Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
100

SUSE: 2022:1552-2 Critical: bci/openjdk-runtime Patch for Unicode Issue

The container bci/openjdk-devel was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:1551-1 Container Tags : bci/openjdk-devel:11 , bci/openjdk-devel:11-14.31 , bci/openjdk-devel:latest Container Release : 14.31 Severity : important Type : security References : 1197718 1199140 1199232 1199232 1200334 1200855 CVE-2022-1586 CVE-2022-1586 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2360-1 Released: Tue Jul 12 12:01:39 2022 Summary: Security update for pcre2 Type: security Severity: important References: 1199232,CVE-2022-1586 This update for pcre2 fixes the following issues: - CVE-2022-1586: Fixed unicode property matching issue. (bsc#1199232) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2361-1 Released: Tue Jul 12 12:05:01 2022 Summary: Security update for pcre Type: security Severity: important References: 1199232,CVE-2022-1586 This update for pcre fixes the following issues: - CVE-2022-1586: Fixed unicode property matching issue. (bsc#1199232) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:2406-1 Released: Fri Jul 15 11:49:01 2022 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1197718,1199140,1200334,1200855 This update for glibc fixes the following issues: - powerpc: Fix VSX register number on __strncpy_power9 (bsc#1200334) - Disable warnings due to deprecated libselinux symbols used by nss and nscd (bsc#1197718) - i386: Remove broken CAN_USE_REGISTER_ASM_EBP(bsc#1197718) - rtld: Avoid using up static TLS surplus for optimizations (bsc#1200855, BZ #25051) This readds the s390 32bit glibc and libcrypt1 libraries (glibc-32bit, glibc-locale-base-32bit, libcrypt1-32bit). The following package changes have been done: - glibc-2.31-150300.31.2 updated - libcrypt1-4.4.15-150300.4.4.3 updated - libpcre1-8.45-150000.20.13.1 updated - libpcre2-8-0-10.39-150400.4.3.1 updated - container:bci-openjdk-11-11-12.15 updated . The latest update for the bci/python-devel container from SUSE addresses critical unicode-related bugs and also incorporates various security enhancements.. OpenJDK Security, Container Update, SUSE Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 19, 2022 Important SuSE
100

