==========================================================================
Ubuntu Security Notice USN-6407-1
October 03, 2023
libx11 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in libx11.
Software Description:
- libx11: X11 client-side library
Details:
Gregory James Duck discovered that libx11 incorrectly handled certain
keyboard symbols. If a user were tricked into connecting to a malicious X
server, a remote attacker could use this issue to cause libx11 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-43785)
Yair Mizrahi discovered that libx11 incorrectly handled certain malformed
XPM image files. If a user were tricked into opening a specially crafted
XPM image file, a remote attacker could possibly use this issue to consume
memory, leading to a denial of service. (CVE-2023-43786)
Yair Mizrahi discovered that libx11 incorrectly handled certain malformed
XPM image files. If a user were tricked into opening a specially crafted
XPM image file, a remote attacker could use this issue to cause libx11 to
crash, leading to a denial of service, or possibly execute arbitrary code.
(CVE-2023-43787)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
libx11-6 2:1.8.4-2ubuntu0.3
Ubuntu 22.04 LTS:
libx11-6 2:1.7.5-1ubuntu0.3
Ubuntu 20.04 LTS:
libx11-6 2:1.6.9-2ubuntu1.6
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6407-1
CVE-2023-43785, CVE-2023-43786, CVE-2023-43787
Package Information:
https://launchpad.net/ubuntu/+source/libx11/2:1.8.4-2ubuntu0.3
https://launchpad.net/ubuntu/+source/libx11/2:1.7.5-1ubuntu0.3
https://launchpad.net/ubuntu/+source/libx11/2:1.6.9-2ubuntu1.6
Tuesday, October 3, 2023
[USN-6408-1] libXpm vulnerabilities
==========================================================================
Ubuntu Security Notice USN-6408-1
October 03, 2023
libxpm vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in libXpm.
Software Description:
- libxpm: X11 pixmap library
Details:
Yair Mizrahi discovered that libXpm incorrectly handled certain malformed
XPM image files. If a user were tricked into opening a specially crafted
XPM image file, a remote attacker could possibly use this issue to consume
memory, leading to a denial of service. (CVE-2023-43786)
Yair Mizrahi discovered that libXpm incorrectly handled certain malformed
XPM image files. If a user were tricked into opening a specially crafted
XPM image file, a remote attacker could use this issue to cause libXpm to
crash, leading to a denial of service, or possibly execute arbitrary code.
(CVE-2023-43787)
Alan Coopersmith discovered that libXpm incorrectly handled certain
malformed XPM image files. If a user were tricked into opening a specially
crafted XPM image file, a remote attacker could possibly use this issue to
cause libXpm to crash, leading to a denial of service. (CVE-2023-43788,
CVE-2023-43789)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
libxpm4 1:3.5.12-1.1ubuntu0.1
Ubuntu 22.04 LTS:
libxpm4 1:3.5.12-1ubuntu0.22.04.2
Ubuntu 20.04 LTS:
libxpm4 1:3.5.12-1ubuntu0.20.04.2
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6408-1
CVE-2023-43786, CVE-2023-43787, CVE-2023-43788, CVE-2023-43789
Package Information:
https://launchpad.net/ubuntu/+source/libxpm/1:3.5.12-1.1ubuntu0.1
https://launchpad.net/ubuntu/+source/libxpm/1:3.5.12-1ubuntu0.22.04.2
https://launchpad.net/ubuntu/+source/libxpm/1:3.5.12-1ubuntu0.20.04.2
Ubuntu Security Notice USN-6408-1
October 03, 2023
libxpm vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in libXpm.
Software Description:
- libxpm: X11 pixmap library
Details:
Yair Mizrahi discovered that libXpm incorrectly handled certain malformed
XPM image files. If a user were tricked into opening a specially crafted
XPM image file, a remote attacker could possibly use this issue to consume
memory, leading to a denial of service. (CVE-2023-43786)
Yair Mizrahi discovered that libXpm incorrectly handled certain malformed
XPM image files. If a user were tricked into opening a specially crafted
XPM image file, a remote attacker could use this issue to cause libXpm to
crash, leading to a denial of service, or possibly execute arbitrary code.
(CVE-2023-43787)
Alan Coopersmith discovered that libXpm incorrectly handled certain
malformed XPM image files. If a user were tricked into opening a specially
crafted XPM image file, a remote attacker could possibly use this issue to
cause libXpm to crash, leading to a denial of service. (CVE-2023-43788,
CVE-2023-43789)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
libxpm4 1:3.5.12-1.1ubuntu0.1
Ubuntu 22.04 LTS:
libxpm4 1:3.5.12-1ubuntu0.22.04.2
Ubuntu 20.04 LTS:
libxpm4 1:3.5.12-1ubuntu0.20.04.2
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6408-1
CVE-2023-43786, CVE-2023-43787, CVE-2023-43788, CVE-2023-43789
Package Information:
https://launchpad.net/ubuntu/+source/libxpm/1:3.5.12-1.1ubuntu0.1
https://launchpad.net/ubuntu/+source/libxpm/1:3.5.12-1ubuntu0.22.04.2
https://launchpad.net/ubuntu/+source/libxpm/1:3.5.12-1ubuntu0.20.04.2
OpenBSD Errata: October 3, 2023 (xlibs)
Errata patches for X11 libraries libX11 and libXpm have been released
for OpenBSD 7.2 and 7.3.
