FEDORA-2021-83fdddca0f created by kdudka 2 weeks ago for Fedora 34
stable
  • fix TELNET stack contents disclosure again (CVE-2021-22925)
  • fix bad connection reuse due to flawed path name checks (CVE-2021-22924)
  • disable metalink support to fix the following vulnerabilities CVE-2021-22923 - metalink download sends credentials CVE-2021-22922 - wrong content via metalink not discarded

How to install

sudo dnf upgrade --advisory=FEDORA-2021-83fdddca0f

This update has been submitted for testing by kdudka.

2 weeks ago

This update's test gating status has been changed to 'failed'.

2 weeks ago

This update's test gating status has been changed to 'waiting'.

2 weeks ago

This update's test gating status has been changed to 'failed'.

2 weeks ago

This update's test gating status has been changed to 'passed'.

2 weeks ago

This update has been pushed to testing.

2 weeks ago
User Icon bojan provided feedback 2 weeks ago
karma
User Icon lnie commented & provided feedback 2 weeks ago
karma

works as usual

This update can be pushed to stable now if the maintainer wishes

2 weeks ago
User Icon vtrefny provided feedback 2 weeks ago
karma

This update has been submitted for stable by bodhi.

2 weeks ago

This update has been pushed to stable.

2 weeks ago
User Icon kdudka commented & provided feedback 2 weeks ago

Thank you for testing the update!


Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
3
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
2 weeks ago
in testing
2 weeks ago
in stable
2 weeks ago
BZ#1984325 CVE-2021-22922 curl: wrong content via metalink is not being discarded [fedora-all]
0
0
BZ#1984326 CVE-2021-22923 curl: Metalink download sends credentials [fedora-all]
0
0
BZ#1984327 CVE-2021-22924 curl: bad connection reuse due to flawed path name checks [fedora-all]
0
0
BZ#1984328 CVE-2021-22925 curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure [fedora-all]
0
0

Automated Test Results