SUSE: 2022:1485-1 Moderate: Python39 DoS And Unicode Issues

An update that solves three vulnerabilities, contains one feature and has two fixes is now available. . SUSE Security Update: Security update for python39 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1485-1 Rating: moderate References: #1186819 #1189241 #1189287 #1189356 #1193179 SLE-23849 Cross-References: CVE-2021-3572 CVE-2021-3733 CVE-2021-3737 CVSS scores: CVE-2021-3572 (NVD) : 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N CVE-2021-3572 (SUSE): 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N CVE-2021-3733 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-3733 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2021-3737 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-3737 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Development Tools 15-SP3 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that solves three vulnerabilities, contains one feature and has two fixes is now available. Description: This update for python39 fixes the following issues: - CVE-2021-3572: Fixed an improper handling of unicode characters in pip (bsc#1186819). - Update to 3.9.10 (jsc#SLE-23849) -Remove shebangs from from python-base libraries in _libdir. (bsc#1193179) - Update to 3.9.9: * Core and Builtins + bpo-30570: Fixed a crash in issubclass() from infinite recursion when searching pathological __bases__ tuples. + bpo-45494: Fix parser crash when reporting errors involving invalid continuation characters. Patch by Pablo Galindo. + bpo-45385: Fix reference leak from descr_check. Patch by Dong-hee Na. + bpo-45167: Fix deepcopying of types.GenericAlias objects. + bpo-44219: Release the GIL while performing isatty system calls on arbitrary file descriptors. In particular, this affects os.isatty(), os.device_encoding() and io.TextIOWrapper. By extension, io.open() in text mode is also affected. This change solves a deadlock in os.isatty(). Patch by Vincent Michel in bpo-44219. + bpo-44959: Added fallback to extension modules with '.sl' suffix on HP-UX + bpo-44050: Extensions that indicate they use global state (by setting m_size to -1) can again be used in multiple interpreters. This reverts to behavior of Python 3.8. + bpo-45121: Fix issue where Protocol.__init__ raises RecursionError when it's called directly or via super(). Patch provided by Yurii Karabas. + bpo-45083: When the interpreter renders an exception, its name now has a complete qualname. Previously only the class name was concatenated to the module name, which sometimes resulted in an incorrect full name being displayed. + bpo-45738: Fix computation of error location for invalid continuation characters in the parser. Patch by Pablo Galindo. + Library + bpo-45678: Fix bug in Python 3.9 that meant functools.singledispatchmethod failed to properly wrap the attributes of the target method. Patch by Alex Waygood. + bpo-45679: Fix caching of multi-value typing.Literal. Literal[True, 2] isno longer equal to Literal[1, 2]. + bpo-45438: Fix typing.Signature string representation for generic builtin types. + bpo-45581: sqlite3.connect() now correctly raises MemoryError if the underlying SQLite API signals memory error. Patch by Erlend E. Aasland. + bpo-39679: Fix bug in functools.singledispatchmethod that caused it to fail when attempting to register a classmethod() or staticmethod() using type annotations. Patch contributed by Alex Waygood. + bpo-45515: Add references to zoneinfo in the datetime documentation, mostly replacing outdated references to dateutil.tz. Change by Paul Ganssle. + bpo-45467: Fix incremental decoder and stream reader in the "raw-unicode-escape" codec. Previously they failed if the escape sequence was split. + bpo-45461: Fix incremental decoder and stream reader in the "unicode-escape" codec. Previously they failed if the escape sequence was split. + bpo-45239: Fixed email.utils.parsedate_tz() crashing with UnboundLocalError on certain invalid input instead of returning None. Patch by Ben Hoyt. + bpo-44904: Fix bug in the doctest module that caused it to fail if a docstring included an example with a classmethod property. Patch by Alex Waygood. + bpo-45406: Make inspect.getmodule() catch FileNotFoundError raised by :'func:inspect.getabsfile, and return None to indicate that the module could not be determined. + bpo-45262: Prevent use-after-free in asyncio. Make sure the cached running loop holder gets cleared on dealloc to prevent use-after-free in get_running_loop + bpo-45386: Make xmlrpc.client more robust to C runtimes where the underlying C strftime function results in a ValueError when testing for year formatting options. + bpo-45371: Fix clang rpath issue in distutils. The UnixCCompiler now uses correct clang option to add a runtime library directory (rpath) to a shared library. + bpo-20028: Improve error message of csv.Dialect when initializing. Patch by Vajrasky Kok and Dong-hee Na. + bpo-45343: Update bundled pip to 21.2.4 and setuptools to 58.1.0 + bpo-41710: On Unix, if the sem_clockwait() function is available in the C library (glibc 2.30 and newer), the threading.Lock.acquire() method now uses the monotonic clock (time.CLOCK_MONOTONIC) for the timeout, rather than using the system clock (time.CLOCK_REALTIME), to not be affected by system clock changes. Patch by Victor Stinner. + bpo-45328: Fixed http.client.HTTPConnection to work properly in OSs that don't support the TCP_NODELAY socket option. + bpo-1596321: Fix the threading._shutdown() function when the threading module was imported first from a thread different than the main thread: no longer log an error at Python exit. + bpo-45274: Fix a race condition in the Thread.join() method of the threading module. If the function is interrupted by a signal and the signal handler raises an exception, make sure that the thread remains in a consistent state to prevent a deadlock. Patch by Victor Stinner. + bpo-45238: Fix unittest.IsolatedAsyncioTestCase.debug(): it runs now asynchronous methods and callbacks. + bpo-36674: unittest.TestCase.debug() raises now a unittest.SkipTest if the class or the test method are decorated with the skipping decorator. + bpo-45235: Fix an issue where argparse would not preserve values in a provided namespace when using a subparser with defaults. + bpo-45234: Fixed a regression in copyfile(), copy(), copy2() raising FileNotFoundError when source is a directory, which should raise IsADirectoryError + bpo-45228: Fix stack buffer overflow in parsing J1939 network address. + bpo-45192: Fix the tempfile._infer_return_type function so that the dir argument of the tempfile functions accepts an object implementing the os.PathLike protocol. + bpo-45160: When tracing a tkinter variable used by a ttk OptionMenu, callbacks are no longer made twice. + bpo-35474: Calling mimetypes.guess_all_extensions() with strict=False no longer affects the result of the following call with strict=True. Also, mutating the returned list no longer affects the global state. + bpo-45166: typing.get_type_hints() now works with Final wrapped in ForwardRef. + bpo-45097: Remove deprecation warnings about the loop argument in asyncio incorrectly emitted in cases when the user does not pass the loop argument. + bpo-45081: Fix issue when dataclasses that inherit from typing.Protocol subclasses have wrong __init__. Patch provided by Yurii Karabas. + bpo-24444: Fixed an error raised in argparse help display when help for an option is set to 1+ blank spaces or when choices arg is an empty container. + bpo-45021: Fix a potential deadlock at shutdown of forked children when using concurrent.futures module + bpo-45030: Fix integer overflow in pickling and copying the range iterator. + bpo-39039: tarfile.open raises ReadError when a zlib error occurs during file extraction. + bpo-44594: Fix an edge case of ExitStack and AsyncExitStack exception chaining. They will now match with block behavior when __context__ is explicitly set to None when the exception is in flight. * Documentation + bpo-45726: Improve documentation for functools.singledispatch() and functools.singledispatchmethod. + bpo-45680: Amend the docs on GenericAlias objects to clarify that non-container classes can also implement __class_getitem__. Patch contributedby Alex Waygood. + bpo-45655: Add a new "relevant PEPs" section to the top of the documentation for the typing module. Patch by Alex Waygood. + bpo-45604: Add level argument to multiprocessing.log_to_stderr function docs. + bpo-45464: Mention in the documentation of Built-in Exceptions that inheriting from multiple exception types in a single subclass is not recommended due to possible memory layout incompatibility. + bpo-45449: Add note about PEP 585 in collections.abc. + bpo-45516: Add protocol description to the importlib.abc.Traversable documentation. + bpo-20692: Add Programming FAQ entry explaining that int literal attribute access requires either a space after or parentheses around the literal. + bpo-45216: Remove extra documentation listing methods in difflib. It was