Fedora Linux 8730 Published by

The following security updates have been released for Fedora Linux:

[SECURITY] Fedora 40 Update: darkhttpd-1.16-1.fc40
[SECURITY] Fedora 40 Update: python-scrapy-2.11.2-1.fc40
[SECURITY] Fedora 40 Update: mod_http2-2.0.29-1.fc40




[SECURITY] Fedora 40 Update: darkhttpd-1.16-1.fc40


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-25f8e34407
2024-07-27 01:45:37.014460
--------------------------------------------------------------------------------

Name : darkhttpd
Product : Fedora 40
Version : 1.16
Release : 1.fc40
URL : https://github.com/emikulic/darkhttpd
Summary : Secure, lightweight, fast, single-threaded HTTP/1.1 server
Description :
darkhttpd is a secure, lightweight, fast and single-threaded HTTP/1.1 server.

Features:
* Simple to set up:
* Single binary, no other files.
* Standalone, doesn't need inetd or ucspi-tcp.
* No messing around with config files.
* Written in C - efficient and portable.
* Small memory footprint.
* Event loop, single threaded - no fork() or pthreads.
* Generates directory listings.
* Supports HTTP GET and HEAD requests.
* Supports Range / partial content.
* Supports If-Modified-Since.
* Supports Keep-Alive connections.
* Can serve 301 redirects based on Host header.
* Uses sendfile().

Security:
* Can log accesses, including Referer and User-Agent.
* Can chroot.
* Can drop privileges.
* Impervious to /../ sniffing.
* Times out idle connections.
* Drops overly long requests.

Limitations:
* This server only serves static content - *NO* CGI supported!

--------------------------------------------------------------------------------
Update Information:

Update to 1.16 fixes rhbz#2259096
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 18 2024 Filipe Rosset [rosset.filipe@gmail.com] - 1.16-1
- Update to 1.16 fixes rhbz#2259096
* Wed Jul 17 2024 Fedora Release Engineering [releng@fedoraproject.org] - 1.14-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2259096 - darkhttpd-1.16 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2259096
[ 2 ] Bug #2259490 - CVE-2024-23770 darkhttpd: allows local users to discover credentials [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2259490
[ 3 ] Bug #2259491 - CVE-2024-23770 darkhttpd: allows local users to discover credentials [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2259491
[ 4 ] Bug #2259493 - CVE-2024-23771 darkhttpd: uses strcmp to verify authentication to bypass authentication via a timing side channel [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2259493
[ 5 ] Bug #2259494 - CVE-2024-23771 darkhttpd: uses strcmp to verify authentication to bypass authentication via a timing side channel [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2259494
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-25f8e34407' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 40 Update: python-scrapy-2.11.2-1.fc40


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-c27b82d702
2024-07-27 01:45:37.014268
--------------------------------------------------------------------------------

Name : python-scrapy
Product : Fedora 40
Version : 2.11.2
Release : 1.fc40
URL : https://scrapy.org
Summary : A high-level Python Screen Scraping framework
Description :
Scrapy is a fast high-level screen scraping and web crawling
framework, used to crawl websites and extract structured data
from their pages. It can be used for a wide range of purposes,
from data mining to monitoring and automated testing.

--------------------------------------------------------------------------------
Update Information:

Update to 2.11.2
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 17 2024 Filipe Rosset [rosset.filipe@gmail.com] - 2.11.2-1
- Update to 2.11.2
* Sun Jun 9 2024 Python Maint - 2.11.0-2
- Rebuilt for Python 3.13
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2238527 - F40FailsToInstall: python3-scrapy
https://bugzilla.redhat.com/show_bug.cgi?id=2238527
[ 2 ] Bug #2238534 - F39FailsToInstall: python3-scrapy
https://bugzilla.redhat.com/show_bug.cgi?id=2238534
[ 3 ] Bug #2239457 - python-scrapy-2.11.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2239457
[ 4 ] Bug #2255110 - python3-scrapy cannot be installed
https://bugzilla.redhat.com/show_bug.cgi?id=2255110
[ 5 ] Bug #2261603 - python-scrapy: FTBFS in Fedora rawhide/f40
https://bugzilla.redhat.com/show_bug.cgi?id=2261603
[ 6 ] Bug #2281624 - CVE-2024-1968 python-scrapy: sensitive information disclosure [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2281624
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-c27b82d702' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 40 Update: mod_http2-2.0.29-1.fc40


--