Tuesday, August 2, 2022

[CentOS-announce] CESA-2022:5542 Important CentOS 7 squid Security Update

CentOS Errata and Security Advisory 2022:5542 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2022:5542

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
7e0f590ddcedeebdbcdd4b72907bb5cb9affb7ffdc5d55c89e57dfc3eae94eb3 squid-3.5.20-17.el7_9.7.x86_64.rpm
3fe92e24b021f0064189e1c7e735a79fffdf4d33994fb8e504bcdbbd19dacb33 squid-migration-script-3.5.20-17.el7_9.7.x86_64.rpm
af7e93ece536de48118743c25ba2dc36958cb213c049a71bf622da7992e28132 squid-sysvinit-3.5.20-17.el7_9.7.x86_64.rpm

Source:
a18b79865c2da4883896084d1d5997ad6c54232c334a322bf4e59faece98dc1d squid-3.5.20-17.el7_9.7.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@libera.chat
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2022:5698 Important CentOS 7 java-1.8.0-openjdk Security Update

CentOS Errata and Security Advisory 2022:5698 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2022:5698

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
bbc54477e470a694a3032e391624ba33b9753f81d283b60a19dca7c1c52b35c4 java-1.8.0-openjdk-1.8.0.342.b07-1.el7_9.i686.rpm
9c883d2d32a12c3f672b6e40119adf476d62ae4bacb40ce0a88634b864d19701 java-1.8.0-openjdk-1.8.0.342.b07-1.el7_9.x86_64.rpm
086c33b98ecb7adbc59297b29fb3fc219e4beda421611ef17471f6cc8e0a9b6f java-1.8.0-openjdk-accessibility-1.8.0.342.b07-1.el7_9.i686.rpm
89218a788c99c93aaa563b09b3f7b71ed061025bda32116e0f5ad78d034e5d94 java-1.8.0-openjdk-accessibility-1.8.0.342.b07-1.el7_9.x86_64.rpm
96d0ea79b3da11f9b3d85598dae3187e501c54728cd8509492569f9dc2c1670f java-1.8.0-openjdk-demo-1.8.0.342.b07-1.el7_9.i686.rpm
f0c9b7b923d47df8b92aa0c427d4754da9c2d22e9eb87e436c06305406998a3c java-1.8.0-openjdk-demo-1.8.0.342.b07-1.el7_9.x86_64.rpm
e1e1b8adc5317dafcd61f9374708c3ef7388ecd2591a47bb2dfdedc0eee9d389 java-1.8.0-openjdk-devel-1.8.0.342.b07-1.el7_9.i686.rpm
5435c138b53b3d77c61b682fd1142b6ebad9946a7aafbb1f722f6f9a4896a265 java-1.8.0-openjdk-devel-1.8.0.342.b07-1.el7_9.x86_64.rpm
c204a4ffd212c3a27c0afea8e7c43b386fac6da8dfb78049b8fff2cea01ea128 java-1.8.0-openjdk-headless-1.8.0.342.b07-1.el7_9.i686.rpm
5941cfa3708aa1d7eae457e8f0abc55a55d5a84eadb56473770f0a82215aa495 java-1.8.0-openjdk-headless-1.8.0.342.b07-1.el7_9.x86_64.rpm
1724001fdb91ff6c4e1fcf64bccf981017dfd7ab649f21c1333810e6cbd8e9c6 java-1.8.0-openjdk-javadoc-1.8.0.342.b07-1.el7_9.noarch.rpm
707c34f7fa9d4787f56722da43ebdb1458d9855c217691d5688c6bde0306a2b7 java-1.8.0-openjdk-javadoc-zip-1.8.0.342.b07-1.el7_9.noarch.rpm
42a032cda37e42e63ccb183ecdaa7710140521828aa8549a8f19dd0bc7fbea36 java-1.8.0-openjdk-src-1.8.0.342.b07-1.el7_9.i686.rpm
cd7ecade58c83774da56075ecbc93181d0299693efa4a31b09f39a234ea8c0d8 java-1.8.0-openjdk-src-1.8.0.342.b07-1.el7_9.x86_64.rpm

