==========================================================================
Ubuntu Security Notice USN-5849-1
February 08, 2023
heimdal vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM
Summary:
Heimdal could be made to crash if it received specially crafted
input.
Software Description:
- heimdal: Heimdal Kerberos Network Authentication Protocol
Details:
Helmut Grohne discovered that Heimdal GSSAPI incorrectly handled logical
conditions that are related to memory management operations.
An attacker could possibly use this issue to cause a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
libgssapi3-heimdal 7.7.0+dfsg-1ubuntu1.4
Ubuntu 18.04 LTS:
libgssapi3-heimdal 7.5.0+dfsg-1ubuntu0.4
Ubuntu 16.04 ESM:
libgssapi3-heimdal 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm4
Ubuntu 14.04 ESM:
libgssapi3-heimdal 1.6~git20131207+dfsg-1ubuntu1.2+esm4
After a standard system update you need to restart any application
using Heimdal libraries to make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5849-1
CVE-2022-45142
Package Information:
https://launchpad.net/ubuntu/+source/heimdal/7.7.0+dfsg-1ubuntu1.4
https://launchpad.net/ubuntu/+source/heimdal/7.5.0+dfsg-1ubuntu0.4
Wednesday, February 8, 2023
Inactive provenpackagers to be removed from group
In accordance with FESCo policy[1], the following provenpackagers will
be submitted for removal in two weeks based on a lack of Koji builds
submitted in the last six months. If you received this directly, you
can reply off-list to indicate you should still be in the
provenpackager group.
Note that removal from this group is not a "punishment" or a lack of
appreciation for the work you have done. The intent of the process is
to ensure contributors with distro-wide package privileges are still
active and responsive. This process is done regularly at the branch
point in each release.
[1] https://docs.fedoraproject.org/en-US/fesco/Provenpackager_policy/#_maintaining_provenpackager_status
Checked 134 provenpackagers
The following 15 provenpackagers have not submitted a Koji build since
at least 2022-08-03 00:00:00:
abompard
mohanboddu
jamatos
jwboyer
till
laxathom
torsava
dwmw2
oget
otaylor
jwilson
oliver
wtogami
steve
bruno
--
Ben Cotton
He / Him / His
Fedora Program Manager
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
be submitted for removal in two weeks based on a lack of Koji builds
submitted in the last six months. If you received this directly, you
can reply off-list to indicate you should still be in the
provenpackager group.
Note that removal from this group is not a "punishment" or a lack of
appreciation for the work you have done. The intent of the process is
to ensure contributors with distro-wide package privileges are still
active and responsive. This process is done regularly at the branch
point in each release.
[1] https://docs.fedoraproject.org/en-US/fesco/Provenpackager_policy/#_maintaining_provenpackager_status
Checked 134 provenpackagers
The following 15 provenpackagers have not submitted a Koji build since
at least 2022-08-03 00:00:00:
abompard
mohanboddu
jamatos
jwboyer
till
laxathom
torsava
dwmw2
oget
otaylor
jwilson
oliver
wtogami
steve
bruno
--
Ben Cotton
He / Him / His
Fedora Program Manager
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Tuesday, February 7, 2023
LibreSSL 3.5.4, 3.6.2 Released
We have released LibreSSL 3.5.4 and 3.6.2, which will be arriving in the
LibreSSL directory of your local OpenBSD mirror soon.
They include the following security fix:
* A malicious certificate revocation list or timestamp response token
would allow an attacker to read arbitrary memory.
LibreSSL 3.5.4 also includes the following reliability fix:
* An uninitialized variable was used in ASN1_STRING_to_UTF8() to decide
whether the no-op freezero(NULL, 0) should be called.
The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.
LibreSSL directory of your local OpenBSD mirror soon.
They include the following security fix:
* A malicious certificate revocation list or timestamp response token
would allow an attacker to read arbitrary memory.
LibreSSL 3.5.4 also includes the following reliability fix:
* An uninitialized variable was used in ASN1_STRING_to_UTF8() to decide
whether the no-op freezero(NULL, 0) should be called.
The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.
[USN-5845-2] OpenSSL vulnerabilities
==========================================================================
Ubuntu Security Notice USN-5845-2
February 07, 2023
openssl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM
Summary:
Several security issues were fixed in OpenSSL.
Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
Details:
USN-5845-1 fixed several vulnerabilities in OpenSSL. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
David Benjamin discovered that OpenSSL incorrectly handled X.400 address
processing. A remote attacker could possibly use this issue to read
arbitrary memory contents or cause OpenSSL to crash, resulting in a denial
of service. (CVE-2023-0286)
Octavio Galland and Marcel Böhme discovered that OpenSSL incorrectly
handled streaming ASN.1 data. A remote attacker could use this issue to
cause OpenSSL to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2023-0215)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 ESM:
libssl1.0.0 1.0.2g-1ubuntu4.20+esm6
Ubuntu 14.04 ESM:
libssl1.0.0 1.0.1f-1ubuntu2.27+esm6
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5845-2
https://ubuntu.com/security/notices/USN-5845-1
CVE-2023-0215, CVE-2023-0286
Ubuntu Security Notice USN-5845-2
February 07, 2023
openssl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM
Summary:
Several security issues were fixed in OpenSSL.
Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
Details:
USN-5845-1 fixed several vulnerabilities in OpenSSL. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
David Benjamin discovered that OpenSSL incorrectly handled X.400 address
processing. A remote attacker could possibly use this issue to read
arbitrary memory contents or cause OpenSSL to crash, resulting in a denial
of service. (CVE-2023-0286)
Octavio Galland and Marcel Böhme discovered that OpenSSL incorrectly
handled streaming ASN.1 data. A remote attacker could use this issue to
cause OpenSSL to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2023-0215)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 ESM:
libssl1.0.0 1.0.2g-1ubuntu4.20+esm6
Ubuntu 14.04 ESM:
libssl1.0.0 1.0.1f-1ubuntu2.27+esm6
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5845-2
https://ubuntu.com/security/notices/USN-5845-1
CVE-2023-0215, CVE-2023-0286
[USN-5847-1] Grunt vulnerabilities
==========================================================================
Ubuntu Security Notice USN-5847-1
February 07, 2023
grunt vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in Grunt.
Software Description:
- grunt: JavaScript task runner/build system/maintainer tool
Details:
It was discovered that Grunt was not properly loading YAML files before
parsing them. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2020-7729)
It was discovered that Grunt was not properly handling symbolic links
when performing file copy operations. An attacker could possibly use this
issue to expose sensitive information or execute arbitrary code.
(CVE-2022-0436)
It was discovered that there was a race condition in the Grunt file copy
function, which could lead to an arbitrary file write. An attacker could
possibly use this issue to perform a local privilege escalation attack or
to execute arbitrary code. (CVE-2022-1537)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
grunt 1.4.1-2ubuntu0.1~esm1
Ubuntu 20.04 LTS:
grunt 1.0.4-2ubuntu0.1~esm1
Ubuntu 18.04 LTS:
grunt 1.0.1-8ubuntu0.1+esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5847-1
CVE-2020-7729, CVE-2022-0436, CVE-2022-1537
Package Information:
https://launchpad.net/ubuntu/+source/grunt/1.4.1-2ubuntu0.1~esm1
https://launchpad.net/ubuntu/+source/grunt/1.0.4-2ubuntu0.1~esm1
https://launchpad.net/ubuntu/+source/grunt/1.0.1-8ubuntu0.1+esm1
Ubuntu Security Notice USN-5847-1
February 07, 2023
grunt vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in Grunt.
Software Description:
- grunt: JavaScript task runner/build system/maintainer tool
Details:
It was discovered that Grunt was not properly loading YAML files before
parsing them. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2020-7729)
It was discovered that Grunt was not properly handling symbolic links
when performing file copy operations. An attacker could possibly use this
issue to expose sensitive information or execute arbitrary code.
