The following Fedora EPEL 6 Security updates need testing:
Age URL
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-b1a5eb3ef5
librabbitmq-0.5.2-2.el6
1
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-22ba261c73
drupal7-ckeditor-1.19-1.el6
1
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-082ab81e5f
php-robrichards-xmlseclibs1-1.4.3-1.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
nrpe-4.0.2-1.el6
Details about builds:
================================================================================
nrpe-4.0.2-1.el6 (FEDORA-EPEL-2020-fc983d39e7)
Host/service/network monitoring agent for Nagios
--------------------------------------------------------------------------------
Update Information:
New upstream version fixes CVEs
--------------------------------------------------------------------------------
ChangeLog:
* Tue Apr 7 2020 Martin Jackson <mhjacks(a)swbell.net> - 4.0.2-1
- New upstream version
- Update patch for indlude_dir
- Fix BZ#1816816 - CVE-2020-6582 nrpe: heap-based buffer overflow due to a wrong integer
type conversion
- Fix BZ#1816805 - CVE-2020-6581 nrpe: insufficient filtering and incorrect parsing of the
configuration file may lead to command injection
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1816805 - CVE-2020-6581 nrpe: insufficient filtering and incorrect parsing of
the configuration file may lead to command injection [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1816805
[ 2 ] Bug #1816816 - CVE-2020-6582 nrpe: heap-based buffer overflow due to a wrong
integer type conversion [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1816816
--------------------------------------------------------------------------------