Security
Mar 12, 2024, 08:01 PM
thunderbird
Version: 115.8.1-alt1
Summary: Thunderbird is Mozilla's e-mail client
Changelog:
- New version. - Security fixes: + CVE-2024-1936 Leaking of encrypted email subjects to other conversations
Mar 7, 2024, 03:55 PM
libxml2
Version: 2.12.5-alt1
Summary: The library for manipulating XML files
Changelog:
- 2.12.5 (Fixes: CVE-2024-25062)
Mar 5, 2024, 10:19 PM
golang
Version: 1.22.1-alt1
Summary: The Go Programming Language
Changelog:
- New version (1.22.1) (Fixes: CVE-2024-24783, CVE-2023-45289, CVE-2023-45290).
Mar 4, 2024, 04:20 PM
libvirt
Version: 9.8.0-alt4
Summary: Library providing a simple API virtualization
Changelog:
- Fix off-by-one error in udevListInterfacesByStatus (Fixes: CVE-2024-1441)
Mar 2, 2024, 05:44 PM
chromium
Version: 122.0.6261.94-alt1
Summary: An open source web browser developed by Google
Changelog:
- New version (122.0.6261.94). - Security fixes: - CVE-2024-1669: Out of bounds memory access in Blink. - CVE-2024-1670: Use after free in Mojo. - CVE-2024-1671: Inappropriate implementation in Site Isolation. - CVE-2024-1672: Inappropriate implementation in Content Security Policy. - CVE-2024-1673: Use after free in Accessibility. - CVE-2024-1674: Inappropriate implementation in Navigation. - CVE-2024-1675: Insufficient policy enforcement in Download. - CVE-2024-1676: Inappropriate implementation in Navigation. - CVE-2024-1938: Type Confusion in V8. - CVE-2024-1939: Type Confusion in V8.
Mar 2, 2024, 03:22 PM
python3-module-dns
Version: 2.6.1-alt1
Summary: DNS toolkit
Changelog:
- new version 2.6.1, change license to ISC - switch to pyproject_build - CVE-2023-29483
Feb 27, 2024, 06:58 AM
zabbix
Version: 6.0.27-alt1
Summary: A network monitor
Changelog:
- 6.0.27 (Fixes: CVE-2023-32725, CVE-2023-32726, CVE-2023-32727 CVE-2023-32728, CVE-2024-22119)
Feb 19, 2024, 08:58 PM
dnsmasq
Version: 2.90-alt1
Summary: A lightweight caching nameserver
Changelog:
- Fixed different signedness comparison on 32bit systems. - Dropped obsoleted patches. - Patches from upstream git: + Add missing CHANGELOG entries for 2.90; + Fix spurious "resource limit exceeded" messages. - Updated to 2.90 (fixes: CVE-2023-50387,CVE 2023-50868).
Feb 19, 2024, 02:51 AM
dotnet-runtime-8.0
Version: 8.0.2-alt1
Summary: Microsoft .NET Runtime and Microsoft.NETCore.App
Changelog:
- .NET 8.0.2 release - CVE-2023-36038: .NET Denial of Service Vulnerability - CVE-2023-36049: .NET Elevation of Privilege Vulnerability - CVE-2023-36558: .NET Security Feature Bypass Vulnerability - CVE-2024-0056: Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data provider Information Disclosure Vulnerability - CVE-2024-0057: .NET Security Feature bypass Vulnerability - CVE-2024-21319: .NET Denial of Service Vulnerability - CVE-2024-21386: .NET Denial of Service Vulnerability - CVE-2024-21404: .NET Denial of Service Vulnerability
Feb 18, 2024, 11:04 PM
dotnet-bootstrap-8.0
Version: 8.0.2-alt1
Summary: .NET 8 SDK binaries
Changelog:
- The .NET 8.0.2 and .NET SDK 8.0.2 release - CVE-2023-36038: .NET Denial of Service Vulnerability - CVE-2023-36049: .NET Elevation of Privilege Vulnerability - CVE-2023-36558: .NET Security Feature Bypass Vulnerability - CVE-2024-0056: Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data provider Information Disclosure Vulnerability - CVE-2024-0057: .NET Security Feature bypass Vulnerability - CVE-2024-21319: .NET Denial of Service Vulnerability - CVE-2024-21386: .NET Denial of Service Vulnerability - CVE-2024-21404: .NET Denial of Service Vulnerability
Feb 18, 2024, 05:05 PM
