Category Archives: Advisories

USN-6566-2: SQLite vulnerability

Read Time:18 Second

USN-6566-1 fixed several vulnerabilities in SQLite. This update provides
the corresponding fix for CVE-2023-7104 for Ubuntu 18.04 LTS.

Original advisory details:

It was discovered that SQLite incorrectly handled certain memory operations
in the sessions extension. A remote attacker could possibly use this issue
to cause SQLite to crash, resulting in a denial of service.

Read More

rust-blowfish-0.9.1-2.el9 rust-dsa-0.6.3-1.el9 rust-num-bigint-dig-0.8.4-1.el9 rust-rand_isaac-0.3.0-6.el9 rust-rsa-0.9.6-2.el9 rust-sequoia-gpg-agent-0.4.2-1.el9 rust-sequoia-keystore-0.5.1-1.el9 rust-sequoia-openpgp-1.21.1-1.el9 rust-sequoia-sq-0.37.0-3.el9

Read Time:42 Second

FEDORA-EPEL-2024-5292ca934e

Packages in this update:

rust-blowfish-0.9.1-2.el9
rust-dsa-0.6.3-1.el9
rust-num-bigint-dig-0.8.4-1.el9
rust-rand_isaac-0.3.0-6.el9
rust-rsa-0.9.6-2.el9
rust-sequoia-gpg-agent-0.4.2-1.el9
rust-sequoia-keystore-0.5.1-1.el9
rust-sequoia-openpgp-1.21.1-1.el9
rust-sequoia-sq-0.37.0-3.el9

Update description:

Update the sequoia-openpgp crate to version 1.21.1. Addresses RUSTSEC-2024-0345.
Update the sequoia-keystore crate to version 0.5.1.
Update the sequoia-gpg-agent crate to version 0.4.2.

This update also includes rebuilds of all affected applications that are affected by RUSTSEC-2024-0345 and a regression in sequoia-openpgp 1.21.0.

Read More

rust-sequoia-chameleon-gnupg-0.10.0-3.fc39 rust-sequoia-gpg-agent-0.4.2-1.fc39 rust-sequoia-keystore-0.5.1-1.fc39 rust-sequoia-openpgp-1.21.1-1.fc39 rust-sequoia-sq-0.37.0-3.fc39

Read Time:33 Second

FEDORA-2024-029752e60b

Packages in this update:

rust-sequoia-chameleon-gnupg-0.10.0-3.fc39
rust-sequoia-gpg-agent-0.4.2-1.fc39
rust-sequoia-keystore-0.5.1-1.fc39
rust-sequoia-openpgp-1.21.1-1.fc39
rust-sequoia-sq-0.37.0-3.fc39

Update description:

Update the sequoia-openpgp crate to version 1.21.1. Addresses RUSTSEC-2024-0345.
Update the sequoia-keystore crate to version 0.5.1.
Update the sequoia-gpg-agent crate to version 0.4.2.

This update also includes rebuilds of all affected applications that are affected by RUSTSEC-2024-0345 and a regression in sequoia-openpgp 1.21.0.

Read More

rust-sequoia-chameleon-gnupg-0.10.0-3.fc40 rust-sequoia-gpg-agent-0.4.2-1.fc40 rust-sequoia-keystore-0.5.1-1.fc40 rust-sequoia-openpgp-1.21.1-1.fc40 rust-sequoia-sq-0.37.0-3.fc40

Read Time:33 Second

FEDORA-2024-12f0caa904

Packages in this update:

rust-sequoia-chameleon-gnupg-0.10.0-3.fc40
rust-sequoia-gpg-agent-0.4.2-1.fc40
rust-sequoia-keystore-0.5.1-1.fc40
rust-sequoia-openpgp-1.21.1-1.fc40
rust-sequoia-sq-0.37.0-3.fc40

Update description:

Update the sequoia-openpgp crate to version 1.21.1. Addresses RUSTSEC-2024-0345.
Update the sequoia-keystore crate to version 0.5.1.
Update the sequoia-gpg-agent crate to version 0.4.2.

This update also includes rebuilds of all affected applications that are affected by RUSTSEC-2024-0345 and a regression in sequoia-openpgp 1.21.0.

Read More

USN-6851-1: Netplan vulnerabilities

Read Time:17 Second

Andreas Hasenack discovered that netplan incorrectly handled the permissions
for netdev files containing wireguard configuration. An attacker could use this to obtain
wireguard secret keys.

It was discovered that netplan configuration could be manipulated into injecting
arbitrary commands while setting up network interfaces. An attacker could
use this to execute arbitrary commands or escalate privileges.

Read More