Maintenance release with fix for CVE-2023-28686 and bug fixes.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-ea6b94395f 2023-04-01 00:15:35.161502 --------------------------------------------------------------------------------Name : dino Product : Fedora 38 Version : 0.4.2 Release : 1.fc38 URL : https://github.com/dino/dino Summary : Modern XMPP ("Jabber") Chat Client using GTK+/Vala Description : A modern XMPP ("Jabber") chat client using GTK+/Vala. --------------------------------------------------------------------------------Update Information: Maintenance release with fix for CVE-2023-28686 and bug fixes. --------------------------------------------------------------------------------ChangeLog: --------------------------------------------------------------------------------References: [ 1 ] Bug #2181357 - CVE-2023-28686 dino: Insufficient message sender validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2181357 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ea6b94395f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
During the SSHv2 handshake when libssh2 is to get a suitable value for 'group order' in the Diffle Hellman negotiation, it would pass in number of bytes to a function that expected number of bits. This would result in the library generating numbers using only an 8th the number of random bits than what were intended: 128 or 256 bits instead of 1023 or 2047 Using such drastically. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-7942ee2cc5 2016-03-09 20:10:36.386658 -------------------------------------------------------------------------------- Name : libssh2 Product : Fedora 22 Version : 1.5.0 Release : 2.fc22 URL : https://libssh2.org/ Summary : A library implementing the SSH2 protocol Description : libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS(22), SECSH-USERAUTH(25), SECSH-CONNECTION(23), SECSH-ARCH(20), SECSH-FILEXFER(06)*, SECSH-DHGEX(04), and SECSH-NUMBERS(10). -------------------------------------------------------------------------------- Update Information: During the SSHv2 handshake when libssh2 is to get a suitable value for 'group order' in the Diffle Hellman negotiation, it would pass in number of bytes to a function that expected number of bits. This would result in the library generating numbers using only an 8th the number of random bits than what were intended: 128 or 256 bits instead of 1023 or 2047 Using such drastically reduced amount of random bits for Diffie Hellman weakened the handshake security significantly. The Common Vulnerabilities and Exposures (CVE) project has assigned the name CVE-2016-0787 to this issue. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1306021 - CVE-2016-0787 libssh2: bits/bytes confusion resulting in truncated Diffie-Hellman secret length https://bugzilla.redhat.com/show_bug.cgi?id=1306021 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libssh2' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Important: tomcat6 security update. Date: Tue, 28 May 2013 19:42:46 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: tomcat6 on SL6.x (noarch) MIME-Version: 1.0 Synopsis: Important: tomcat6 security update Advisory ID: SLSA-2013:0869-1 Issue Date: 2013-05-28 CVE Numbers: CVE-2013-1976 CVE-2013-2051 -- A flaw was found in the way the tomcat6 init script handled the tomcat6-initd.log log file. A malicious web application deployed on Tomcat could use this flaw to perform a symbolic link attack to change the ownership of an arbitrary system file to that of the tomcat user, allowing them to escalate their privileges to root. (CVE-2013-1976) Note: With this update, tomcat6-initd.log has been moved from /var/log/tomcat6/ to the /var/log/ directory. It was found that the SLSA-2013:0623 update did not correctly fix CVE-2012-5887, a weakness in the Tomcat DIGEST authentication implementation. A remote attacker could use this flaw to perform replay attacks in some circumstances. Additionally, this problem also prevented users from being able to authenticate using DIGEST authentication. (CVE-2013-2051) Tomcat must be restarted for this update to take effect. -- SL6 noarch tomcat6-6.0.24-55.el6_4.noarch.rpm tomcat6-admin-webapps-6.0.24-55.el6_4.noarch.rpm tomcat6-docs-webapp-6.0.24-55.el6_4.noarch.rpm tomcat6-el-2.1-api-6.0.24-55.el6_4.noarch.rpm tomcat6-javadoc-6.0.24-55.el6_4.noarch.rpm tomcat6-jsp-2.1-api-6.0.24-55.el6_4.noarch.rpm tomcat6-lib-6.0.24-55.el6_4.noarch.rpm tomcat6-servlet-2.5-api-6.0.24-55.el6_4.noarch.rpm tomcat6-webapps-6.0.24-55.el6_4.noarch.rpm - Scientific Linux Development Team . Important tomcat6 security notice for Scientific Linux SL6.x confronting various vulnerabilities and increasing risks.. tomcat6 Security Update, Scientific Linux Advisory, Privilege Escalation Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.