Source:
4a69a3523f64a58f0321f1012cf9cdf8b8b5a25f55ad5dca977a6567cd2bb19a java-1.8.0-openjdk-1.8.0.342.b07-1.el7_9.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@libera.chat
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2022:5687 Important CentOS 7 java-11-openjdk Security Update

CentOS Errata and Security Advisory 2022:5687 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2022:5687

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
839aadc2fbe0a7a4b708e39eb1e3e9359bbbad64641fd674e425f561de5d004a java-11-openjdk-11.0.16.0.8-1.el7_9.i686.rpm
e63709673c8670886d3e9e2205785adba63f0186853bcf74298fcce168c18f0d java-11-openjdk-11.0.16.0.8-1.el7_9.x86_64.rpm
4660a5a7faa79cea2990c384533fca3da9b3ac6afdf6f55b36b2cad51352c3e0 java-11-openjdk-demo-11.0.16.0.8-1.el7_9.i686.rpm
6bba16931590ee051b717e6cc7eaf6319e483746bab088b484dada27e5f230d5 java-11-openjdk-demo-11.0.16.0.8-1.el7_9.x86_64.rpm
3e729bea301dda80bd7dad924182af1a8859d3473da42b7cb9ed78adebef8963 java-11-openjdk-devel-11.0.16.0.8-1.el7_9.i686.rpm
d91a5237171093f889f2e37c55c5cbf4f02728ff2fb050c08f0547c1c7cf5f63 java-11-openjdk-devel-11.0.16.0.8-1.el7_9.x86_64.rpm
1619875cba8598818f4bb31d4ba22a7d88804cab9b8ed1e66cb4cf18b1b446cb java-11-openjdk-headless-11.0.16.0.8-1.el7_9.i686.rpm
3038e1befe3903f7b2bfb4fb5ed1ee07a0ba36db33ae2aae4ba05e4040d2b65f java-11-openjdk-headless-11.0.16.0.8-1.el7_9.x86_64.rpm
499aafdde42137b651f07de95acdb9b2b0426c0923756ba0bb98c74731260deb java-11-openjdk-javadoc-11.0.16.0.8-1.el7_9.i686.rpm
e9370bcf27554400437736d6d3c4091baa10166592baf0f0a1912084c024255d java-11-openjdk-javadoc-11.0.16.0.8-1.el7_9.x86_64.rpm
8127547ec74cf787276b994c2f00085304d697481622d6712560f5c1fde57dd1 java-11-openjdk-javadoc-zip-11.0.16.0.8-1.el7_9.i686.rpm
a11deef2840f7fe80ce1b946609ec3aa04069da0557383edb2dd88107312e356 java-11-openjdk-javadoc-zip-11.0.16.0.8-1.el7_9.x86_64.rpm
5ef7809b46025089f784a5c5eef97c5cb1c0ae4576bd7a05f04c657f2231d054 java-11-openjdk-jmods-11.0.16.0.8-1.el7_9.i686.rpm
7d5c7ed2663b8b4d93ccdce3e87fa7b84c42697397d9594170591871b706c60d java-11-openjdk-jmods-11.0.16.0.8-1.el7_9.x86_64.rpm
39b2ee3cdead3a8fa94b2f7fb082014e56dc28992ac2740a46795004ac7dd6c0 java-11-openjdk-src-11.0.16.0.8-1.el7_9.i686.rpm
6cd18c7d7a47f7f1e42e63865172f463162be9c7697c5e7b1953c41099a4d25d java-11-openjdk-src-11.0.16.0.8-1.el7_9.x86_64.rpm
2128f5867b50e91bf6e0f43a02f4d16b03085189d8040f386c115ab75f5a842b java-11-openjdk-static-libs-11.0.16.0.8-1.el7_9.i686.rpm
9dc6103c894580255acdaca6f10c631843d1f93573f2546118ae35826f597314 java-11-openjdk-static-libs-11.0.16.0.8-1.el7_9.x86_64.rpm

Source:
2f184d374f33230217eaec88a85599c8f898bb5028cbaee37cc63480709aa168 java-11-openjdk-11.0.16.0.8-1.el7_9.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@libera.chat
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[USN-5545-1] Linux kernel (OEM) vulnerability

==========================================================================
Ubuntu Security Notice USN-5545-1
August 02, 2022

linux-oem-5.14, linux-oem-5.17 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

The system could be made to run programs as an administrator.

