ELSA-2021-4464

ELSA-2021-4464 - dnf security and bug fix update

Type:SECURITY
Severity:MODERATE
Release Date:2021-11-16

Description


dnf
[4.7.0-4.0.1]
-Fixed python stack trace with updateinfo list cves command [Orabug: 32749660]
- Replaced upstream bugzilla reporting reference. [Orabug: 32829849]

[4.7.0-4]
- Update translations (RhBug:1961632)

[4.7.0-3]
- Improve signature checking using rpmkeys (RhBug:1967454)

[4.7.0-2]
- Fix covscan issue: dnf/rpm/miscutils.py: fix usage of _()

[4.7.0-1]
- Update to 4.7.0
- New optional parameter for filter_modules enables following modular obsoletes based on a config option module_obsoletes
- Fix module remove --all when no match spec (RhBug:1904490)
- Make an error message more informative (RhBug:1814831)
- Expand history to full term size when output is redirected (RhBug:1852577) (RhBug:1852577,1906970)
- Print additional information when verifying GPG key using DNS
- Enhanced detection of plugins removed in transaction (RhBug:1929163)
- Improve repo config path ordering to fix a comps merging issue (RhBug:1928181)
- Keep reason when package is removed (RhBug:1921063)
- Improve mechanism for application of security filters (RhBug:1918475)
- [API] Add new method for reset of security filters
- Remove hardcoded logfile permissions (RhBug:1910084)
- Preserve file mode during log rotation (RhBug:1910084)
- Increase loglevel in case of invalid config options
- Prevent traceback (catch ValueError) if pkg is from cmdline
- Check for specific key string when verifing signatures (RhBug:1915990)
- Use rpmkeys binary to verify package signature (RhBug:1915990)
- [doc] Improve description of modular filtering
- [doc] deprecated alias for dnf repoquery --deplist
- [doc] Describe install with just a name and obsoletes (RhBug:1902279)
- [doc] Fix: 'sslcacert' contains path to the file
- [doc] Added proxy ssl configuration options, increase libdnf require
- [doc] Update documentation for module_obsoletes and module_stream_switch
- [doc] Improve documentation for Hotfix repositories
- [doc] fix: 'makecache' command downloads only enabled repositories
- [doc] Add info that maximum parallel downloads is 20
- [doc] installonly_limit documentation follows behavior
- [doc] Add documentation for config option sslverifystatus (RhBug:1814383)
- The noroot plugin no longer exists, remove mention


Related CVEs


CVE-2021-3445

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 8 (aarch64) dnf-4.7.0-4.0.1.el8.src.rpmda86e63b314edaf2fec0412e6cdcce16-
dnf-plugins-core-4.0.21-3.0.1.el8.src.rpmcdcc9b9741a2f1b402ee8b15d239f67e-
libdnf-0.63.0-3.0.1.el8.src.rpm822139881eeb389f02c1adf50d27c118-
dnf-4.7.0-4.0.1.el8.noarch.rpm4b8dd514ef553adcb0481c6ebf1a38f0-
dnf-automatic-4.7.0-4.0.1.el8.noarch.rpmdf16ff402d8f6971e16cd8d5cb7619ec-
dnf-data-4.7.0-4.0.1.el8.noarch.rpmb6ee305d49266f21444a8211e9122f64-
dnf-plugins-core-4.0.21-3.0.1.el8.noarch.rpmba51f55ce7bb34ea4494a0683dc1a35e-
libdnf-0.63.0-3.0.1.el8.aarch64.rpm93b29224dbb6575604041abc8c89159b-
libdnf-devel-0.63.0-3.0.1.el8.aarch64.rpm3e81ba770c8a80e4d8ff5c1cc98d6293-
python3-dnf-4.7.0-4.0.1.el8.noarch.rpm4c889f2f2a7aa0613430c37cb08d638b-
python3-dnf-plugin-post-transaction-actions-4.0.21-3.0.1.el8.noarch.rpm5dd943dfb648a6522847d6ab6030099f-
python3-dnf-plugin-versionlock-4.0.21-3.0.1.el8.noarch.rpm6f1ef4f266f197fcab330e0ed64c1f95-
python3-dnf-plugins-core-4.0.21-3.0.1.el8.noarch.rpm8b2fcaf4ab31e6d91facfdabb29574b4-
python3-hawkey-0.63.0-3.0.1.el8.aarch64.rpm9b07175fce56d23f557861684fa2e703-
python3-libdnf-0.63.0-3.0.1.el8.aarch64.rpm2a40f167d2e598e9fbf07e7a49f8520f-
yum-4.7.0-4.0.1.el8.noarch.rpm9074af245a947c6a107940383c80d238-
yum-utils-4.0.21-3.0.1.el8.noarch.rpm8cbbf9640450080707ab395988bb1c51-
Oracle Linux 8 (x86_64) dnf-4.7.0-4.0.1.el8.src.rpmda86e63b314edaf2fec0412e6cdcce16-
dnf-plugins-core-4.0.21-3.0.1.el8.src.rpmcdcc9b9741a2f1b402ee8b15d239f67e-
libdnf-0.63.0-3.0.1.el8.src.rpm822139881eeb389f02c1adf50d27c118-
dnf-4.7.0-4.0.1.el8.noarch.rpm4b8dd514ef553adcb0481c6ebf1a38f0-
dnf-automatic-4.7.0-4.0.1.el8.noarch.rpmdf16ff402d8f6971e16cd8d5cb7619ec-
dnf-data-4.7.0-4.0.1.el8.noarch.rpmb6ee305d49266f21444a8211e9122f64-
dnf-plugins-core-4.0.21-3.0.1.el8.noarch.rpmba51f55ce7bb34ea4494a0683dc1a35e-
libdnf-0.63.0-3.0.1.el8.i686.rpmfbf28a61c4b3431222819448d87c39d3-
libdnf-0.63.0-3.0.1.el8.x86_64.rpm1dc1792b54098bbb5ff39f858d2dad38-
libdnf-devel-0.63.0-3.0.1.el8.i686.rpmcc491275fe4ee55cb81dbb3ff226c14a-
libdnf-devel-0.63.0-3.0.1.el8.x86_64.rpm7e21a48ea802e0708dff2a7f4f1263ad-
python3-dnf-4.7.0-4.0.1.el8.noarch.rpm4c889f2f2a7aa0613430c37cb08d638b-
python3-dnf-plugin-post-transaction-actions-4.0.21-3.0.1.el8.noarch.rpm5dd943dfb648a6522847d6ab6030099f-
python3-dnf-plugin-versionlock-4.0.21-3.0.1.el8.noarch.rpm6f1ef4f266f197fcab330e0ed64c1f95-
python3-dnf-plugins-core-4.0.21-3.0.1.el8.noarch.rpm8b2fcaf4ab31e6d91facfdabb29574b4-
python3-hawkey-0.63.0-3.0.1.el8.x86_64.rpm50b2ec02d544b6e8a9e147f8036bb003-
python3-libdnf-0.63.0-3.0.1.el8.x86_64.rpm0da59f498fad9ac5a079788d04d4d0dc-
yum-4.7.0-4.0.1.el8.noarch.rpm9074af245a947c6a107940383c80d238-
yum-utils-4.0.21-3.0.1.el8.noarch.rpm8cbbf9640450080707ab395988bb1c51-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete