A potential bug is found on libetpan that when IMAP client receives invalid STATUS response, an invalid free can occur on mailimap_mailbox_data_status_free(). This bug is now assigned as CVE-2022-4121. Although the formal fix is under discussion, this update rpm adds a quick fix for this issue.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-f092bc8f7b 2022-12-02 01:19:01.664504 --------------------------------------------------------------------------------Name : libetpan Product : Fedora 37 Version : 1.9.4 Release : 9.fc37 URL : Summary : Portable, efficient middle-ware for different kinds of mail access Description : The purpose of this mail library is to provide a portable, efficient middle-ware for different kinds of mail access. When using the drivers interface, the interface is the same for all kinds of mail access, remote and local mailboxes. --------------------------------------------------------------------------------Update Information: A potential bug is found on libetpan that when IMAP client receives invalid STATUS response, an invalid free can occur on mailimap_mailbox_data_status_free(). This bug is now assigned as CVE-2022-4121. Although the formal fix is under discussion, this update rpm adds a quick fix for this issue. --------------------------------------------------------------------------------ChangeLog: * Wed Nov 23 2022 Mamoru TASAKA - 1.9.4-9 - Workaround for CVE-2022-4121 (bug 2144914) --------------------------------------------------------------------------------References: [ 1 ] Bug #2144915 - libetpan: Null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2144915 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2022-f092bc8f7b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
update to 4.5.3 ---- broken AMD FPU FIP/FDP/FOP leak workaround [XSA-172, CVE-2016-3158, CVE-2016-3159]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-e5432ca977 2016-04-09 10:22:58.046533 -------------------------------------------------------------------------------- Name : xen Product : Fedora 23 Version : 4.5.3 Release : 1.fc23 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: update to 4.5.3 ---- broken AMD FPU FIP/FDP/FOP leak workaround [XSA-172, CVE-2016-3158, CVE-2016-3159] -------------------------------------------------------------------------------- References: [ 1 ] Bug #1317969 - CVE-2016-3158 CVE-2016-3159 xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172) https://bugzilla.redhat.com/show_bug.cgi?id=1317969 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update xen' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
update to 4.5.3 ---- broken AMD FPU FIP/FDP/FOP leak workaround [XSA-172, CVE-2016-3158, CVE-2016-3159]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-5f196e4e4a 2016-04-09 10:20:41.903381 -------------------------------------------------------------------------------- Name : xen Product : Fedora 22 Version : 4.5.3 Release : 1.fc22 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: update to 4.5.3 ---- broken AMD FPU FIP/FDP/FOP leak workaround [XSA-172, CVE-2016-3158, CVE-2016-3159] -------------------------------------------------------------------------------- References: [ 1 ] Bug #1317969 - CVE-2016-3158 CVE-2016-3159 xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172) https://bugzilla.redhat.com/show_bug.cgi?id=1317969 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update xen' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
#136455 workaround to prevent gdb from failing and getting stuck when hitting certain DWARF-2 symbols.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-427 2004-11-12 --------------------------------------------------------------------- Product : Fedora Core 3 Name : gdb Version : 6.1post Release : 1.20040607.43 Summary : A GNU source-level debugger for C, C++ and other languages. Description : GDB, the GNU debugger, allows you to debug programs written in C, C++, and other languages, by executing them in a controlled fashion and printing their data. --------------------------------------------------------------------- #136455 workaround to prevent gdb from failing and getting stuck when hitting certain DWARF-2 symbols. --------------------------------------------------------------------- * Tue Oct 26 2004 Andrew Cagney 1.200400607.43 - Hack around broken PT_FPSCR defined in headers. - Import latest s390 fixes. - Disable sigstep.exp - s390 has problems. - Use PC's symtab when looking for a symbol. - Work around DW_OP_piece. * Fri Oct 22 2004 Andrew Cagney 1.200400607.42 - For 64-bit PPC, convert _dl_debug_state descriptor into a code address. - Fix --ignore option. --------------------------------------------------------------------- This update can be downloaded from: f2378ff5d82d43098fc741f5b4efe4a2 SRPMS/gdb-6.1post-1.20040607.43.src.rpm 5d9d8ecab4c0b70bd308d3ceb30c8026 x86_64/gdb-6.1post-1.20040607.43.x86_64.rpm 8b02a26c1fb8e85ad43e77735eade9e7 x86_64/debug/gdb-debuginfo-6.1post-1.20040607.43.x86_64.rpm 094cb2c74acc9b8b9be0b361dd79abeb i386/gdb-6.1post-1.20040607.43.i386.rpm 49c48b93df53d8f67589d988e925f27e i386/debug/gdb-debuginfo-6.1post-1.20040607.43.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- -- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.