Multiple stack-based buffer overflows have been fixed in the net-tools network utilities. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4202-1
- New upstream version (83.0). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-f9f7305137 2020-11-19 01:27:53.541679 --------------------------------------------------------------------------------Name : firefox Product : Fedora 33 Version : 83.0 Release : 3.fc33 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. --------------------------------------------------------------------------------Update Information: - New upstream version (83.0) --------------------------------------------------------------------------------ChangeLog: * Fri Nov 13 2020 Martin Stransky - 83.0-3 - Updated to 83.0 Build 2 * Thu Nov 12 2020 Martin Stransky - 83.0-1 - Updated to 83.0 - Updated PipeWire patches from mozbz#1672944 * Tue Nov 10 2020 Martin Stransky - 82.0.3-2 - Added fix for mozbz#1885133 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-f9f7305137' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
openSUSE: openSUSE Leap 42.3 has reached end of SUSE support. Hi all, With the release of release-notes-openSUSE on July 1st, 2019 the SUSE sponsored maintenance of openSUSE Leap 42.3 has ended. openSUSE Leap 42.3 is now officially discontinued and out of support by SUSE. The currently maintained stable release are openSUSE Leap 15.0 and 15.1, which will be maintained until Nov 2019 / Nov 2020. See Upgrading is easy. See the links below for instructions: Customers using Leap 42.3 workloads can also consider migrate to SUSE Linux Enterprise 12 SP4 if they are not able to upgrade to openSUSE Leap 15. openSUSE Leap 42.3 was released in July 2017, making it 24 months of security and bugfix support. It was the third hybrid distribution which used sources from SUSE Linux Enterprise and from our community developers to bridge a gap between matured packages and newer packages found in openSUSE Tumbleweed. Some statistics on the released patches (compared to Leap 42.2), (reminder that 42.2 had 14 months of support runtime, while leap 42.3 had 24). Agenda: current number (42.2 number / total diff / weighted diff 14/24) Total updates: 1734 (1286 / +448 / -275) Updates imported from SUSE Linux Enterprise: 994 (648 / +146 / -70) Updates provided by community developers: 740 (638 / +102 / -207) Security: 901 (569 / + 332 / -44) Recommended: 794 (677 / +114 / -216) Optional: 37 (39 / -2 / -18) Feature: 2 (1 / +1 / +1) Fixed CVE-entries: 3181 (2239 / +942 / -384) Fixed Bugs (overall): 5355 (3887 / +1468 / -764) A huge thanks to our awesome packagers, community, and all involved people, who made the next great release possible! Your maintenance- and security-team . OpenSUSE Leap 42.3 has concluded its support; explore updating and migration choices for continued security.. openSUSE, support end, version upgrade, security patches, release management. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. It An update that fixes one vulnerability is now available. It An update that fixes one vulnerability is now available. It includes one version update. includes one version update.. SUSE Security Update: Security update for bind ______________________________________________________________________________ Announcement ID: SUSE-SU-2012:1390-1 Rating: important References: #784602 Cross-References: CVE-2012-5166 Affected Products: SUSE Linux Enterprise Software Development Kit 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP1 LTSS SUSE Linux Enterprise Server 10 SP4 SUSE Linux Enterprise Server 10 SP3 LTSS SUSE Linux Enterprise Desktop 11 SP2 SUSE Linux Enterprise Desktop 10 SP4 SLE SDK 10 SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. It includes one version update. Description: The following issue has been fixed: * Specially crafted RDATA could have caused bind to lockup. This was a different flaw than CVE-2012-4244. Security Issue reference: * CVE-2012-5166 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP2: zypper in -t patch sdksp2-bind-6944 - SUSE Linux Enterprise Server 11 SP2 for VMware: zypper in -t patch slessp2-bind-6944 - SUSE Linux Enterprise Server 11 SP2: zypper in -t patch slessp2-bind-6944 - SUSE Linux Enterprise Server 11 SP1 LTSS: zypper in -t patch slessp1-bind-6980 - SUSE Linux Enterprise Desktop 11 SP2: zypper in -tpatch sledsp2-bind-6944 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 9.6ESVR7P4]: bind-devel-9.6ESVR7P4-0.8.1 - SUSE Linux Enterprise Software Development Kit 11 SP2 (ppc64) [New Version: 9.6ESVR7P4]: bind-devel-32bit-9.6ESVR7P4-0.8.1 - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64) [New Version: 9.6ESVR7P4]: bind-9.6ESVR7P4-0.8.1 