rendering twice in pydoc and was outdated in some places. + bpo-45772: socket.socket documentation is corrected to a class from a function. + bpo-45392: Update the docstring of the type built-in to remove a redundant line and to mention keyword arguments for the constructor. * Tests + bpo-45578: Add tests for dis.distb() + bpo-45577: Add subtests for all pickle protocols in test_zoneinfo. + bpo-43592: test.libregrtest now raises the soft resource limit for the maximum number of file descriptors when the default is too low for our test suite as was often the case on macOS. + bpo-40173: Fix test.support.import_helper.import_fresh_module(). + bpo-45280: Add a test case for empty typing.NamedTuple. + bpo-45269: Cover case when invalid markers type is supplied to c_make_encoder. + bpo-45209: Fix UserWarning: resource_tracker warning in _test_multiprocessing._TestSharedMemory.test_shared_memory_cleaned_after_pr ocess_termination + bpo-45195: Fix test_readline.test_nonascii(): sometimes, the newline character is not written at the end, so don't expect it in the output. Patch by Victor Stinner. + bpo-45156: Fixes infinite loop on unittest.mock.seal() of mocks created by create_autospec(). + bpo-45042: Fixes that test classes decorated with @hashlib_helper.requires_hashdigest were skipped all the time. + bpo-45235: Reverted an argparse bugfix that caused regression in the handling of default arguments for subparsers. This prevented leaf level arguments from taking precedence over root level arguments. + bpo-45765: In importlib.metadata, fix distribution discovery for an empty path. + bpo-45644: In-place JSON file formatting using python3 -m json.tool infile infile now works correctly, previously it left the file empty. Patch by Chris Wesseling. * Build + bpo-43158: setup.py now uses values from configure script to build the _uuid extension module. Configure now detects util-linux's libuuid, too. + bpo-45571: Modules/Setup now use PY_CFLAGS_NODIST instead of PY_CFLAGS to compile shared modules. + bpo-45532: Update sys.version to use main as fallback information. Patch by Jeong YunWon. + bpo-45405: Prevent internal configure error when running configure with recent versions of non-Apple clang. Patch by David Bohman. + bpo-45220: Avoid building with the Windows 11 SDK previews automatically. This may be overridden by setting the DefaultWindowsSDKVersion environment variable before building. * C API + bpo-44687: BufferedReader.peek() no longer raises ValueError when the entire file has already been buffered. + bpo-44751: Remove crypt.h include from the public Python.h header. - rpm-build-python dependency is available on the current Factory, not with SLE. - BuildRequire rpm-build-python: The provider to inject python(abi) has been moved there. rpm-buildpulls rpm-build-python automatically in when building anything against python3-base, but this implies that the initial build of python3-base does not trigger the automatic installation. - Update to 3.9.7: - Security - Replaced usage of tempfile.mktemp() with TemporaryDirectory to avoid a potential race condition. - Add auditing events to the marshal module, and stop raising code.__init__ events for every unmarshalled code object. Directly instantiated code objects will continue to raise an event, and audit event handlers should inspect or collect the raw marshal data. This reduces a significant performance overhead when loading from .pyc files. - Made the internal putcmd function in smtplib sanitize input for presence of \r and \n characters to avoid (unlikely) command injection. - Core and Builtins - Fixed pickling of range iterators that iterated for over 2**32 times. - Fix a race in WeakKeyDictionary, WeakValueDictionary and WeakSet when two threads attempt to commit the last pending removal. This fixes asyncio.create_task and fixes a data loss in asyncio.run where shutdown_asyncgens is not run - Fixed a corner case bug where the result of float.fromhex('0x.8p-1074') was rounded the wrong way. - Refine the syntax error for trailing commas in import statements. Patch by Pablo Galindo. - Restore behaviour of complex exponentiation with integer-valued exponent of type float or complex. - Correct the ast locations of f-strings with format specs and repeated expressions. Patch by Pablo Galindo - Use new trashcan macros (Py_TRASHCAN_BEGIN/END) in frameobject.c instead of the old ones (Py_TRASHCAN_SAFE_BEGIN/END). - Fix segmentation fault with deep recursion when cleaning method objects. Patch by Augusto Goulart and Pablo Galindo. - Fix bug wherePyErr_SetObject hangs when the current exception has a cycle in its context chain. - Fix reference leaks in the error paths of update_bases() and __build_class__. Patch by Pablo Galindo. - Fix undefined behaviour in complex object exponentiation. - Remove uses of PyObject_GC_Del() in error path when initializing types.GenericAlias. - Remove the pass-through for hash() of weakref.proxy objects to prevent unintended consequences when the original referred object dies while the proxy is part of a hashable object. Patch by Pablo Galindo. - Fix ltrace functionality when exceptions are raised. Patch by Pablo Galindo - Fix a crash at Python exit when a deallocator function removes the last strong reference to a heap type. Patch by Victor Stinner. - Fix crash when using passing a non-exception to a generator's throw() method. Patch by Noah Oxer - Library - run() now always return a TestResult instance. Previously it returned None if the test class or method was decorated with a skipping decorator. - Fix bugs in cleaning up classes and modules in unittest: - Functions registered with addModuleCleanup() were not called unless the user defines tearDownModule() in their test module. - Functions registered with addClassCleanup() were not called if tearDownClass is set to None. - Buffering in TestResult did not work with functions registered with addClassCleanup() and addModuleCleanup(). - Errors in functions registered with addClassCleanup() and addModuleCleanup() were not handled correctly in buffered and debug modes. - Errors in setUpModule() and functions registered with addModuleCleanup() were reported in wrong order. - And several lesser bugs. - Made email date parsing more robust against malformed input, namely a whitespace-only Date: header. Patch by WouterBolsterlee. - Fix a crash in the signal handler of the faulthandler module: no longer modify the reference count of frame objects. Patch by Victor Stinner. - Method stopTestRun() is now always called in pair with method startTestRun() for TestResult objects implicitly created in run(). Previously it was not called for test methods and classes decorated with a skipping decorator. - argparse.BooleanOptionalAction's default value is no longer printed twice when used with argparse.ArgumentDefaultsHelpFormatter. - Upgrade bundled pip to 21.2.3 and setuptools to 57.4.0 - Fix the os.set_inheritable() function on FreeBSD 14 for file descriptor opened with the O_PATH flag: ignore the EBADF error on ioctl(), fallback on the fcntl() implementation. Patch by Victor Stinner. - The @functools.total_ordering() decorator now works with metaclasses. - sqlite3 user-defined functions and aggregators returning strings with embedded NUL characters are no longer truncated. Patch by Erlend E. Aasland. - Always show loop= arg deprecations in asyncio.gather() and asyncio.sleep() - Non-protocol subclasses of typing.Protocol ignore now the __init__ method inherited from protocol base classes. - The tokenize.tokenize() doesn't incorrectly generate a NEWLINE token if the source doesn't end with a new line character but the last line is a comment, as the function is already generating a NL token. Patch by Pablo Galindo - Fix http.client.HTTPSConnection fails to download > 2GiB data. - rcompleter does not call getattr() on property objects to avoid the side-effect of evaluating the corresponding method. - weakref.proxy objects referencing non-iterators now raise TypeError rather than dereferencing the null tp_iternext slot and crashing. - The implementation of collections.abc.Set._hash()now matches that of frozenset.