Binary updates for the amd64, arm64 and i386 platform are available
via the syspatch utility. Source code patches can be found on the
respective errata page:
https://www.openbsd.org/errata72.html
https://www.openbsd.org/errata73.html
for OpenBSD 7.2 and 7.3.
Binary updates for the amd64, arm64 and i386 platform are available
via the syspatch utility. Source code patches can be found on the
respective errata page:
https://www.openbsd.org/errata72.html
https://www.openbsd.org/errata73.html
[USN-6406-1] SpiderMonkey vulnerabilities
==========================================================================
Ubuntu Security Notice USN-6406-1
October 03, 2023
mozjs102 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in SpiderMonkey.
Software Description:
- mozjs102: SpiderMonkey JavaScript library
Details:
Several security issues were discovered in the SpiderMonkey JavaScript
library. If a user were tricked into opening malicious JavaScript
applications or processing malformed data, a remote attacker could exploit
a variety of issues related to JavaScript security, including denial of
service attacks, and arbitrary code execution.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
libmozjs-102-0 102.15.1-0ubuntu0.23.04.1
Ubuntu 22.04 LTS:
libmozjs-102-0 102.15.1-0ubuntu0.22.04.1
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6406-1
CVE-2023-4046
Package Information:
https://launchpad.net/ubuntu/+source/mozjs102/102.15.1-0ubuntu0.23.04.1
https://launchpad.net/ubuntu/+source/mozjs102/102.15.1-0ubuntu0.22.04.1
Ubuntu Security Notice USN-6406-1
October 03, 2023
mozjs102 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in SpiderMonkey.
Software Description:
- mozjs102: SpiderMonkey JavaScript library
Details:
Several security issues were discovered in the SpiderMonkey JavaScript
library. If a user were tricked into opening malicious JavaScript
applications or processing malformed data, a remote attacker could exploit
a variety of issues related to JavaScript security, including denial of
service attacks, and arbitrary code execution.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
libmozjs-102-0 102.15.1-0ubuntu0.23.04.1
Ubuntu 22.04 LTS:
libmozjs-102-0 102.15.1-0ubuntu0.22.04.1
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6406-1
CVE-2023-4046
Package Information:
https://launchpad.net/ubuntu/+source/mozjs102/102.15.1-0ubuntu0.23.04.1
https://launchpad.net/ubuntu/+source/mozjs102/102.15.1-0ubuntu0.22.04.1
Fedora Linux 39 Final Freeze
Hi all,
Today, 2023-10-03, is an important day on the Fedora Linux 39 schedule
[1], with significant cut-offs.
Today we have the Final Freeze [2] which starts at 14:00 UTC. This means
that only packages that fix accepted blocker or freeze exception bugs
[3][4][5] will be marked as 'stable' and included in the Final composes.
Other builds will remain in updates-testing until the Final release is
approved, at which point the Final freeze is lifted and packages can
move to the 'updates' repository. Pending updates will be pushed before
the final release as zero day updates.
Regards,
Fedora Release Engineering
[1] https://fedorapeople.org/groups/schedule/f-39/f-39-key-tasks.html
[2] https://fedoraproject.org/wiki/Milestone_freezes
[3] https://fedoraproject.org/wiki/QA:SOP_blocker_bug_process
[4] https://fedoraproject.org/wiki/QA:SOP_freeze_exception_bug_process
[5] https://qa.fedoraproject.org/blockerbugs/milestone/39/final/buglist
--
Tomas Hrcka
fas: humaton
libera.CHAT: jednorozec
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Today, 2023-10-03, is an important day on the Fedora Linux 39 schedule
[1], with significant cut-offs.
Today we have the Final Freeze [2] which starts at 14:00 UTC. This means
that only packages that fix accepted blocker or freeze exception bugs
[3][4][5] will be marked as 'stable' and included in the Final composes.
Other builds will remain in updates-testing until the Final release is
approved, at which point the Final freeze is lifted and packages can
move to the 'updates' repository. Pending updates will be pushed before
the final release as zero day updates.
