openSUSE Recommended Update: Recommended update for podman
______________________________________________________________________________
Announcement ID: openSUSE-RU-2020:0437-1
Rating: moderate
References: #1165738
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for podman fixes the following issues:
- Added README.SUSE about current support status (jsc#SLE-9112,
jsc#CAASP-60)
- Configure br_netfilter for podman automatically (bsc#1165738)
This update was imported from the SUSE:SLE-15-SP1:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-437=1
Package List:
- openSUSE Leap 15.1 (x86_64):
podman-1.8.0-lp151.3.13.1
- openSUSE Leap 15.1 (noarch):
podman-cni-config-1.8.0-lp151.3.13.1
References:
https://bugzilla.suse.com/1165738
openSUSE Security Update: Security update for python-nltk
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0436-1
Rating: moderate
References: #1146427
Cross-References: CVE-2019-14751
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update for python-nltk fixes the following issues:
Update to 3.4.5 (boo#1146427, CVE-2019-14751):
* CVE-2019-14751: Fixed Zip slip vulnerability in downloader for the
unlikely situation where a user configures their downloader to use a
compromised server (boo#1146427)
Update to 3.4.4:
* fix bug in plot function (probability.py)
* add improved PanLex Swadesh corpus reader
* add Text.generate()
* add QuadgramAssocMeasures
* add SSP to tokenizers
* return confidence of best tag from AveragedPerceptron
* make plot methods return Axes objects
* don't require list arguments to PositiveNaiveBayesClassifier.train
* fix Tree classes to work with native Python copy library
* fix inconsistency for NomBank
* fix random seeding in LanguageModel.generate
* fix ConditionalFreqDist mutation on tabulate/plot call
* fix broken links in documentation
* fix misc Wordnet issues
* update installation instructions
Version update to 3.4.1:
* add chomsky_normal_form for CFGs
* add meteor score
* add minimum edit/Levenshtein distance based alignment function
* allow access to collocation list via text.collocation_list()
* support corenlp server options
* drop support for Python 3.4
* other minor fixes
Update to v3.4:
* Support Python 3.7
* New Language Modeling package
* Cistem Stemmer for German
* Support Russian National Corpus incl POS tag model
* Krippendorf Alpha inter-rater reliability test
* Comprehensive code clean-ups
* Switch continuous integration from Jenkins to Travis
Updated to v3.3:
* Support Python 3.6
* New interface to CoreNLP
* Support synset retrieval by sense key
* Minor fixes to CoNLL Corpus Reader
* AlignedSent
* Fixed minor inconsistencies in APIs and API documentation
* Better conformance to PEP8
* Drop Moses Tokenizer (incompatible license)
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-436=1
Package List:
- openSUSE Leap 15.1 (noarch):
python2-nltk-3.4.5-lp151.4.3.1
python3-nltk-3.4.5-lp151.4.3.1
References:
https://www.suse.com/security/cve/CVE-2019-14751.htmlhttps://bugzilla.suse.com/1146427
openSUSE Recommended Update: Recommended update for lighttpd
______________________________________________________________________________
Announcement ID: openSUSE-RU-2020:0433-1
Rating: moderate
References: #1156198
Affected Products:
openSUSE Backports SLE-15-SP1
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for lighttpd fixes the following issues:
- Removed deprecated GeoIP support (boo#1156198)
* dropped mod_geoip subpackage
Update to 1.4.55:
- a multitude of bug fixes
This update was imported from the openSUSE:Leap:15.1:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP1:
zypper in -t patch openSUSE-2020-433=1
Package List:
- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):
lighttpd-1.4.55-bp151.4.6.1
lighttpd-mod_authn_gssapi-1.4.55-bp151.4.6.1
lighttpd-mod_authn_ldap-1.4.55-bp151.4.6.1
lighttpd-mod_authn_mysql-1.4.55-bp151.4.6.1
lighttpd-mod_authn_pam-1.4.55-bp151.4.6.1
lighttpd-mod_authn_sasl-1.4.55-bp151.4.6.1
lighttpd-mod_cml-1.4.55-bp151.4.6.1
lighttpd-mod_magnet-1.4.55-bp151.4.6.1
lighttpd-mod_maxminddb-1.4.55-bp151.4.6.1
lighttpd-mod_mysql_vhost-1.4.55-bp151.4.6.1
lighttpd-mod_rrdtool-1.4.55-bp151.4.6.1
lighttpd-mod_trigger_b4_dl-1.4.55-bp151.4.6.1
lighttpd-mod_vhostdb_dbi-1.4.55-bp151.4.6.1
lighttpd-mod_vhostdb_ldap-1.4.55-bp151.4.6.1
lighttpd-mod_vhostdb_mysql-1.4.55-bp151.4.6.1
lighttpd-mod_vhostdb_pgsql-1.4.55-bp151.4.6.1
lighttpd-mod_webdav-1.4.55-bp151.4.6.1
References:
https://bugzilla.suse.com/1156198
openSUSE Recommended Update: Recommended update for netsniff-ng
______________________________________________________________________________
Announcement ID: openSUSE-RU-2020:0426-1
Rating: moderate
References:
Affected Products:
openSUSE Backports SLE-15-SP1
______________________________________________________________________________
An update that has 0 recommended fixes can now be installed.