__hash__(). - Fixed issue in compileall.compile_file() when sys.stdout is redirected. Patch by Stefan Hölzl. - Give priority to using the current class constructor in inspect.signature(). Patch by Weipeng Hong. - Fix memory leak in _tkinter._flatten() if it is called with a sequence or set, but not list or tuple. - Update shutil.copyfile() to raise FileNotFoundError instead of confusing IsADirectoryError when a path ending with a os.path.sep does not exist; shutil.copy() and shutil.copy2() are also affected. - handle StopIteration subclass raised from @contextlib.contextmanager generator - Make the implementation consistency of indexOf() between C and Python versions. Patch by Dong-hee Na. - Fixes TypedDict to work with typing.get_type_hints() and postponed evaluation of annotations across modules. - Fix bug with pdb's handling of import error due to a package which does not have a __main__ module - Fixed an exception thrown while parsing a malformed multipart email by email.message.EmailMessage. - pathlib.PureWindowsPath.is_reserved() now identifies a greater range of reserved filenames, including those with trailing spaces or colons. - Handle exceptions from parsing the arg of pdb's run/restart command. - The sqlite3 context manager now performs a rollback (thus releasing the database lock) if commit failed. Patch by Luca Citi and Erlend E. Aasland. - Improved string handling for sqlite3 user-defined functions and aggregates: - It is now possible to pass strings with embedded null characters to UDFs - Conversion failures now correctly raise MemoryError - Patch by Erlend E. Aasland. - Handle RecursionError in TracebackException's constructor, so that long exceptions chains are truncated instead of causingtraceback formatting to fail. - Fix email.message.EmailMessage.set_content() when called with binary data and 7bit content transfer encoding. - The compresslevel and preset keyword arguments of tarfile.open() are now both documented and tested. - Fixed a Y2k38 bug in the compileall module where it would fail to compile files with a modification time after the year 2038. - Fix test___all__ on platforms lacking a shared memory implementation. - Pass multiprocessing BaseProxy argument manager_owned through AutoProxy. - email.utils.getaddresses() now accepts email.header.Header objects along with string values. Patch by Zackery Spytz. - lib2to3 now recognizes async generators everywhere. - Fix TypeError when required subparsers without dest do not receive arguments. Patch by Anthony Sottile. - Documentation - Removed the othergui.rst file, any references to it, and the list of GUI frameworks in the FAQ. In their place I've added links to the Python Wiki page on GUI frameworks. - Update the definition of __future__ in the glossary by replacing the confusing word "pseudo-module" with a more accurate description. - Add typical examples to os.path.splitext docs - Clarify that shutil.make_archive() is not thread-safe due to reliance on changing the current working directory. - Update of three expired hyperlinks in Doc/distributing/index.rst: "Project structure", "Building and packaging the project", and "Uploading the project to the Python Packaging Index". - Updated the docstring and docs of filecmp.cmp() to be more accurate and less confusing especially in respect to shallow arg. - Match the docstring and python implementation of countOf() to the behavior of its c implementation. - List all kwargs for textwrap.wrap(), textwrap.fill(), and textwrap.shorten(). Now,there are nav links to attributes of TextWrap, which makes navigation much easier while minimizing duplication in the documentation. - Clarify that atexit uses equality comparisons internally. - Documentation of csv.Dialect is more descriptive. - Fix documentation for the return type of sysconfig.get_path(). - Add a "Security Considerations" index which links to standard library modules that have explicitly documented security considerations. - Remove the unqualified claim that tkinter is threadsafe. It has not been true for several years and likely never was. An explanation of what is true may be added later, after more discussion, and possibly after patching _tkinter.c, - Tests - Add calls of gc.collect() in tests to support PyPy. - Made tests relying on the _asyncio C extension module optional to allow running on alternative Python implementations. Patch by Serhiy Storchaka. - Fix auto history tests of test_readline: sometimes, the newline character is not written at the end, so don't expect it in the output. - Add ability to wholesale silence DeprecationWarnings while running the regression test suite. - Notify users running test_decimal regression tests on macOS of potential harmless "malloc can't allocate region" messages spewed by test_decimal. - Fixed floating point precision issue in turtle tests. - Regression tests, when run with -w, are now re-running only the affected test methods instead of re-running the entire test file. - Add test for nested queues when using multiprocessing shared objects AutoProxy[Queue] inside ListProxy and DictProxy - Add building with --with-system-libmpdec option (bsc#1189356). - test_faulthandler is still problematic under qemu linux-user emulation, disable it there - Reenable profileopt with qemu emulation, test_faulthandler is no longer run during profiling - bpo-44022 (bsc#1189241, CVE-2021-3737): http.client now avoids infinitely reading potential HTTP headers after a 100 Continue status response from the server. - bpo-43075 (CVE-2021-3733, bsc#1189287): Fix Regular Expression Denial of Service (ReDoS) vulnerability in urllib.request.AbstractBasicAuthHandler. The ReDoS-vulnerable regex has quadratic worst-case complexity and it allows cause a denial of service when identifying crafted invalid RFCs. This ReDoS issue is on the client side and needs remote attackers to control the HTTP server. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-1485=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-1485=1 - SUSE Linux Enterprise Module for Development Tools 15-SP3: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP3-2022-1485=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-1485=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): libpython3_9-1_0-3.9.10-150300.4.8.1 libpython3_9-1_0-debuginfo-3.9.10-150300.4.8.1 python39-3.9.10-150300.4.8.2 python39-base-3.9.10-150300.4.8.1 python39-base-debuginfo-3.9.10-150300.4.8.1 python39-core-debugsource-3.9.10-150300.4.8.1 python39-curses-3.9.10-150300.4.8.2 python39-curses-debuginfo-3.9.10-150300.4.8.2 python39-dbm-3.9.10-150300.4.8.2 python39-dbm-debuginfo-3.9.10-150300.4.8.2 python39-debuginfo-3.9.10-150300.4.8.2 python39-debugsource-3.9.10-150300.4.8.2 python39-devel-3.9.10-150300.4.8.1 python39-doc-3.9.10-150300.4.8.1 python39-doc-devhelp-3.9.10-150300.4.8.1 python39-idle-3.9.10-150300.4.8.2 python39-testsuite-3.9.10-150300.4.8.1 python39-testsuite-debuginfo-3.9.10-150300.4.8.1 python39-tk-3.9.10-150300.4.8.2 python39-tk-debuginfo-3.9.10-150300.4.8.2 python39-tools-3.9.10-150300.4.8.1 - openSUSE Leap 15.4 (x86_64): libpython3_9-1_0-32bit-3.9.10-150300.4.8.1 libpython3_9-1_0-32bit-debuginfo-3.9.10-150300.4.8.1 python39-32bit-3.9.10-150300.4.8.2 python39-32bit-debuginfo-3.9.10-150300.4.8.2 python39-base-32bit-3.9.10-150300.4.8.1 python39-base-32bit-debuginfo-3.9.10-150300.4.8.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): libpython3_9-1_0-3.9.10-150300.4.8.1 libpython3_9-1_0-debuginfo-3.9.10-150300.4.8.1 python39-3.9.10-150300.4.8.2 python39-base-3.9.10-150300.4.8.1 python39-base-debuginfo-3.9.10-150300.4.8.1 python39-core-debugsource-3.9.10-150300.4.8.1 python39-curses-3.9.10-150300.4.8.2 python39-curses-debuginfo-3.9.10-150300.4.8.2 python39-dbm-3.9.10-150300.4.8.2 python39-dbm-debuginfo-3.9.10-150300.4.8.2 python39-debuginfo-3.9.10-150300.4.8.2 python39-debugsource-3.9.10-150300.4.8.2 python39-devel-3.9.10-150300.4.8.1 python39-doc-3.9.10-150300.4.8.1 python39-doc-devhelp-3.9.10-150300.4.8.1 python39-idle-3.9.10-150300.4.8.2 python39-testsuite-3.9.10-150300.4.8.1 python39-testsuite-debuginfo-3.9.10-150300.4.8.1 python39-tk-3.9.10-150300.4.8.2 python39-tk-debuginfo-3.9.10-150300.4.8.2 python39-tools-3.9.10-150300.4.8.1 - openSUSE Leap 15.3 (x86_64): libpython3_9-1_0-32bit-3.9.10-150300.4.8.1 libpython3_9-1_0-32bit-debuginfo-3.9.10-150300.4.8.1 python39-32bit-3.9.10-150300.4.8.2 python39-32bit-debuginfo-3.9.10-150300.4.8.2 python39-base-32bit-3.9.10-150300.4.8.1 python39-base-32bit-debuginfo-3.9.10-150300.4.8.1 - SUSE Linux Enterprise Module for Development Tools 15-SP3(aarch64 ppc64le s390x x86_64): python39-core-debugsource-3.9.10-150300.4.8.1 python39-tools-3.9.10-150300.4.8.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): libpython3_9-1_0-3.9.10-150300.4.8.1 libpython3_9-1_0-debuginfo-3.9.10-150300.4.8.1 python39-3.9.10-150300.4.8.2 python39-base-3.9.10-150300.4.8.1 python39-base-debuginfo-3.9.10-150300.4.8.1 python39-core-debugsource-3.9.10-150300.4.8.1 python39-curses-3.9.10-150300.4.8.2 python39-curses-debuginfo-3.9.10-150300.4.8.2 python39-dbm-3.9.10-150300.4.8.2 python39-dbm-debuginfo-3.9.10-150300.4.8.2 python39-debuginfo-3.9.10-150300.4.8.2 python39-debugsource-3.9.10-150300.4.8.2 python39-devel-3.9.10-150300.4.8.1 python39-idle-3.9.10-150300.4.8.2 python39-tk-3.9.10-150300.4.8.2 python39-tk-debuginfo-3.9.10-150300.4.8.2 References: https://www.suse.com/security/cve/CVE-2021-3572.html https://www.suse.com/security/cve/CVE-2021-3733.html https://www.suse.com/security/cve/CVE-2021-3737.html https://bugzilla.suse.com/1186819 https://bugzilla.suse.com/1189241 https://bugzilla.suse.com/1189287 https://bugzilla.suse.com/1189356 https://bugzilla.suse.com/1193179 . Release update for python39 focused on vital fixes, boosting efficiency and safeguarding features on SUSE Linux environments.. Python39 Security Fix, SUSE Update, SUSE Linux Security Advisory, DoS Vulnerability, Linux Software Update. . LinuxSecurity.com Team

