openSUSE-2022-10112 Recommended update for hello moderate openSUSE Backports SLE-15-SP5 Update This update for hello is a test update. hello-2.10-bp155.3.2.1.src.rpm hello-2.10-bp155.3.2.1.x86_64.rpm hello-lang-2.10-bp155.3.2.1.noarch.rpm hello-2.10-bp155.3.2.1.i586.rpm hello-2.10-bp155.3.2.1.aarch64.rpm hello-2.10-bp155.3.2.1.ppc64le.rpm hello-2.10-bp155.3.2.1.s390x.rpm openSUSE-2023-113 Recommended update for vectorscan moderate openSUSE Backports SLE-15-SP5 Update This update for vectorscan fixes the following issues: Update to 5.4.9: * Major change: Enable SVE & SVE2 builds and make it a supported architecture! (thanks to @abondarev84) * Fix various clang-related bugs * Fix Aarch64 bug in Parser.rl because of char signedness. Make unsigned char the default in the Parser for all architectures. * Fix Power bug, multiple tests were failing. * C++20 related change, use prefixed assume_aligned to avoid conflict with C++20 std::assume_aligned. - devel package must require libhs%{sover}%{so_suffix}%{sover} libhs5-vectorscan5-5.4.9-bp155.4.3.8.x86_64.rpm vectorscan-5.4.9-bp155.4.3.8.src.rpm vectorscan-devel-5.4.9-bp155.4.3.8.x86_64.rpm vectorscan-examples-5.4.9-bp155.4.3.8.x86_64.rpm libhs5-vectorscan5-5.4.9-bp155.4.3.8.aarch64.rpm vectorscan-devel-5.4.9-bp155.4.3.8.aarch64.rpm vectorscan-examples-5.4.9-bp155.4.3.8.aarch64.rpm openSUSE-2023-104 Recommended update for python-usbsdmux moderate openSUSE Backports SLE-15-SP5 Update This update for python-usbsdmux fixes the following issues: - Update to 0.2.1. Main changes: * cli: Handle well-known Exceptions * usb2642i2c: Do not create if device node does not exist * commandline: 'get' must respect hardware signal priority - Main changes in 0.2.0: * Remove the service/client split and access /dev/sg* directly * usb2642i2c: Fix sg device open arguments * Simplify the read-only to read-write mode transition * usbsdmux: honor wait argument in mode_disconnect() * main/service: add get action * usdbsdmux: set/enable default output values only for writes - Move udev to a separate package - Use update-alternatives - Add udev rule to have /dev/usb-sd-mux/id-<SERIAL> links - Version 0.1.8 python-usbsdmux-0.2.1-bp155.2.1.src.rpm python3-usbsdmux-0.2.1-bp155.2.1.x86_64.rpm usbsdmux-udev-0.2.1-bp155.2.1.x86_64.rpm python3-usbsdmux-0.2.1-bp155.2.1.i586.rpm usbsdmux-udev-0.2.1-bp155.2.1.i586.rpm python3-usbsdmux-0.2.1-bp155.2.1.aarch64.rpm usbsdmux-udev-0.2.1-bp155.2.1.aarch64.rpm python3-usbsdmux-0.2.1-bp155.2.1.ppc64le.rpm usbsdmux-udev-0.2.1-bp155.2.1.ppc64le.rpm python3-usbsdmux-0.2.1-bp155.2.1.s390x.rpm usbsdmux-udev-0.2.1-bp155.2.1.s390x.rpm openSUSE-2023-119 Recommended update for erofs-utils moderate openSUSE Backports SLE-15-SP5 Update This update for erofs-utils fixes the following issues: Update to release 1.6 * support fragments by using `-Efragments` * support compressed data deduplication by using `-Ededupe` * (erofsfuse) support extended attributes * (mkfs.erofs) support multiple algorithms in a single image * (mkfs.erofs) support chunk-based sparse files * (mkfs.erofs) add volume-label setting support * (mkfs.erofs) add uid/gid offsetting support * (mkfs.erofs) pack files entirely by using `-Eall-fragments` * various bugfixes and cleanups; erofs-utils-1.6-bp155.2.3.1.src.rpm erofs-utils-1.6-bp155.2.3.1.x86_64.rpm erofs-utils-1.6-bp155.2.3.1.i586.rpm erofs-utils-1.6-bp155.2.3.1.aarch64.rpm erofs-utils-1.6-bp155.2.3.1.ppc64le.rpm erofs-utils-1.6-bp155.2.3.1.s390x.rpm openSUSE-2023-122 Recommended update for tryton, trytond, trytond_account, trytond_account_invoice, trytond_purchase, trytond_stock_supply