glpi
Version: 10.0.12-alt1
Summary: IT and asset management software
Changelog:
- New version 10.0.12 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2024-23645 : Reflected XSS in reports pages + CVE-2023-51446 : LDAP Injection during authentication ()
Feb 18, 2024, 05:03 PM
libuv
Version: 1.48.0-alt1
Summary: Evented I/O for NodeJS
Changelog:
- new version 1.48.0 (with rpmrb script) - CVE-2024-24806
Feb 14, 2024, 12:59 PM
exiv2
Version: 0.28.2-alt1
Summary: Command line tool to access EXIF data in image files
Changelog:
- 0.28.2 (fixed CVE-2024-24826, CVE-2024-25112)
Feb 12, 2024, 12:03 PM
postgresql15-1C
Version: 15.5-alt4
Summary: PostgreSQL client programs and libraries (edition for 1C 8.3.13 and later)
Changelog:
- Update 1C patch - Fixes CVE-2024-0985
Feb 12, 2024, 12:02 PM
postgresql15
Version: 15.6-alt1
Summary: PostgreSQL client programs and libraries
Changelog:
- 15.6 (Fixes CVE-2024-0985)
Feb 12, 2024, 11:59 AM
postgresql14
Version: 14.11-alt1
Summary: PostgreSQL client programs and libraries
Changelog:
- 14.11 (Fixes CVE-2024-0985)
Feb 12, 2024, 11:55 AM
postgresql13
Version: 13.14-alt1
Summary: PostgreSQL client programs and libraries
Changelog:
- 13.14 (Fixes CVE-2024-0985)
Feb 12, 2024, 11:51 AM
postgresql12
Version: 12.18-alt1
Summary: PostgreSQL client programs and libraries
Changelog:
- 12.18 (Fixes CVE-2024-0985)
Feb 12, 2024, 11:42 AM
postgresql16
Version: 16.2-alt1
Summary: PostgreSQL client programs and libraries
Changelog:
- 16.2 (Fixes CVE-2024-0985)
Feb 11, 2024, 04:47 AM
dropbear
Version: 2022.83-alt2
Summary: A smallish SSH server and client
Changelog:
- Backport the fix for the Terrapin attack (fixes CVE-2023-48795). - Undo static linking (ALT#49349).
Feb 9, 2024, 03:20 AM
gem-nokogiri
Version: 1.16.2-alt1
Summary: Ruby libraries for Nokogiri (HTML, XML, SAX, and Reader parser)
Changelog:
- ^ 1.15.5 -> 1.16.2 - ! fixed CVE-2024-25062
Feb 5, 2024, 12:49 PM
java-17-openjdk
Version: 17.0.10.0.7-alt1
Summary: OpenJDK 17 Runtime Environment
Changelog:
- New version. - Security fixes: - CVE-2024-20918 - CVE-2024-20919 - CVE-2024-20921 - CVE-2024-20932 - CVE-2024-20945 - CVE-2024-20952
Feb 3, 2024, 01:42 PM
java-11-openjdk
Version: 11.0.22.0.7-alt1
Summary: OpenJDK Runtime Environment 11
Changelog:
- New version. - Security fixes - CVE-2024-20918 - CVE-2024-20919 - CVE-2024-20921 - CVE-2024-20926 - CVE-2024-20945 - CVE-2024-20952
Feb 2, 2024, 05:31 PM
runc
Version: 1.1.12-alt1
Summary: CLI for running Open Containers
Changelog:
- New version 1.1.12 (Fixes: CVE-2024-21626). - Drop tmpfiles.d/runc.conf
Feb 1, 2024, 12:18 PM
shim
Version: 15.8-alt1
Summary: First-stage UEFI bootloader
Changelog:
- new version - update shim-15.8-alt-Bump-grub-SBAT-revocation-to-4 patch - Fixes: + CVE-2023-40546 mok: fix LogError() invocation + CVE-2023-40547 - avoid incorrectly trusting HTTP headers + CVE-2023-40548 Fix integer overflow on SBAT section size on 32-bit system + CVE-2023-40549 Authenticode: verify that the signature header is in bounds. + CVE-2023-40550 pe: Fix an out-of-bound read in verify_buffer_sbat() + CVE-2023-40551: pe-relocate: Fix bounds check for MZ binaries
Jan 31, 2024, 03:18 PM
curl
Version: 8.6.0-alt1
Summary: Gets a file from a FTP, GOPHER or HTTP server
Changelog:
- 8.5.0 -> 8.6.0 - Fixes: * CVE-2024-0853 : OCSP verification bypass with TLS session reuse
Jan 31, 2024, 08:00 AM
glibc
Version: 2.38.0.44.d37c2b20a4-alt1
Summary: The GNU libc libraries
Changelog:
- Updated to glibc-2.38-44-gd37c2b20a4 (fixes: CVE-2023-6246, CVE-2023-6779, CVE-2023-6780).