Description:
This update for netsniff-ng fixes the following issues:
GeoIP has been discontinued by Maxmind. Please see
https://support.maxmind.com/geolite-legacy-discontinuation-notice/ for
details. Without the database GeoIP is useless.
Update to version 0.6.6:
* implement rotating capture files in netsniff-ng
* fixed '--in -' to work again with STDIN in trafgen
* fixed -t 0 option to use sendto in trafgen
* checksum calculation for ICMP and TCP in astraceroute
* fix for reading mirrors from file in astraceroute
* use GZIP_ENV instead of GZIP in build system
* fixed manpage warnings
* added error handling for mismatched address families in mausezahn.
Update to version 0.6.5:
* add DCCP support to netsniff-ng
* fix segfault in mausezahn
* add date format strings to --out in netsniff-ng
* restore handling of raw hex string passed in on command line in mausezahn
* support ICMPv6 checksums in trafgen
* improve random mac address generation in mausezahn
* man page updates and reformatting
This update was imported from the openSUSE:Leap:15.1:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP1:
zypper in -t patch openSUSE-2020-426=1
Package List:
- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):
netsniff-ng-0.6.6-bp151.5.3.1
References:
openSUSE Recommended Update: Recommended update for inxi
______________________________________________________________________________
Announcement ID: openSUSE-RU-2020:0431-1
Rating: moderate
References: #1085951 #1167611
Affected Products:
openSUSE Backports SLE-15-SP1
______________________________________________________________________________
An update that has two recommended fixes can now be
installed.
Description:
This update for inxi fixes the following issues:
- Update to version 3.0.38:
* See /usr/share/doc/packages/inxi/inxi.changelog
- Add additional requirements (boo#1085951).
This update was imported from the openSUSE:Leap:15.1:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP1:
zypper in -t patch openSUSE-2020-431=1
Package List:
- openSUSE Backports SLE-15-SP1 (noarch):
inxi-3.0.38-bp151.4.3.1
References:
https://bugzilla.suse.com/1085951https://bugzilla.suse.com/1167611
openSUSE Recommended Update: Recommended update for goaccess
______________________________________________________________________________
Announcement ID: openSUSE-RU-2020:0425-1
Rating: moderate
References: #1156207
Affected Products:
openSUSE Backports SLE-15-SP1
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for goaccess fixes the following issues:
- build with libmaxminddb as GeoIP is discontinued (boo#1156207)
- Fixed garbage in HTML reports.
This update was imported from the openSUSE:Leap:15.1:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP1:
zypper in -t patch openSUSE-2020-425=1
Package List:
- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):
goaccess-1.3-bp151.2.3.1
References:
https://bugzilla.suse.com/1156207
openSUSE Recommended Update: Recommended update for geoipupdate, geolite2legacy
______________________________________________________________________________
Announcement ID: openSUSE-RU-2020:0432-1
Rating: moderate
References: #1156194
Affected Products:
openSUSE Backports SLE-15-SP1
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for geoipupdate, geolite2legacy fixes the following issues:
Changes in geoipupdate:
- introduce geoipupdate-legacy script [boo#1156194]
Update geoipupdate to version 4.2.2:
* Prepare for 4.2.2
* Use go get on 1.10
* Only use debug.ReadBuildInfo on 1.12+
* Update changelog
* Set required Go version to 1.10
* Test back to Go 1.10
* Do not unnecessarily use errors.Is
* Add changelog for #76
* Update for GoReleaser nfpm section change
* Bump copyright year
- added systemd timer for weekly updates (needs to be enabled by admin)
Changes in geolite2legacy:
- require python3-ipaddr [boo#1156194]
Update to version 0+git20200101.56d8a4f:
* silence pycharm warning
* add version in comment using dirname inside zip
* use geoname2fips.csv in script dir if not specified
* remap country code from AS to AP (GH-6)
* correct city v6 database version
This update was imported from the openSUSE:Leap:15.1:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP1:
zypper in -t patch openSUSE-2020-432=1
Package List:
- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):
geoipupdate-4.2.2-bp151.4.3.1
geoipupdate-legacy-4.2.2-bp151.4.3.1
References:
https://bugzilla.suse.com/1156194
openSUSE Security Update: Security update for python-mysql-connector-python
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0430-1
Rating: moderate
References: #1122204