moderate openSUSE Backports SLE-15-SP5 Update This update for tryton, trytond, trytond_account, trytond_account_invoice, trytond_purchase, trytond_stock_supply fixes the following issues: Changes in trytond: - Version 6.0.32 - Bugfix Release Changes in tryton: - Version 6.0.27 - Bugfix Release Changes in trytond_account: - Version 6.0.17 - Bugfix Release Changes in trytond_account_invoice: - Version 6.0.12 - Bugfix Release Changes in trytond_purchase: - Version 6.0.11 - Bugfix Release Changes in trytond_stock_supply: - Version 6.0.6 - Bugfix Release tryton-6.0.27-bp155.2.3.1.noarch.rpm tryton-6.0.27-bp155.2.3.1.src.rpm trytond-6.0.32-bp155.2.3.1.noarch.rpm trytond-6.0.32-bp155.2.3.1.src.rpm trytond_account-6.0.17-bp155.2.3.1.noarch.rpm trytond_account-6.0.17-bp155.2.3.1.src.rpm trytond_account_invoice-6.0.12-bp155.2.3.1.noarch.rpm trytond_account_invoice-6.0.12-bp155.2.3.1.src.rpm trytond_purchase-6.0.11-bp155.2.3.1.noarch.rpm trytond_purchase-6.0.11-bp155.2.3.1.src.rpm trytond_stock_supply-6.0.6-bp155.2.3.1.noarch.rpm trytond_stock_supply-6.0.6-bp155.2.3.1.src.rpm openSUSE-2023-163 Security update for keepass important openSUSE Backports SLE-15-SP5 Update This update for keepass fixes the following issues: - Update to 2.54 * Security: + Improved process memory protection of secure edit controls (CVE-2023-32784, boo#1211397). * New Features: + Triggers, global URL overrides, password generator profiles and a few more settings are now stored in the enforced configuration file. + Added dialog 'Enforce Options (All Users)' (menu 'Tools' → 'Advanced Tools' → 'Enforce Options'), which facilitates storing certain options in the enforced configuration file. + In report dialogs, passwords (and other sensitive data) are now hidden using asterisks by default (if hiding is activated in the main window); the hiding can be toggled using the new '***' button in the toolbar. + The 'Print' command in most report dialogs now requires the 'Print' application policy flag, and the master key must be entered if the 'Print - No Key Repeat' application policy flag is deactivated. + The 'Export' command in most report dialogs now requires the 'Export' application policy flag, and the master key must be entered. + Single line edit dialogs now support hiding the value using asterisks. + Commands that require elevation now have a shield icon like on Windows. + TrlUtil: added 'Move Selected Unused Text to Dialog Control' command. * Improvements: * The content mode of the configuration elements '/Configuration/Application/TriggerSystem', '/Configuration/Integration/UrlSchemeOverrides' and '/Configuration/PasswordGenerator/UserProfiles' is now 'Replace' by default. * The built-in override for the 'ssh' URI scheme is now deactivated by default (it can be activated in the 'URL Overrides' dialog). * When opening the password generator dialog without a derived profile, the '(Automatically generated passwords for new entries)' profile is now selected by default, if profiles are enabled (otherwise the default profile is used). * The clipboard workarounds are now disabled by default (they are not needed anymore on most systems). * Improved clipboard clearing. * Improved starting of an elevated process. * Bugfixes: + In report dialogs, the 'Print' and 'Export' commands now always use the actual data (in previous versions, asterisks were printed/exported when the application policy flag 'Unhide Passwords' was turned off). keepass-2.54-bp155.2.3.1.noarch.rpm keepass-2.54-bp155.2.3.1.src.rpm openSUSE-2023-158 Recommended update for qFlipper moderate