Jan 31, 2024, 12:56 AM
palemoon
Version: 33.0.0-alt1
Summary: The New Moon browser, an unofficial branding of the Pale Moon project browser
Changelog:
- Release 33.0.0 (CVE-2024-0746, CVE-2024-0741, CVE-2024-0743 DiD, CVE-2024-0750 DiD, and CVE-2024-0753)
Jan 30, 2024, 08:37 AM
libssh2
Version: 1.11.0-alt2
Summary: A library implementing the SSH2 protocol
Changelog:
- Applied security fix from upstream (Fixes: CVE-2023-48795).
Jan 18, 2024, 11:08 PM
MySQL
Version: 8.0.36-alt1
Summary: A very fast and reliable SQL database engine
Changelog:
- new version + (fixes: CVE-2024-20960, CVE-2024-20961, CVE-2024-20962, CVE-2024-20963) + (fixes: CVE-2024-20964, CVE-2024-20965, CVE-2024-20966, CVE-2024-20967) + (fixes: CVE-2024-20968, CVE-2024-20969, CVE-2024-20970, CVE-2024-20971) + (fixes: CVE-2024-20972, CVE-2024-20973, CVE-2024-20974, CVE-2024-20975) + (fixes: CVE-2024-20976, CVE-2024-20977, CVE-2024-20978, CVE-2024-20981) + (fixes: CVE-2024-20982, CVE-2024-20983, CVE-2024-20984, CVE-2024-20985) - update mysql-shell 8.0.35 -> 8.0.36
Jan 18, 2024, 12:21 AM
gnutls30
Version: 3.8.3-alt1
Summary: A TLS protocol implementation
Changelog:
- Updated to 3.8.3 (fixes: CVE-2024-0553, CVE-2024-0567).
Jan 16, 2024, 03:40 PM
frr
Version: 9.0.2-alt1
Summary: FRRouting Routing daemon
Changelog:
- 9.0.2 (Fixes: CVE-2023-46752, CVE-2023-46753, CVE-2023-47234, CVE-2023-47235)
Jan 12, 2024, 10:52 AM
libssh
Version: 0.10.6-alt1
Summary: C library to authenticate in a simple manner to one or more SSH servers
Changelog:
- new version (fixes: CVE-2023-6004 CVE-2023-48795 CVE-2023-6918) (closes: 49050)
Jan 9, 2024, 02:05 AM
dotnet-runtime-6.0
Version: 6.0.25-alt1
Summary: Microsoft .NET Runtime and Microsoft.NETCore.App
Changelog:
- .NET 6.0.25 - CVE-2023-36049: .NET Elevation of Privilege Vulnerability - CVE-2023-36558: .NET Security Feature Bypass Vulnerability - CVE-2023-36792: .NET Remote Code Execution Vulnerability - CVE-2023-36793: .NET Remote Code Execution Vulnerability - CVE-2023-36794: .NET Remote Code Execution Vulnerability - CVE-2023-36796: .NET Remote Code Execution Vulnerability - CVE-2023-36799: .NET Denial of Service Vulnerability - CVE-2023-44487: .NET Denial of Service Vulnerability - CVE-2023-44487: .NET Denial of Service Vulnerability - CVE-2023-36792: .NET Remote Code Execution Vulnerability - CVE-2023-36793: .NET Remote Code Execution Vulnerability - CVE-2023-36794: .NET Remote Code Execution Vulnerability - CVE-2023-36796: .NET Remote Code Execution Vulnerability - CVE-2023-36799: .NET Denial of Service Vulnerability - CVE-2023-35390: .NET Remote Code Execution Vulnerability - CVE-2023-38180: .NET Denial of Service Vulnerability - CVE-2023-35391: .NET Information Disclosure Vulnerability
Jan 9, 2024, 02:01 AM
dotnet-bootstrap-6.0
Version: 6.0.25-alt1
Summary: .NET Core SDK binaries
Changelog:
- The .NET 6.0.25 and .NET SDK 6.0.125 releases - CVE-2023-36049: .NET Elevation of Privilege Vulnerability - CVE-2023-36558: .NET Security Feature Bypass Vulnerability - CVE-2023-36792: .NET Remote Code Execution Vulnerability - CVE-2023-36793: .NET Remote Code Execution Vulnerability - CVE-2023-36794: .NET Remote Code Execution Vulnerability - CVE-2023-36796: .NET Remote Code Execution Vulnerability - CVE-2023-36799: .NET Denial of Service Vulnerability - CVE-2023-44487: .NET Denial of Service Vulnerability - CVE-2023-44487: .NET Denial of Service Vulnerability - CVE-2023-36792: .NET Remote Code Execution Vulnerability - CVE-2023-36793: .NET Remote Code Execution Vulnerability - CVE-2023-36794: .NET Remote Code Execution Vulnerability - CVE-2023-36796: .NET Remote Code Execution Vulnerability - CVE-2023-36799: .NET Denial of Service Vulnerability - CVE-2023-35390: .NET Remote Code Execution Vulnerability - CVE-2023-38180: .NET Denial of Service Vulnerability - CVE-2023-35391: .NET Information Disclosure Vulnerability