Software Description:
- linux-oem-5.17: Linux kernel for OEM systems
- linux-oem-5.14: Linux kernel for OEM systems

Details:

Arthur Mongodin discovered that the netfilter subsystem in the Linux kernel
did not properly perform data validation. A local attacker could use this
to escalate privileges in certain situations.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
linux-image-5.17.0-1014-oem 5.17.0-1014.15
linux-image-oem-22.04 5.17.0.1014.13
linux-image-oem-22.04a 5.17.0.1014.13

Ubuntu 20.04 LTS:
linux-image-5.14.0-1046-oem 5.14.0-1046.53
linux-image-oem-20.04 5.14.0.1046.42
linux-image-oem-20.04b 5.14.0.1046.42
linux-image-oem-20.04c 5.14.0.1046.42
linux-image-oem-20.04d 5.14.0.1046.42

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-5545-1
CVE-2022-34918

Package Information:
https://launchpad.net/ubuntu/+source/linux-oem-5.17/5.17.0-1014.15
https://launchpad.net/ubuntu/+source/linux-oem-5.14/5.14.0-1046.53

[USN-5463-2] NTFS-3G vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5463-2
August 02, 2022

ntfs-3g vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in ntfs-3g.

Software Description:
- ntfs-3g: read/write NTFS driver for FUSE

Details:

USN-5463-1 fixed vulnerabilities in NTFS-3G. This update provides the
corresponding updates for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

Original advisory details:

Roman Fiedler discovered that NTFS-3G incorrectly handled certain
return codes. A local attacker could possibly use this issue to
intercept protocol traffic between FUSE and the kernel.
(CVE-2022-30783)

It was discovered that NTFS-3G incorrectly handled certain NTFS disk
images. If a user or automated system were tricked into mounting a
specially crafted disk image, a remote attacker could use this issue to
cause a denial of service, or possibly execute arbitrary code.
(CVE-2022-30784, CVE-2022-30786, CVE-2022-30788, CVE-2022-30789)

Roman Fiedler discovered that NTFS-3G incorrectly handled certain file
handles. A local attacker could possibly use this issue to read and
write arbitrary memory. (CVE-2022-30785, CVE-2022-30787)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
ntfs-3g 1:2015.3.14AR.1-1ubuntu0.3+esm3

Ubuntu 14.04 ESM:
ntfs-3g 1:2013.1.13AR.1-2ubuntu2+esm3

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5463-2
https://ubuntu.com/security/notices/USN-5463-1
CVE-2022-30783, CVE-2022-30784, CVE-2022-30785, CVE-2022-30786,
CVE-2022-30787, CVE-2022-30788, CVE-2022-30789

Orphaned packages looking for new maintainers

The following packages are orphaned and will be retired when they
are orphaned for six weeks, unless someone adopts them. If you know for sure
that the package should be retired, please do so now with a proper reason:
https://fedoraproject.org/wiki/How_to_remove_a_package_at_end_of_life

Note: If you received this mail directly you (co)maintain one of the affected
packages or a package that depends on one. Please adopt the affected package or
retire your depending package to avoid broken dependencies, otherwise your
package will fail to install and/or build when the affected package gets retired.

Request package ownership via the *Take* button in he left column on
https://src.fedoraproject.org/rpms/<pkgname>

Full report available at:
https://churchyard.fedorapeople.org/orphans-2022-08-02.txt
grep it for your FAS username and follow the dependency chain.