Calendar%202 May 02, 2022 SuSE
100

SUSE: 2021:4051-1 Moderate: Python-Pip Unicode Handling Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-pip ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:4051-1 Rating: moderate References: #1186819 Cross-References: CVE-2021-3572 CVSS scores: CVE-2021-3572 (SUSE): 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N Affected Products: SUSE Linux Enterprise Module for Public Cloud 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-pip fixes the following issues: - CVE-2021-3572: Fixed incorrect handling of unicode separators in git references (bsc#1186819). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Public Cloud 12: zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2021-4051=1 Package List: - SUSE Linux Enterprise Module for Public Cloud 12 (noarch): python-pip-10.0.1-13.6.1 python3-pip-10.0.1-13.6.1 References: https://www.suse.com/security/cve/CVE-2021-3572.html https://bugzilla.suse.com/1186819 . Explore the SUSE Security Patch for python-pip that tackles medium severity concerns related to unicode processing. Find out further details here.. SUSE Security Update, Python-Pip Fixes, Unicode Handling, Patch Installation, Public Cloud Security. . LinuxSecurity.com Team

Calendar%202 Dec 14, 2021 SuSE
98

RedHat: RHSA-2021-4743 Moderate: llvm-toolset:rhel8 Trojan Source Threat

An update for the llvm-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: llvm-toolset:rhel8 security update Advisory ID: RHSA-2021:4743-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:4743 Issue date: 2021-11-18 CVE Names: CVE-2021-42574 ==================================================================== 1. Summary: An update for the llvm-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: LLVM Toolset provides the LLVM compiler infrastructure framework, the Clang compiler for the C and C++ languages, the LLDB debugger, and related tools for code analysis. Security Fix(es): * Developer environment: Unicode's bidirectional (BiDi) override characterscan cause trojan source attacks (CVE-2021-42574) The following changes were introduced in clang in order to facilitate detection of BiDi Unicode characters: clang-tidy now finds identifiers that contain Unicode characters with right-to-left direction, which can be confusing as they may change the understanding of a whole statement. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in theReferences section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2005819 - CVE-2021-42574 Developer environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.src.rpm compiler-rt-12.0.1-1.module+el8.5.0+11871+08d0eab5.src.rpm libomp-12.0.1-1.module+el8.5.0+11871+08d0eab5.src.rpm lld-12.0.1-1.module+el8.5.0+11871+08d0eab5.src.rpm lldb-12.0.1-1.module+el8.5.0+11871+08d0eab5.src.rpm llvm-12.0.1-2.module+el8.5.0+12488+254d2a07.src.rpm llvm-toolset-12.0.1-1.module+el8.5.0+11871+08d0eab5.src.rpm python-lit-12.0.1-1.module+el8.5.0+11871+08d0eab5.src.rpm aarch64: clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm clang-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm clang-debugsource-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm clang-devel-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm clang-libs-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm clang-libs-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm clang-resource-filesystem-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm clang-tools-extra-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm clang-tools-extra-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm compiler-rt-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm compiler-rt-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm compiler-rt-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm git-clang-format-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm libomp-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm libomp-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm libomp-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm libomp-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm libomp-test-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm libomp-test-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm lld-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm lld-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm lld-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm lld-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm lld-libs-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm lld-libs-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm lld-test-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm lld-test-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm lldb-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm lldb-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm lldb-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm lldb-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm llvm-12.0.1-2.module+el8.5.0+12488+254d2a07.aarch64.rpm llvm-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.aarch64.rpm llvm-debugsource-12.0.1-2.module+el8.5.0+12488+254d2a07.aarch64.rpm llvm-devel-12.0.1-2.module+el8.5.0+12488+254d2a07.aarch64.rpm llvm-devel-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.aarch64.rpm llvm-googletest-12.0.1-2.module+el8.5.0+12488+254d2a07.aarch64.rpm llvm-libs-12.0.1-2.module+el8.5.0+12488+254d2a07.aarch64.rpm llvm-libs-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.aarch64.rpm llvm-static-12.0.1-2.module+el8.5.0+12488+254d2a07.aarch64.rpm llvm-test-12.0.1-2.module+el8.5.0+12488+254d2a07.aarch64.rpm llvm-test-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.aarch64.rpm llvm-toolset-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm python3-clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm python3-lldb-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm noarch: clang-analyzer-12.0.1-4.module+el8.5.0+13246+cefb5d4c.noarch.rpm llvm-doc-12.0.1-2.module+el8.5.0+12488+254d2a07.noarch.rpm python3-lit-12.0.1-1.module+el8.5.0+11871+08d0eab5.noarch.rpm ppc64le: clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.ppc64le.rpm clang-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.ppc64le.rpm clang-debugsource-12.0.1-4.module+el8.5.0+13246+cefb5d4c.ppc64le.rpm clang-devel-12.0.1-4.module+el8.5.0+13246+cefb5d4c.ppc64le.rpm clang-libs-12.0.1-4.module+el8.5.0+13246+cefb5d4c.ppc64le.rpm clang-libs-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.ppc64le.rpm clang-resource-filesystem-12.0.1-4.module+el8.5.0+13246+cefb5d4c.ppc64le.rpm clang-tools-extra-12.0.1-4.module+el8.5.0+13246+cefb5d4c.ppc64le.rpm clang-tools-extra-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.ppc64le.rpm compiler-rt-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm compiler-rt-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm compiler-rt-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm git-clang-format-12.0.1-4.module+el8.5.0+13246+cefb5d4c.ppc64le.rpm libomp-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm libomp-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm libomp-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm libomp-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm libomp-test-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm libomp-test-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm lld-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm lld-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm lld-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm lld-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm lld-libs-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm lld-libs-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm lld-test-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm lld-test-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm lldb-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm lldb-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm lldb-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm lldb-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm llvm-12.0.1-2.module+el8.5.0+12488+254d2a07.ppc64le.rpm llvm-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.ppc64le.rpm llvm-debugsource-12.0.1-2.module+el8.5.0+12488+254d2a07.ppc64le.rpm llvm-devel-12.0.1-2.module+el8.5.0+12488+254d2a07.ppc64le.rpm llvm-devel-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.ppc64le.rpm llvm-googletest-12.0.1-2.module+el8.5.0+12488+254d2a07.ppc64le.rpm llvm-libs-12.0.1-2.module+el8.5.0+12488+254d2a07.ppc64le.rpm llvm-libs-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.ppc64le.rpm llvm-static-12.0.1-2.module+el8.5.0+12488+254d2a07.ppc64le.rpm llvm-test-12.0.1-2.module+el8.5.0+12488+254d2a07.ppc64le.rpm llvm-test-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.ppc64le.rpm llvm-toolset-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm python3-clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.ppc64le.rpm python3-lldb-12.0.1-1.module+el8.5.0+11871+08d0eab5.ppc64le.rpm s390x: clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.s390x.rpm clang-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.s390x.rpm clang-debugsource-12.0.1-4.module+el8.5.0+13246+cefb5d4c.s390x.rpm clang-devel-12.0.1-4.module+el8.5.0+13246+cefb5d4c.s390x.rpm clang-libs-12.0.1-4.module+el8.5.0+13246+cefb5d4c.s390x.rpm clang-libs-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.s390x.rpm clang-resource-filesystem-12.0.1-4.module+el8.5.0+13246+cefb5d4c.s390x.rpm clang-tools-extra-12.0.1-4.module+el8.5.0+13246+cefb5d4c.s390x.rpm clang-tools-extra-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.s390x.rpm compiler-rt-12.0.1-1.module+el8.5.0+11871+08d0eab5.s390x.rpm compiler-rt-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.s390x.rpm compiler-rt-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.s390x.rpm git-clang-format-12.0.1-4.module+el8.5.0+13246+cefb5d4c.s390x.rpm lldb-12.0.1-1.module+el8.5.0+11871+08d0eab5.s390x.rpm lldb-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.s390x.rpm lldb-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.s390x.rpm lldb-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.s390x.rpm llvm-12.0.1-2.module+el8.5.0+12488+254d2a07.s390x.rpm llvm-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.s390x.rpm llvm-debugsource-12.0.1-2.module+el8.5.0+12488+254d2a07.s390x.rpm llvm-devel-12.0.1-2.module+el8.5.0+12488+254d2a07.s390x.rpm llvm-devel-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.s390x.rpm llvm-googletest-12.0.1-2.module+el8.5.0+12488+254d2a07.s390x.rpm llvm-libs-12.0.1-2.module+el8.5.0+12488+254d2a07.s390x.rpm llvm-libs-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.s390x.rpm llvm-static-12.0.1-2.module+el8.5.0+12488+254d2a07.s390x.rpm llvm-test-12.0.1-2.module+el8.5.0+12488+254d2a07.s390x.rpm llvm-test-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.s390x.rpm llvm-toolset-12.0.1-1.module+el8.5.0+11871+08d0eab5.s390x.rpm python3-clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.s390x.rpm python3-lldb-12.0.1-1.module+el8.5.0+11871+08d0eab5.s390x.rpm x86_64: clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.i686.rpm clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.x86_64.rpm clang-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.i686.rpm clang-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.x86_64.rpm clang-debugsource-12.0.1-4.module+el8.5.0+13246+cefb5d4c.i686.rpm clang-debugsource-12.0.1-4.module+el8.5.0+13246+cefb5d4c.x86_64.rpm clang-devel-12.0.1-4.module+el8.5.0+13246+cefb5d4c.i686.rpm clang-devel-12.0.1-4.module+el8.5.0+13246+cefb5d4c.x86_64.rpm clang-libs-12.0.1-4.module+el8.5.0+13246+cefb5d4c.i686.rpm clang-libs-12.0.1-4.module+el8.5.0+13246+cefb5d4c.x86_64.rpm clang-libs-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.i686.rpm clang-libs-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.x86_64.rpm clang-resource-filesystem-12.0.1-4.module+el8.5.0+13246+cefb5d4c.i686.rpm clang-resource-filesystem-12.0.1-4.module+el8.5.0+13246+cefb5d4c.x86_64.rpm clang-tools-extra-12.0.1-4.module+el8.5.0+13246+cefb5d4c.i686.rpm clang-tools-extra-12.0.1-4.module+el8.5.0+13246+cefb5d4c.x86_64.rpm clang-tools-extra-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.i686.rpm clang-tools-extra-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.x86_64.rpm compiler-rt-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm compiler-rt-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm compiler-rt-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm compiler-rt-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm compiler-rt-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm compiler-rt-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm git-clang-format-12.0.1-4.module+el8.5.0+13246+cefb5d4c.i686.rpm git-clang-format-12.0.1-4.module+el8.5.0+13246+cefb5d4c.x86_64.rpm libomp-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm libomp-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm libomp-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm libomp-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm libomp-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm libomp-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm libomp-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm libomp-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm libomp-test-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm libomp-test-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm libomp-test-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm libomp-test-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm lld-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm lld-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm lld-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm lld-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm lld-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm lld-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm lld-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm lld-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm lld-libs-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm lld-libs-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm lld-libs-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm lld-libs-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm lld-test-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm lld-test-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm lld-test-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm lld-test-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm lldb-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm lldb-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm lldb-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm lldb-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm lldb-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm lldb-debugsource-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm lldb-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm lldb-devel-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm llvm-12.0.1-2.module+el8.5.0+12488+254d2a07.i686.rpm llvm-12.0.1-2.module+el8.5.0+12488+254d2a07.x86_64.rpm llvm-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.i686.rpm llvm-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.x86_64.rpm llvm-debugsource-12.0.1-2.module+el8.5.0+12488+254d2a07.i686.rpm llvm-debugsource-12.0.1-2.module+el8.5.0+12488+254d2a07.x86_64.rpm llvm-devel-12.0.1-2.module+el8.5.0+12488+254d2a07.i686.rpm llvm-devel-12.0.1-2.module+el8.5.0+12488+254d2a07.x86_64.rpm llvm-devel-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.i686.rpm llvm-devel-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.x86_64.rpm llvm-googletest-12.0.1-2.module+el8.5.0+12488+254d2a07.i686.rpm llvm-googletest-12.0.1-2.module+el8.5.0+12488+254d2a07.x86_64.rpm llvm-libs-12.0.1-2.module+el8.5.0+12488+254d2a07.i686.rpm llvm-libs-12.0.1-2.module+el8.5.0+12488+254d2a07.x86_64.rpm llvm-libs-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.i686.rpm llvm-libs-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.x86_64.rpm llvm-static-12.0.1-2.module+el8.5.0+12488+254d2a07.i686.rpm llvm-static-12.0.1-2.module+el8.5.0+12488+254d2a07.x86_64.rpm llvm-test-12.0.1-2.module+el8.5.0+12488+254d2a07.i686.rpm llvm-test-12.0.1-2.module+el8.5.0+12488+254d2a07.x86_64.rpm llvm-test-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.i686.rpm llvm-test-debuginfo-12.0.1-2.module+el8.5.0+12488+254d2a07.x86_64.rpm llvm-toolset-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm llvm-toolset-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm python3-clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.i686.rpm python3-clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.x86_64.rpm python3-lldb-12.0.1-1.module+el8.5.0+11871+08d0eab5.i686.rpm python3-lldb-12.0.1-1.module+el8.5.0+11871+08d0eab5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-42574 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2021-007 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYZa6X9zjgjWX9erEAQjo3A/7BUxFnHLLt5RMcs1yxVt0jALclFN8F+2u WOts5QfkhmH84ljGf+A9vO5icjuGjALJ0amHfHGWoSXzK2BNqR/yrvX99roj+DqH NyKLMAMcSKIYKBD2fPB+54HoQyP1WRFTpwXAMcO4XKIZ6FRXiqGXdVzjGrEEwdgF 99PwKnWz96CcQIagEy+VmaAo9iUPDFRvPzVoee+T/ceN2YwiG3zVJw5cFhfug7Qj tzML+rGaZ1ocF8Hqz3cGmswGIBCTgHamWfSaekQSJZAkkxDSrulKdrDQ+TuU6Iok wFTRfk6qW5RJoOc968buKyhqtFXPiGEiXaLh4VJVnWZWz5eFk6TgOvEuM+67j+QY fpdgziy5XU4jiKNC7PQQBOezUBa71/LN1pnMYKpFYIZJMojbZvvJaF8Xsx1DO0KL 4nx5iYuy50fLSWJr56cUeEgLfysb7up3OP+HaXeisrMYnQL431Rc6HMzuVDllq9E ECeFMg6FpMPpW0Am7jRKl6BgMIfRxFWFij/URuI5yFSGMsc21AZjdTZT3cfz6222 JN6sijPiN7vtvpUb82WyDUOP0Pt/RvD8r7833Qcn7XwjbYfo/1v5o56pEfoJIywu PiZPciIflSNis09z3D77GmGliQEXKeGdoUB3pNSZJbLuf5ukQvMxXls0zXu6fToj pBKwrLzOfhI=jzty -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A significant update has been released for llvm-toolset in Red Hat Enterprise Linux 8 to address potential trojan source vulnerabilities. Ensure you download it promptly.. Red Hat, llvm-toolset, security update, trojan source, RHEL. . LinuxSecurity.com Team