Regards,
Fedora Release Engineering
[1] https://fedorapeople.org/groups/schedule/f-39/f-39-key-tasks.html
[2] https://fedoraproject.org/wiki/Milestone_freezes
[3] https://fedoraproject.org/wiki/QA:SOP_blocker_bug_process
[4] https://fedoraproject.org/wiki/QA:SOP_freeze_exception_bug_process
[5] https://qa.fedoraproject.org/blockerbugs/milestone/39/final/buglist
--
Tomas Hrcka
fas: humaton
libera.CHAT: jednorozec
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
[USN-6405-1] Thunderbird vulnerabilities
-----BEGIN PGP PUBLIC KEY BLOCK-----
xsDNBGK5OrIBDADeLgnKbZAczyFmpnG91E7lU8HAU3oGg8kZ58ji/SoKFoSMyca4
SUOzw0O1ex3N2J2dA1pWEW0ZL/YXI6LRUeg+qkGnoEDRnY/VUqGB6//N/rLgOlNL
RlhZ3V7Ywr1Hycho5Ai5XdBLxeGza+4uzL3BVEIKzIDZtDpdoHH8z5/OZakvWqDD
xhCU+YtjPsxsY76kHioTMx0hi6ZOrp9pl9/PgHMFNgA77d681XrNEiMWIveplYyc
9bcXc/iRX/WKA4IJGQ9oPqMzC4yzOoinrVHpWCs9mic5DaVx1HI4tusORCo8vcE7
6f4WmBJQPjoOqIq7MRGPuN2tRt1Xyltl3KcaSFB3tBywTKVTA++BumyJoTMyPh6g
rFkUIq3nYS76C7834IaQ05MgOWSobt44QP0Z/hT2/gXx3ko6ORpsjMLo1kwiSXrj
KmZM+UPbHmTxssZk+9z8iqv0xPpYb70LmvsIMy7B7v/q6hMJrA/1gX8CPmIlfXwi
9brhCqRWKgdBqxkAEQEAAc0vTmlzaGl0IE1haml0aGlhIDxuaXNoaXQubWFqaXRo
aWFAY2Fub25pY2FsLmNvbT7CwQ4EEwEKADgWIQSzXrzTXGcXvAresIrshzrO1Ghy
PAUCYrk6sgIbAwULCQgHAgYVCgkICwIEFgIDAQIeAQIXgAAKCRDshzrO1GhyPN0T
DACKYNAdtnps1/kJZnpggDQqmrmMWqURZ7zzv1qGESUibKnt6u6MMFjK2ifdN6q+
U7bElcrdAil8Jaxs2rdMV7q/UJ+9hjb+J5C8ypHYSLLiJLxO1BPxAeZNWpstzgOG
oeA+FTg9840DbaVHdaXlHizfRpqV0EZOiVf8KblQT0aMF8DB/Uocy47XNXW/Xlb5
GO+NjC3nwmwzweBCdkF19Vt9sdeeIevv52e9RyMizYJ06VW0u5Q+3rksuTx4zt2g
lGFkckNJ9PQoH92ldZFxQ610PiMivKXiGh3j+kCYtjwSfa0kmSAw++gi15+KdRgL
7sG1IbRrbPvJ1VB/yapXtbutW2U+ruOT0+PxgO1P1yfaTn/UoTBu6BTpooV4+txI
6amTmtcyvZ5p3dfoACwlDAFJuc9qzFe4E9hMlpBIVII29JtprsP012QCKYnMKStJ
aL6kzwpYP5lOrFDJBVSc2491OXNmzBZ2RBuZQaJ2fnzWaWgGmk0eABuuoj8KBWOp
Z1DOwM0EYrk6sgEMAMuVroyE5zf5KIPVZ3QqbbuznAg3hTIk8/Gcn1YjgEWTz5gK
407lxZ4rzZTJK1Pd1+kMlXa9c9mKdFg1C82hAOJKQAh6YDm41COX7W+0C7Vcu9CW
uenyu7K42PHw/MvgYDM+Ub7uth77tip30RVxYGJvoKe7qtoNWSVMgcepfq9ootaE
mLJPruhAW6fF+07QxH2muAp7c/yqm2/UQ207r6Culh1gvXwdmrejjhCwQHYhtQpG
D2Z6a4Gtzr+Ae9MV6D4e7SrDWBMYVe90qgmJWBJ2sWo/qA/Ysqpy0hOHfqktonLJ
ucUgkpI0+pb0BmxiJB5ywLSiiHYEnmJu1CqVT+FtL0FxgRlL1MbardKZ7dOV6yhk
HEk6JHv0KSYKnbA3G8LQtgib35TD+QtXTWqV9ceYpLbSOzf2MdVi1Dl484iwXkQQ
dGZvg+cYRsRjQaLchw30oPyz4f4eiEJ+sl94hVbenPpC4WcU9Otdm5/beqRP6poR
Z36V+WsGiTBsjc1bQQARAQABwsD2BBgBCgAgFiEEs16801xnF7wK3rCK7Ic6ztRo
cjwFAmK5OrICGwwACgkQ7Ic6ztRocjztzgwAq35GuEokox7sAWD6ICPFjqdQbPGU
vzskbN1qQDg4roM1NsBsFU96jQng1qAy3CvZYla+cjmxgiFQPNR2uZNmrXVYm7G8
RjX1p+MDT6Z3OMIcJFLBkmpxEbEqM2B1QQsO5WmBbnFnrcv2dIGe/NDgKhULGGVN
SOB3EMjxpeuQDOqrvCoY8RLEPwMh19sXvQqio0iSmRFyyOsRjdpEoyIyKjwrPpU2
0s5HwCWpsVNIZt1FUIOnOgf6GHox1R827o0zzLDpOVuOVFaOxk+iyjG7ufA0bT0/
h8NTN4SXZrwwxtjciJVCu44ekSy3NOuBiYceaTCKlfPyBUf82B6ui6/uoSS2lBkg
PrjdOkbvZDBU+/V7y3DeJNdvSm3hFKBiSouAt1u888HixXKErJ7tbDkUk+7xo1jK
h1IRafaoptIi8pe6cX+EhjpU9WnJXTQUf94pFFSmibtbGArbaZvzV4r0GSMFDrGK
if2Y7MHUqRJzk/D7DIi4ClSBOwKXYbnh5m4b
=rCMH
-----END PGP PUBLIC KEY BLOCK-----
==========================================================================
Ubuntu Security Notice USN-6405-1
October 03, 2023
thunderbird vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Thunderbird.
Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client
Details:
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-4057, CVE-2023-4577,
CVE-2023-4578, CVE-2023-4583, CVE-2023-4585, CVE-2023-5169, CVE-2023-5171,
CVE-2023-5176)
Andrew McCreight discovered that Thunderbird did not properly manage during
the worker lifecycle. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2023-3600)
Harveer Singh discovered that Thunderbird did not store push notifications
in private browsing mode in encrypted form. An attacker could potentially
exploit this issue to obtain sensitive information. (CVE-2023-4580)
Clément Lecigne discovered that Thunderbird did not properly manage memory
when handling VP8 media stream. An attacker-controlled VP8 media stream
could lead to a heap buffer overflow in the content process, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2023-5217)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
thunderbird 1:115.3.1+build1-0ubuntu0.23.04.1
Ubuntu 22.04 LTS:
thunderbird 1:115.3.1+build1-0ubuntu0.22.04.2
Ubuntu 20.04 LTS:
thunderbird 1:115.3.1+build1-0ubuntu0.20.04.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6405-1
CVE-2023-3600, CVE-2023-4057, CVE-2023-4577, CVE-2023-4578,
CVE-2023-4580, CVE-2023-4583, CVE-2023-4585, CVE-2023-5169,
CVE-2023-5171, CVE-2023-5176, CVE-2023-5217
Package Information:
https://launchpad.net/ubuntu/+source/thunderbird/1:115.3.1+build1-0ubuntu0.23.04.1
https://launchpad.net/ubuntu/+source/thunderbird/1:115.3.1+build1-0ubuntu0.22.04.2
https://launchpad.net/ubuntu/+source/thunderbird/1:115.3.1+build1-0ubuntu0.20.04.1
xsDNBGK5OrIBDADeLgnKbZAczyFmpnG91E7lU8HAU3oGg8kZ58ji/SoKFoSMyca4
SUOzw0O1ex3N2J2dA1pWEW0ZL/YXI6LRUeg+qkGnoEDRnY/VUqGB6//N/rLgOlNL
RlhZ3V7Ywr1Hycho5Ai5XdBLxeGza+4uzL3BVEIKzIDZtDpdoHH8z5/OZakvWqDD
xhCU+YtjPsxsY76kHioTMx0hi6ZOrp9pl9/PgHMFNgA77d681XrNEiMWIveplYyc
9bcXc/iRX/WKA4IJGQ9oPqMzC4yzOoinrVHpWCs9mic5DaVx1HI4tusORCo8vcE7
6f4WmBJQPjoOqIq7MRGPuN2tRt1Xyltl3KcaSFB3tBywTKVTA++BumyJoTMyPh6g
rFkUIq3nYS76C7834IaQ05MgOWSobt44QP0Z/hT2/gXx3ko6ORpsjMLo1kwiSXrj
KmZM+UPbHmTxssZk+9z8iqv0xPpYb70LmvsIMy7B7v/q6hMJrA/1gX8CPmIlfXwi
9brhCqRWKgdBqxkAEQEAAc0vTmlzaGl0IE1haml0aGlhIDxuaXNoaXQubWFqaXRo
aWFAY2Fub25pY2FsLmNvbT7CwQ4EEwEKADgWIQSzXrzTXGcXvAresIrshzrO1Ghy
PAUCYrk6sgIbAwULCQgHAgYVCgkICwIEFgIDAQIeAQIXgAAKCRDshzrO1GhyPN0T
DACKYNAdtnps1/kJZnpggDQqmrmMWqURZ7zzv1qGESUibKnt6u6MMFjK2ifdN6q+
U7bElcrdAil8Jaxs2rdMV7q/UJ+9hjb+J5C8ypHYSLLiJLxO1BPxAeZNWpstzgOG
oeA+FTg9840DbaVHdaXlHizfRpqV0EZOiVf8KblQT0aMF8DB/Uocy47XNXW/Xlb5
GO+NjC3nwmwzweBCdkF19Vt9sdeeIevv52e9RyMizYJ06VW0u5Q+3rksuTx4zt2g
lGFkckNJ9PQoH92ldZFxQ610PiMivKXiGh3j+kCYtjwSfa0kmSAw++gi15+KdRgL
7sG1IbRrbPvJ1VB/yapXtbutW2U+ruOT0+PxgO1P1yfaTn/UoTBu6BTpooV4+txI
6amTmtcyvZ5p3dfoACwlDAFJuc9qzFe4E9hMlpBIVII29JtprsP012QCKYnMKStJ
aL6kzwpYP5lOrFDJBVSc2491OXNmzBZ2RBuZQaJ2fnzWaWgGmk0eABuuoj8KBWOp
Z1DOwM0EYrk6sgEMAMuVroyE5zf5KIPVZ3QqbbuznAg3hTIk8/Gcn1YjgEWTz5gK
407lxZ4rzZTJK1Pd1+kMlXa9c9mKdFg1C82hAOJKQAh6YDm41COX7W+0C7Vcu9CW
uenyu7K42PHw/MvgYDM+Ub7uth77tip30RVxYGJvoKe7qtoNWSVMgcepfq9ootaE
mLJPruhAW6fF+07QxH2muAp7c/yqm2/UQ207r6Culh1gvXwdmrejjhCwQHYhtQpG
D2Z6a4Gtzr+Ae9MV6D4e7SrDWBMYVe90qgmJWBJ2sWo/qA/Ysqpy0hOHfqktonLJ
ucUgkpI0+pb0BmxiJB5ywLSiiHYEnmJu1CqVT+FtL0FxgRlL1MbardKZ7dOV6yhk
HEk6JHv0KSYKnbA3G8LQtgib35TD+QtXTWqV9ceYpLbSOzf2MdVi1Dl484iwXkQQ
dGZvg+cYRsRjQaLchw30oPyz4f4eiEJ+sl94hVbenPpC4WcU9Otdm5/beqRP6poR
Z36V+WsGiTBsjc1bQQARAQABwsD2BBgBCgAgFiEEs16801xnF7wK3rCK7Ic6ztRo
cjwFAmK5OrICGwwACgkQ7Ic6ztRocjztzgwAq35GuEokox7sAWD6ICPFjqdQbPGU
vzskbN1qQDg4roM1NsBsFU96jQng1qAy3CvZYla+cjmxgiFQPNR2uZNmrXVYm7G8
RjX1p+MDT6Z3OMIcJFLBkmpxEbEqM2B1QQsO5WmBbnFnrcv2dIGe/NDgKhULGGVN
SOB3EMjxpeuQDOqrvCoY8RLEPwMh19sXvQqio0iSmRFyyOsRjdpEoyIyKjwrPpU2
0s5HwCWpsVNIZt1FUIOnOgf6GHox1R827o0zzLDpOVuOVFaOxk+iyjG7ufA0bT0/
h8NTN4SXZrwwxtjciJVCu44ekSy3NOuBiYceaTCKlfPyBUf82B6ui6/uoSS2lBkg
PrjdOkbvZDBU+/V7y3DeJNdvSm3hFKBiSouAt1u888HixXKErJ7tbDkUk+7xo1jK
h1IRafaoptIi8pe6cX+EhjpU9WnJXTQUf94pFFSmibtbGArbaZvzV4r0GSMFDrGK
if2Y7MHUqRJzk/D7DIi4ClSBOwKXYbnh5m4b
=rCMH
-----END PGP PUBLIC KEY BLOCK-----
==========================================================================
Ubuntu Security Notice USN-6405-1
October 03, 2023
thunderbird vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Thunderbird.
Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client
Details:
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-4057, CVE-2023-4577,
CVE-2023-4578, CVE-2023-4583, CVE-2023-4585, CVE-2023-5169, CVE-2023-5171,
CVE-2023-5176)
Andrew McCreight discovered that Thunderbird did not properly manage during
the worker lifecycle. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2023-3600)
Harveer Singh discovered that Thunderbird did not store push notifications
in private browsing mode in encrypted form. An attacker could potentially
exploit this issue to obtain sensitive information. (CVE-2023-4580)
Clément Lecigne discovered that Thunderbird did not properly manage memory
when handling VP8 media stream. An attacker-controlled VP8 media stream
could lead to a heap buffer overflow in the content process, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2023-5217)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
thunderbird 1:115.3.1+build1-0ubuntu0.23.04.1
Ubuntu 22.04 LTS:
thunderbird 1:115.3.1+build1-0ubuntu0.22.04.2
Ubuntu 20.04 LTS:
thunderbird 1:115.3.1+build1-0ubuntu0.20.04.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6405-1
CVE-2023-3600, CVE-2023-4057, CVE-2023-4577, CVE-2023-4578,
CVE-2023-4580, CVE-2023-4583, CVE-2023-4585, CVE-2023-5169,
CVE-2023-5171, CVE-2023-5176, CVE-2023-5217
Package Information:
https://launchpad.net/ubuntu/+source/thunderbird/1:115.3.1+build1-0ubuntu0.23.04.1
https://launchpad.net/ubuntu/+source/thunderbird/1:115.3.1+build1-0ubuntu0.22.04.2
https://launchpad.net/ubuntu/+source/thunderbird/1:115.3.1+build1-0ubuntu0.20.04.1
[USN-6404-1] Firefox vulnerabilities
==========================================================================
Ubuntu Security Notice USN-6404-1
October 03, 2023
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-5169,
CVE-2023-5170, CVE-2023-5171, CVE-2023-5172, CVE-2023-5175, CVE-2023-5176)
Ronald Crane discovered that Firefox did not properly manage memory when
non-HTTPS Alternate Services (network.http.altsvc.oe) is enabled. An
attacker could potentially exploit this issue to cause a denial of service.