For human readable dependency chains,
see https://packager-dashboard.fedoraproject.org/
For all orphaned packages,
see https://packager-dashboard.fedoraproject.org/orphan

Package (co)maintainers Status Change
============================================================
RBTools orphan 3 weeks ago
csound orphan 0 weeks ago
evolution-rss mcrha, orphan 3 weeks ago
ez-pine-gpg orphan 4 weeks ago
fawkes orphan, rmattes, timn 2 weeks ago
gpart dcantrell, orphan 4 weeks ago
lancer orphan 0 weeks ago
libnss-pgsql orphan 3 weeks ago
module-macros orphan 4 weeks ago
python-bigsuds orphan 1 weeks ago
rpkg-util orphan 4 weeks ago
sourcetrail orphan 3 weeks ago
test-interface orphan 0 weeks ago
toped orphan, tnorth 2 weeks ago
zuul openstack-sig, orphan, zuul 6 weeks ago

The following packages require above mentioned packages:
Depending on: rpkg-util (1), status change: 2022-07-02 (4 weeks ago)
copr-rpmbuild (maintained by: copr-sig, dturecek, frostyx, praiskup)
copr-builder-0.60-1.fc37.x86_64 requires rpkg = 3.2-3.fc37

Depending on: test-interface (1), status change: 2022-08-01 (0 weeks ago)
scalacheck (maintained by: jjames)
scalacheck-1.16.0-3.fc37.noarch requires mvn(org.scala-sbt:test-interface) = 1.0
scalacheck-1.16.0-3.fc37.src requires mvn(org.scala-sbt:test-interface) = 1.0

See dependency chains of your packages at
https://packager-dashboard.fedoraproject.org/
See all orphaned packages at https://packager-dashboard.fedoraproject.org/orphan

Affected (co)maintainers (either directly or via packages' dependencies):
copr-sig: rpkg-util
dcantrell: gpart
dturecek: rpkg-util
frostyx: rpkg-util
jjames: test-interface
mcrha: evolution-rss
openstack-sig: zuul
praiskup: rpkg-util
rmattes: fawkes
timn: fawkes
tnorth: toped
zuul: zuul

--
The script creating this output is run and developed by Fedora
Release Engineering. Please report issues at its pagure instance:
https://pagure.io/releng/
The sources of this script can be found at:
https://pagure.io/releng/blob/main/f/scripts/find_unblocked_orphans.py

Report finished at 2022-08-02 09:27:07 UTC
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

[USN-5544-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5544-1
August 02, 2022

linux, linux-hwe-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15
vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-lowlatency: Linux low latency kernel
- linux-hwe-5.15: Linux hardware enablement (HWE) kernel
- linux-lowlatency-hwe-5.15: Linux low latency kernel

Details:

It was discovered that the Atheros ath9k wireless device driver in the
Linux kernel did not properly handle some error conditions, leading to a
use-after-free vulnerability. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2022-1679)

Felix Fu discovered that the Sun RPC implementation in the Linux kernel did
not properly handle socket states, leading to a use-after-free
vulnerability. A remote attacker could possibly use this to cause a denial
of service (system crash) or execute arbitrary code. (CVE-2022-28893)

Arthur Mongodin discovered that the netfilter subsystem in the Linux kernel
did not properly perform data validation. A local attacker could use this
to escalate privileges in certain situations. (CVE-2022-34918)

Minh Yuan discovered that the floppy disk driver in the Linux kernel
contained a race condition, leading to a use-after-free vulnerability. A
local attacker could possibly use this to cause a denial of service (system
crash) or execute arbitrary code. (CVE-2022-1652)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
linux-image-5.15.0-43-generic 5.15.0-43.46
linux-image-5.15.0-43-generic-64k 5.15.0-43.46
linux-image-5.15.0-43-generic-lpae 5.15.0-43.46
linux-image-5.15.0-43-lowlatency 5.15.0-43.46
linux-image-5.15.0-43-lowlatency-64k 5.15.0-43.46
linux-image-generic 5.15.0.43.44
linux-image-generic-64k 5.15.0.43.44
linux-image-generic-64k-hwe-22.04 5.15.0.43.44
linux-image-generic-hwe-22.04 5.15.0.43.44
linux-image-generic-lpae 5.15.0.43.44
linux-image-generic-lpae-hwe-22.04 5.15.0.43.44
linux-image-lowlatency 5.15.0.43.41
linux-image-lowlatency-64k 5.15.0.43.41
linux-image-lowlatency-64k-hwe-22.04 5.15.0.43.41
linux-image-lowlatency-hwe-22.04 5.15.0.43.41
linux-image-oem-20.04 5.15.0.43.44
linux-image-virtual 5.15.0.43.44
linux-image-virtual-hwe-22.04 5.15.0.43.44