Calendar%202 Nov 18, 2021 Red Hat
98

Red Hat: RHSA-2021-4724 Moderate: Devtoolset-10 Annobin Trojan Source Risk

An update for devtoolset-10-annobin is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: devtoolset-10-annobin security update Advisory ID: RHSA-2021:4724-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2021:4724 Issue date: 2021-11-17 CVE Names: CVE-2021-42574 ==================================================================== 1. Summary: An update for devtoolset-10-annobin is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: Annobin provides a compiler plugin to annotate and tools to examine compiled binary files. Security Fix(es): * Developer environment: Unicode's bidirectional (BiDi) override characterscan cause trojan source attacks (CVE-2021-42574) The following changes were introduced in annobin in order to facilitate detection of BiDi Unicode characters: This update of annobin adds a new annocheck test to detect the presence of multibyte characters in symbol names. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, andother related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2005819 - CVE-2021-42574 Developer environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: devtoolset-10-annobin-9.23-4.el7.1.src.rpm ppc64: devtoolset-10-annobin-9.23-4.el7.1.ppc64.rpm devtoolset-10-annobin-annocheck-9.23-4.el7.1.ppc64.rpm devtoolset-10-annobin-debuginfo-9.23-4.el7.1.ppc64.rpm ppc64le: devtoolset-10-annobin-9.23-4.el7.1.ppc64le.rpm devtoolset-10-annobin-annocheck-9.23-4.el7.1.ppc64le.rpm devtoolset-10-annobin-debuginfo-9.23-4.el7.1.ppc64le.rpm s390x: devtoolset-10-annobin-9.23-4.el7.1.s390x.rpm devtoolset-10-annobin-annocheck-9.23-4.el7.1.s390x.rpm devtoolset-10-annobin-debuginfo-9.23-4.el7.1.s390x.rpm x86_64: devtoolset-10-annobin-9.23-4.el7.1.x86_64.rpm devtoolset-10-annobin-annocheck-9.23-4.el7.1.x86_64.rpm devtoolset-10-annobin-debuginfo-9.23-4.el7.1.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7): Source: devtoolset-10-annobin-9.23-4.el7.1.src.rpm ppc64: devtoolset-10-annobin-9.23-4.el7.1.ppc64.rpm devtoolset-10-annobin-annocheck-9.23-4.el7.1.ppc64.rpm devtoolset-10-annobin-debuginfo-9.23-4.el7.1.ppc64.rpm ppc64le: devtoolset-10-annobin-9.23-4.el7.1.ppc64le.rpm devtoolset-10-annobin-annocheck-9.23-4.el7.1.ppc64le.rpm devtoolset-10-annobin-debuginfo-9.23-4.el7.1.ppc64le.rpm s390x: devtoolset-10-annobin-9.23-4.el7.1.s390x.rpm devtoolset-10-annobin-annocheck-9.23-4.el7.1.s390x.rpm devtoolset-10-annobin-debuginfo-9.23-4.el7.1.s390x.rpm x86_64: devtoolset-10-annobin-9.23-4.el7.1.x86_64.rpm devtoolset-10-annobin-annocheck-9.23-4.el7.1.x86_64.rpm devtoolset-10-annobin-debuginfo-9.23-4.el7.1.x86_64.rpm Red HatSoftware Collections for Red Hat Enterprise Linux Workstation (v. 7): Source: devtoolset-10-annobin-9.23-4.el7.1.src.rpm x86_64: devtoolset-10-annobin-9.23-4.el7.1.x86_64.rpm devtoolset-10-annobin-annocheck-9.23-4.el7.1.x86_64.rpm devtoolset-10-annobin-debuginfo-9.23-4.el7.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-42574 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2021-007 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYZVo3NzjgjWX9erEAQgefA//dZWTXbypGX+WI7w68obTa7ee9+E+aSgY rLZnnr6txOPe8OQBl6/jDT3TLHTLiLwGeUT0uaHTlUdl7FrKjwNSdT9IRa8ML2Dv cosi46e/axoSPMCJUNjhK6pNwJ+z5ZOIdvo55n8rwEPnQnG+0jLwolFrnQv5vUHJ nZBN1b255R7OMRtONknL/OVq6fgwUQ+R6tk4hxSi3RVpb2bvqqwcKoYhkkobqGwr /a/ocbx8wJCRPHICx8cn75Ld1OQKaQkQz1sGY61Dk84V99IAtAUjlV4v6MidOH4g LMJdsMH/DkY/bsWZ/eY5tNEXHSr7KcjTdczUrEC4P4oTEfZtCEYJSNczeMfs9Eh5 2aTKtHZAbkKiE81QIC0u/Nhb4e7e1sQ+z4ldr5V8eVsUxdVS4sQh8WP4xV6GQqy2 uuEzbBucih2PtPHg51YWaQTFui/3um6PO+ZOb+1edoZFTsYRXQIC5jFuW3HfVYCB cAr+1S9zwDE2L91yj7KFQO9xvKQK2cVF/ZWRR0ZnDGnd6skupCVKRyYW0f/DAG/T 6GqLPezdc6WW+cHKB7qeHw5RakO6R0PEopC0oDLzJ8RJhhPsJrsrnV3Uzpyz/7VJ iu6ssbkEqh8vFbo/WCuO1QJ/HtNWUMQurPKNIZ4LtW95pmHD3dIMv3qmtcySR8Zt eoIclr2N/VI=qSzT -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Security advisory addressing trojan source impacts in Red Hat's devtoolset-10-annobin with a moderate threat level.. devtoolset-10-annobin, security update, red hat software collections. . LinuxSecurity.com Team