Jan 9, 2024, 01:48 AM
dotnet-runtime-7.0
Version: 7.0.14-alt1
Summary: Microsoft .NET Runtime and Microsoft.NETCore.App
Changelog:
- .NET 7.0.14 - CVE-2023-36049: .NET Elevation of Privilege Vulnerability - CVE-2023-36558: .NET Security Feature Bypass Vulnerability - CVE-2023-36792: .NET Remote Code Execution Vulnerability - CVE-2023-36793: .NET Remote Code Execution Vulnerability - CVE-2023-36794: .NET Remote Code Execution Vulnerability - CVE-2023-36796: .NET Remote Code Execution Vulnerability - CVE-2023-36799: .NET Denial of Service Vulnerability - CVE-2023-44487: .NET Denial of Service Vulnerability - CVE-2023-38171: .NET Denial of Service Vulnerability - CVE-2023-36435: .NET Denial of Service Vulnerability - CVE-2023-44487: .NET Denial of Service Vulnerability - CVE-2023-38171: .NET Denial of Service Vulnerability - CVE-2023-36435: .NET Denial of Service Vulnerability - CVE-2023-38178: .NET Denial of Service Vulnerability - CVE-2023-35390: .NET Remote Code Execution Vulnerability - CVE-2023-38180: .NET Denial of Service Vulnerability - CVE-2023-35391: .NET Information Disclosure Vulnerability
Jan 9, 2024, 01:34 AM
dotnet-bootstrap-7.0
Version: 7.0.14-alt1
Summary: .NET Core SDK binaries
Changelog:
- The .NET 7.0.14 and .NET SDK 7.0.114 releases - CVE-2023-36049: .NET Elevation of Privilege Vulnerability - CVE-2023-36558: .NET Security Feature Bypass Vulnerability - CVE-2023-36792: .NET Remote Code Execution Vulnerability - CVE-2023-36793: .NET Remote Code Execution Vulnerability - CVE-2023-36794: .NET Remote Code Execution Vulnerability - CVE-2023-36796: .NET Remote Code Execution Vulnerability - CVE-2023-36799: .NET Denial of Service Vulnerability - CVE-2023-44487: .NET Denial of Service Vulnerability - CVE-2023-38171: .NET Denial of Service Vulnerability - CVE-2023-36435: .NET Denial of Service Vulnerability - CVE-2023-44487: .NET Denial of Service Vulnerability - CVE-2023-38171: .NET Denial of Service Vulnerability - CVE-2023-36435: .NET Denial of Service Vulnerability - CVE-2023-38178: .NET Denial of Service Vulnerability - CVE-2023-35390: .NET Remote Code Execution Vulnerability - CVE-2023-38180: .NET Denial of Service Vulnerability - CVE-2023-35391: .NET Information Disclosure Vulnerability
Jan 5, 2024, 02:31 PM
openquantumsafe-openssh
Version: 8.9p1.202310-alt2
Summary: OQS-OpenSSH is a fork of OpenSSH that adds quantum-safe algorithms
Changelog:
- Security backports (fixes CVE-2023-48795, CVE-2023-51384, CVE-2023-51385). - Update version shown in 'ssh -V' to the actual one.
Jan 4, 2024, 10:57 AM
itop
Version: 3.1.1.1-alt1
Summary: IT Operations Portal
Changelog:
- New version 3.1.1.1 - Security fixes: + CVE-2023-48710 : Restrict pages/exec.php to PHP files + CVE-2023-48709 : Fix CSV injection in Excel from an iTop CSV export file + CVE-2023-46734 : Fix potential XSS vulnerabilities in TWIG CodeExtension filters + CVE-2023-47123 : Fix XSS vulnerability in n:n relations "tagset" widget + CVE-2023-47622 : Fix XSS vulnerabilities in ajax operations + CVE-2023-47626 : Fix XSS vulnerabilities in authent token + CVE-2023-44396 : Fix XSS vulnerabilities in dashlet ajax operations + CVE-2023-43790 : Fix XSS vulnerabilities in friendlyname in object details + CVE-2023-38511 : Fix dashboard allowing to load multiple files and urls + CVE-2023-45808 : Fix object creation in non allowed org by forging http query in both Console and Portal
Jan 1, 2024, 02:49 PM
tinyssh
Version: 20240101-alt1
Summary: TinySSH is small server
Changelog:
- Update to 20240101 (2024-01-01). (Fixes: CVE-2023-48795).
Dec 26, 2023, 02:09 PM
guacamole
Version: 1.5.4-alt1
Summary: Clientless remote desktop gateway
Changelog:
- 1.5.4 (Fixes: CVE-2023-43826).
Dec 25, 2023, 05:34 PM
guacamole-server
Version: 1.5.4-alt1
Summary: Server-side native components that form the Guacamole proxy
Changelog:
- New version 1.5.4 (Fixes: CVE-2023-43826).
Dec 25, 2023, 12:08 PM
raptor2
Version: 2.0.16-alt1
Summary: RDF Parser Toolkit for Redland
Changelog:
- new version (fixes: CVE-2017-18926 CVE-2020-25713) (closes: 48916)
Dec 20, 2023, 09:44 PM
phpipam
Version: 1.6.0-alt1
Summary: PHP-based virtual machine control tool
Changelog:
- 1.6.0 (Fixes: CVE-2023-24657). - Build with php8.2.
Dec 4, 2023, 05:48 PM
nextcloud
Version: 27.1.4-alt1
Summary: Cloud platform
Changelog:
- New version (fixes: CVE-2023-48306, CVE-2023-48305, CVE-2023-48304, CVE-2023-48303, CVE-2023-48302, CVE-2023-48301, CVE-2023-48239, CVE-2023-45148).
Dec 1, 2023, 05:28 PM
kubernetes1.25
Version: 1.25.16-alt1
Summary: Container cluster management
Changelog:
- 1.25.15 -> 1.25.16 (Fixes: CVE-2023-5528)
Nov 28, 2023, 09:55 AM
exim
Version: 4.97-alt1
Summary: Exim MTA
Changelog:
- update to 4.97 (fix CVE-2023-42114 ... CVE-2023-42116) - fix RM_COMMAND in scripts (#47254 #47255)
Nov 27, 2023, 11:11 AM
csync2
Version: 2.0-alt3
Summary: Csync2 is a cluster synchronization tool
Changelog:
- added commits from upstream git (Fixes: CVE-2019-15522, CVE-2019-15523)
Nov 24, 2023, 11:27 AM
tang
Nov 23, 2023, 02:54 PM
rabbitmq-c
Nov 22, 2023, 11:15 AM
uwsgi
Version: 2.0.23-alt1
Summary: fast (pure C), self-healing, developer-friendly WSGI server
Changelog:
- update to 2.0.23 (Fixes: CVE-2023-27522)
Nov 15, 2023, 12:54 AM
firmware-intel-ucode
Version: 23-alt1.20231114
Summary: Microcode definitions for Intel processors
Changelog:
- New upstream microcode datafile 20231114: + Security updates for INTEL-SA-00950 (CVE-2023-23583). + Updated microcodes: sig 0x000606a6, pf_mask 0x87, 2023-09-01, rev 0xd0003b9, size 299008 sig 0x000606c1, pf_mask 0x10, 2023-09-08, rev 0x1000268, size 290816 sig 0x000706e5, pf_mask 0x80, 2023-09-03, rev 0x00c2, size 113664 sig 0x000806c1, pf_mask 0x80, 2023-09-07, rev 0x00b4, size 111616 sig 0x000806c2, pf_mask 0xc2, 2023-09-07, rev 0x0034, size 98304 sig 0x000806d1, pf_mask 0xc2, 2023-09-07, rev 0x004e, size 104448 sig 0x000806f4, pf_mask 0x87, 2023-06-16, rev 0x2b0004d0, size 572416 sig 0x000806f4, pf_mask 0x10, 2023-06-26, rev 0x2c000290, size 605184 sig 0x000806f5, pf_mask 0x87, 2023-06-16, rev 0x2b0004d0, size 572416 sig 0x000806f5, pf_mask 0x10, 2023-06-26, rev 0x2c000290, size 605184 sig 0x000806f6, pf_mask 0x87, 2023-06-16, rev 0x2b0004d0, size 572416 sig 0x000806f6, pf_mask 0x10, 2023-06-26, rev 0x2c000290, size 605184 sig 0x000806f7, pf_mask 0x87, 2023-06-16, rev 0x2b0004d0, size 572416 sig 0x000806f8, pf_mask 0x87, 2023-06-16, rev 0x2b0004d0, size 572416 sig 0x000806f8, pf_mask 0x10, 2023-06-26, rev 0x2c000290, size 605184 sig 0x00090672, pf_mask 0x07, 2023-06-07, rev 0x0032, size 222208 sig 0x00090675, pf_mask 0x07, 2023-06-07, rev 0x0032, size 222208 sig 0x000906a3, pf_mask 0x80, 2023-06-07, rev 0x0430, size 220160 sig 0x000906a4, pf_mask 0x80, 