Ubuntu 20.04 LTS:
linux-image-5.15.0-43-generic 5.15.0-43.46~20.04.1
linux-image-5.15.0-43-generic-64k 5.15.0-43.46~20.04.1
linux-image-5.15.0-43-generic-lpae 5.15.0-43.46~20.04.1
linux-image-5.15.0-43-lowlatency 5.15.0-43.46~20.04.1
linux-image-5.15.0-43-lowlatency-64k 5.15.0-43.46~20.04.1
linux-image-generic-64k-hwe-20.04 5.15.0.43.46~20.04.14
linux-image-generic-hwe-20.04 5.15.0.43.46~20.04.14
linux-image-generic-lpae-hwe-20.04 5.15.0.43.46~20.04.14
linux-image-lowlatency-64k-hwe-20.04 5.15.0.43.46~20.04.13
linux-image-lowlatency-hwe-20.04 5.15.0.43.46~20.04.13
linux-image-virtual-hwe-20.04 5.15.0.43.46~20.04.14

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-5544-1
CVE-2022-1652, CVE-2022-1679, CVE-2022-28893, CVE-2022-34918

Package Information:
https://launchpad.net/ubuntu/+source/linux/5.15.0-43.46
https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-43.46
https://launchpad.net/ubuntu/+source/linux-hwe-5.15/5.15.0-43.46~20.04.1
https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-5.15/5.15.0-43.46~20.04.1

Monday, August 1, 2022

OpenBSD Errata: August 2, 2022 (bgpd)

Errata patch for BGP daemon has been released for OpenBSD 7.1.

Binary updates for the amd64, i386 and arm64 platform are available
via the syspatch utility. Source code patches can be found on the
respective errata page:

https://www.openbsd.org/errata71.html

[USN-5543-1] Net-SNMP vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5543-1
August 01, 2022

net-snmp vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in Net-SNMP.

Software Description:
- net-snmp: SNMP (Simple Network Management Protocol) server and applications

Details:

Yu Zhang and Nanyu Zhong discovered that Net-SNMP incorrectly handled
memory operations when processing certain requests. A remote attacker could
use this issue to cause Net-SNMP to crash, resulting in a denial of
service, or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
libsnmp-perl 5.9.1+dfsg-1ubuntu2.2
libsnmp40 5.9.1+dfsg-1ubuntu2.2
snmp 5.9.1+dfsg-1ubuntu2.2
snmpd 5.9.1+dfsg-1ubuntu2.2

Ubuntu 20.04 LTS:
libsnmp-perl 5.8+dfsg-2ubuntu2.4
libsnmp35 5.8+dfsg-2ubuntu2.4
snmp 5.8+dfsg-2ubuntu2.4
snmpd 5.8+dfsg-2ubuntu2.4

Ubuntu 18.04 LTS:
libsnmp-perl 5.7.3+dfsg-1.8ubuntu3.7
libsnmp30 5.7.3+dfsg-1.8ubuntu3.7
snmp 5.7.3+dfsg-1.8ubuntu3.7
snmpd 5.7.3+dfsg-1.8ubuntu3.7

After a standard system update you need to restart snmpd to make all the
necessary changes.