openSUSE Backports SLE-15-SP5 Update This update for qFlipper fixes the following issues: - Update to version 1.3.1~rc1+git1.1684488882.0199220: * New indexer (#143) * Improve keyboard navigation in File Manager * Fix unknown type error in Qt5 builds * Fix ScreenStreaming freeze after pressing Save Screenshot button - Update to version 1.3.0: * New Features: - Keyboard navigation in file manager (by @gncnpk) - Lefty mode support * Bug Fixes: - Display proper operation progress when downloading multiple files from Flipper - When reinstalling firmware updates, verify the md5 sums (#156) - Make the self update dialog closable in case of failure - Improve font antialiasing with Qt6 - Improve DPI handling (incl. multi-monitor configurations) - Do not fail if a .tgz update file has been renamed - Improve scrolling animations - Show an error when the user drops a file from a .zip folder - Other small fixes and improvements * Under the Hood: - Increase write chunk size to 1K (slighly faster file uploads) - Improved USB device handling and error reporting * Other improvements - Fix typos and improve text messages qFlipper-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.src.rpm qFlipper-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.x86_64.rpm qFlipper-base-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.noarch.rpm qFlipper-cli-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.x86_64.rpm qFlipper-libflipperproto-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.x86_64.rpm qFlipper-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.i586.rpm qFlipper-cli-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.i586.rpm qFlipper-libflipperproto-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.i586.rpm qFlipper-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.aarch64.rpm qFlipper-cli-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.aarch64.rpm qFlipper-libflipperproto-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.aarch64.rpm qFlipper-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.ppc64le.rpm qFlipper-cli-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.ppc64le.rpm qFlipper-libflipperproto-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.ppc64le.rpm qFlipper-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.s390x.rpm qFlipper-cli-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.s390x.rpm qFlipper-libflipperproto-1.3.1~rc1+git1.1684488882.0199220-bp155.2.3.1.s390x.rpm openSUSE-2023-123 Security update for chromium important openSUSE Backports SLE-15-SP5 Update This update for chromium fixes the following issues: Update to version 114.0.5735.106: - CVE-2023-3079: Type Confusion in V8 (boo#1212044) chromedriver-114.0.5735.106-bp155.2.4.1.x86_64.rpm chromium-114.0.5735.106-bp155.2.4.1.src.rpm chromium-114.0.5735.106-bp155.2.4.1.x86_64.rpm chromedriver-114.0.5735.106-bp155.2.4.1.aarch64.rpm chromium-114.0.5735.106-bp155.2.4.1.aarch64.rpm openSUSE-2023-126 Security update for syncthing moderate openSUSE Backports SLE-15-SP5 Update This update for syncthing fixes the following issues: - Update to 1.13.5 * This release fixes CVE-2022-46165 “Cross-site Scripting (XSS) in Web GUI” * Bugfixes: #8503: "syncthing cli config devices add" reflect error when using --addresses flag #8764: Ignore patterns creating during folder addition are not loaded #8778: Tests fail on Windows with Go 1.20 #8779: Test cleanup fails all model tests on Windows on Go 1.20 #8859: Incorrect handling of path for auto accepted folder * Other issues: #8799: "fatal error: checkptr: converted pointer straddles