Calendar%202 Nov 17, 2021 Red Hat
98

Red Hat: RHSA-2021-4588 Moderate: gcc-toolset-10-binutils Source Threat

An update for gcc-toolset-10-binutils is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: gcc-toolset-10-binutils security update Advisory ID: RHSA-2021:4588-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:4588 Issue date: 2021-11-10 CVE Names: CVE-2021-42574 ==================================================================== 1. Summary: An update for gcc-toolset-10-binutils is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.4) - aarch64, ppc64le, s390x, x86_64 3. Description: The binutils packages provide a collection of binary utilities for the manipulation of object code in various object file formats. It includes the ar, as, gprof, ld, nm, objcopy, objdump, ranlib, readelf, size, strings, strip, and addr2line utilities. Security Fix(es): * Developer environment: Unicode's bidirectional (BiDi) override characterscan cause trojan source attacks (CVE-2021-42574) The following changes were introduced in binutils in order to facilitate detection of BiDi Unicode characters: Tools which display names or strings (readelf, strings, nm, objdump) have a new command line option --unicode / -U which controls how Unicode characters are handled. Using "--unicode=default" will treat them as normal forthe tool. This is the default behaviour when --unicode option is not used. Using "--unicode=locale" will display them according to the current locale. Using "--unicode=hex" will display them as hex byte values. Using "--unicode=escape" will display them as Unicode escape sequences. Using "--unicode=highlight" will display them as Unicode escape sequences highlighted in red, if supported by the output device. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2005819 - CVE-2021-42574 Developer environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.4): Source: gcc-toolset-10-binutils-2.35-8.el8_4.5.src.rpm aarch64: gcc-toolset-10-binutils-2.35-8.el8_4.5.aarch64.rpm gcc-toolset-10-binutils-debuginfo-2.35-8.el8_4.5.aarch64.rpm gcc-toolset-10-binutils-devel-2.35-8.el8_4.5.aarch64.rpm ppc64le: gcc-toolset-10-binutils-2.35-8.el8_4.5.ppc64le.rpm gcc-toolset-10-binutils-debuginfo-2.35-8.el8_4.5.ppc64le.rpm gcc-toolset-10-binutils-devel-2.35-8.el8_4.5.ppc64le.rpm s390x: gcc-toolset-10-binutils-2.35-8.el8_4.5.s390x.rpm gcc-toolset-10-binutils-debuginfo-2.35-8.el8_4.5.s390x.rpm gcc-toolset-10-binutils-devel-2.35-8.el8_4.5.s390x.rpm x86_64: gcc-toolset-10-binutils-2.35-8.el8_4.5.x86_64.rpm gcc-toolset-10-binutils-debuginfo-2.35-8.el8_4.5.i686.rpm gcc-toolset-10-binutils-debuginfo-2.35-8.el8_4.5.x86_64.rpm gcc-toolset-10-binutils-devel-2.35-8.el8_4.5.i686.rpm gcc-toolset-10-binutils-devel-2.35-8.el8_4.5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-42574 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2021-007 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYYvZqtzjgjWX9erEAQhoWw/9EVuSFuHlxa3dYEd1kJxsu9aBya2KHWDF SRC4mxt5P3M1XqUfUPRQbVKn9hVx0sXP5E509zJoxNW8VtQY3/Po+na3l8MOPeZM attpmoRJmmzJb8QOegZyshOJy+DpSdgmMUfBPZdKP7+W7U50OvpamBS+barCwNXL IE9R1Nr7FlQGuQ+NyYW7XTvZTbfh7OH9K3v4QOaQJ1DaRJVngOcXvIWtBy77co5C Vc+UZaLQhpa0azPgKW0fqJ7iGIcNg65RE3+kS2Ozki1IWvkeNOzY1rID0o+4jUv9 94z6J6iJPrDOMXAaiyqPSMtK4SGB1uNuTanNgNalykjgtLpQIQYDF8x4S+DHMP51 x5aZXuNKqRowA3svL5PyRPAZ9Bz9p6Y9s8Tw0GjXlpADxwGXwfMY2jg+xAJ1Y2Pu QWT8+rTqzQCCHTdRFp6zMjS4u+WDGcZgqvX075tDRdU1YQvyg6NzlJwof3OxmG3e QXRkAzPIKCa7aOG9A0YEV1r/scv295uUBTo9P3+ou6IBEh8VJOXUN/XV78E3w0TB p99ODbtkNHk8STinNHLF20Gt5KQ3YbGy9SI4WnyxS+fXvf18Xx9D3nGLaGD38e5I FAQww41RhqeX+OeNQJz+QR4nBmUm873M9ZRyYMD3iUVrce2uc5m3+1ZZOeoJFRfB u+Lmu7pXbos=jcbp -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat issued a notable security notice regarding gcc-toolset-10-binutils, focusing on potential vulnerabilities that could facilitate two-way attacks.. Red Hat Security, gcc-toolset-10-binutils Update, Security Advisory Linux, Moderate Security Update. . LinuxSecurity.com Team