References:
https://ubuntu.com/security/notices/USN-5543-1
CVE-2022-24805, CVE-2022-24806, CVE-2022-24807, CVE-2022-24808,
CVE-2022-24809, CVE-2022-24810

Package Information:
https://launchpad.net/ubuntu/+source/net-snmp/5.9.1+dfsg-1ubuntu2.2
https://launchpad.net/ubuntu/+source/net-snmp/5.8+dfsg-2ubuntu2.4
https://launchpad.net/ubuntu/+source/net-snmp/5.7.3+dfsg-1.8ubuntu3.7

[USN-5542-1] Samba vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5542-1
August 01, 2022

samba vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in Samba.

Software Description:
- samba: SMB/CIFS file, print, and login server for Unix

Details:

It was discovered that Samba did not handle MaxQueryDuration when being
used in AD DC configurations, contrary to expectations. This issue only
affected Ubuntu 20.04 LTS. (CVE-2021-3670)

Luke Howard discovered that Samba incorrectly handled certain restrictions
associated with changing passwords. A remote attacker being requested to
change passwords could possibly use this issue to escalate privileges.
(CVE-2022-2031)

Luca Moro discovered that Samba incorrectly handled certain SMB1
communications. A remote attacker could possibly use this issue to obtain
sensitive memory contents. (CVE-2022-32742)

Joseph Sutton discovered that Samba incorrectly handled certain password
change requests. A remote attacker could use this issue to change passwords
of other users, resulting in privilege escalation. (CVE-2022-32744)

Joseph Sutton discovered that Samba incorrectly handled certain LDAP add or
modify requests. A remote attacker could possibly use this issue to cause
Samba to crash, resulting in a denial of service. (CVE-2022-32745)

Joseph Sutton and Andrew Bartlett discovered that Samba incorrectly handled
certain LDAP add or modify requests. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-32746)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
samba 2:4.15.9+dfsg-0ubuntu0.2

Ubuntu 20.04 LTS:
samba 2:4.13.17~dfsg-0ubuntu1.20.04.1

The update for Ubuntu 22.04 LTS uses a new upstream release, which includes
additional bug fixes. In general, a standard system update will make all
the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5542-1
CVE-2021-3670, CVE-2022-2031, CVE-2022-32742, CVE-2022-32744,
CVE-2022-32745, CVE-2022-32746

Package Information:
https://launchpad.net/ubuntu/+source/samba/2:4.15.9+dfsg-0ubuntu0.2
https://launchpad.net/ubuntu/+source/samba/2:4.13.17~dfsg-0ubuntu1.20.04.1

List of long term FTBFS packages to be retired in 1 week

Dear maintainers.

Based on the current fail to build from source policy, the following packages
will be retired from Fedora 37 approximately one week before branching (next week).

Policy:
https://docs.fedoraproject.org/en-US/fesco/Fails_to_build_from_source_Fails_to_install/

The packages in rawhide were not successfully built at least since Fedora 35.

This report is based on dist tags.

Packages collected via:
https://github.com/hroncok/fedora-report-ftbfs-retirements/blob/master/ftbfs-retirements.ipynb

If you see a package that was built, please let me know.
If you see a package that should be exempted from the process, please let me
know and we can work together to get a FESCo approval for that.

If you see a package that can be rebuilt, please do so.

Package (co)maintainers
==================================================================
golang-grpc-go4 eclipseo, go-sig, jchaloup
lancer willb
php-aws-sdk3 lcts
php-pimple lcts
recorder ddd
rubygem-coffee-rails jaruga, ruby-packagers-sig, vondruch
rubygem-minitest-reporters pvalena
tinygo go-sig, qulogic
uom-parent lberk, mgoodwin, nathans
xs petersen


The following packages require above mentioned packages:
Depending on: golang-grpc-go4 (1)
golang-x-build (maintained by: eclipseo, go-sig, jchaloup)
golang-x-build-0-0.19.20201229git0a4bf69.fc35.src requires
golang(grpc.go4.org) = 0-0.9.20180421git11d0a25.fc34,
golang(grpc.go4.org/codes) = 0-0.9.20180421git11d0a25.fc34
golang-x-build-devel-0-0.19.20201229git0a4bf69.fc35.noarch requires
golang(grpc.go4.org) = 0-0.9.20180421git11d0a25.fc34,
golang(grpc.go4.org/codes) = 0-0.9.20180421git11d0a25.fc34


