https://bugzilla.redhat.com/show_bug.cgi?id=2093358
Bug ID: 2093358
Summary: CVE-2021-46790 ntfs-3g: heap-based buffer overflow in
ntfsck
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: gsuckevi(a)redhat.com
CC: ddepaula(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
jferlan(a)redhat.com, kparal(a)redhat.com,
ngompa13(a)gmail.com, rjones(a)redhat.com,
spotrh(a)gmail.com, virt-maint(a)redhat.com
Target Milestone: ---
Classification: Other
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving
buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated;
however, it is shipped by some Linux distributions.
References:
https://github.com/tuxera/ntfs-3g/issues/16http://www.openwall.com/lists/oss-security/2022/05/26/1
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2093358
https://bugzilla.redhat.com/show_bug.cgi?id=2093348
Bug ID: 2093348
Summary: CVE-2022-30789 ntfs-3g: crafted NTFS image can cause a
heap-based buffer overflow in
ntfs_check_log_client_array
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: gsuckevi(a)redhat.com
CC: ddepaula(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
jferlan(a)redhat.com, kparal(a)redhat.com,
ngompa13(a)gmail.com, rjones(a)redhat.com,
spotrh(a)gmail.com, virt-maint(a)redhat.com
Target Milestone: ---
Classification: Other
A crafted NTFS image can cause a heap-based buffer overflow in
ntfs_check_log_client_array in NTFS-3G through 2021.8.22.
References:
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4xhttps://github.com/tuxera/ntfs-3g/releases
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2093348
https://bugzilla.redhat.com/show_bug.cgi?id=2093340
Bug ID: 2093340
Summary: CVE-2022-30788 ntfs-3g: crafted NTFS image can cause a
heap-based buffer overflow in ntfs_mft_rec_alloc
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: gsuckevi(a)redhat.com
CC: ddepaula(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
jferlan(a)redhat.com, kparal(a)redhat.com,
ngompa13(a)gmail.com, rjones(a)redhat.com,
spotrh(a)gmail.com, virt-maint(a)redhat.com
Target Milestone: ---
Classification: Other
A crafted NTFS image can cause a heap-based buffer overflow in
ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.
References:
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4xhttps://github.com/tuxera/ntfs-3g/releases
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2093340
https://bugzilla.redhat.com/show_bug.cgi?id=2093326
Bug ID: 2093326
Summary: CVE-2022-30786 ntfs-3g: crafted NTFS image can cause a
heap-based buffer overflow in ntfs_names_full_collate
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: gsuckevi(a)redhat.com
CC: ddepaula(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
jferlan(a)redhat.com, kparal(a)redhat.com,
ngompa13(a)gmail.com, rjones(a)redhat.com,
spotrh(a)gmail.com, virt-maint(a)redhat.com
Target Milestone: ---
Classification: Other
A crafted NTFS image can cause a heap-based buffer overflow in
ntfs_names_full_collate in NTFS-3G through 2021.8.22.
References:
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4xhttps://github.com/tuxera/ntfs-3g/releases
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2093326
https://bugzilla.redhat.com/show_bug.cgi?id=2093314
Bug ID: 2093314
Summary: CVE-2022-30784 ntfs-3g: crafted NTFS image can cause
heap exhaustion in ntfs_get_attribute_value
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: gsuckevi(a)redhat.com
CC: ddepaula(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
jferlan(a)redhat.com, kparal(a)redhat.com,
ngompa13(a)gmail.com, rjones(a)redhat.com,
spotrh(a)gmail.com, virt-maint(a)redhat.com
Target Milestone: ---
Classification: Other
A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in
NTFS-3G through 2021.8.22.
References:
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4xhttps://github.com/tuxera/ntfs-3g/releases
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2093314
https://bugzilla.redhat.com/show_bug.cgi?id=2120929
Bug ID: 2120929
Summary: python-bcrypt-4.0.0 is available
Product: Fedora
Version: rawhide
Status: NEW
Component: python-bcrypt
Keywords: FutureFeature, Triaged
Assignee: pingou(a)pingoured.fr
Reporter: upstream-release-monitoring(a)fedoraproject.org
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
infra-sig(a)lists.fedoraproject.org, mhayden(a)redhat.com,
pingou(a)pingoured.fr,
python-sig(a)lists.fedoraproject.org,
williamjmorenor(a)gmail.com
Target Milestone: ---
Classification: Fedora
Releases retrieved: 4.0.0
Upstream release that is considered latest: 4.0.0
Current version/release in rawhide: 3.2.2-4.fc37
URL: http://pypi.python.org/pypi/bcrypt
Please consult the package updates policy before you issue an update to a
stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/
More information about the service that created this bug can be found at:
https://fedoraproject.org/wiki/Upstream_release_monitoring
Please keep in mind that with any upstream change, there may also be packaging
changes that need to be made. Specifically, please remember that it is your
responsibility to review the new version to ensure that the licensing is still
correct and that no non-free or legally problematic items have been added
upstream.