multiple allocations" in crypto tests - Update to 1.23.4 - Bugfixes: #8851: "Running global migration to fix encryption file sizes" on every start - Update to 1.23.3 * Bugfixes: #5408: Selection of time in versions GUI not possible without editing the string inside the textfield #8277: Mutual encrypted sharing doesn't work (both sides with password) #8556: Increased file size when sharing between encrypted devices #8599: Key generation at connect time is slow for encrypted connections * Enhancements: #7859: Allow sub-second watcher delay (use case: remote development) * Other issues: #8828: cmd/stdiscosrv: TestDatabaseGetSet flake - Adding a desktop file for the Web UI - Update to 1.23.2 * Bugfixes: #8749: Relay listener does not restart sometimes * Enhancements: #8660: GUI editor for xattr filter patterns #8781: gui: Remove duplicate Spanish translation * Other issues: #8768: Update quic-go for Go 1.20 syncthing-1.23.5-bp155.2.3.1.src.rpm syncthing-1.23.5-bp155.2.3.1.x86_64.rpm syncthing-relaysrv-1.23.5-bp155.2.3.1.x86_64.rpm syncthing-1.23.5-bp155.2.3.1.i586.rpm syncthing-relaysrv-1.23.5-bp155.2.3.1.i586.rpm syncthing-1.23.5-bp155.2.3.1.aarch64.rpm syncthing-relaysrv-1.23.5-bp155.2.3.1.aarch64.rpm syncthing-1.23.5-bp155.2.3.1.ppc64le.rpm syncthing-relaysrv-1.23.5-bp155.2.3.1.ppc64le.rpm syncthing-1.23.5-bp155.2.3.1.s390x.rpm syncthing-relaysrv-1.23.5-bp155.2.3.1.s390x.rpm openSUSE-2023-127 Recommended update for kdenlive moderate openSUSE Backports SLE-15-SP5 Update This update for kdenlive fixes the following issues: - Require knewstuff-imports during installation kdenlive-22.12.3-bp155.2.3.1.src.rpm kdenlive-22.12.3-bp155.2.3.1.x86_64.rpm kdenlive-lang-22.12.3-bp155.2.3.1.noarch.rpm kdenlive-22.12.3-bp155.2.3.1.aarch64.rpm kdenlive-22.12.3-bp155.2.3.1.ppc64le.rpm kdenlive-22.12.3-bp155.2.3.1.s390x.rpm openSUSE-2023-129 Recommended update for mirrorsorcerer moderate openSUSE Backports SLE-15-SP5 Update This update for mirrorsorcerer fixes the following issues: - Update to version 0.1.1~3: * Add -u to allow upstream mirror restoring. * Add br-1 br-2 for replaceable * Phase out mirrorsorcerer-0.1.1~3-bp155.2.3.1.src.rpm mirrorsorcerer-0.1.1~3-bp155.2.3.1.x86_64.rpm mirrorsorcerer-0.1.1~3-bp155.2.3.1.aarch64.rpm openSUSE-2023-130 Recommended update for tesseract-ocr moderate openSUSE Backports SLE-15-SP5 Update This update for tesseract-ocr fixes the following issues: update to 5.3.1 - Build AVX2 enabled hwcaps library for x86_64-v3 - Define TESSDATA_PREFIX during build to point at /usr/share (since it's the prefix) rather than package name, tessdata suffix is automatically added. - Move unversioned libraries to main package - Update to version 5.3.0: * Fix memory issues in ScrollView::MessageReceiver * autotools: Add rule for svpaint executable * Replace call of exit function by return statement in main function * Fix the build on CodeQL/Analyze by @arseniy-sonar in #3888 * CI: Remove Ubuntu 18.04 * configure.ac: fix build on aarch64_be * SW CI: Add paths filter * Create .mailmap * Fix tesseract.pc from cmake to match autotools * Update README.md * Fixed 2 errors * fix issue #3940 - remove colormap before thresholding * Update upload-artifact action * Update checkout action to version 3 * Fix Markdownlint * Fix broken links in CONTRIBUTING.md * pdfrenderer.cpp: Ignore non-text blocks * lstm.train: allow .box from .raw.png too * Fix a number of performance issues (reported by Coverity Scan) * Fix training tools for legacy engine (issue #3925) * Fix function tesseract::WriteFeature (issue #3925) * Modernize function