Affected (co)maintainers (directly and indirectly):
ddd: recorder
eclipseo: golang-grpc-go4
go-sig: golang-grpc-go4, tinygo
jaruga: rubygem-coffee-rails
jchaloup: golang-grpc-go4
lberk: uom-parent
lcts: php-aws-sdk3, php-pimple
mgoodwin: uom-parent
nathans: uom-parent
petersen: xs
pvalena: rubygem-minitest-reporters
qulogic: tinygo
ruby-packagers-sig: rubygem-coffee-rails
vondruch: rubygem-coffee-rails
willb: lancer

--
Miro Hrončok
--
Phone: +420777974800
IRC: mhroncok
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Friday, July 29, 2022

Important changes to software license information in Fedora packages (SPDX and more!)

On behalf of all of the folks working on Fedora licensing improvements,
I have a few things to announce!


New docs site for licensing and other legal topics
--------------------------------------------------

All documentation related to Fedora licensing has moved to a new
section in Fedora Docs, which you can find at:

https://docs.fedoraproject.org/en-US/legal/

Other legal documentation will follow. This follows the overall Fedora
goal of moving active user and contributor documentation away from the
wiki.


Fedora license information in a structured format
-------------------------------------------------

The "good" (allowed) and "bad" (not-allowed) licenses for Fedora are
now stored in a repository, using a simple structured file format for
each license (it's TOML). You can find this at:

https://gitlab.com/fedora/legal/fedora-license-data

This data is then presented in easy tabular format in the
documentation, at:

https://docs.fedoraproject.org/en-US/legal/allowed-licenses/



New policy for the License field in packages — SPDX identifiers!
----------------------------------------------------------------

We're changing the policy for the "License" field in package spec files
to use SPDX license identifiers. Historically, Fedora has represented
licenses using short abbreviations specific to Fedora. In the meantime,
SPDX license identifiers have emerged as a standard, and other
projects, vendors, and developers have started using them. Adopting
SPDX license identifiers provides greater accuracy as to what license
applies, and will make it easier for us to collaborate with other
projects.


Updated licensing policies and processes
----------------------------------------

Fedora licensing policies and processes have been updated to reflect
the above changes. In some cases, this forced deeper thought as to how
these things are decided and why, which led to various discussion on
Fedora mailing lists. In other cases, it prompted better articulation
of guidance that was implicitly understood but not necessarily
explicitly stated.


New guidance on "effective license" analysis
--------------------------------------------

Many software packages consist of code with different free and open
source licenses. Previous practice often involved "simplification" of
the package license field when the packager believed that one license
subsumed the other — for example, using just "GPL" when the source code
includes parts licensed under a BSD-style license as well. Going
forward, packagers and reviewers should not make this kind of analysis,
and rather use (for example) "GPL-2.0-or-later AND MIT". This approach
is easier for packagers to apply in a consistent way.


When do these changes take effect?
----------------------------------

The resulting changes in practice will be applied to new packages and
licenses going forward. It is not necessary to revise existing packages
at this time, although we have provided some guidance for package
maintainers who want to get started. We're in the process of planning a
path for updating existing packages at a larger scale — stay tuned for
more on that!


Thank you everyone!
-------------------

A huge thanks to some key people who have worked tirelessly to make
this happen: David Cantrell, Richard Fontana, Jilayne Lovejoy, Miroslav
Suchý. Behind the scenes support was also provided by David Levine,
Bryan Sutula, and Beatriz Couto. Thank you as well for the valuable
feedback from Fedora community members in various Fedora forums.

Please have a look at the updated information. If you have questions,
please post them to the Fedora Legal mailing list:

https://lists.fedoraproject.org/archives/list/legal@lists.fedoraproject.org/



--
Matthew Miller
<mattdm@fedoraproject.org>
Fedora Project Leader
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure