Category Archives: Advisories

rust-bat-0.21.0-6.fc36 rust-cargo-c-0.9.12-3.fc36 rust-exa-0.10.1-9.fc36 rust-git-delta-0.13.0-4.fc36 rust-gitui-0.20.1-6.fc36 rust-pore-0.1.8-2.fc36 rust-pretty-git-prompt-0.2.1-15.fc36 rust-rd-agent-2.1.2-7.fc36 rust-rd-hashd-2.1.2-7.fc36 rust-resctl-bench-2.1.2-8.fc36 rust-resctl-demo-2.1.2-8.fc36 rust-silver-2.0.1-4.fc36 rust-tokei-12.1.2-4.fc36

Read Time:48 Second

FEDORA-2023-3ec32f6d4e

Packages in this update:

rust-bat-0.21.0-6.fc36
rust-cargo-c-0.9.12-3.fc36
rust-exa-0.10.1-9.fc36
rust-git-delta-0.13.0-4.fc36
rust-gitui-0.20.1-6.fc36
rust-pore-0.1.8-2.fc36
rust-pretty-git-prompt-0.2.1-15.fc36
rust-rd-agent-2.1.2-7.fc36
rust-rd-hashd-2.1.2-7.fc36
rust-resctl-bench-2.1.2-8.fc36
rust-resctl-demo-2.1.2-8.fc36
rust-silver-2.0.1-4.fc36
rust-tokei-12.1.2-4.fc36

Update description:

This update contains rebuilds of all Rust applications against versions of the libgit2-sys crate that ship fixes for CVE-2022-24765 and CVE-2022-29187 in the bundled copies of libgit2.

Updates pore to 0.1.8

Speed up update_remote_refs
Fall back to /etc/pore.toml if it exists.

Read More

rust-bat-0.21.0-6.fc37 rust-cargo-c-0.9.12-3.fc37 rust-exa-0.10.1-9.fc37 rust-git-delta-0.13.0-4.fc37 rust-gitui-0.20.1-6.fc37 rust-pore-0.1.8-2.fc37 rust-pretty-git-prompt-0.2.1-15.fc37 rust-rd-agent-2.1.2-7.fc37 rust-rd-hashd-2.1.2-7.fc37 rust-resctl-bench-2.1.2-8.fc37 rust-resctl-demo-2.1.2-8.fc37 rust-silver-2.0.1-4.fc37 rust-tokei-12.1.2-4.fc37

Read Time:48 Second

FEDORA-2023-e3c8abd37e

Packages in this update:

rust-bat-0.21.0-6.fc37
rust-cargo-c-0.9.12-3.fc37
rust-exa-0.10.1-9.fc37
rust-git-delta-0.13.0-4.fc37
rust-gitui-0.20.1-6.fc37
rust-pore-0.1.8-2.fc37
rust-pretty-git-prompt-0.2.1-15.fc37
rust-rd-agent-2.1.2-7.fc37
rust-rd-hashd-2.1.2-7.fc37
rust-resctl-bench-2.1.2-8.fc37
rust-resctl-demo-2.1.2-8.fc37
rust-silver-2.0.1-4.fc37
rust-tokei-12.1.2-4.fc37

Update description:

This update contains rebuilds of all Rust applications against versions of the libgit2-sys crate that ship fixes for CVE-2022-24765 and CVE-2022-29187 in the bundled copies of libgit2.

Updates pore to 0.1.8

Speed up update_remote_refs
Fall back to /etc/pore.toml if it exists.

Read More

CVE-2019-25053

Read Time:9 Second

A path traversal vulnerability exists in Sage FRP 1000 before November 2019. This allows remote unauthenticated attackers to access files outside of the web tree via a crafted URL.

Read More

USN-5831-1: Linux kernel (Azure CVM) vulnerabilities

Read Time:48 Second

Kyle Zeng discovered that the sysctl implementation in the Linux kernel
contained a stack-based buffer overflow. A local attacker could use this to
cause a denial of service (system crash) or execute arbitrary code.
(CVE-2022-4378)

Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation
in the Linux kernel contained multiple use-after-free vulnerabilities. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2022-42896)

It was discovered that the Xen netback driver in the Linux kernel did not
properly handle packets structured in certain ways. An attacker in a guest
VM could possibly use this to cause a denial of service (host NIC
availability). (CVE-2022-3643)

It was discovered that an integer overflow vulnerability existed in the
Bluetooth subsystem in the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (system crash).
(CVE-2022-45934)

Read More

USN-5830-1: Linux kernel vulnerabilities

Read Time:50 Second

It was discovered that the NFSD implementation in the Linux kernel did not
properly handle some RPC messages, leading to a buffer overflow. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2022-43945)

Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation
in the Linux kernel contained multiple use-after-free vulnerabilities. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2022-42896)

It was discovered that the Xen netback driver in the Linux kernel did not
properly handle packets structured in certain ways. An attacker in a guest
VM could possibly use this to cause a denial of service (host NIC
availability). (CVE-2022-3643)

It was discovered that an integer overflow vulnerability existed in the
Bluetooth subsystem in the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (system crash).
(CVE-2022-45934)

Read More