(CVE-2022-0436)
It was discovered that there was a race condition in the Grunt file copy
function, which could lead to an arbitrary file write. An attacker could
possibly use this issue to perform a local privilege escalation attack or
to execute arbitrary code. (CVE-2022-1537)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
grunt 1.4.1-2ubuntu0.1~esm1
Ubuntu 20.04 LTS:
grunt 1.0.4-2ubuntu0.1~esm1
Ubuntu 18.04 LTS:
grunt 1.0.1-8ubuntu0.1+esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5847-1
CVE-2020-7729, CVE-2022-0436, CVE-2022-1537
Package Information:
https://launchpad.net/ubuntu/+source/grunt/1.4.1-2ubuntu0.1~esm1
https://launchpad.net/ubuntu/+source/grunt/1.0.4-2ubuntu0.1~esm1
https://launchpad.net/ubuntu/+source/grunt/1.0.1-8ubuntu0.1+esm1
[USN-5845-1] OpenSSL vulnerabilities
==========================================================================
Ubuntu Security Notice USN-5845-1
February 07, 2023
openssl1.0 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in OpenSSL.
Software Description:
- openssl1.0: Secure Socket Layer (SSL) cryptographic library and tools
Details:
David Benjamin discovered that OpenSSL incorrectly handled X.400 address
processing. A remote attacker could possibly use this issue to read
arbitrary memory contents or cause OpenSSL to crash, resulting in a denial
of service. (CVE-2023-0286)
Octavio Galland and Marcel Böhme discovered that OpenSSL incorrectly
handled streaming ASN.1 data. A remote attacker could use this issue to
cause OpenSSL to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2023-0215)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
libssl1.0.0 1.0.2n-1ubuntu5.11
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5845-1
CVE-2023-0215, CVE-2023-0286
Package Information:
https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu5.11
Ubuntu Security Notice USN-5845-1
February 07, 2023
openssl1.0 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in OpenSSL.
Software Description:
- openssl1.0: Secure Socket Layer (SSL) cryptographic library and tools
Details:
David Benjamin discovered that OpenSSL incorrectly handled X.400 address
processing. A remote attacker could possibly use this issue to read
arbitrary memory contents or cause OpenSSL to crash, resulting in a denial
of service. (CVE-2023-0286)
Octavio Galland and Marcel Böhme discovered that OpenSSL incorrectly
handled streaming ASN.1 data. A remote attacker could use this issue to
cause OpenSSL to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2023-0215)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
libssl1.0.0 1.0.2n-1ubuntu5.11
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5845-1
CVE-2023-0215, CVE-2023-0286
Package Information:
https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu5.11
[USN-5846-1] X.Org X Server vulnerability
==========================================================================
Ubuntu Security Notice USN-5846-1
February 07, 2023
xorg-server, xorg-server-hwe-18.04, xwayland vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
X.Org X Server could be made to crash or run programs as the administrator
if it received specially crafted input.
Software Description:
- xorg-server: X.Org X11 server
- xwayland: X server for running X clients under Wayland
- xorg-server-hwe-18.04: X.Org X11 server
Details:
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled
certain memory operations. An attacker could possibly use these issues to
cause the X Server to crash, execute arbitrary code, or escalate
privileges.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.10:
xserver-xorg-core 2:21.1.4-2ubuntu1.5
xwayland 2:22.1.3-2ubuntu0.3
Ubuntu 22.04 LTS:
xserver-xorg-core 2:21.1.3-2ubuntu2.7
xwayland 2:22.1.1-1ubuntu0.5
Ubuntu 20.04 LTS:
xserver-xorg-core 2:1.20.13-1ubuntu1~20.04.6
xwayland 2:1.20.13-1ubuntu1~20.04.6
Ubuntu 18.04 LTS:
xserver-xorg-core 2:1.19.6-1ubuntu4.14
xserver-xorg-core-hwe-18.04 2:1.20.8-2ubuntu2.2~18.04.10
xwayland 2:1.19.6-1ubuntu4.14
xwayland-hwe-18.04 2:1.20.8-2ubuntu2.2~18.04.10
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5846-1
CVE-2023-0494
Package Information:
https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.4-2ubuntu1.5
https://launchpad.net/ubuntu/+source/xwayland/2:22.1.3-2ubuntu0.3
https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.3-2ubuntu2.7
https://launchpad.net/ubuntu/+source/xwayland/2:22.1.1-1ubuntu0.5
https://launchpad.net/ubuntu/+source/xorg-server/2:1.20.13-1ubuntu1~20.04.6
https://launchpad.net/ubuntu/+source/xorg-server/2:1.19.6-1ubuntu4.14
https://launchpad.net/ubuntu/+source/xorg-server-hwe-18.04/2:1.20.8-2ubuntu2.2~18.04.10
Ubuntu Security Notice USN-5846-1
February 07, 2023
xorg-server, xorg-server-hwe-18.04, xwayland vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
X.Org X Server could be made to crash or run programs as the administrator
if it received specially crafted input.
