You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa nghttp2

Sigurnosni nedostaci programskog paketa nghttp2

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2018-cec96a9c41
2018-04-21 03:38:52.949232
——————————————————————————–

Name : nghttp2
Product : Fedora 27
Version : 1.31.1
Release : 1.fc27
URL : https://nghttp2.org/
Summary : Experimental HTTP/2 client, server and proxy
Description :
This package contains the HTTP/2 client, server and proxy programs.

——————————————————————————–
Update Information:

– update to the latest upstream release (fixes CVE-2018-1000168)
——————————————————————————–
ChangeLog:

* Fri Apr 13 2018 Kamil Dudka <kdudka@redhat.com> 1.31.1-1
– update to the latest upstream release (fixes CVE-2018-1000168)
* Thu Mar 15 2018 Kamil Dudka <kdudka@redhat.com> 1.31.0-2
– make fetch-ocsp-response use Python 3
* Tue Feb 27 2018 Kamil Dudka <kdudka@redhat.com> 1.31.0-1
– update to the latest upstream release
* Mon Feb 19 2018 Kamil Dudka <kdudka@redhat.com> 1.30.0-3
– add explicit BR for the gcc-c++ compiler
* Thu Feb 8 2018 Fedora Release Engineering <releng@fedoraproject.org> – 1.30.0-2
– Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Mon Feb 5 2018 Kamil Dudka <kdudka@redhat.com> 1.30.0-1
– update to the latest upstream release
* Sat Feb 3 2018 Igor Gnatenko <ignatenkobrain@fedoraproject.org> – 1.29.0-2
– Switch to %ldconfig_scriptlets
* Tue Dec 19 2017 Kamil Dudka <kdudka@redhat.com> 1.29.0-1
– update to the latest upstream release
* Sun Nov 26 2017 Kamil Dudka <kdudka@redhat.com> 1.28.0-1
– update to the latest upstream release
* Wed Oct 25 2017 Kamil Dudka <kdudka@redhat.com> 1.27.0-1
– update to the latest upstream release
* Wed Sep 20 2017 Kamil Dudka <kdudka@redhat.com> 1.26.0-1
– update to the latest upstream release
——————————————————————————–
References:

[ 1 ] Bug #1566990 – CVE-2018-1000168 nghttp2: Null pointer dereference when too large ALTSVC frame is received [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1566990
[ 2 ] Bug #1566772 – nghttp2-1.31.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1566772
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2018-cec96a9c41’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

AutorPetar Bertok
Cert idNCERT-REF-2018-04-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa jgraphx

Otkriveni su sigurnosni nedostaci u programskom paketu jgraphx za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju stjecanje viših privilegija,...

Close