Based on the information from Anitya:
https://release-monitoring.org/project/9047/
To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/python-bcrypt
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2120929
https://bugzilla.redhat.com/show_bug.cgi?id=2082587
Bug ID: 2082587
Summary: Busybox 1.35.0-2 crashes
Product: Fedora
Version: 36
Status: NEW
Component: busybox
Severity: high
Assignee: spotrh(a)gmail.com
Reporter: stefanb(a)us.ibm.com
QA Contact: extras-qa(a)fedoraproject.org
CC: admiller(a)redhat.com, dcavalca(a)fb.com,
dvlasenk(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
spotrh(a)gmail.com
Target Milestone: ---
Classification: Fedora
Description of problem:
Busybox 1.35.0-2 is crashing for me
Version-Release number of selected component (if applicable):
1.35.0-2
How reproducible:
I need to downgrade busybox to have it working ...
[stefanb@test ~]$ busybox sh
Segmentation fault (core dumped)
[stefanb@test ~]$ gdb --args busybox sh
GNU gdb (GDB) Fedora 11.2-3.fc36
Copyright (C) 2022 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
Type "show copying" and "show warranty" for details.
This GDB was configured as "x86_64-redhat-linux-gnu".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<https://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
<http://www.gnu.org/software/gdb/documentation/>.
For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from busybox...
This GDB supports auto-downloading debuginfo from the following URLs:
https://debuginfod.fedoraproject.org/
Enable debuginfod for this session? (y or [n]) y
Debuginfod has been enabled.
To make this setting permanent, add 'set debuginfod enabled on' to .gdbinit.
Reading symbols from
/home/stefanb/.cache/debuginfod_client/88baa87c0a47de9361e9abdbea1d01d5ee79f832/debuginfo...
(gdb) r
Starting program: /usr/sbin/busybox sh
Downloading separate debug info for /home/stefanb/system-supplied DSO at
0x7ffff7ffd000...
Program received signal SIGSEGV, Segmentation fault.
0x0000000000409597 in parse_config_file () at libbb/appletlib.c:329
329 {
(gdb) q
A debugging session is active.
Inferior 1 [process 3691] will be killed.
Quit anyway? (y or n) y
[stefanb@test ~]$ sudo su -
[root@test ~]# busybox sh
Segmentation fault (core dumped)
[root@test ~]# sudo dnf -y reinstall busybox
Last metadata expiration check: 3:08:06 ago on Fri 06 May 2022 06:09:36 AM.
Dependencies resolved.
===========================================================================================================================================================
Package Architecture Version
Repository Size
===========================================================================================================================================================
Reinstalling:
busybox x86_64
1:1.35.0-2.fc36 fedora
775 k
Transaction Summary
===========================================================================================================================================================
Total download size: 775 k
Installed size: 1.5 M
Downloading Packages:
busybox-1.35.0-2.fc36.x86_64.rpm
4.9 MB/s | 775 kB 00:00
-----------------------------------------------------------------------------------------------------------------------------------------------------------
Total
2.0 MB/s | 775 kB 00:00
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
Preparing :
1/1
Reinstalling : busybox-1:1.35.0-2.fc36.x86_64
1/2
Cleanup : busybox-1:1.35.0-2.fc36.x86_64
2/2
Running scriptlet: busybox-1:1.35.0-2.fc36.x86_64
2/2
Verifying : busybox-1:1.35.0-2.fc36.x86_64
1/2
Verifying : busybox-1:1.35.0-2.fc36.x86_64
2/2
Reinstalled:
busybox-1:1.35.0-2.fc36.x86_64
Complete!
[root@test ~]# busybox ls
Segmentation fault (core dumped)
[root@test ~]# dnf remove busybox
Dependencies resolved.
===========================================================================================================================================================
Package Architecture Version
Repository Size
===========================================================================================================================================================
Removing:
busybox x86_64
1:1.35.0-2.fc36 @fedora
1.5 M
Transaction Summary
===========================================================================================================================================================
Remove 1 Package
Freed space: 1.5 M
Is this ok [y/N]: y
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
Preparing :
1/1
Erasing : busybox-1:1.35.0-2.fc36.x86_64
1/1
Running scriptlet: busybox-1:1.35.0-2.fc36.x86_64
1/1
Verifying : busybox-1:1.35.0-2.fc36.x86_64
1/1
Removed:
busybox-1:1.35.0-2.fc36.x86_64
Complete!