Software Description:
- xorg-server: X.Org X11 server
- xwayland: X server for running X clients under Wayland
- xorg-server-hwe-18.04: X.Org X11 server
Details:
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled
certain memory operations. An attacker could possibly use these issues to
cause the X Server to crash, execute arbitrary code, or escalate
privileges.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.10:
xserver-xorg-core 2:21.1.4-2ubuntu1.5
xwayland 2:22.1.3-2ubuntu0.3
Ubuntu 22.04 LTS:
xserver-xorg-core 2:21.1.3-2ubuntu2.7
xwayland 2:22.1.1-1ubuntu0.5
Ubuntu 20.04 LTS:
xserver-xorg-core 2:1.20.13-1ubuntu1~20.04.6
xwayland 2:1.20.13-1ubuntu1~20.04.6
Ubuntu 18.04 LTS:
xserver-xorg-core 2:1.19.6-1ubuntu4.14
xserver-xorg-core-hwe-18.04 2:1.20.8-2ubuntu2.2~18.04.10
xwayland 2:1.19.6-1ubuntu4.14
xwayland-hwe-18.04 2:1.20.8-2ubuntu2.2~18.04.10
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5846-1
CVE-2023-0494
Package Information:
https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.4-2ubuntu1.5
https://launchpad.net/ubuntu/+source/xwayland/2:22.1.3-2ubuntu0.3
https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.3-2ubuntu2.7
https://launchpad.net/ubuntu/+source/xwayland/2:22.1.1-1ubuntu0.5
https://launchpad.net/ubuntu/+source/xorg-server/2:1.20.13-1ubuntu1~20.04.6
https://launchpad.net/ubuntu/+source/xorg-server/2:1.19.6-1ubuntu4.14
https://launchpad.net/ubuntu/+source/xorg-server-hwe-18.04/2:1.20.8-2ubuntu2.2~18.04.10
[USN-5844-1] OpenSSL vulnerabilities
==========================================================================
Ubuntu Security Notice USN-5844-1
February 07, 2023
openssl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in OpenSSL.
Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
Details:
David Benjamin discovered that OpenSSL incorrectly handled X.400 address
processing. A remote attacker could possibly use this issue to read
arbitrary memory contents or cause OpenSSL to crash, resulting in a denial
of service. (CVE-2023-0286)
Corey Bonnell discovered that OpenSSL incorrectly handled X.509 certificate
verification. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-4203)
Hubert Kario discovered that OpenSSL had a timing based side channel in the
OpenSSL RSA Decryption implementation. A remote attacker could possibly use
this issue to recover sensitive information. (CVE-2022-4304)
Dawei Wang discovered that OpenSSL incorrectly handled parsing certain PEM
data. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service. (CVE-2022-4450)
Octavio Galland and Marcel Böhme discovered that OpenSSL incorrectly
handled streaming ASN.1 data. A remote attacker could use this issue to
cause OpenSSL to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2023-0215)
Marc Schönefeld discovered that OpenSSL incorrectly handled malformed PKCS7
data. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS and Ubuntu 22.10. (CVE-2023-0216)
Kurt Roeckx discovered that OpenSSL incorrectly handled validating certain
DSA public keys. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2023-0217)
Hubert Kario and Dmitry Belyavsky discovered that OpenSSL incorrectly
validated certain signatures. A remote attacker could possibly use this
issue to cause OpenSSL to crash, resulting in a denial of service. This
issue only affected Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2023-0401)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.10:
libssl3 3.0.5-2ubuntu2.1
Ubuntu 22.04 LTS:
libssl3 3.0.2-0ubuntu1.8
Ubuntu 20.04 LTS:
libssl1.1 1.1.1f-1ubuntu2.17
Ubuntu 18.04 LTS:
libssl1.1 1.1.1-1ubuntu2.1~18.04.21
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5844-1
CVE-2022-4203, CVE-2022-4304, CVE-2022-4450, CVE-2023-0215,
CVE-2023-0216, CVE-2023-0217, CVE-2023-0286, CVE-2023-0401
Package Information:
https://launchpad.net/ubuntu/+source/openssl/3.0.5-2ubuntu2.1
https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.8
https://launchpad.net/ubuntu/+source/openssl/1.1.1f-1ubuntu2.17
https://launchpad.net/ubuntu/+source/openssl/1.1.1-1ubuntu2.1~18.04.21
Ubuntu Security Notice USN-5844-1
February 07, 2023
openssl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in OpenSSL.
Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
Details:
David Benjamin discovered that OpenSSL incorrectly handled X.400 address
processing. A remote attacker could possibly use this issue to read
arbitrary memory contents or cause OpenSSL to crash, resulting in a denial
of service. (CVE-2023-0286)
Corey Bonnell discovered that OpenSSL incorrectly handled X.509 certificate
verification. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-4203)
Hubert Kario discovered that OpenSSL had a timing based side channel in the
OpenSSL RSA Decryption implementation. A remote attacker could possibly use
this issue to recover sensitive information. (CVE-2022-4304)
Dawei Wang discovered that OpenSSL incorrectly handled parsing certain PEM
data. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service. (CVE-2022-4450)
Octavio Galland and Marcel Böhme discovered that OpenSSL incorrectly
handled streaming ASN.1 data. A remote attacker could use this issue to
cause OpenSSL to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2023-0215)
Marc Schönefeld discovered that OpenSSL incorrectly handled malformed PKCS7
data. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS and Ubuntu 22.10. (CVE-2023-0216)
Kurt Roeckx discovered that OpenSSL incorrectly handled validating certain
DSA public keys. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2023-0217)
Hubert Kario and Dmitry Belyavsky discovered that OpenSSL incorrectly
validated certain signatures. A remote attacker could possibly use this
issue to cause OpenSSL to crash, resulting in a denial of service. This
issue only affected Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2023-0401)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.10:
libssl3 3.0.5-2ubuntu2.1
Ubuntu 22.04 LTS:
libssl3 3.0.2-0ubuntu1.8
Ubuntu 20.04 LTS:
libssl1.1 1.1.1f-1ubuntu2.17
Ubuntu 18.04 LTS:
libssl1.1 1.1.1-1ubuntu2.1~18.04.21
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5844-1
CVE-2022-4203, CVE-2022-4304, CVE-2022-4450, CVE-2023-0215,
CVE-2023-0216, CVE-2023-0217, CVE-2023-0286, CVE-2023-0401
Package Information:
https://launchpad.net/ubuntu/+source/openssl/3.0.5-2ubuntu2.1
https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.8
https://launchpad.net/ubuntu/+source/openssl/1.1.1f-1ubuntu2.17
https://launchpad.net/ubuntu/+source/openssl/1.1.1-1ubuntu2.1~18.04.21
[USN-5810-3] Git vulnerabilities
==========================================================================
Ubuntu Security Notice USN-5810-3
February 07, 2023
git vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 ESM
Summary:
Several security issues were fixed in Git.
Software Description:
- git: fast, scalable, distributed revision control system
Details:
USN-5810-1 fixed several vulnerabilities in Git. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Markus Vervier and Eric Sesterhenn discovered that Git incorrectly handled certain
gitattributes. An attacker could possibly use this issue to cause a crash
or execute arbitrary code. (CVE-2022-23521)
Joern Schneeweisz discovered that Git incorrectly handled certain commands.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. (CVE-2022-41903)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 ESM:
git 1:2.7.4-0ubuntu1.10+esm4
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5810-3
https://ubuntu.com/security/notices/USN-5810-1
CVE-2022-23521, CVE-2022-41903
Ubuntu Security Notice USN-5810-3
February 07, 2023
git vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 ESM
Summary:
Several security issues were fixed in Git.