Cross-References: CVE-2019-2435
Affected Products:
openSUSE Backports SLE-15-SP1
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update for python-mysql-connector-python fixes the following issues:
python-mysql-connector-python was updated to 8.0.19 (boo#1122204 -
CVE-2019-2435):
- WL#13531: Remove xplugin namespace
- WL#13372: DNS SRV support
- WL#12738: Specify TLS ciphers to be used by a client or session
- BUG#30270760: Fix reserved filed should have a length of 22
- BUG#29417117: Close file in handle load data infile
- WL#13330: Single C/Python (Win) MSI installer
- WL#13335: Connectors should handle expired password sandbox without SET
operations
- WL#13194: Add support for Python 3.8
- BUG#29909157: Table scans of floats causes memory leak with the C
extension
- BUG#25349794: Add read_default_file alias for option_files in connect()
- WL#13155: Support new utf8mb4 bin collation
- WL#12737: Add overlaps and not_overlaps as operator
- WL#12735: Add README.rst and CONTRIBUTING.rst files
- WL#12227: Indexing array fields
- WL#12085: Support cursor prepared statements with C extension
- BUG#29855733: Fix error during connection using charset and collation
combination
- BUG#29833590: Calling execute() should fetch active results
- BUG#21072758: Support for connection attributes classic
- WL#12864: Upgrade of Protobuf version to 3.6.1
- WL#12863: Drop support for Django versions older than 1.11
- WL#12489: Support new session reset functionality
- WL#12488: Support for session-connect-attributes
- WL#12297: Expose metadata about the source and binaries
- WL#12225: Prepared statement support
- BUG#29324966: Add missing username connection argument for driver
compatibility
- BUG#29278489: Fix wrong user and group for Solaris packages
- BUG#29001628: Fix access by column label in Table.select()
- BUG#28479054: Fix Python interpreter crash due to memory corruption
- BUG#27897881: Empty LONG BLOB throws an IndexError
- BUG#29260128: Disable load data local infile by default
- WL#12607: Handling of Default Schema
- WL#12493: Standardize count method
- WL#12492: Be prepared for initial notice on connection
- BUG#28646344: Remove expression parsing on values
- BUG#28280321: Fix segmentation fault when using unicode characters in
tables
- BUG#27794178: Using use_pure=False should raise an error if cext is not
available
- BUG#27434751: Add a TLS/SSL option to verify server name
- WL#12239: Add support for Python 3.7
- WL#12226: Implement connect timeout
- WL#11897: Implement connection pooling for xprotocol
- BUG#28278352: C extension mysqlx Collection.add() leaks memory in
sequential calls
- BUG#28037275: Missing bind parameters causes segfault or unclear error
message
- BUG#27528819: Support special characters in the user and password using
URI
- WL#11951: Consolidate discrepancies between pure and c extension
- WL#11932: Remove Fabric support
- WL#11898: Core API v1 alignment
- BUG#28188883: Use utf8mb4 as the default character set
- BUG#28133321: Fix incorrect columns names representing aggregate
functions
- BUG#27962293: Fix Django 2.0 and MySQL 8.0 compatibility issues
- BUG#27567999: Fix wrong docstring in ModifyStatement.patch()
- BUG#27277937: Fix confusing error message when using an unsupported
collation
- BUG#26834200: Deprecate Row.get_string() method
- BUG#26660624: Fix missing install option in documentation
- WL#11668: Add SHA256_MEMORY authentication mechanism
- WL#11614: Enable C extension by default
- WL#11448: New document _id generation support
- WL#11282: Support new locking modes NOWAIT and SKIP LOCKED
- BUG#27639119: Use a list of dictionaries to store warnings
- BUG#27634885: Update error codes for MySQL 8.0.11
- BUG#27589450: Remove upsert functionality from WriteStatement class
- BUG#27528842: Fix internal queries open for SQL injection
- BUG#27364914: Cursor prepared statements do not convert strings
- BUG#24953913: Fix failing unittests
- BUG#24948205: Results from JSON_TYPE() are returned as bytearray
- BUG#24948186: JSON type results are bytearray instead of corresponding
python type
- WL#11372: Remove configuration API
- WL#11303: Remove CreateTable and CreateView
- WL#11281: Transaction savepoints
- WL#11278: Collection.create_index
- WL#11149: Create Pylint test for mysqlx
- WL#11142: Modify/MergePatch
- WL#11079: Add support for Python 3.6
- WL#11073: Add caching_sha2_password authentication plugin
- WL#10975: Add Single document operations
- WL#10974: Add Row locking methods to find and select operations
- WL#10973: Allow JSON types as operands for IN operator
