NCSC report warns of surging threat to the third sector
Monthly Archives: January 2023
USN-5817-1: Setuptools vulnerability
Sebastian Chnelik discovered that setuptools incorrectly handled
certain regex inputs. An attacker could possibly use this issue
to cause a denial of service.
git-credential-oauth-0.1.5-1.fc36
FEDORA-2023-2663dc67d8
Packages in this update:
git-credential-oauth-0.1.5-1.fc36
Update description:
Rebuild for security fix
git-credential-oauth-0.4.1-1.fc37
FEDORA-2023-267503a090
Packages in this update:
git-credential-oauth-0.4.1-1.fc37
Update description:
new upstream version
USN-5816-1: Firefox vulnerabilities
Niklas Baumstark discovered that a compromised web child process of Firefox
could disable web security opening restrictions, leading to a new child
process being spawned within the file:// context. An attacker could
potentially exploits this to obtain sensitive information. (CVE-2023-23597)
Tom Schuster discovered that Firefox was not performing a validation check
on GTK drag data. An attacker could potentially exploits this to obtain
sensitive information. (CVE-2023-23598)
Vadim discovered that Firefox was not properly sanitizing a curl command
output when copying a network request from the developer tools panel. An
attacker could potentially exploits this to hide and execute arbitrary
commands. (CVE-2023-23599)
Luan Herrera discovered that Firefox was not stopping navigation when
dragging a URL from a cross-origin iframe into the same tab. An attacker
potentially exploits this to spoof the user. (CVE-2023-23601)
Dave Vandyke discovered that Firefox did not properly implement CSP policy
when creating a WebSocket in a WebWorker. An attacker who was able to
inject markup into a page otherwise protected by a Content Security Policy
may have been able to inject an executable script. (CVE-2023-23602)
Dan Veditz discovered that Firefox did not properly implement CSP policy
on regular expression when using console.log. An attacker potentially
exploits this to exfiltrate data from the browser. (CVE-2023-23603)
Nika Layzell discovered that Firefox was not performing a validation check
when parsing a non-system html document via DOMParser::ParseFromSafeString.
An attacker potentially exploits this to bypass web security checks.
(CVE-2023-23604)
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-23605,
CVE-2023-23606)
advancecomp-2.5-1.el8
FEDORA-EPEL-2023-5792a74fc0
Packages in this update:
advancecomp-2.5-1.el8
Update description:
Update to 2.5 (close RHBZ#2162990; fix RHBZ#2161641): “Fix segmentation fault on invalid MNG size”
DSA-5324 linux – security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
advancecomp-2.5-1.el9
FEDORA-EPEL-2023-aba6bd8086
Packages in this update:
advancecomp-2.5-1.el9
Update description:
Update to 2.5 (close RHBZ#2162990; fix RHBZ#2161641): “Fix segmentation fault on invalid MNG size”
advancecomp-2.5-1.fc36
FEDORA-2023-e8c294f93d
Packages in this update:
advancecomp-2.5-1.fc36
Update description:
Update to 2.5 (close RHBZ#2162990; fix RHBZ#2161641): “Fix segmentation fault on invalid MNG size”
advancecomp-2.5-1.fc37
FEDORA-2023-f685c3dcc5
Packages in this update:
advancecomp-2.5-1.fc37
Update description:
Update to 2.5 (close RHBZ#2162990; fix RHBZ#2161641): “Fix segmentation fault on invalid MNG size”