Calendar%202 Nov 10, 2021 Red Hat
98

Red Hat 7 Moderate: RHSA-2021-4039-01 Vulnerability in devtoolset-10-gcc

An update for devtoolset-10-gcc is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: devtoolset-10-gcc security update Advisory ID: RHSA-2021:4039-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2021:4039 Issue date: 2021-11-01 CVE Names: CVE-2021-42574 ==================================================================== 1. Summary: An update for devtoolset-10-gcc is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: The GNU Compiler Collection (GCC) is a portable compiler suite with support for various programming languages, including C, C++, and Fortran. The devtoolset-10-gcc packages provide the Red Hat Developer Toolset 10 version of GCC, as well as related libraries. Security Fix(es): * Developer environment: Unicode's bidirectional (BiDi) override characterscan cause trojan source attacks (CVE-2021-42574) The following changes were introduced in binutils in order to facilitate detection of BiDi Unicode characters: This gcc update implements-Wbidirectional=[none|unpaired|any] to warn about possibly dangerous bidirectional characters. There are three levels of warning supported by GCC: "-Wbidirectional=unpaired", which warns about improperly terminated bidi contexts. (This is the default) "-Wbidirectional=none", turns the warning off. "-Wbidirectional=any" warns about any use of bidirectional characters. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2005819 - CVE-2021-42574 Developer environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v.7): Source: devtoolset-10-gcc-10.2.1-11.2.el7.src.rpm ppc64: devtoolset-10-gcc-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-gcc-c++-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-gcc-debuginfo-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-gcc-gdb-plugin-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-gcc-gfortran-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-gcc-plugin-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libasan-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libatomic-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libgccjit-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libgccjit-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libgccjit-docs-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libitm-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-liblsan-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libquadmath-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libstdc++-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libstdc++-docs-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libtsan-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libubsan-devel-10.2.1-11.2.el7.ppc64.rpm libasan6-10.2.1-11.2.el7.ppc64.rpm liblsan-10.2.1-11.2.el7.ppc64.rpm libtsan-10.2.1-11.2.el7.ppc64.rpm libubsan1-10.2.1-11.2.el7.ppc64.rpm ppc64le: devtoolset-10-gcc-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-gcc-c++-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-gcc-debuginfo-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-gcc-gdb-plugin-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-gcc-gfortran-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-gcc-plugin-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libasan-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libatomic-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libgccjit-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libgccjit-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libgccjit-docs-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libitm-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-liblsan-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libquadmath-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libstdc++-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libstdc++-docs-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libtsan-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libubsan-devel-10.2.1-11.2.el7.ppc64le.rpm libasan6-10.2.1-11.2.el7.ppc64le.rpm liblsan-10.2.1-11.2.el7.ppc64le.rpm libtsan-10.2.1-11.2.el7.ppc64le.rpm libubsan1-10.2.1-11.2.el7.ppc64le.rpm s390x: devtoolset-10-gcc-10.2.1-11.2.el7.s390x.rpm devtoolset-10-gcc-c++-10.2.1-11.2.el7.s390x.rpm devtoolset-10-gcc-debuginfo-10.2.1-11.2.el7.s390x.rpm devtoolset-10-gcc-gdb-plugin-10.2.1-11.2.el7.s390x.rpm devtoolset-10-gcc-gfortran-10.2.1-11.2.el7.s390x.rpm devtoolset-10-gcc-plugin-devel-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libasan-devel-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libatomic-devel-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libgccjit-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libgccjit-devel-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libgccjit-docs-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libitm-devel-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libstdc++-devel-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libstdc++-docs-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libubsan-devel-10.2.1-11.2.el7.s390x.rpm libasan6-10.2.1-11.2.el7.s390x.rpm libubsan1-10.2.1-11.2.el7.s390x.rpm x86_64: devtoolset-10-gcc-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-c++-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-debuginfo-10.2.1-11.2.el7.i686.rpm devtoolset-10-gcc-debuginfo-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-gdb-plugin-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-gfortran-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-plugin-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libasan-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libasan-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libatomic-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libatomic-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libgccjit-10.2.1-11.2.el7.i686.rpm devtoolset-10-libgccjit-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libgccjit-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libgccjit-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libgccjit-docs-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libitm-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libitm-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-liblsan-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libquadmath-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libquadmath-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libstdc++-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libstdc++-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libstdc++-docs-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libtsan-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libubsan-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libubsan-devel-10.2.1-11.2.el7.x86_64.rpm libasan6-10.2.1-11.2.el7.i686.rpm libasan6-10.2.1-11.2.el7.x86_64.rpm liblsan-10.2.1-11.2.el7.x86_64.rpm libtsan-10.2.1-11.2.el7.x86_64.rpm libubsan1-10.2.1-11.2.el7.i686.rpm libubsan1-10.2.1-11.2.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.7): Source: devtoolset-10-gcc-10.2.1-11.2.el7.src.rpm ppc64: devtoolset-10-gcc-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-gcc-c++-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-gcc-debuginfo-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-gcc-gdb-plugin-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-gcc-gfortran-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-gcc-plugin-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libasan-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libatomic-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libgccjit-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libgccjit-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libgccjit-docs-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libitm-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-liblsan-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libquadmath-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libstdc++-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libstdc++-docs-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libtsan-devel-10.2.1-11.2.el7.ppc64.rpm devtoolset-10-libubsan-devel-10.2.1-11.2.el7.ppc64.rpm libasan6-10.2.1-11.2.el7.ppc64.rpm liblsan-10.2.1-11.2.el7.ppc64.rpm libtsan-10.2.1-11.2.el7.ppc64.rpm libubsan1-10.2.1-11.2.el7.ppc64.rpm ppc64le: devtoolset-10-gcc-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-gcc-c++-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-gcc-debuginfo-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-gcc-gdb-plugin-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-gcc-gfortran-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-gcc-plugin-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libasan-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libatomic-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libgccjit-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libgccjit-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libgccjit-docs-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libitm-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-liblsan-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libquadmath-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libstdc++-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libstdc++-docs-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libtsan-devel-10.2.1-11.2.el7.ppc64le.rpm devtoolset-10-libubsan-devel-10.2.1-11.2.el7.ppc64le.rpm libasan6-10.2.1-11.2.el7.ppc64le.rpm liblsan-10.2.1-11.2.el7.ppc64le.rpm libtsan-10.2.1-11.2.el7.ppc64le.rpm libubsan1-10.2.1-11.2.el7.ppc64le.rpm s390x: devtoolset-10-gcc-10.2.1-11.2.el7.s390x.rpm devtoolset-10-gcc-c++-10.2.1-11.2.el7.s390x.rpm devtoolset-10-gcc-debuginfo-10.2.1-11.2.el7.s390x.rpm devtoolset-10-gcc-gdb-plugin-10.2.1-11.2.el7.s390x.rpm devtoolset-10-gcc-gfortran-10.2.1-11.2.el7.s390x.rpm devtoolset-10-gcc-plugin-devel-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libasan-devel-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libatomic-devel-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libgccjit-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libgccjit-devel-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libgccjit-docs-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libitm-devel-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libstdc++-devel-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libstdc++-docs-10.2.1-11.2.el7.s390x.rpm devtoolset-10-libubsan-devel-10.2.1-11.2.el7.s390x.rpm libasan6-10.2.1-11.2.el7.s390x.rpm libubsan1-10.2.1-11.2.el7.s390x.rpm x86_64: devtoolset-10-gcc-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-c++-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-debuginfo-10.2.1-11.2.el7.i686.rpm devtoolset-10-gcc-debuginfo-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-gdb-plugin-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-gfortran-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-plugin-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libasan-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libasan-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libatomic-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libatomic-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libgccjit-10.2.1-11.2.el7.i686.rpm devtoolset-10-libgccjit-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libgccjit-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libgccjit-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libgccjit-docs-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libitm-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libitm-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-liblsan-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libquadmath-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libquadmath-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libstdc++-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libstdc++-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libstdc++-docs-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libtsan-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libubsan-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libubsan-devel-10.2.1-11.2.el7.x86_64.rpm libasan6-10.2.1-11.2.el7.i686.rpm libasan6-10.2.1-11.2.el7.x86_64.rpm liblsan-10.2.1-11.2.el7.x86_64.rpm libtsan-10.2.1-11.2.el7.x86_64.rpm libubsan1-10.2.1-11.2.el7.i686.rpm libubsan1-10.2.1-11.2.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v.7): Source: devtoolset-10-gcc-10.2.1-11.2.el7.src.rpm x86_64: devtoolset-10-gcc-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-c++-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-debuginfo-10.2.1-11.2.el7.i686.rpm devtoolset-10-gcc-debuginfo-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-gdb-plugin-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-gfortran-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-gcc-plugin-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libasan-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libasan-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libatomic-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libatomic-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libgccjit-10.2.1-11.2.el7.i686.rpm devtoolset-10-libgccjit-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libgccjit-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libgccjit-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libgccjit-docs-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libitm-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libitm-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-liblsan-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libquadmath-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libquadmath-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libstdc++-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libstdc++-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libstdc++-docs-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libtsan-devel-10.2.1-11.2.el7.x86_64.rpm devtoolset-10-libubsan-devel-10.2.1-11.2.el7.i686.rpm devtoolset-10-libubsan-devel-10.2.1-11.2.el7.x86_64.rpm libasan6-10.2.1-11.2.el7.i686.rpm libasan6-10.2.1-11.2.el7.x86_64.rpm liblsan-10.2.1-11.2.el7.x86_64.rpm libtsan-10.2.1-11.2.el7.x86_64.rpm libubsan1-10.2.1-11.2.el7.i686.rpm libubsan1-10.2.1-11.2.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2021-42574 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2021-007 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYX+dgNzjgjWX9erEAQh1ng/+KfHZZVGBNpHlFb8SXUezGupFvsWm6JXL fw94jqsWnRWpK97aV/7PJVR0+/o2xDzI8zDZJmukQNyYhoG94Mhy0QuHM9Jt9pWf 0Xj7JLYhIi+rP0PqbzoeKJ+XZWSlfm+h2DZVf9nFwpKZnbrRpersKYu51wWVcMNI agB26pbmKL/5VR8/Y1UI4dzehZ5dkgAZWYiroL7Ec9HbkKFTSk6umvqWrbzQLb6I wnbn17ot0G1hAOoXjDGTruMSBXZqHw6U9QZLFzLy6XRoDxkiLDTqqAOO6mcDjKRC j58mH8ULeKtfd8NzuC1ldOWzXhJAkno2Kd+c/JwZ1PhMcGKJQrg/nWY+sqyCMoXn YoMO6SvlcHLe4Fr0lp428uf1lDpD9q4NgAxKLaIRdlhJKSrbqDUDRycwuCVu21dk 5gqaM6lRxvtA77yTOZi1RYu9eoIIOc7qib+bTvcoEnMjxs1hS4jAWS5+TLdvzXfu HbibKadGtfHveWcYt6b4y9Wu9TJPiFbMUu80ytSooP1BY9mnZ79JzEP+wmDCb8/+ IVvQuN1a/hq4/FbPwHDtAO/mBr2ndDlqy2qd74N2dlRpYTJeG8yHh9PDhx2NU7AR lMjPc9aynS/gHAMkvDQzGA0o2bZTfu/5lCkSHz7HlBgjPYuI6oWhqgn8voLjtPq6 sRRx46jlqlE=Zfa/ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A significant patch for devtoolset-10-gcc resolves BiDi Unicode flaws and improves development resources.. Red Hat, Devtoolset-10-GCC, Unicode Attack, Security Fix, Security Update. . LinuxSecurity.com Team

Calendar%202 Nov 01, 2021 Red Hat
89

Fedora 24 Security Update: pcre Buffer Overflow Remediation

This release fixes a crash when finding a Unicode property for a character with a code point greater than 0x10ffff in UTF-32 library while UTF mode is disabled and JIT mde enabled. It also fixes a buffer overlflow in pcretest tool when copying a string in UTF-32 mode.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-3b367c896f 2017-05-09 21:16:27.649666 --------------------------------------------------------------------------------Name : pcre Product : Fedora 24 Version : 8.40 Release : 7.fc24 URL : Summary : Perl-compatible regular expression library Description : PCRE, Perl-compatible regular expression, library has its own native API, but a set of wrapper functions that are based on the POSIX API are also supplied in the libpcreposix library. Note that this just provides a POSIX calling interface to PCRE: the regular expressions themselves still follow Perl syntax and semantics. Detailed change log is provided by pcre-doc package. --------------------------------------------------------------------------------Update Information: This release fixes a crash when finding a Unicode property for a character with a code point greater than 0x10ffff in UTF-32 library while UTF mode is disabled and JIT mde enabled. It also fixes a buffer overlflow in pcretest tool when copying a string in UTF-32 mode. --------------------------------------------------------------------------------References: [ 1 ] Bug #1434504 - CVE-2017-7186 pcre: Invalid Unicode property lookup (8.41/7, 10.24/2) https://bugzilla.redhat.com/show_bug.cgi?id=1434504 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade pcre' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with theFedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance system security by applying the essential patch for the pcre library on Fedora 24. This update fixes vital Unicode issues and mitigates buffer overflow risks. pcre update,Fedora security fix,buffer overflow,unicode error. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 10, 2017 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200