(CVE-2023-5173)
Clément Lecigne discovered that Firefox did not properly manage memory when
handling VP8 media stream. An attacker-controlled VP8 media stream could
lead to a heap buffer overflow in the content process, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2023-5217)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
firefox 118.0.1+build1-0ubuntu0.20.04.1
After a standard system update you need to restart Firefox to make all the
necessary changes.
References:
https://ubuntu.com/security/notices/USN-6404-1
CVE-2023-5169, CVE-2023-5170, CVE-2023-5171, CVE-2023-5172,
CVE-2023-5173, CVE-2023-5175, CVE-2023-5176, CVE-2023-5217
Package Information:
https://launchpad.net/ubuntu/+source/firefox/118.0.1+build1-0ubuntu0.20.04.1
Ubuntu Security Notice USN-6404-1
October 03, 2023
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-5169,
CVE-2023-5170, CVE-2023-5171, CVE-2023-5172, CVE-2023-5175, CVE-2023-5176)
Ronald Crane discovered that Firefox did not properly manage memory when
non-HTTPS Alternate Services (network.http.altsvc.oe) is enabled. An
attacker could potentially exploit this issue to cause a denial of service.
(CVE-2023-5173)
Clément Lecigne discovered that Firefox did not properly manage memory when
handling VP8 media stream. An attacker-controlled VP8 media stream could
lead to a heap buffer overflow in the content process, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2023-5217)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
firefox 118.0.1+build1-0ubuntu0.20.04.1
After a standard system update you need to restart Firefox to make all the
necessary changes.
References:
https://ubuntu.com/security/notices/USN-6404-1
CVE-2023-5169, CVE-2023-5170, CVE-2023-5171, CVE-2023-5172,
CVE-2023-5173, CVE-2023-5175, CVE-2023-5176, CVE-2023-5217
Package Information:
https://launchpad.net/ubuntu/+source/firefox/118.0.1+build1-0ubuntu0.20.04.1
Monday, October 2, 2023
[USN-6403-1] libvpx vulnerabilities
==========================================================================
Ubuntu Security Notice USN-6403-1
October 02, 2023
libvpx vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in libvpx.
Software Description:
- libvpx: VP8 and VP9 video codec
Details:
It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
libvpx7 1.12.0-1ubuntu1.2
Ubuntu 22.04 LTS:
libvpx7 1.11.0-2ubuntu2.2
Ubuntu 20.04 LTS:
libvpx6 1.8.2-1ubuntu0.2
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6403-1
CVE-2023-44488, CVE-2023-5217
Package Information:
https://launchpad.net/ubuntu/+source/libvpx/1.12.0-1ubuntu1.2
https://launchpad.net/ubuntu/+source/libvpx/1.11.0-2ubuntu2.2
https://launchpad.net/ubuntu/+source/libvpx/1.8.2-1ubuntu0.2
Ubuntu Security Notice USN-6403-1
October 02, 2023
libvpx vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in libvpx.
Software Description:
- libvpx: VP8 and VP9 video codec
Details:
It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
libvpx7 1.12.0-1ubuntu1.2
Ubuntu 22.04 LTS:
libvpx7 1.11.0-2ubuntu2.2
Ubuntu 20.04 LTS:
libvpx6 1.8.2-1ubuntu0.2
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6403-1
CVE-2023-44488, CVE-2023-5217
Package Information:
https://launchpad.net/ubuntu/+source/libvpx/1.12.0-1ubuntu1.2
https://launchpad.net/ubuntu/+source/libvpx/1.11.0-2ubuntu2.2
https://launchpad.net/ubuntu/+source/libvpx/1.8.2-1ubuntu0.2
[USN-6402-1] LibTomMath vulnerability
==========================================================================
Ubuntu Security Notice USN-6402-1
October 02, 2023
libtommath vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
Summary:
LibTomMatch could be made to execute arbitrary code or
denial of service if it received a specially crafted input.
Software Description:
- libtommath: multiple-precision integer library [development files]
Details:
It was discovered that LibTomMath incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code
and cause a denial of service (DoS).
