An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for nim ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1585-1 Rating: moderate References: #1192712 Cross-References: CVE-2021-41259 CVSS scores: CVE-2021-41259 (NVD) : 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for nim fixes the following issues: - CVE-2021-41259: Fixed vulnerability in URL parser that allowed a null byte bypass (boo#1192712) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1585=1 Package List: - openSUSE Leap 15.2 (x86_64): nim-1.2.12-lp152.2.6.1 nim-debuginfo-1.2.12-lp152.2.6.1 References: https://www.suse.com/security/cve/CVE-2021-41259.html https://bugzilla.suse.com/1192712 . The latest update for openSUSE addresses a security flaw in nim's URL parser. Users are encouraged to apply the patch through standard installation procedures.. openSUSE Updates, Nim Security Patch, Security Vulnerability Fix. . LinuxSecurity.com Team
Backport fix for CVE-2021-33503.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-b14975e43d 2021-06-19 01:08:02.703506 --------------------------------------------------------------------------------Name : mingw-python-urllib3 Product : Fedora 34 Version : 1.25.10 Release : 3.fc34 URL : https://urllib3.readthedocs.io/en/latest/ Summary : MinGW Windows Python urllib3 Description : MinGW Windows Python urllib3. --------------------------------------------------------------------------------Update Information: Backport fix for CVE-2021-33503. --------------------------------------------------------------------------------ChangeLog: * Thu Jun 10 2021 Sandro Mani - 1.25.10-3 - Backport fix for CVE-2021-33503 --------------------------------------------------------------------------------References: [ 1 ] Bug #1968077 - CVE-2021-33503 mingw-python-urllib3: python-urllib3: Catastrophic backtracking in URL authority parser [fedora-34] https://bugzilla.redhat.com/show_bug.cgi?id=1968077 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-b14975e43d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.