205799 https://bugzilla.suse.com/1205800 https://bugzilla.suse.com/1205801 https://bugzilla.suse.com/1207976 . Nextcloud-desktop has undergone a crucial security enhancement aimed at addressing HTML injection vulnerabilities and problems with TLS trust.. Nextcloud Desktop Security, openSUSE HTML Injection, Important Security Patch. . Severity: Important. LinuxSecurity.com Team
Update to 2022.12.7, fixes CVE-2022-23491.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-7ed04fe4a7 2023-03-30 01:14:14.931077 --------------------------------------------------------------------------------Name : mingw-python-certifi Product : Fedora 36 Version : 2022.12.7 Release : 1.fc36 URL : https://certifi.io/ Summary : MinGW Windows Python certifi library Description : MinGW Windows Python certifi. --------------------------------------------------------------------------------Update Information: Update to 2022.12.7, fixes CVE-2022-23491. --------------------------------------------------------------------------------ChangeLog: * Tue Mar 21 2023 Sandro Mani - 2022.12.7-1 - Update to 2022.12.7 * Thu Jul 21 2022 Fedora Release Engineering - 2021.10.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Mon Feb 14 2022 Sandro Mani - 2021.10.8-1 - Update to 2021.10.8 --------------------------------------------------------------------------------References: [ 1 ] Bug #2180096 - CVE-2022-23491 mingw-python-certifi: python-certifi: untrusted root certificates [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2180096 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-7ed04fe4a7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
There have been a number of updates to the set of Certificate Authority (CA) certificates that are considered "valid" or otherwise should be trusted. . Package : ca-certificates Version : 20141019+deb8u4 Debian Bugs : #858064 #858539 #867461 #894070 There have been a number of updates to the set of Certificate Authority (CA) certificates that are considered "valid" or otherwise should be trusted. For Debian 8 "Jessie", these issues have been fixed in ca-certificates version 20141019+deb8u4. We recommend that you upgrade your ca-certificates packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Zane Bitter from Red Hat discovered a vulnerability in Aodh, the alarm engine for OpenStack. Aodh does not verify that the user creating the alarm is the trustor or has the same rights as the trustor, nor that the trust is for the same project as the alarm. The bug allows that an . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3953-1
A printf format string attack and "web of trust" pollution vulnerabilities have been fixed.. ------------------------------------------------------------------------ Debian Security Advisory DSA-061-1
Get the latest Linux and open source security news straight to your inbox.