The following Fedora EPEL 6 Security updates need testing: Age URL 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-b1a5eb3ef5 librabbitmq-0.5.2-2.el6 1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-22ba261c73 drupal7-ckeditor-1.19-1.el6 1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-082ab81e5f php-robrichards-xmlseclibs1-1.4.3-1.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
nrpe-4.0.2-1.el6
Details about builds:
================================================================================ nrpe-4.0.2-1.el6 (FEDORA-EPEL-2020-fc983d39e7) Host/service/network monitoring agent for Nagios -------------------------------------------------------------------------------- Update Information:
New upstream version fixes CVEs -------------------------------------------------------------------------------- ChangeLog:
* Tue Apr 7 2020 Martin Jackson mhjacks@swbell.net - 4.0.2-1 - New upstream version - Update patch for indlude_dir - Fix BZ#1816816 - CVE-2020-6582 nrpe: heap-based buffer overflow due to a wrong integer type conversion - Fix BZ#1816805 - CVE-2020-6581 nrpe: insufficient filtering and incorrect parsing of the configuration file may lead to command injection -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1816805 - CVE-2020-6581 nrpe: insufficient filtering and incorrect parsing of the configuration file may lead to command injection [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1816805 [ 2 ] Bug #1816816 - CVE-2020-6582 nrpe: heap-based buffer overflow due to a wrong integer type conversion [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1816816 --------------------------------------------------------------------------------
epel-devel@lists.fedoraproject.org