2023-06-07, rev 0x0430, size 220160 sig 0x000a0671, pf_mask 0x02, 2023-09-03, rev 0x005d, size 104448 sig 0x000b0671, pf_mask 0x32, 2023-08-29, rev 0x011d, size 210944 sig 0x000b06a2, pf_mask 0xe0, 2023-08-30, rev 0x411c, size 216064 sig 0x000b06a3, pf_mask 0xe0, 2023-08-30, rev 0x411c, size 216064 sig 0x000b06e0, pf_mask 0x11, 2023-06-26, rev 0x0012, size 136192 sig 0x000b06f2, pf_mask 0x07, 2023-06-07, rev 0x0032, size 222208 sig 0x000b06f5, pf_mask 0x07, 2023-06-07, rev 0x0032, size 222208 - source: update symlinks to reflect id of the latest release, 20231114.
Nov 7, 2023, 06:32 PM
libetpan
Version: 1.9.4-alt4
Summary: This mail library provide a portable, efficient middleware for different kinds of mail access
Changelog:
- Patches from upstream git: + Fix buffer overwrite for empty string in remove_trailing_eol (upstream issue #408); + Detect extra data after STARTTLS response and exit (upstrem issue #387) (fixes: CVE-2020-15953); + Missing boundary fix (upstream issue #384); + Fix potential null pointer deferenced (upstream issue #363); + Fix potential null pointer deferenced (upstream issue #361); + Fix potential null pointer deference (upstream issue #348).
Nov 3, 2023, 12:06 AM
kubernetes1.24
Version: 1.24.17-alt1
Summary: Container cluster management
Changelog:
- 1.24.17 (Fixes: CVE-2023-2728) - Rename the package to include major and minor versions - Make kubernetes-common and kubernetes-crio noarch packages - Allow write to config dir /etc/kubernetes for kube group - Allow write to home dir /var/lib/kubernetes for kube group
Oct 27, 2023, 05:27 PM
open-vm-tools
Version: 12.3.5-alt1
Summary: Open Virtual Machine Tools for virtual machines hosted on VMware
Changelog:
- 12.3.5 (CVE-2023-34058, CVE-2023-34059)
Oct 19, 2023, 05:11 PM
json-c
Version: 0.17-alt1
Summary: JSON implementation in C
Changelog:
- Updated to 0.17 (Fixes: CVE-2021-32292).
Oct 19, 2023, 04:50 PM
libfastjson
Version: 1.2304.0-alt1
Summary: A JSON implementation in C
Changelog:
- New version 1.2304.0 (Fixed: CVE-2020-12762).
Oct 11, 2023, 04:19 PM
moodle
Version: 4.3.0-alt1
Summary: The world's open source learning platform
Changelog:
- New version. - Use PHP 8.2. - Security fixes: CVE-2023-40316, CVE-2023-40317, CVE-2023-40318, CVE-2023-40319, CVE-2023-40320, CVE-2022-39369, CVE-2023-40322, CVE-2023-40323, CVE-2023-40324, CVE-2023-40325 - Requires exif PHP module. - Set PHP parameter max_input_vars=5000.
Oct 11, 2023, 08:36 AM
libcue2
Version: 2.3.0-alt1
Summary: Cue sheet parser library
Changelog:
- new version 2.3.0 (with rpmrb script) - CVE-2023-43641
Oct 7, 2023, 07:00 AM
netatalk
Version: 3.1.18-alt1
Summary: Open Source Apple Filing Protocol(AFP) File Server
Changelog:
- 3.1.18 (fixed CVE-2022-22995)
Oct 4, 2023, 09:14 AM
libX11
Oct 4, 2023, 08:58 AM
libXpm
Sep 29, 2023, 03:25 PM
libppd
Version: 2.0.0-alt1
Summary: Library for retro-fitting legacy printer drivers
Changelog:
- 2.0.0 (Fixes: CVE-2023-4504)
Sep 29, 2023, 08:00 AM
openssl1.1
Version: 1.1.1w-alt1
Summary: OpenSSL - Secure Sockets Layer and cryptography shared libraries and tools
Changelog:
- Updated to 1.1.1w (fixes CVE-2023-3817, CVE-2023-3446, CVE-2023-4807).
