PaulHowarth/Blog/2023-06-05

Monday 5th June 2023

Fedora Project

  • Updated perl-true (1.0.2) in Rawhide to use SPDX-format license tag

  • Updated python-should_dsl (2.1.2) in Rawhide to update to current Python packaging guidelines, as far as possible

Local Packages

  • Updated c-ares to 1.19.1:

    • CVE-2023-32067 (High): 0-byte UDP payload causes Denial of Service

    • CVE-2023-31147 (Moderate): Insufficient randomness in generation of DNS query IDs

    • CVE-2023-31130 (Moderate): Buffer Underwrite in ares_inet_net_pton()

    • CVE-2023-31124 (Low): AutoTools does not set CARES_RANDOM_FILE during cross compilation

    • Fix uninitialized memory warning in test
    • Turn off IPV6_V6ONLY on Windows to allow IPv4-mapped IPv6 addresses

    • ares_getaddrinfo() should allow a port of 0

    • Fix memory leak in ares_send() on error

    • Fix comment style in ares_data.h

    • Remove unneeded ifdef for Windows

    • Fix typo in ares_init_options.3

    • Re-add support for Watcom compiler
    • Sync ax_pthread.m4 with upstream

    • Windows: Invalid stack variable used out of scope for HOSTS path
    • Sync ax_cxx_compile_stdcxx_11.m4 with upstream to fix uclibc support

  • Updated perl-true (1.0.2) as per the Fedora version

  • Updated sendmail to 8.17.2 (see RELEASE_NOTES for details)

  • Updated unrar to 6.22


Recent