ObjectCache::DeleteUnusedObjects (fix issue with s… * More fixes for issue #3925 - Fixed packaging to include missing shared libs: * libcommon_training.so * libunicharset_training.so - Update to version 5.2.0: * Improvements and fixes for continuous integration, autoconf and cmake builds * Set /Os for some 32 bit MS compilers * Improve comments and other documentation * Add initial support for Intel AVX512F * Fix for very large PDF files on 32 bit hosts * Fix NEON detection on FreeBSD * Fix regression with UZN files * Fix calling delete[] for memory allocated by malloc in C API * Add an API function to init tesseract with traineddata from memory * Replace direct access to Leptonica internal data structures by function calls and support latest releases of Leptonica. * Replace std::regex by std::string functions. * Use compiled-in TESSDATA_PREFIX also on Windows * Add new parameter 'invert_threshold', change the default threshold from 0.5 to 0.7 and mark parameter 'tessedit_do_invert' as deprecated - Update to version 5.1.0: * Handle image and line regions in output formats ALTO, hOCR and text. * New parameter curl_timeout for curl_easy_setop. * Build fixes and improvements. * Catch nullptr in PageIterator::Orientation to improve robustness. * Remove unused code. - Update to version 5.0.1: * Add SPDX-License-Identifier to public include files. * Support redirections when running OCR on a URL. * Lots of fixes and improvements for cmake builds. * Distributions should use the autoconf build. * Fix broken msys2 build with gcc 11. * Fix parameter certainty_scale (was duplicated). * Fix some compiler warnings and clean code. * Correctly detect amd64 and i386 on FreeBSD. * Add libarchive and libcurl in continuous integration actions. * Update submodule googletest to release v1.11.0. - Update to version 5.0.0: * Enable fast float32 LSTM by default * Switch to NFC normalisation everywhere * Remove banner message * Disable music staff detection and removal * Add new command line option --loglevel * Fix regression for OCR with more than one model file * Optimizations * Improve training messages * Add RowAttributes getter to PageIterator * Limit BCER to interval [0,1] * Improved build process * Cleaned code - Update to version 4.1.3: * Fix broken autoconf build - Update to version 4.1.2: * Allow line images with larger width for training * Bugfixes * Build updates and fixes libtesseract5-5.3.1-bp155.3.3.1.x86_64.rpm tesseract-ocr-5.3.1-bp155.3.3.1.src.rpm tesseract-ocr-5.3.1-bp155.3.3.1.x86_64.rpm tesseract-ocr-devel-5.3.1-bp155.3.3.1.x86_64.rpm libtesseract5-5.3.1-bp155.3.3.1.aarch64.rpm libtesseract5-64bit-5.3.1-bp155.3.3.1.aarch64_ilp32.rpm tesseract-ocr-5.3.1-bp155.3.3.1.aarch64.rpm tesseract-ocr-devel-5.3.1-bp155.3.3.1.aarch64.rpm libtesseract5-5.3.1-bp155.3.3.1.ppc64le.rpm tesseract-ocr-5.3.1-bp155.3.3.1.ppc64le.rpm tesseract-ocr-devel-5.3.1-bp155.3.3.1.ppc64le.rpm libtesseract5-5.3.1-bp155.3.3.1.s390x.rpm tesseract-ocr-5.3.1-bp155.3.3.1.s390x.rpm tesseract-ocr-devel-5.3.1-bp155.3.3.1.s390x.rpm openSUSE-2023-131 Security update for chromium critical openSUSE Backports SLE-15-SP5 Update This update for chromium fixes the following issues: Chromium 114.0.5735.133 (boo#1212302): - CVE-2023-3214: Use after free in Autofill payments - CVE-2023-3215: Use after free in WebRTC - CVE-2023-3216: Type Confusion in V8 - CVE-2023-3217: Use after free in WebXR - Various fixes from internal audits, fuzzing and other initiatives chromedriver-114.0.5735.133-bp155.2.7.1.x86_64.rpm chromium-114.0.5735.133-bp155.2.7.1.src.rpm chromium-114.0.5735.133-bp155.2.7.1.x86_64.rpm chromedriver-114.0.5735.133-bp155.2.7.1.aarch64.rpm chromium-114.0.5735.133-bp155.2.7.1.aarch64.rpm openSUSE-2023-161 Security update for libjxl moderate openSUSE Backports SLE-15-SP5 Update This update for libjxl fixes the following issues: Update to release 0.8.2 * CVE-2023-35790: Fix an integer underflow bug in patch decoding. (bsc#1212492) libjxl-0.8.2-bp155.2.3.1.src.rpm libjxl-devel-0.8.2-bp155.2.3.1.x86_64.rpm libjxl-tools-0.8.2-bp155.2.3.1.x86_64.rpm libjxl0_8-0.8.2-bp155.2.3.1.x86_64.rpm libjxl-devel-0.8.2-bp155.2.3.1.aarch64.rpm libjxl-tools-0.8.2-bp155.2.3.1.aarch64.rpm libjxl0_8-0.8.2-bp155.2.3.1.aarch64.rpm libjxl0_8-64bit-0.8.2-bp155.2.3.1.aarch64_ilp32.rpm libjxl-devel-0.8.2-bp155.2.3.1.s390x.rpm libjxl-tools-0.8.2-bp155.2.3.1.s390x.rpm libjxl0_8-0.8.2-bp155.2.3.1.s390x.rpm openSUSE-2023-164 Recommended update for bazel6 moderate openSUSE Backports SLE-15-SP5 Update This update for bazel6 fixes the following issues: - initial package based on Bazel 3.2 bazel6-6.1.2-bp155.2.1.src.rpm bazel6-6.1.2-bp155.2.1.x86_64.rpm bazel6-6.1.2-bp155.2.1.aarch64.rpm bazel6-6.1.2-bp155.2.1.s390x.rpm openSUSE-2023-133 Recommended update for git-subrepo moderate openSUSE Backports SLE-15-SP5 Update This update for git-subrepo fixes the following issues: Update to 0.4.6: * Removes stale worktrees after using the push command git-subrepo-0.4.6-bp155.2.3.1.noarch.rpm git-subrepo-0.4.6-bp155.2.3.1.src.rpm git-subrepo-bash-completion-0.4.6-bp155.2.3.1.noarch.rpm git-subrepo-zsh-completion-0.4.6-bp155.2.3.1.noarch.rpm openSUSE-2023-162 Security update for xonotic moderate openSUSE Backports SLE-15-SP5 Update This update for xonotic fixes the following issues: Update to version 0.8.6 SECURITY ALERT: A bug was discovered in versions older than 0.8.6 that is believed to be exploitable by malicious server admins to crash clients or, if they defeat mitigations, execute arbitrary code. (boo#1212632) update to 0.8.5: * https://xonotic.org/posts/2022/xonotic-0-8-5-release/ xonotic-0.8.6-bp155.2.3.1.src.rpm xonotic-0.8.6-bp155.2.3.1.x86_64.rpm xonotic-data-0.8.6-bp155.2.3.1.noarch.rpm xonotic-debuginfo-0.8.6-bp155.2.3.1.x86_64.rpm xonotic-debugsource-0.8.6-bp155.2.3.1.x86_64.rpm xonotic-server-0.8.6-bp155.2.3.1.x86_64.rpm xonotic-server-debuginfo-0.8.6-bp155.2.3.1.x86_64.rpm xonotic-0.8.6-bp155.2.3.1.aarch64.rpm xonotic-debuginfo-0.8.6-bp155.2.3.1.aarch64.rpm xonotic-debugsource-0.8.6-bp155.2.3.1.aarch64.rpm xonotic-server-0.8.6-bp155.2.3.1.aarch64.rpm xonotic-server-debuginfo-0.8.6-bp155.2.3.1.aarch64.rpm xonotic-0.8.6-bp155.2.3.1.ppc64le.rpm xonotic-debuginfo-0.8.6-bp155.2.3.1.ppc64le.rpm xonotic-debugsource-0.8.6-bp155.2.3.1.ppc64le.rpm xonotic-server-0.8.6-bp155.2.3.1.ppc64le.rpm xonotic-server-debuginfo-0.8.6-bp155.2.3.1.ppc64le.rpm xonotic-0.8.6-bp155.2.3.1.s390x.rpm xonotic-debuginfo-0.8.6-bp155.2.3.1.s390x.rpm xonotic-debugsource-0.8.6-bp155.2.3.1.s390x.rpm xonotic-server-0.8.6-bp155.2.3.1.s390x.rpm xonotic-server-debuginfo-0.8.6-bp155.2.3.1.s390x.rpm openSUSE-2023-160 Security update for gifsicle important openSUSE Backports SLE-15-SP5 Update This update for gifsicle fixes the following issues: - Update to version 1.94: * Fix some bugs, including fix for CVE-2023-36193: heap buffer overflow (read) via the ambiguity_error component at /src/clp.c (boo#1212645). gifsicle-1.94-bp155.3.3.1.src.rpm gifsicle-1.94-bp155.3.3.1.x86_64.rpm gifsicle-debuginfo-1.94-bp155.3.3.1.x86_64.rpm gifsicle-debugsource-1.94-bp155.3.3.1.x86_64.rpm gifsicle-1.94-bp155.3.3.1.i586.rpm gifsicle-debuginfo-1.94-bp155.3.3.1.i586.rpm gifsicle-debugsource-1.94-bp155.3.3.1.i586.rpm