Sep 14, 2023, 10:02 AM
libwebp
Version: 1.3.2-alt1
Summary: Library and tools for the WebP graphics format
Changelog:
- 1.3.2 (fixed CVE-2023-4863)
Aug 25, 2023, 01:15 PM
java-1.8.0-openjdk
Version: 1.8.0.382.b05-alt0_1jpp8
Summary: OpenJDK Runtime Environment 8
Changelog:
- New version. - Seciruty fixes: + CVE-2023-22045 + CVE-2023-22049 - Removed implicit requirements.
Aug 8, 2023, 08:16 PM
connman
Version: 1.42-alt1
Summary: ConnMan is a daemon for managing internet connections.
Changelog:
- New version 1.42. (Fixes: CVE-2022-32292, CVE-2022-32293, CVE-2023-28488)
Jul 29, 2023, 03:38 AM
burp
Version: 2.5.4-alt4
Summary: Burp is a network-based backup and restore program
Changelog:
- Support for OpenSSL 3 (to access Blowfish encryption). - Apply fixes to bundled yajl (CVE-2023-33460, CVE-2022-24795, CVE-2017-16516).
Jul 14, 2023, 07:53 PM
pesign
Version: 116-alt1
Summary: Signing tool for PE-COFF binaries
Changelog:
- new version 116 (Fixes: CVE-2022-3560) + rebase ALT commits + remove obsolete patches
Jul 13, 2023, 05:12 PM
less
Version: 633-alt1
Summary: A text file browser similar to more, but better
Changelog:
- New version (633). - Security fixes: + CVE-2022-46663: less -R filtering bypass.
Jun 14, 2023, 09:32 AM
yajl
May 27, 2023, 03:54 AM
libtpms
Version: 0.9.6-alt1
Summary: Library providing Trusted Platform Module (TPM) functionality
Changelog:
- New version 0.9.6 (Fixes: CVE-2023-1017, CVE-2023-1018).
May 23, 2023, 12:02 PM
python3-module-requests
Version: 2.31.0-alt1
Summary: HTTP library, written in Python, for human beings
Changelog:
- 2.29.0 -> 2.31.0 (fixes: CVE-2023-32681).
Apr 8, 2023, 03:00 AM
ctags
Version: 5.8-alt6
Summary: A C programming language indexing and/or cross-reference tool
Changelog:
- Fixed arbitrary command execution via a tag file with a crafted filename (fixes CVE-2022-4515).
Mar 29, 2023, 07:29 AM
libmemcached
Version: 1.1.4-alt1
Summary: Client library to the memcached
Changelog:
- 1.1.4 (Fixes CVE-2023-27478) - Change URL to new upstream project - Use CMAKE
Mar 21, 2023, 04:53 PM
firejail
Version: 0.9.72-alt1
Summary: Linux namespaces sandbox program
Changelog:
- 0.9.68 -> 0.9.72 (Fixes: CVE-2022-31214)
Mar 9, 2023, 11:59 AM
clamav
Version: 0.103.8-alt1
Summary: Clam Antivirus scanner
Changelog:
- 0.103.8 (CVE-2023-20032, CVE-2023-20052)
Feb 18, 2023, 05:05 PM
tpm2-tss
Dec 5, 2022, 03:48 PM
libarchive
Version: 3.6.1-alt2
Summary: A library for handling streaming archive formats
Changelog:
- security (fixes: CVE-2022-36227)
Nov 2, 2022, 09:12 AM
perl-DBI
Version: 1.643-alt3
Summary: Database independent interface for Perl
Changelog:
- rename patch lib-DBD-File.pm-fix-CVE-2014-10401.patch - fixes changelog
Oct 29, 2022, 11:07 PM
expat
Version: 2.5.0-alt1
Summary: An XML parser written in C
Changelog:
- Updated to 2.5.0 (fixes: CVE-2022-43680 Fix heap use-after-free after overeager destruction of a shared DTD in function XML_ExternalEntityParserCreate in out-of-memory situations, DoS or potentially ACE).
Oct 25, 2022, 05:31 PM
arj
Version: 3.10.22-alt9
Summary: An compressor and uncompressor for .arj format archive files
Changelog:
- Fixes patch CVE-2015-0557-security-traversal-dir (ALT #44143).
