From 04ac238703da84168e02b06fb131d1d17d85be23 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sun, 29 Sep 2024 01:25:46 +0100 Subject: gentoo auto-resync : 29:09:2024 - 01:25:46 --- metadata/glsa/Manifest | 30 ++++++------- metadata/glsa/Manifest.files.gz | Bin 589322 -> 590436 bytes metadata/glsa/glsa-202409-26.xml | 88 +++++++++++++++++++++++++++++++++++++++ metadata/glsa/glsa-202409-27.xml | 42 +++++++++++++++++++ metadata/glsa/glsa-202409-28.xml | 42 +++++++++++++++++++ metadata/glsa/glsa-202409-29.xml | 60 ++++++++++++++++++++++++++ metadata/glsa/glsa-202409-30.xml | 46 ++++++++++++++++++++ metadata/glsa/glsa-202409-31.xml | 58 ++++++++++++++++++++++++++ metadata/glsa/glsa-202409-32.xml | 45 ++++++++++++++++++++ metadata/glsa/timestamp.chk | 2 +- metadata/glsa/timestamp.commit | 2 +- 11 files changed, 398 insertions(+), 17 deletions(-) create mode 100644 metadata/glsa/glsa-202409-26.xml create mode 100644 metadata/glsa/glsa-202409-27.xml create mode 100644 metadata/glsa/glsa-202409-28.xml create mode 100644 metadata/glsa/glsa-202409-29.xml create mode 100644 metadata/glsa/glsa-202409-30.xml create mode 100644 metadata/glsa/glsa-202409-31.xml create mode 100644 metadata/glsa/glsa-202409-32.xml (limited to 'metadata/glsa') diff --git a/metadata/glsa/Manifest b/metadata/glsa/Manifest index 9cb3c11d36b8..25283758b50d 100644 --- a/metadata/glsa/Manifest +++ b/metadata/glsa/Manifest @@ -1,23 +1,23 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 -MANIFEST Manifest.files.gz 589322 BLAKE2B 6789f452bb091cab1551fd39d1eb24aad056758ab4927e345d12b32324a84240dc49fd5fbc0c8eddd74cdd9181d8eadd04df6c040625d04494a51f9fe347a4f8 SHA512 2ec038957c010fa082d365808e04a0bfd93388a083821ce8a50b3347e2e7bfed61bc8686450f62c8347c91a57ede6dc514c9b54f8164db4e2ad4d04c0268e09c -TIMESTAMP 2024-09-27T23:40:44Z +MANIFEST Manifest.files.gz 590436 BLAKE2B 15aabc4185729e136cdcfaf5f8f985f8037a950c2674b40f4a60d6db55b6e66ddf62465183eec797a8745737731f08c9f5b7997b3092ca23932abe139760e3a2 SHA512 d4bc062a4c9898005fcd53314c2db40baaef3e5725ab92e762d55ae3747dcb34a1602299c2aa4bdf60a06b6f322e89ee0b897eafffb10de6e5392274ab828bc5 +TIMESTAMP 2024-09-28T23:40:40Z -----BEGIN PGP SIGNATURE----- -iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAmb3QnxfFIAAAAAALgAo +iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAmb4k/hfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEUx RDZBQkI2M0JGQ0ZCNEJBMDJGREYxQ0VDNTkwRUVBQzkxODkyNTAACgkQ7FkO6skY -klA/+A/8D7L6MmWT1Rw2sOGr6AsN+xIlX5MuJXFZSF/ejTsbwm4O/VZbqcbSAsG+ -jVg3RqAq2VIgNN0X0s82s2Oowb66I69Hv1IjZ0/atA2M3jsmdk3NP22ShiUo9+uo -hObF4O5m998nMmYRoDs8zSpSW5cfA/VEr/zP/kXLagIzEVFOw3HjNHT0jsMVLhy+ -7KmYyIXczK3sih+GqsfYm8+ox00Z7a5/gypAKMBdPuCHCanXSRfeNaOWfn6kOHBr -M703XWLjOUJEVCXWj73+xr3KphRTYRhr3Y1o0E/YD3oUSMifC1ZyZajem1RC/ifG -6Z8MWF6jsnn7dqfs0uq8gulwkcAcFQ6v7kZOD2Y2kob5y+BkUUEmVf/AtMxEnU0d -82y+FmY2V08OxMxKOewLX1sa9GvJcbck5U3GcxuafZW2E46gASrl5l+Qju4/ElJF -FVMFH13fTrnKXw9ZmpSHmJZqNp0+elJs0o3d60fqiBf5rdo6z+ZcEQwP956Q/iaS -BXOCfFOB2xDToI1rkRDMSu1lUMwnn8Aw65TAoEtkwhEqgzJdQ3VjgQWjzx2UHjv0 -6Um88/32JEsNBEq9joUeXJjuPi6wRLPyNxRFTyV+2YQ5izzO0PaLnOXCBGunTbeX -cU7xrAID8WvraE8QmFl4QgfGvzkOSvPjn5gsJTzK6qG25h1lUEI= -=RkMh +klCZYxAApNKNELRSlYb2jQ+E+WJJO6M8PIYSWXgvJeD/4dPGdJrc+XGbD8hXWbyW +Nn4ZY1tTLz6mrxexjJHCti+JDvKRerqEI6mxPPF+qsMf4T7P8Vhk5OjKLWYzELwU +M9JVYftlrelkMwZUU2XiC79AhfnT1bHmfq33MA/rw6TFCEEkIu06APu4QjKRZP3b +RdNp9JyC+ZG0yTlTwV/Jvh/FgR4yXqdeOSVJ2Cthq4bXvVpWNMdeNwZnorVY0RX3 +4grchRQKaFt2G+0skAiZqtC/DQ5A9w2suCYgPs7PVZ77MMM4HOgfSor+ibk8vYEi +CYUnqQVlcI5rKlEnX2fy9iiGG+6fHEWHeB1B47r072w/uKwhyUg5DBA/4iXM3U7V +NKLAUwsRtW4Mll4niBuDlaY3aQgj0Fh4xkJaXcmASWVML62w92jwL1IZCqOa0f5b +k2PkVFr9Z/joS7d9eNRRah3m3rTFoEYkKIn4eW9Vs3tIjiJtXVPsxVBcALx7LZDW ++AmHcon9G/0DePk1un60oGbdw43QMA0SBBWW1AMF0yWr1C2lIsh1UBlVkknCtf1K +MkVk4aj4EN+V1fUrB6i0jatkRrPl1c2Iyn4g8A3ShBgB4nMzlXmr67V/xdcF8gnE +fa2AxlrJomKBKatBeAih4J0pVcVoapYyp2iMpk+7we+GryT6xVg= +=8rKm -----END PGP SIGNATURE----- diff --git a/metadata/glsa/Manifest.files.gz b/metadata/glsa/Manifest.files.gz index 946bc1adaad4..3b2eab36a094 100644 Binary files a/metadata/glsa/Manifest.files.gz and b/metadata/glsa/Manifest.files.gz differ diff --git a/metadata/glsa/glsa-202409-26.xml b/metadata/glsa/glsa-202409-26.xml new file mode 100644 index 000000000000..c06fb1aaa200 --- /dev/null +++ b/metadata/glsa/glsa-202409-26.xml @@ -0,0 +1,88 @@ + + + + IcedTea: Multiple Vulnerabilities + Multiple vulnerabilities have been found in IcedTea, the worst of which could result in arbitrary code execution. + icedtea,icedtea-bin + 2024-09-28 + 2024-09-28 + 732628 + 803608 + 877599 + local + + + 3.21.0 + + + 3.16.0-r2 + + + +