gifsicle-1.94-bp155.3.3.1.aarch64.rpm gifsicle-debuginfo-1.94-bp155.3.3.1.aarch64.rpm gifsicle-debugsource-1.94-bp155.3.3.1.aarch64.rpm gifsicle-1.94-bp155.3.3.1.ppc64le.rpm gifsicle-debuginfo-1.94-bp155.3.3.1.ppc64le.rpm gifsicle-debugsource-1.94-bp155.3.3.1.ppc64le.rpm gifsicle-1.94-bp155.3.3.1.s390x.rpm gifsicle-debuginfo-1.94-bp155.3.3.1.s390x.rpm gifsicle-debugsource-1.94-bp155.3.3.1.s390x.rpm openSUSE-2023-159 Security update for chromium important openSUSE Backports SLE-15-SP5 Update This update for chromium fixes the following issues: - Chromium 114.0.5735.198 (boo#1212755): * CVE-2023-3420: Type Confusion in V8 * CVE-2023-3421: Use after free in Media * CVE-2023-3422: Use after free in Guest View - Install Qt5 library & prepare for Qt6 in 115 chromedriver-114.0.5735.198-bp155.2.10.1.x86_64.rpm chromedriver-debuginfo-114.0.5735.198-bp155.2.10.1.x86_64.rpm chromium-114.0.5735.198-bp155.2.10.1.src.rpm chromium-114.0.5735.198-bp155.2.10.1.x86_64.rpm chromium-debuginfo-114.0.5735.198-bp155.2.10.1.x86_64.rpm chromedriver-114.0.5735.198-bp155.2.10.1.aarch64.rpm chromedriver-debuginfo-114.0.5735.198-bp155.2.10.1.aarch64.rpm chromium-114.0.5735.198-bp155.2.10.1.aarch64.rpm chromium-debuginfo-114.0.5735.198-bp155.2.10.1.aarch64.rpm openSUSE-2023-170 Recommended update for sshuttle moderate openSUSE Backports SLE-15-SP5 Update This update for sshuttle fixes the following issues: - Remove restrictions settings: * PrivateDevices=true * ProtectHostname=true * ProtectClock=true * ProtectKernelTunables=true * ProtectKernelModules=true * ProtectKernelLogs=true * RestrictRealtime=true from systemd service file as they imply NNP, which doesn't work with the sudo setup sshuttle uses (boo#1212949) sshuttle-1.1.1-bp155.2.3.1.noarch.rpm sshuttle-1.1.1-bp155.2.3.1.src.rpm openSUSE-2023-171 Security update for nextcloud-desktop important openSUSE Backports SLE-15-SP5 Update This update for nextcloud-desktop fixes the following issues: Update ot 3.8.0 - Resize WebView widget once the loginpage rendered - Feature/secure file drop - Check German translation for wrong wording - L10n: Correct word - Fix displaying of file details button for local syncfileitem activities - Improve config upgrade warning dialog - Only accept folder setup page if overrideLocalDir is set - Update CHANGELOG. - Prevent ShareModel crash from accessing bad pointers - Bugfix/init value for pointers - Log to stdout when built in Debug config - Clean up account creation and deletion code - L10n: Added dot to end of sentence - L10n: Fixed grammar - Fix "Create new folder" menu entries in settings not working correctly on macOS - Ci/clang tidy checks init variables - Fix share dialog infinite loading - Fix edit locally job not finding the user account: wrong user id - Skip e2e encrypted files with empty filename in metadata - Use new connect syntax - Fix avatars not showing up in settings dialog account actions until clicked on - Always discover blacklisted folders to avoid data loss when modifying selectivesync list. - Fix infinite loading in the share dialog when public link shares are disabled on the server - With cfapi when dehydrating files add missing flag - Fix text labels in Sync Status component - Display 'Search globally' as the last sharees list element - Fix display of 2FA notification. - Bugfix/do not restore virtual files - Show server name in tray main window - Add Ubuntu Lunar - Debian build classification 'beta' cannot override 'release'. - Update changelog - Follow shouldNotify flag to hide notifications when needed - Bugfix/stop after