FEDORA-2022-5f746c8e5b
Packages in this update:
golang-github-containerd-imgcrypt-1.1.4-1.fc35
Update description:
Update to 1.1.4 (rhbz#2068719). Mitigates CVE-2022-24778 (rhbz#2069368, rhbz#2069369).
golang-github-containerd-imgcrypt-1.1.4-1.fc35
Update to 1.1.4 (rhbz#2068719). Mitigates CVE-2022-24778 (rhbz#2069368, rhbz#2069369).
golang-github-containerd-imgcrypt-1.1.4-1.fc36
Update to 1.1.4 (rhbz#2068719). Mitigates CVE-2022-24778 (rhbz#2069368, rhbz#2069369).
golang-github-containerd-imgcrypt-1.1.4-1.fc37
Automatic update for golang-github-containerd-imgcrypt-1.1.4-1.fc37.
* Sat Apr 2 2022 Maxwell G <gotmax@e.email> 1.1.4-1
– Update to 1.1.4 (rhbz#2068719). Mitigates CVE-2022-24778 (rhbz#2069368,
rhbz#2069369)
Multiple security issues were discovered in Chromium, which could result
in the execution of arbitrary code, denial of service or information
disclosure.
unrealircd-6.0.3-1.el8
A number of serious issues were discovered in UnrealIRCd 6. Among these is an issue which will likely crash the IRCd sooner or later if you /REHASH with any active clients connected.
Crash in WATCH if the IRCd has been rehashed at least once. After doing a REHASH with active clients it will likely corrupt memory. It may take several days until after the rehash for the crash to occur, or even weeks/months on smaller networks (accidental triggering, that is).
A REHASH with certain remote includes setups could cause a crash or other weird and confusing problems such as complaining about unable to open an ipv6-database or missing snomask configuration. This only affected some people with remote includes, not all.
Potential out-of-bounds write in sending code. In practice it seems harmless on most servers but this cannot be 100% guaranteed.
Unlikely triggered log message would log uninitialized stack data to the log file or send it to ircops.
Channel ops could not remove halfops from a user (-h).
After using the RESTART command (not recommended) the new IRCd was often no longer writing to log files.
Fix compile problem if you choose to use cURL remote includes but don’t have cURL on the system and ask UnrealIRCd to compile cURL.
The default text log format on disk changed. It now includes the server name where the event was generated. Without this, it was sometimes difficult to trace problems, since previously it sometimes looked like there was a problem on your server when it was actually another server on the network.
Old log format: [DATE TIME] subsystem.EVENT_ID loglevel: ……..
New log format: [DATE TIME] servername subsystem.EVENT_ID loglevel: ……..
Any MOTD lines added by services via SVSMOTD are now shown at the end of the MOTD-on-connect (unless using a shortmotd). Previously the lines were only shown if you manually ran the MOTD command.
LIST C<xx now means: filter on channels that are created less than xx minutes ago. This is the opposite of what we had earlier. LIST T<xx is now supported as well (topic changed in last xx minutes), it was already advertised in ELIST but support was not enabled previously.
unrealircd-6.0.3-1.el7
A number of serious issues were discovered in UnrealIRCd 6. Among these is an issue which will likely crash the IRCd sooner or later if you /REHASH with any active clients connected.
Crash in WATCH if the IRCd has been rehashed at least once. After doing a REHASH with active clients it will likely corrupt memory. It may take several days until after the rehash for the crash to occur, or even weeks/months on smaller networks (accidental triggering, that is).
A REHASH with certain remote includes setups could cause a crash or other weird and confusing problems such as complaining about unable to open an ipv6-database or missing snomask configuration. This only affected some people with remote includes, not all.
Potential out-of-bounds write in sending code. In practice it seems harmless on most servers but this cannot be 100% guaranteed.
Unlikely triggered log message would log uninitialized stack data to the log file or send it to ircops.
Channel ops could not remove halfops from a user (-h).
After using the RESTART command (not recommended) the new IRCd was often no longer writing to log files.
Fix compile problem if you choose to use cURL remote includes but don’t have cURL on the system and ask UnrealIRCd to compile cURL.
The default text log format on disk changed. It now includes the server name where the event was generated. Without this, it was sometimes difficult to trace problems, since previously it sometimes looked like there was a problem on your server when it was actually another server on the network.
Old log format: [DATE TIME] subsystem.EVENT_ID loglevel: ……..
New log format: [DATE TIME] servername subsystem.EVENT_ID loglevel: ……..
Any MOTD lines added by services via SVSMOTD are now shown at the end of the MOTD-on-connect (unless using a shortmotd). Previously the lines were only shown if you manually ran the MOTD command.
LIST C<xx now means: filter on channels that are created less than xx minutes ago. This is the opposite of what we had earlier. LIST T<xx is now supported as well (topic changed in last xx minutes), it was already advertised in ELIST but support was not enabled previously.
unrealircd-6.0.3-1.fc35
A number of serious issues were discovered in UnrealIRCd 6. Among these is an issue which will likely crash the IRCd sooner or later if you /REHASH with any active clients connected.
Crash in WATCH if the IRCd has been rehashed at least once. After doing a REHASH with active clients it will likely corrupt memory. It may take several days until after the rehash for the crash to occur, or even weeks/months on smaller networks (accidental triggering, that is).