[root@test ~]# rpm -Uvh
https://kojipkgs.fedoraproject.org//packages/busybox/1.34.1/1.fc36/x86_64/b…
Retrieving
https://kojipkgs.fedoraproject.org//packages/busybox/1.34.1/1.fc36/x86_64/b…
Verifying... ################################# [100%]
Preparing... ################################# [100%]
Updating / installing...
1:busybox-1:1.34.1-1.fc36 ################################# [100%]
[root@test ~]# busybox sh
~ #
[root@test ~]#
logout
[stefanb@test ~]$ busybox sh
~ $
Expected results:
Busybox should work.
Additional info:
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2082587
https://bugzilla.redhat.com/show_bug.cgi?id=2113645
Bug ID: 2113645
Summary: python-postorius: FTBFS in Fedora rawhide/f37
Product: Fedora
Version: rawhide
Status: NEW
Component: python-postorius
Assignee: michel(a)michel-slm.name
Reporter: releng(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
infra-sig(a)lists.fedoraproject.org,
michel(a)michel-slm.name, ngompa13(a)gmail.com,
python-sig(a)lists.fedoraproject.org
Blocks: 2045102 (F37FTBFS,RAWHIDEFTBFS)
Target Milestone: ---
Classification: Fedora
python-postorius failed to build from source in Fedora rawhide/f37
https://koji.fedoraproject.org/koji/taskinfo?taskID=89886097
For details on the mass rebuild see:
https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
Please fix python-postorius at your earliest convenience and set the bug's
status to
ASSIGNED when you start fixing it. If the bug remains in NEW state for 8 weeks,
python-postorius will be orphaned. Before branching of Fedora 38,
python-postorius will be retired, if it still fails to build.
For more details on the FTBFS policy, please visit:
https://docs.fedoraproject.org/en-US/fesco/Fails_to_build_from_source_Fails…
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=2045102
[Bug 2045102] Fedora 37 FTBFS Tracker
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2113645
https://bugzilla.redhat.com/show_bug.cgi?id=2046878
Bug ID: 2046878
Summary: python-hyperkitty: FTBFS in Fedora rawhide/f36
Product: Fedora
Version: rawhide
Status: NEW
Component: python-hyperkitty
Assignee: michel(a)michel-slm.name
Reporter: releng(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
infra-sig(a)lists.fedoraproject.org,
michel(a)michel-slm.name, ngompa13(a)gmail.com,
python-sig(a)lists.fedoraproject.org
Blocks: 1992484 (F36FTBFS)
Target Milestone: ---
Classification: Fedora
python-hyperkitty failed to build from source in Fedora rawhide/f36
https://koji.fedoraproject.org/koji/taskinfo?taskID=81985454
For details on the mass rebuild see:
https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
Please fix python-hyperkitty at your earliest convenience and set the bug's
status to
ASSIGNED when you start fixing it. If the bug remains in NEW state for 8 weeks,
python-hyperkitty will be orphaned. Before branching of Fedora 37,
python-hyperkitty will be retired, if it still fails to build.
For more details on the FTBFS policy, please visit:
https://docs.fedoraproject.org/en-US/fesco/Fails_to_build_from_source_Fails…
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=1992484
[Bug 1992484] Fedora 36 FTBFS Tracker
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2046878
https://bugzilla.redhat.com/show_bug.cgi?id=2049668
Bug ID: 2049668
Summary: libimagequant-4.0.0 is available
Product: Fedora
Version: rawhide
Status: NEW
Component: libimagequant
Keywords: FutureFeature, Triaged
Assignee: manisandro(a)gmail.com
Reporter: upstream-release-monitoring(a)fedoraproject.org
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
infra-sig(a)lists.fedoraproject.org,
manisandro(a)gmail.com,
python-sig(a)lists.fedoraproject.org, sergio(a)serjux.com
Target Milestone: ---
Classification: Fedora
Latest upstream release: 4.0.0
Current version/release in rawhide: 2.17.0-2.fc36
URL: https://pngquant.org/lib/
Please consult the package updates policy before you issue an update to a
stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/
More information about the service that created this bug can be found at:
https://fedoraproject.org/wiki/Upstream_release_monitoring
Please keep in mind that with any upstream change, there may also be packaging
changes that need to be made. Specifically, please remember that it is your
responsibility to review the new version to ensure that the licensing is still
correct and that no non-free or legally problematic items have been added
upstream.
Based on the information from Anitya:
https://release-monitoring.org/project/12768/
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2049668