- WL#10899: Add support for pure Python implementation of Protobuf
- WL#10771: Add SHA256 authentication
- WL#10053: Configuration handling interface
- WL#10772: Cleanup Drop APIs
- WL#10770: Ensure all Session connections are secure by default
- WL#10754: Forbid modify() and remove() with no condition
- WL#10659: Support utf8mb4 as default charset
- WL#10658: Remove concept of NodeSession
- WL#10657: Move version number to 8.0
- WL#10198: Add Protobuf C++ extension implementation
- WL#10004: Document UUID generation
- BUG#26175003: Fix Session.sql() when using unicode SQL statements with
Python 2.7
- BUG#26161838: Dropping an non-existing index should succeed silently
- BUG#26160876: Fix issue when using empty condition in
Collection.remove() and Table.delete()
- BUG#26029811: Improve error thrown when using an invalid parameter in
bind()
- BUG#25991574: Fix Collection.remove() and Table.delete() missing filters
- WL#10452: Add Protobuf C++ extension for Linux variants and Mac OSX
- WL#10081: DevAPI: IPv6 support
- BUG#25614860: Fix defined_as method in the view creation
- BUG#25519251: SelectStatement does not implement order_by() method
- BUG#25436568: Update available operators for XPlugin
- BUG#24954006: Add missing items in CHANGES.txt
- BUG#24578507: Fix import error using Python 2.6
- BUG#23636962: Fix improper error message when creating a Session
- BUG#23568207: Fix default aliases for projection fields
- BUG#23567724: Fix operator names
- DevAPI: Schema.create_table
- DevAPI: Flexible Parameter Lists
- DevAPI: New transports: Unix domain socket
- DevAPI: Core TLS/SSL options for the mysqlx URI scheme
- DevAPI: View DDL with support for partitioning in a cluster / sharding
- BUG#24520850: Fix unexpected behavior when using an empty collection name
- Add support for Protocol Buffers 3
- Add View support (without DDL)
- Implement get_default_schema() method in BaseSchema
- DevAPI: Per ReplicaSet SQL execution
- DevAPI: XSession accepts a list of routers
- DevAPI: Define action on adding empty list of documents
- BUG#23729357: Fix fetching BIT datatype
- BUG#23583381: Add who_am_i and am_i_real methods to DatabaseObject
- BUG#23568257: Add fetch_one method to mysqlx.result
- BUG#23550743: Add close method to XSession and NodeSession
- BUG#23550057: Add support for URI as connection data
- Provide initial implementation of new DevAPI
This update was imported from the openSUSE:Leap:15.1:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP1:
zypper in -t patch openSUSE-2020-430=1
Package List:
- openSUSE Backports SLE-15-SP1 (noarch):
python2-mysql-connector-python-8.0.19-bp151.4.3.1
python3-mysql-connector-python-8.0.19-bp151.4.3.1
References:
https://www.suse.com/security/cve/CVE-2019-2435.htmlhttps://bugzilla.suse.com/1122204
openSUSE Security Update: Security update for tor
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0428-1
Rating: moderate
References: #1167013 #1167014
Cross-References: CVE-2020-10592 CVE-2020-10593
Affected Products:
openSUSE Backports SLE-15-SP1
______________________________________________________________________________
An update that fixes two vulnerabilities is now available.
Description:
This update for tor to version 0.3.5.10 fixes the following issues:
- tor was updated to version 0.3.5.10:
- CVE-2020-10592: Fixed a CPU consumption denial of service and timing
patterns (boo#1167013)
- CVE-2020-10593: Fixed a circuit padding memory leak (boo#1167014)
This update was imported from the openSUSE:Leap:15.1:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP1:
zypper in -t patch openSUSE-2020-428=1
Package List:
- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):
tor-0.3.5.10-bp151.3.3.1
References:
https://www.suse.com/security/cve/CVE-2020-10592.htmlhttps://www.suse.com/security/cve/CVE-2020-10593.htmlhttps://bugzilla.suse.com/1167013https://bugzilla.suse.com/1167014
openSUSE Recommended Update: Recommended update for subnetcalc
______________________________________________________________________________
Announcement ID: openSUSE-RU-2020:0435-1
Rating: moderate
References: #1156201
Affected Products:
openSUSE Backports SLE-15-SP1
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for subnetcalc fixes the following issues:
Remove the dependency on deprecated GeoIP-devel, fixes boo#1156201
Update to version 2.4.14.
This update was imported from the openSUSE:Leap:15.1:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP1:
zypper in -t patch openSUSE-2020-435=1
Package List:
- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):
subnetcalc-2.4.14-bp151.4.3.1
References:
https://bugzilla.suse.com/1156201