A REHASH with certain remote includes setups could cause a crash or other weird and confusing problems such as complaining about unable to open an ipv6-database or missing snomask configuration. This only affected some people with remote includes, not all.
Potential out-of-bounds write in sending code. In practice it seems harmless on most servers but this cannot be 100% guaranteed.
Unlikely triggered log message would log uninitialized stack data to the log file or send it to ircops.
Channel ops could not remove halfops from a user (-h).
After using the RESTART command (not recommended) the new IRCd was often no longer writing to log files.
Fix compile problem if you choose to use cURL remote includes but don’t have cURL on the system and ask UnrealIRCd to compile cURL.
The default text log format on disk changed. It now includes the server name where the event was generated. Without this, it was sometimes difficult to trace problems, since previously it sometimes looked like there was a problem on your server when it was actually another server on the network.
Old log format: [DATE TIME] subsystem.EVENT_ID loglevel: ……..
New log format: [DATE TIME] servername subsystem.EVENT_ID loglevel: ……..
Any MOTD lines added by services via SVSMOTD are now shown at the end of the MOTD-on-connect (unless using a shortmotd). Previously the lines were only shown if you manually ran the MOTD command.
LIST C<xx now means: filter on channels that are created less than xx minutes ago. This is the opposite of what we had earlier. LIST T<xx is now supported as well (topic changed in last xx minutes), it was already advertised in ELIST but support was not enabled previously.
unrealircd-6.0.3-1.fc36
A number of serious issues were discovered in UnrealIRCd 6. Among these is an issue which will likely crash the IRCd sooner or later if you /REHASH with any active clients connected.
Crash in WATCH if the IRCd has been rehashed at least once. After doing a REHASH with active clients it will likely corrupt memory. It may take several days until after the rehash for the crash to occur, or even weeks/months on smaller networks (accidental triggering, that is).
A REHASH with certain remote includes setups could cause a crash or other weird and confusing problems such as complaining about unable to open an ipv6-database or missing snomask configuration. This only affected some people with remote includes, not all.
Potential out-of-bounds write in sending code. In practice it seems harmless on most servers but this cannot be 100% guaranteed.
Unlikely triggered log message would log uninitialized stack data to the log file or send it to ircops.
Channel ops could not remove halfops from a user (-h).
After using the RESTART command (not recommended) the new IRCd was often no longer writing to log files.
Fix compile problem if you choose to use cURL remote includes but don’t have cURL on the system and ask UnrealIRCd to compile cURL.
The default text log format on disk changed. It now includes the server name where the event was generated. Without this, it was sometimes difficult to trace problems, since previously it sometimes looked like there was a problem on your server when it was actually another server on the network.
Old log format: [DATE TIME] subsystem.EVENT_ID loglevel: ……..
New log format: [DATE TIME] servername subsystem.EVENT_ID loglevel: ……..
Any MOTD lines added by services via SVSMOTD are now shown at the end of the MOTD-on-connect (unless using a shortmotd). Previously the lines were only shown if you manually ran the MOTD command.
LIST C<xx now means: filter on channels that are created less than xx minutes ago. This is the opposite of what we had earlier. LIST T<xx is now supported as well (topic changed in last xx minutes), it was already advertised in ELIST but support was not enabled previously.
unrealircd-6.0.3-1.el9
A number of serious issues were discovered in UnrealIRCd 6. Among these is an issue which will likely crash the IRCd sooner or later if you /REHASH with any active clients connected.
Crash in WATCH if the IRCd has been rehashed at least once. After doing a REHASH with active clients it will likely corrupt memory. It may take several days until after the rehash for the crash to occur, or even weeks/months on smaller networks (accidental triggering, that is).
A REHASH with certain remote includes setups could cause a crash or other weird and confusing problems such as complaining about unable to open an ipv6-database or missing snomask configuration. This only affected some people with remote includes, not all.
Potential out-of-bounds write in sending code. In practice it seems harmless on most servers but this cannot be 100% guaranteed.
Unlikely triggered log message would log uninitialized stack data to the log file or send it to ircops.
Channel ops could not remove halfops from a user (-h).
After using the RESTART command (not recommended) the new IRCd was often no longer writing to log files.
Fix compile problem if you choose to use cURL remote includes but don’t have cURL on the system and ask UnrealIRCd to compile cURL.
The default text log format on disk changed. It now includes the server name where the event was generated. Without this, it was sometimes difficult to trace problems, since previously it sometimes looked like there was a problem on your server when it was actually another server on the network.
Old log format: [DATE TIME] subsystem.EVENT_ID loglevel: ……..
New log format: [DATE TIME] servername subsystem.EVENT_ID loglevel: ……..
Any MOTD lines added by services via SVSMOTD are now shown at the end of the MOTD-on-connect (unless using a shortmotd). Previously the lines were only shown if you manually ran the MOTD command.
LIST C<xx now means: filter on channels that are created less than xx minutes ago. This is the opposite of what we had earlier. LIST T<xx is now supported as well (topic changed in last xx minutes), it was already advertised in ELIST but support was not enabled previously.
Multiple vulnerabilities have been discovered in Apple products, the most severe of which could allow for local code execution. Successful exploitation of the most severe vulnerability could allow an attacker to execute code in the context of the kernel. Malicious actors with administrative access may be able to install programs; view, change, or delete data; or create new accounts with full user rights.