Linux 2932 Published by

The following security updates have been released for Fedora Linux:

Fedora 40 Update: erlang-jose-1.11.10-1.fc40
Fedora 40 Update: mingw-python-certifi-2024.7.4-1.fc40
Fedora 39 Update: yt-dlp-2024.07.09-1.fc39
Fedora 39 Update: erlang-jose-1.11.10-1.fc39




Fedora 40 Update: erlang-jose-1.11.10-1.fc40


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-a8d7972ef6
2024-07-16 04:30:43.411039
--------------------------------------------------------------------------------

Name : erlang-jose
Product : Fedora 40
Version : 1.11.10
Release : 1.fc40
URL : https://github.com/potatosalad/erlang-jose
Summary : JSON Object Signing and Encryption (JOSE) for Erlang and Elixir
Description :
JSON Object Signing and Encryption (JOSE) for Erlang and Elixir.

--------------------------------------------------------------------------------
Update Information:

Re-reviewed Jose ver. 1.11.10
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 7 2024 Peter Lemenkov [lemenkov@gmail.com] - 1.11.10-1
- Jose ver. 1.11.10
* Wed Jan 24 2024 Fedora Release Engineering [releng@fedoraproject.org] - 1.11.2-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Fri Jan 19 2024 Fedora Release Engineering [releng@fedoraproject.org] - 1.11.2-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Wed Jul 19 2023 Fedora Release Engineering [releng@fedoraproject.org] - 1.11.2-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jan 19 2023 Fedora Release Engineering [releng@fedoraproject.org] - 1.11.2-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Mon Aug 22 2022 Peter Lemenkov [lemenkov@gmail.com] - 1.11.2-1
- Update to 1.11.2
* Thu Jul 21 2022 Fedora Release Engineering [releng@fedoraproject.org] - 1.10.1-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #1901352 - erlang-jose-1.11.6 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1901352
[ 2 ] Bug #2171479 - erlang-jose: FTBFS in Fedora rawhide/f38
https://bugzilla.redhat.com/show_bug.cgi?id=2171479
[ 3 ] Bug #2225778 - erlang-jose: FTBFS in Fedora rawhide/f39
https://bugzilla.redhat.com/show_bug.cgi?id=2225778
[ 4 ] Bug #2270312 - TRIAGE CVE-2023-50966 erlang-jose: Denial-of-service due to high CPU consumption [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2270312
[ 5 ] Bug #2295183 - Re-Review Request: erlang-jose - JSON Object Signing and Encryption (JOSE) for Erlang and Elixir
https://bugzilla.redhat.com/show_bug.cgi?id=2295183
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-a8d7972ef6' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



Fedora 40 Update: mingw-python-certifi-2024.7.4-1.fc40


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-599bb2cb73
2024-07-16 04:30:43.410974
--------------------------------------------------------------------------------

Name : mingw-python-certifi
Product : Fedora 40
Version : 2024.7.4
Release : 1.fc40
URL : https://certifi.io/en/latest/
Summary : MinGW Windows Python certifi library
Description :
MinGW Windows Python certifi.

--------------------------------------------------------------------------------
Update Information:

Update to 2024.7.4.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 7 2024 Sandro Mani [manisandro@gmail.com] - 2024.7.4-1
- Update to 2024.7.4
* Sat Jun 8 2024 Sandro Mani [manisandro@gmail.com] - 2024.6.2-1
- Update to 2024.6.2
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2296071 - CVE-2024-39689 mingw-python-certifi: Remove root certificates from `GLOBALTRUST` from the root store [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2296071
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-599bb2cb73' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



Fedora 39 Update: yt-dlp-2024.07.09-1.fc39


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-72fb215fcd
2024-07-16 01:40:19.985633
--------------------------------------------------------------------------------

Name : yt-dlp
Product : Fedora 39
Version : 2024.07.09
Release : 1.fc39
URL : https://github.com/yt-dlp/yt-dlp
Summary : A command-line program to download videos from online video platforms
Description :
yt-dlp is a command-line program to download videos from many different online
video platforms, such as youtube.com. The project is a fork of youtube-dl with
additional features and fixes.

--------------------------------------------------------------------------------
Update Information:

Update to 2024.07.09
Update to 2024.07.07
Update to 2024.07.02
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 11 2024 Mikel Olasagasti Uranga [mikel@olasagasti.info] - 2024.07.09-1
- Update to 2024.07.09. Fixes rhbz#2297344
* Mon Jul 8 2024 Mikel Olasagasti Uranga [mikel@olasagasti.info] - 2024.07.07-1
- Update to 2024.07.07. Fixes rhbz#2296356
* Thu Jul 4 2024 Mikel Olasagasti Uranga [mikel@olasagasti.info] - 2024.07.02-1
- Update to 2024.07.02. Fixes rhbz#2295769
* Fri Jun 7 2024 Python Maint - 2024.05.27-2
- Rebuilt for Python 3.13
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2295956 - CVE-2024-38519 yt-dlp: File system modification and RCE through improper file-extension sanitization [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2295956
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-72fb215fcd' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



Fedora 39 Update: erlang-jose-1.11.10-1.fc39


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-9484b6915b
2024-07-16 01:40:19.985580
--------------------------------------------------------------------------------

Name : erlang-jose
Product : Fedora 39
Version : 1.11.10
Release : 1.fc39
URL : https://github.com/potatosalad/erlang-jose
Summary : JSON Object Signing and Encryption (JOSE) for Erlang and Elixir
Description :
JSON Object Signing and Encryption (JOSE) for Erlang and Elixir.

--------------------------------------------------------------------------------
Update Information:

Re-reviewed Jose ver. 1.11.10
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 7 2024 Peter Lemenkov [lemenkov@gmail.com] - 1.11.10-1
- Jose ver. 1.11.10
* Wed Jan 24 2024 Fedora Release Engineering [releng@fedoraproject.org] - 1.11.2-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Fri Jan 19 2024 Fedora Release Engineering [releng@fedoraproject.org] - 1.11.2-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Wed Jul 19 2023 Fedora Release Engineering [releng@fedoraproject.org] - 1.11.2-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jan 19 2023 Fedora Release Engineering [releng@fedoraproject.org] - 1.11.2-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Mon Aug 22 2022 Peter Lemenkov [lemenkov@gmail.com] - 1.11.2-1
- Update to 1.11.2
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #1901352 - erlang-jose-1.11.6 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1901352
[ 2 ] Bug #2171479 - erlang-jose: FTBFS in Fedora rawhide/f38
https://bugzilla.redhat.com/show_bug.cgi?id=2171479
[ 3 ] Bug #2225778 - erlang-jose: FTBFS in Fedora rawhide/f39
https://bugzilla.redhat.com/show_bug.cgi?id=2225778
[ 4 ] Bug #2270312 - TRIAGE CVE-2023-50966 erlang-jose: Denial-of-service due to high CPU consumption [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2270312
[ 5 ] Bug #2295183 - Re-Review Request: erlang-jose - JSON Object Signing and Encryption (JOSE) for Erlang and Elixir
https://bugzilla.redhat.com/show_bug.cgi?id=2295183
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-9484b6915b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--