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
libtommath1 1.2.0-6ubuntu0.23.04.1
Ubuntu 22.04 LTS:
libtommath1 1.2.0-6ubuntu0.22.04.1
Ubuntu 20.04 LTS:
libtommath1 1.2.0-3ubuntu0.1
Ubuntu 18.04 LTS (Available with Ubuntu Pro):
libtommath1 1.0.1-1ubuntu0.1~esm1
Ubuntu 16.04 LTS (Available with Ubuntu Pro):
libtommath0 0.42.0-1.2ubuntu0.1~esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6402-1
CVE-2023-36328
Package Information:
https://launchpad.net/ubuntu/+source/libtommath/1.2.0-6ubuntu0.23.04.1
https://launchpad.net/ubuntu/+source/libtommath/1.2.0-6ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/libtommath/1.2.0-3ubuntu0.1
Ubuntu Security Notice USN-6402-1
October 02, 2023
libtommath vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
Summary:
LibTomMatch could be made to execute arbitrary code or
denial of service if it received a specially crafted input.
Software Description:
- libtommath: multiple-precision integer library [development files]
Details:
It was discovered that LibTomMath incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code
and cause a denial of service (DoS).
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
libtommath1 1.2.0-6ubuntu0.23.04.1
Ubuntu 22.04 LTS:
libtommath1 1.2.0-6ubuntu0.22.04.1
Ubuntu 20.04 LTS:
libtommath1 1.2.0-3ubuntu0.1
Ubuntu 18.04 LTS (Available with Ubuntu Pro):
libtommath1 1.0.1-1ubuntu0.1~esm1
Ubuntu 16.04 LTS (Available with Ubuntu Pro):
libtommath0 0.42.0-1.2ubuntu0.1~esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6402-1
CVE-2023-36328
Package Information:
https://launchpad.net/ubuntu/+source/libtommath/1.2.0-6ubuntu0.23.04.1
https://launchpad.net/ubuntu/+source/libtommath/1.2.0-6ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/libtommath/1.2.0-3ubuntu0.1
OpenBGPD 8.2 released
We have released OpenBGPD 8.2, which will be arriving in the
OpenBGPD directory of your local OpenBSD mirror soon.
This release includes the following changes to the previous release:
* Update ASPA support to follow draft-ietf-sidrops-aspa-verification-16
and draft-ietf-sidrops-aspa-profile-16 by making the ASPA lookup
tables AFI-agnostic.
* Fix a fatal error in the Linux netlink parser which was triggered
because of a mismatched netlink message size.
* Rework UPDATE message generation to use the new ibuf API instead
of the hand-rolled solution before.
* Improve error message in bgpctl for features not supported by the
portable version of OpenBGPD.
* Adjusted example GRACEFUL_SHUTDOWN filter rule in the example config
to only match on ebgp sessions.
OpenBGPD-portable is known to compile and run on FreeBSD and the
Linux distributions Alpine, Debian, Fedora, RHEL/CentOS and Ubuntu.
It is our hope that packagers take interest and help adapt OpenBGPD-portable
to more distributions.
We welcome feedback and improvements from the broader community.
Thanks to all of the contributors who helped make this release
possible.
OpenBGPD directory of your local OpenBSD mirror soon.
This release includes the following changes to the previous release:
* Update ASPA support to follow draft-ietf-sidrops-aspa-verification-16
and draft-ietf-sidrops-aspa-profile-16 by making the ASPA lookup
tables AFI-agnostic.
* Fix a fatal error in the Linux netlink parser which was triggered
because of a mismatched netlink message size.
* Rework UPDATE message generation to use the new ibuf API instead
of the hand-rolled solution before.
* Improve error message in bgpctl for features not supported by the
portable version of OpenBGPD.
* Adjusted example GRACEFUL_SHUTDOWN filter rule in the example config
to only match on ebgp sessions.
OpenBGPD-portable is known to compile and run on FreeBSD and the
Linux distributions Alpine, Debian, Fedora, RHEL/CentOS and Ubuntu.
It is our hope that packagers take interest and help adapt OpenBGPD-portable
to more distributions.
We welcome feedback and improvements from the broader community.
Thanks to all of the contributors who helped make this release
possible.