IcedTea’s aim is to provide OpenJDK in a form suitable for easy configuration, compilation and distribution with the primary goal of allowing inclusion in GNU/Linux distributions.

+
+ +

Multiple vulnerabilities have been discovered in IcedTea. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

Gentoo has discontinued support for IcedTea. We recommend that users unmerge it:

+ + + # emerge --sync + # emerge --ask --depclean "dev-java/icedtea" "dev-java/icedtea-bin" + +
+ + CVE-2020-14556 + CVE-2020-14562 + CVE-2020-14573 + CVE-2020-14577 + CVE-2020-14578 + CVE-2020-14579 + CVE-2020-14581 + CVE-2020-14583 + CVE-2020-14593 + CVE-2020-14621 + CVE-2020-14664 + CVE-2020-14779 + CVE-2020-14781 + CVE-2020-14782 + CVE-2020-14792 + CVE-2020-14796 + CVE-2020-14797 + CVE-2020-14798 + CVE-2020-14803 + CVE-2021-2341 + CVE-2021-2369 + CVE-2021-2388 + CVE-2021-2432 + CVE-2021-35550 + CVE-2021-35556 + CVE-2021-35559 + CVE-2021-35561 + CVE-2021-35564 + CVE-2021-35565 + CVE-2021-35567 + CVE-2021-35578 + CVE-2021-35586 + CVE-2021-35588 + CVE-2021-35603 + CVE-2022-21618 + CVE-2022-21619 + CVE-2022-21624 + CVE-2022-21626 + CVE-2022-21628 + CVE-2022-39399 + CVE-2023-21830 + CVE-2023-21835 + CVE-2023-21843 + + ajak + graaff +
\ No newline at end of file diff --git a/metadata/glsa/glsa-202409-27.xml b/metadata/glsa/glsa-202409-27.xml new file mode 100644 index 000000000000..829708a77229 --- /dev/null +++ b/metadata/glsa/glsa-202409-27.xml @@ -0,0 +1,42 @@ + + + + tmux: Null Pointer Dereference + A vulnerability has been found in tmux which could result in application crash. + tmux + 2024-09-28 + 2024-09-28 + 891783 + remote + + + 3.4 + 3.4 + + + +

tmux is a terminal multiplexer.

+
+ +

A null pointer dereference issue was discovered in function window_pane_set_event in window.c in which allows attackers to cause denial of service or other unspecified impacts.

+
+ +

Manipulating tmux window state could result in a null pointer dereference.

+
+ +

There is no known workaround at this time.

+
+ +

All tmux users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-misc/tmux-3.4" + +
+ + CVE-2022-47016 + + ajak + graaff +
\ No newline at end of file diff --git a/metadata/glsa/glsa-202409-28.xml b/metadata/glsa/glsa-202409-28.xml new file mode 100644 index 000000000000..014f558570ed --- /dev/null +++ b/metadata/glsa/glsa-202409-28.xml @@ -0,0 +1,42 @@ + + + + HashiCorp Consul: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service. + consul + 2024-09-28 + 2024-09-28 + 885997 + remote + + + 1.15.10 + 1.15.10 + + + +

HashiCorp Consul is a tool for service discovery, monitoring and configuration.

+
+ +

Multiple vulnerabilities have been found in HashiCorp Consul. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the CVE identifiers referenced below for details.

+
+ +

There is no known workaround at this time.

+
+ +

All HashiCorp Consul users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-admin/consul-1.15.10" + +
+ + CVE-2022-41717 + + ajak + graaff +
\ No newline at end of file diff --git a/metadata/glsa/glsa-202409-29.xml b/metadata/glsa/glsa-202409-29.xml new file mode 100644 index 000000000000..6450cffbf690 --- /dev/null +++ b/metadata/glsa/glsa-202409-29.xml @@ -0,0 +1,60 @@ + + + + Docker: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in Docker, the worst of which could result in denial of service. + docker + 2024-09-28 + 2024-09-28 + 816273 + 869407 + 877653 + 886509 + 903804 + 905336 + 925022 + remote + + + 25.0.4 + 25.0.4 + + + +

Docker contains the the core functions you need to create Docker images and run Docker containers