bind-chrootenv-9.6ESVR7P4-0.8.1 bind-doc-9.6ESVR7P4-0.8.1 bind-libs-9.6ESVR7P4-0.8.1 bind-utils-9.6ESVR7P4-0.8.1 - SUSE Linux Enterprise Server 11 SP2 for VMware (x86_64) [New Version: 9.6ESVR7P4]: bind-libs-32bit-9.6ESVR7P4-0.8.1 - SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 9.6ESVR7P4]: bind-9.6ESVR7P4-0.8.1 bind-chrootenv-9.6ESVR7P4-0.8.1 bind-doc-9.6ESVR7P4-0.8.1 bind-libs-9.6ESVR7P4-0.8.1 bind-utils-9.6ESVR7P4-0.8.1 - SUSE Linux Enterprise Server 11 SP2 (ppc64 s390x x86_64) [New Version: 9.6ESVR7P4]: bind-libs-32bit-9.6ESVR7P4-0.8.1 - SUSE Linux Enterprise Server 11 SP2 (ia64) [New Version: 9.6ESVR7P4]: bind-libs-x86-9.6ESVR7P4-0.8.1 - SUSE Linux Enterprise Server 11 SP1 LTSS (i586 s390x x86_64) [New Version: 9.6ESVR7P4]: bind-9.6ESVR7P4-0.2.3.1 bind-chrootenv-9.6ESVR7P4-0.2.3.1 bind-doc-9.6ESVR7P4-0.2.3.1 bind-libs-9.6ESVR7P4-0.2.3.1 bind-utils-9.6ESVR7P4-0.2.3.1 - SUSE Linux Enterprise Server 11 SP1 LTSS (s390x x86_64) [New Version: 9.6ESVR7P4]: bind-libs-32bit-9.6ESVR7P4-0.2.3.1 - SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x x86_64) [New Version: 9.6ESVR7P4]: bind-9.6ESVR7P4-0.7.1 bind-chrootenv-9.6ESVR7P4-0.7.1 bind-devel-9.6ESVR7P4-0.7.1 bind-doc-9.6ESVR7P4-0.7.1 bind-libs-9.6ESVR7P4-0.7.1 bind-utils-9.6ESVR7P4-0.7.1 - SUSE Linux Enterprise Server 10 SP4 (s390x x86_64) [NewVersion: 9.6ESVR7P4]: bind-libs-32bit-9.6ESVR7P4-0.7.1 - SUSE Linux Enterprise Server 10 SP4 (ia64) [New Version: 9.6ESVR7P4]: bind-libs-x86-9.6ESVR7P4-0.7.1 - SUSE Linux Enterprise Server 10 SP4 (ppc) [New Version: 9.6ESVR7P4]: bind-devel-64bit-9.6ESVR7P4-0.7.1 bind-libs-64bit-9.6ESVR7P4-0.7.1 - SUSE Linux Enterprise Server 10 SP3 LTSS (i586 s390x x86_64): bind-9.3.4-1.42.1 bind-chrootenv-9.3.4-1.42.1 bind-devel-9.3.4-1.42.1 bind-doc-9.3.4-1.42.1 bind-libs-9.3.4-1.42.1 bind-utils-9.3.4-1.42.1 - SUSE Linux Enterprise Server 10 SP3 LTSS (s390x x86_64): bind-libs-32bit-9.3.4-1.42.1 - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 9.6ESVR7P4]: bind-libs-9.6ESVR7P4-0.8.1 bind-utils-9.6ESVR7P4-0.8.1 - SUSE Linux Enterprise Desktop 11 SP2 (x86_64) [New Version: 9.6ESVR7P4]: bind-libs-32bit-9.6ESVR7P4-0.8.1 - SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64) [New Version: 9.6ESVR7P4]: bind-libs-9.6ESVR7P4-0.7.1 bind-utils-9.6ESVR7P4-0.7.1 - SUSE Linux Enterprise Desktop 10 SP4 (x86_64) [New Version: 9.6ESVR7P4]: bind-libs-32bit-9.6ESVR7P4-0.7.1 - SLE SDK 10 SP4 (i586 ia64 ppc s390x x86_64) [New Version: 9.6ESVR7P4]: bind-9.6ESVR7P4-0.7.1 bind-chrootenv-9.6ESVR7P4-0.7.1 bind-devel-9.6ESVR7P4-0.7.1 bind-doc-9.6ESVR7P4-0.7.1 - SLE SDK 10 SP4 (ppc) [New Version: 9.6ESVR7P4]: bind-devel-64bit-9.6ESVR7P4-0.7.1 References: https://www.suse.com/security/cve/CVE-2012-5166.html https://login.microfocus.com/nidp/app/login?sid=0 https://login.microfocus.com/nidp/app/login?sid=0 https://login.microfocus.com/nidp/app/login?sid=0 https://login.microfocus.com/nidp/app/login?sid=0 https://login.microfocus.com/nidp/app/login?sid=0 . SUSE addresses critical binding freeze problem with a significant upgrade; make certain your devices are fortified with the newest updates!. SUSE Bind Security Update, Important BindPatch, Bind Lockup Issue. . Severity: Important. LinuxSecurity.com Team
A vulnerability has been found in Atheme which may lead to Denial of Service or a bypass of security restrictions.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201209-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Atheme IRC Services: Denial of Service Date: September 25, 2012 Bugs: #409103 ID: 201209-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been found in Atheme which may lead to Denial of Service or a bypass of security restrictions. Background ========= Atheme is a portable and secure set of open-source and modular IRC services. CertFP is certificate fingerprinting used to authenticate users to nicknames. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-irc/atheme-services < 6.0.10 > = 6.0.10 Description ========== The myuser_delete() function in account.c does not properly remove CertFP entries when deleting user accounts. Impact ===== A remote authenticated attacker may be able to cause a Denial of Service condition or gain access to an Atheme IRC Services user account. Workaround ========= There is no known workaround at this time. Resolution ========= All Atheme users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-irc/atheme-services-6.0.10" References ========= [ 1 ] CVE-2012-1576 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1576 Availability =========== This GLSA and any updates to it are available for viewing at the GentooSecurity Website: https://security.gentoo.org/glsa/201209-09 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.