- update to latest upstream release (fixes CVE-2021-45444). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-0a06987c3c 2022-02-22 02:58:18.425583 --------------------------------------------------------------------------------Name : zsh Product : Fedora 34 Version : 5.8.1 Release : 1.fc34 URL : https://zsh.sourceforge.io/ Summary : Powerful interactive shell Description : The zsh shell is a command interpreter usable as an interactive login shell and as a shell script command processor. Zsh resembles the ksh shell (the Korn shell), but includes many enhancements. Zsh supports command line editing, built-in spelling correction, programmable command completion, shell functions (with autoloading), a history mechanism, and more. --------------------------------------------------------------------------------Update Information: - update to latest upstream release (fixes CVE-2021-45444) --------------------------------------------------------------------------------ChangeLog: * Sun Feb 13 2022 Kamil Dudka - 5.8.1-1 - update to latest upstream release (fixes CVE-2021-45444) * Thu Nov 25 2021 Debarshi Ray - 5.8-7 - Overwrite PROMPT only if it's set to the built-in default (#2026749) * Fri Jul 23 2021 Fedora Release Engineering - 5.8-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2054089 - CVE-2021-45444 zsh: Prompt expansion vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2054089 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-0a06987c3c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packagesare signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- drop privileges securely when unsetting PRIVILEGED option (CVE-2019-20044). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-3f38f3e517 2020-03-12 21:55:08.821447 --------------------------------------------------------------------------------Name : zsh Product : Fedora 31 Version : 5.7.1 Release : 6.fc31 URL : https://zsh.sourceforge.io/ Summary : Powerful interactive shell Description : The zsh shell is a command interpreter usable as an interactive login shell and as a shell script command processor. Zsh resembles the ksh shell (the Korn shell), but includes many enhancements. Zsh supports command line editing, built-in spelling correction, programmable command completion, shell functions (with autoloading), a history mechanism, and more. --------------------------------------------------------------------------------Update Information: - drop privileges securely when unsetting PRIVILEGED option (CVE-2019-20044) --------------------------------------------------------------------------------ChangeLog: * Tue Mar 3 2020 Kamil Dudka - 5.7.1-6 - improve printing of error messages introduced by the fix of CVE-2019-20044 * Mon Feb 24 2020 Kamil Dudka - 5.7.1-5 - drop privileges securely when unsetting PRIVILEGED option (CVE-2019-20044) --------------------------------------------------------------------------------References: [ 1 ] Bug #1804860 - CVE-2019-20044 zsh: insecure dropping of privileges when unsetting PRIVILEGED option [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1804860 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-3f38f3e517' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed withthe Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.