+
+ +

Multiple vulnerabilities have been discovered in Docker. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Docker users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-containers/docker-25.0.4" + +
+ + CVE-2021-41089 + CVE-2021-41091 + CVE-2022-36109 + CVE-2022-41717 + CVE-2023-26054 + CVE-2023-28840 + CVE-2023-28841 + CVE-2023-28842 + CVE-2024-23650 + CVE-2024-23651 + CVE-2024-23652 + CVE-2024-23653 + CVE-2024-24557 + + ajak + graaff +
\ No newline at end of file diff --git a/metadata/glsa/glsa-202409-30.xml b/metadata/glsa/glsa-202409-30.xml new file mode 100644 index 000000000000..3f0096074d63 --- /dev/null +++ b/metadata/glsa/glsa-202409-30.xml @@ -0,0 +1,46 @@ + + + + yt-dlp: Multiple Vulnerabilities + Multiple vulnerabilities have been found in yt-dlp, the worst of which could result in arbitrary code execution. + yt-dlp + 2024-09-28 + 2024-09-28 + 909780 + 917355 + 935316 + remote + + + 2024.07.01 + 2024.07.01 + + + +

yt-dlp is a youtube-dl fork with additional features and fixes.

+
+ +

Multiple vulnerabilities have been found in yt-dlp. Please review the referenced CVE identifiers for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All yt-dlp users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/yt-dlp-2024.07.01" + +
+ + CVE-2023-35934 + CVE-2023-46121 + CVE-2024-38519 + + ajak + graaff +
\ No newline at end of file diff --git a/metadata/glsa/glsa-202409-31.xml b/metadata/glsa/glsa-202409-31.xml new file mode 100644 index 000000000000..cf98ba3e87e2 --- /dev/null +++ b/metadata/glsa/glsa-202409-31.xml @@ -0,0 +1,58 @@ + + + + Apache HTTPD: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Apache HTTPD, the worst of which could result in denial of service. + apache + 2024-09-28 + 2024-09-28 + 928540 + 935296 + 935427 + 936257 + remote + + + 2.4.62 + 2.4.62 + + + +

The Apache HTTP server is one of the most popular web servers on the Internet.

+
+ +

Multiple vulnerabilities have been discovered in Apache HTTPD. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Apache HTTPD users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-servers/apache-2.4.62" + +
+ + CVE-2023-38709 + CVE-2024-24795 + CVE-2024-27316 + CVE-2024-36387 + CVE-2024-38472 + CVE-2024-38473 + CVE-2024-38474 + CVE-2024-38475 + CVE-2024-38476 + CVE-2024-38477 + CVE-2024-39573 + CVE-2024-39884 + CVE-2024-40725 + CVE-2024-40898 + + ajak + graaff +
\ No newline at end of file diff --git a/metadata/glsa/glsa-202409-32.xml b/metadata/glsa/glsa-202409-32.xml new file mode 100644 index 000000000000..d9784c35e645 --- /dev/null +++ b/metadata/glsa/glsa-202409-32.xml @@ -0,0 +1,45 @@ + + + + nginx: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in nginx, the worst of which could result in denial of service. + nginx + 2024-09-28 + 2024-09-28 + 924619 + 937938 + remote + + + 1.26.2-r2 + 1.26.2-r2 + + + +

nginx is a robust, small, and high performance HTTP and reverse proxy server.

+
+ +

Multiple vulnerabilities have been discovered in nginx. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All nginx users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-servers/nginx-1.26.2-r2" + +
+ + CVE-2024-7347 + CVE-2024-24989 + CVE-2024-24990 + + ajak + graaff +
\ No newline at end of file diff --git a/metadata/glsa/timestamp.chk b/metadata/glsa/timestamp.chk index a81507ba4d98..c692a8b72177 100644 --- a/metadata/glsa/timestamp.chk +++ b/metadata/glsa/timestamp.chk @@ -1 +1 @@ -Fri, 27 Sep 2024 23:40:41 +0000 +Sat, 28 Sep 2024 23:40:35 +0000 diff --git a/metadata/glsa/timestamp.commit b/metadata/glsa/timestamp.commit index 4f92925ecd18..7474dc84acd3 100644 --- a/metadata/glsa/timestamp.commit +++ b/metadata/glsa/timestamp.commit @@ -1 +1 @@ -fe5f44a92c358b6196f8c599e9199edaa35a33ad 1727245785 2024-09-25T06:29:45Z +93155fde00088b123d8b46acf068ecadcf7bcfdb 1727512056 2024-09-28T08:27:36Z -- cgit v1.2.3