Software Description:
- git: fast, scalable, distributed revision control system
Details:
USN-5810-1 fixed several vulnerabilities in Git. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Markus Vervier and Eric Sesterhenn discovered that Git incorrectly handled certain
gitattributes. An attacker could possibly use this issue to cause a crash
or execute arbitrary code. (CVE-2022-23521)
Joern Schneeweisz discovered that Git incorrectly handled certain commands.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. (CVE-2022-41903)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 ESM:
git 1:2.7.4-0ubuntu1.10+esm4
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5810-3
https://ubuntu.com/security/notices/USN-5810-1
CVE-2022-23521, CVE-2022-41903
OpenBSD Errata: February 7, 2023 (x509 xserver smtpd)
Errata patches for LibreSSL libcrypto, X11 server, and smtpd have
been released for OpenBSD 7.1 and 7.2.
Binary updates for the amd64, i386 and arm64 platform are available
via the syspatch utility. Source code patches can be found on the
respective errata page:
https://www.openbsd.org/errata71.html
https://www.openbsd.org/errata72.html
been released for OpenBSD 7.1 and 7.2.
Binary updates for the amd64, i386 and arm64 platform are available
via the syspatch utility. Source code patches can be found on the
respective errata page:
https://www.openbsd.org/errata71.html
https://www.openbsd.org/errata72.html
Monday, February 6, 2023
Fedora 38 mass branching postpone for 1 day
Hello, the mass branching of Fedora Linux 38 was planned to happen on
2023-02-07.
Due to traveling from FOSDEM and the re-signing of rawhide with a new
key we will postpone the branching to 2023-02-08.
Sorry for the inconvenience
Tomas Hrcka
Fedora release engineering
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
2023-02-07.
Due to traveling from FOSDEM and the re-signing of rawhide with a new
key we will postpone the branching to 2023-02-08.
Sorry for the inconvenience
Tomas Hrcka
Fedora release engineering
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
[USN-5843-1] tmux vulnerability
==========================================================================
Ubuntu Security Notice USN-5843-1
February 06, 2023
tmux vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM
Summary:
tmux could be made to crash if it received a specially crafted input.
Software Description:
- tmux: terminal multiplexer
Details:
It was discovered that tmux incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.10:
tmux 3.3a-1ubuntu0.1
Ubuntu 22.04 LTS:
tmux 3.2a-4ubuntu0.2
Ubuntu 20.04 LTS:
tmux 3.0a-2ubuntu0.4
Ubuntu 18.04 LTS:
tmux 2.6-3ubuntu0.3
Ubuntu 16.04 ESM:
tmux 2.1-3ubuntu0.1~esm1
Ubuntu 14.04 ESM:
tmux 1.8-5ubuntu0.1~esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5843-1
CVE-2022-47016
Package Information:
https://launchpad.net/ubuntu/+source/tmux/3.3a-1ubuntu0.1
https://launchpad.net/ubuntu/+source/tmux/3.2a-4ubuntu0.2
https://launchpad.net/ubuntu/+source/tmux/3.0a-2ubuntu0.4
https://launchpad.net/ubuntu/+source/tmux/2.6-3ubuntu0.3
Ubuntu Security Notice USN-5843-1
February 06, 2023
tmux vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM
Summary:
tmux could be made to crash if it received a specially crafted input.
Software Description:
- tmux: terminal multiplexer
Details:
It was discovered that tmux incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.10:
tmux 3.3a-1ubuntu0.1
Ubuntu 22.04 LTS:
tmux 3.2a-4ubuntu0.2
Ubuntu 20.04 LTS:
tmux 3.0a-2ubuntu0.4
Ubuntu 18.04 LTS:
tmux 2.6-3ubuntu0.3
Ubuntu 16.04 ESM:
tmux 2.1-3ubuntu0.1~esm1
Ubuntu 14.04 ESM:
tmux 1.8-5ubuntu0.1~esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5843-1
CVE-2022-47016
Package Information:
https://launchpad.net/ubuntu/+source/tmux/3.3a-1ubuntu0.1
https://launchpad.net/ubuntu/+source/tmux/3.2a-4ubuntu0.2
https://launchpad.net/ubuntu/+source/tmux/3.0a-2ubuntu0.4
https://launchpad.net/ubuntu/+source/tmux/2.6-3ubuntu0.3
Subscribe to:
Posts (Atom)