creating config file - E2EE cut extra zeroes from derypted byte array. - When local sync folder is overriden, respect this choice - Feature/e2ee fixes - This update also fixes security issues: - (boo#1205798, CVE-2022-39331) - Arbitrary HyperText Markup Language injection in notifications - (boo#1205799, CVE-2022-39332) - Arbitrary HyperText Markup Language injection in user status and information - (boo#1205800, CVE-2022-39333) - Arbitrary HyperText Markup Language injection in desktop client application - (boo#1205801, CVE-2022-39334) - Client incorrectly trusts invalid TLS certificates - (boo#1207976, CVE-2023-23942) - missing sanitisation on qml labels leading to javascript injection caja-extension-nextcloud-3.8.0-bp155.2.3.1.noarch.rpm cloudproviders-extension-nextcloud-3.8.0-bp155.2.3.1.noarch.rpm libnextcloudsync-devel-3.8.0-bp155.2.3.1.x86_64.rpm libnextcloudsync0-3.8.0-bp155.2.3.1.x86_64.rpm nautilus-extension-nextcloud-3.8.0-bp155.2.3.1.noarch.rpm nemo-extension-nextcloud-3.8.0-bp155.2.3.1.noarch.rpm nextcloud-desktop-3.8.0-bp155.2.3.1.src.rpm nextcloud-desktop-3.8.0-bp155.2.3.1.x86_64.rpm nextcloud-desktop-doc-3.8.0-bp155.2.3.1.noarch.rpm nextcloud-desktop-dolphin-3.8.0-bp155.2.3.1.x86_64.rpm nextcloud-desktop-lang-3.8.0-bp155.2.3.1.noarch.rpm libnextcloudsync-devel-3.8.0-bp155.2.3.1.aarch64.rpm libnextcloudsync0-3.8.0-bp155.2.3.1.aarch64.rpm nextcloud-desktop-3.8.0-bp155.2.3.1.aarch64.rpm nextcloud-desktop-dolphin-3.8.0-bp155.2.3.1.aarch64.rpm openSUSE-2023-172 Recommended update for monitoring-plugins-zypper moderate openSUSE Backports SLE-15-SP5 Update This update for monitoring-plugins-zypper fixes the following issues: monitoring-plugins-zypper was updated to 1.98.9 + remove openSUSE Leap 15.2 + remove SLE-15-SP2 + remove Tumbleweed < 2023 update to 1.98.8 + allow more recent versions: - openSUSE 15.5 - Tumbleweed 2023* - SLE 15.5 * get rid of get_distribution_from_os_release() function: use - update to 1.98.4 + allow rpm to read files below /etc/popt.d/ - update to 1.98.9 + remove openSUSE Leap 15.2 + remove SLE-15-SP2 + remove Tumbleweed < 2023 - update to 1.98.8 + allow more recent versions: - openSUSE 15.5 - Tumbleweed 2023* - SLE 15.5 - update to 1.98.7: + remove unsupported Leap 15.1 and SLE 15 GA and and SP1 + add Leap 15.4 and SLE 15 SP4 as supported + Tumbleweed should be at least from 2021 + Add user icinga to the sudo configuration (PR#1 thanks to mhauke) - Update to 1.98.6 (fixes boo#1173872) Beside other, small updates, this release includes first support for the rolling release named openSUSE Tumbleweed. Per default, a Tumbleweed installation which is older than 30 days will trigger a warning state - and an installation older than 60 days will trigger a critical state. You can fine tune this behavior with the new command line options --tw_outdated_warn and --tw_outdated_crit. Other changes: * use proper Copyright * use Perl modules: POSIX and Time::Local * die, if release-file could not be opened * get rid of get_distribution_from_os_release() function: use get_distribution() for all cases * new test_tumbleweed() and check_returncode() functions (internal) * trim quotation marks in trim() function * added some os-release files for testing - Recommend perl only on openSUSE based distributions - Require needed Perl modules: Getopt::Long, POSIX, Time::Local - Update to 1.98.5 * Adjust support status of SLE, Leap and Tumbleweed releases - update to 1.98.4 + allow rpm to read files below /etc/popt.d/ monitoring-plugins-zypper-1.98.9-bp155.3.3.1.noarch.rpm monitoring-plugins-zypper-1.98.9-bp155.3.3.1.src.rpm