Oct 18, 2022, 12:14 AM
adcli
Version: 0.9.2-alt1
Summary: Active Directory enrollment
Changelog:
- Add support LDAP add/mod operation to set/change password: + fix unable to join to active directory after KB5008380/CVE-2021-42287 with option '--ldap-passwd'; + https://gitlab.freedesktop.org/realmd/adcli/-/issues/27 - Add support fall back to LDAPS if CLDAP ping was not successful + If the --use-ldaps option is used and there is no reply on the CLDAP 389/udp port adcli will try to send the request to the LDAPS port 636/tcp. - Fix write SID before secret to Samba's db looks like 'net changesecretpw' - Add passwd-user sub-command for (re)set a user password. - Add dont-expire-password option for computer.
Oct 14, 2022, 03:47 PM
aspell
Version: 0.60.8-alt2
Summary: An Open Source interactive spelling checker program
Changelog:
- fixes CVE-2019-25051
Oct 12, 2022, 02:52 PM
lrzsz
Version: 0.12.20-alt2
Summary: Programs for communicating over Z-, Y- & X-modem protocols.
Changelog:
- fixes CVE-2018-10195.
Oct 12, 2022, 07:45 AM
unzip
May 15, 2022, 08:57 PM
xpdf
Version: 4.04-alt1
Summary: The PDF viewer and tools
Changelog:
- Version bump - Many bugfixes, including security, including: Fixes: CVE-2022-24106, CVE-2022-27135
May 15, 2022, 08:53 AM
unrar
Version: 6.1.7-alt1
Summary: RAR unarchiver
Changelog:
- Autobuild version bump to 6.1.7 - Fixes: CVE-2022-30333
Feb 10, 2022, 07:20 PM
pgbouncer
Version: 1.16.1-alt1
Summary: Lightweight connection pooler for PostgreSQL
Changelog:
- 1.16.1 (Fixes: CVE-2021-3935).
Dec 14, 2021, 03:13 PM
mailman
Version: 2.1.39-alt1
Summary: Mailing list manager with built in web access
Changelog:
- 2.1.38 -> 2.1.39 (fixes for CVE-2021-42097 and CVE-2021-44227).
Nov 11, 2021, 03:28 PM
screen
Version: 4.8.0-alt2
Summary: A screen manager that supports multiple sessions on one terminal
Changelog:
- Applied SUSE combchar.diff to prevent DoS via crafted UTF-8 character sequence (fixes CVE-2021-26937).
Oct 30, 2021, 09:02 AM
libgfbgraph
Version: 0.2.5-alt1
Summary: A GObject library for Facebook Graph API
Changelog:
- 0.2.5 (fixed CVE-2021-39358)
Sep 23, 2021, 02:36 PM
libiec61850
Version: 1.5.0-alt1
Summary: Open source libraries for IEC 61850 and IEC 60870-5-104
Changelog:
- New version (Fixes: CVE-2020-15158).
Jun 27, 2021, 10:12 PM
mediawiki-extensions-Widgets
Version: 1.3.0-alt1git
Summary: Widgets extension allows adding widgets to wiki by just creating pages in Widget namespace
Changelog:
- new version (1.3.0) with rpmgs script - CVE-2020-9382, CVE-2020-35625
Apr 28, 2021, 02:38 PM
avahi
Version: 0.8-alt2
Summary: Local network service discovery
Changelog:
- avoid infinite-loop in avahi-daemon (closes: #39357) (fixes: CVE-2021-3468)
Jan 22, 2021, 10:54 AM
shellinabox
Version: 2.20-alt2
Summary: AJAX based terminal emulator exporting a console to the browser
Changelog:
- Applied security fix from upstream (Fixes CVE-2018-16789).
Jan 22, 2021, 10:20 AM
libevt
Version: 20140411-alt2
Summary: Library and tools to access the Windows Event Log (EVT) format
Changelog:
- Applied security fix from upstream (Fixes CVE-2018-8754).
Jan 21, 2021, 02:37 PM
fleet
Version: 3.6.0-alt1
Summary: The premier osquery fleet manager.
Changelog:
- Updated to upstream version 3.6.0 (Fixes: CVE-2020-26276).
Dec 18, 2020, 10:46 AM
icoutils
Version: 0.32.3-alt1
Summary: Utility for extracting and converting Microsoft icon and cursor files
Changelog:
- Updated to upstream version 0.32.3 (Fixes: CVE-2017-5208, CVE-2017-5331, CVE-2017-5332, CVE-2017-5333).
Dec 17, 2020, 04:07 PM
dnstracer
Version: 1.9-alt2
Summary: A tool to trace DNS queries
Changelog:
- Applied security patch from Gentoo (Fixes: CVE-2017-9430).