Friday, September 29, 2023
[USN-6386-2] Linux kernel (Raspberry Pi) vulnerabilities
==========================================================================
Ubuntu Security Notice USN-6386-2
September 29, 2023
linux-raspi vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-raspi: Linux kernel for Raspberry Pi systems
Details:
Jana Hofmann, Emanuele Vannacci, Cedric Fournet, Boris Kopf, and Oleksii
Oleksenko discovered that some AMD processors could leak stale data from
division operations in certain situations. A local attacker could possibly
use this to expose sensitive information. (CVE-2023-20588)
It was discovered that the bluetooth subsystem in the Linux kernel did not
properly handle L2CAP socket release, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-40283)
It was discovered that some network classifier implementations in the Linux
kernel contained use-after-free vulnerabilities. A local attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2023-4128)
Lonial Con discovered that the netfilter subsystem in the Linux kernel
contained a memory leak when handling certain element flush operations. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2023-4569)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
linux-image-5.15.0-1038-raspi 5.15.0-1038.41
linux-image-raspi 5.15.0.1038.36
linux-image-raspi-nolpae 5.15.0.1038.36
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-6386-2
https://ubuntu.com/security/notices/USN-6386-1
CVE-2023-20588, CVE-2023-40283, CVE-2023-4128, CVE-2023-4569
Package Information:
https://launchpad.net/ubuntu/+source/linux-raspi/5.15.0-1038.41
Ubuntu Security Notice USN-6386-2
September 29, 2023
linux-raspi vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-raspi: Linux kernel for Raspberry Pi systems
Details:
Jana Hofmann, Emanuele Vannacci, Cedric Fournet, Boris Kopf, and Oleksii
Oleksenko discovered that some AMD processors could leak stale data from
division operations in certain situations. A local attacker could possibly
use this to expose sensitive information. (CVE-2023-20588)
It was discovered that the bluetooth subsystem in the Linux kernel did not
properly handle L2CAP socket release, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-40283)
It was discovered that some network classifier implementations in the Linux
kernel contained use-after-free vulnerabilities. A local attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2023-4128)
Lonial Con discovered that the netfilter subsystem in the Linux kernel
contained a memory leak when handling certain element flush operations. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2023-4569)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
linux-image-5.15.0-1038-raspi 5.15.0-1038.41
linux-image-raspi 5.15.0.1038.36
linux-image-raspi-nolpae 5.15.0.1038.36
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-6386-2
https://ubuntu.com/security/notices/USN-6386-1
CVE-2023-20588, CVE-2023-40283, CVE-2023-4128, CVE-2023-4569
Package Information:
https://launchpad.net/ubuntu/+source/linux-raspi/5.15.0-1038.41
Thursday, September 28, 2023
Contact attempt for the Inactive Packagers Policy for the F39 release cycle
****
This email was sent both to the mailing list for raising awareness to
the community and BCC directly to the affected users from which we need
a reply. If you have received this email only from the mailing list, you
can ignore the next part.
****
Hello,
during our periodic check as per the "Inactive packagers policy" [1] we
detected no activity from you as a packager, nor in other Fedora
community places, like Bodhi or mailing lists.
In order to reduce security risks from possible accounts hijacking we
tried to contact you by tagging your username in the appropriate ticket
within pagure.io repository [2], but your username is not registered
there, so we cannot contact you in that way.
Please, let us know if you're still intersted in participating in Fedora
and if you still need your account to be listed in the packager group.
You can reply here in the mailing list, so that your activity can be
detected by the script, or just login in pagure.io with your Fedora
account and reply to the ticket which refers to your username.
Without any reply from you, one week after the release of F39 the
`packager` group membership will be removed from your account and any
package for which you are the main admin will be orphaned, so that
co-maintainers can pick them up.
[1]
https://docs.fedoraproject.org/en-US/fesco/Policy_for_inactive_packagers/
[2] https://pagure.io/find-inactive-packagers/issues
Thank you.
Mattia
---------
This is the full list of usernames which cannot be reached by tag in
pagure.io:
gsgatlin
dmarlin
andriy
buytenh
jbernard
shardy
bhills
lgao
lgoncalv
krionbsd
rkennke
angelonord
athomas
dmaley
eglynn
endur
florencia
mwringe
rosslagerwall
sgros
tlavocat
xinghong
pcullen
jshort
---------
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
This email was sent both to the mailing list for raising awareness to
the community and BCC directly to the affected users from which we need
a reply. If you have received this email only from the mailing list, you
can ignore the next part.
****
Hello,
during our periodic check as per the "Inactive packagers policy" [1] we
detected no activity from you as a packager, nor in other Fedora
community places, like Bodhi or mailing lists.
In order to reduce security risks from possible accounts hijacking we
tried to contact you by tagging your username in the appropriate ticket
within pagure.io repository [2], but your username is not registered
there, so we cannot contact you in that way.
Please, let us know if you're still intersted in participating in Fedora
and if you still need your account to be listed in the packager group.
You can reply here in the mailing list, so that your activity can be
detected by the script, or just login in pagure.io with your Fedora
account and reply to the ticket which refers to your username.
Without any reply from you, one week after the release of F39 the
`packager` group membership will be removed from your account and any
package for which you are the main admin will be orphaned, so that
co-maintainers can pick them up.
[1]
https://docs.fedoraproject.org/en-US/fesco/Policy_for_inactive_packagers/
[2] https://pagure.io/find-inactive-packagers/issues
Thank you.
Mattia
---------
This is the full list of usernames which cannot be reached by tag in
pagure.io:
gsgatlin
dmarlin
andriy
buytenh
jbernard
shardy
bhills
lgao
lgoncalv
krionbsd
rkennke
angelonord
athomas
dmaley
eglynn
endur
florencia
mwringe
rosslagerwall
sgros
tlavocat
xinghong
pcullen
jshort
---------
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Subscribe to:
Posts (Atom)