FEDORA-EPEL-2023-a0df121fab
Packages in this update:
ImageMagick-6.9.12.77-1.el8
Update description:
Update to 6.9.12-77
ImageMagick-6.9.12.77-1.el8
Update to 6.9.12-77
ImageMagick-6.9.12.77-1.el9
Update to 6.9.12-77
ImageMagick-6.9.12.77-1.fc36
Update to 6.9.12-77
ImageMagick-6.9.12.77-1.fc37
Update to 6.9.12-77
git-2.39.2-1.fc37
Update to 2.39.2 (CVE-2023-22490, CVE-2023-23946)
Refer to the upstream release notes and the security advisories (CVE-2023-22490, CVE-2023-23946) for details.
git-2.39.2-1.fc36
Update to 2.39.2 (CVE-2023-22490, CVE-2023-23946)
Refer to the upstream release notes and the security advisories (CVE-2023-22490, CVE-2023-23946) for details.
Ronald Crane discovered that APR-util did not properly handled memory when
encoding or decoding certain input data. An attacker could possibly use
this issue to cause a denial of service, or possibly execute arbitrary
code.
It was discovered that Git incorrectly handled certain repositories.
An attacker could use this issue to make Git uses its local
clone optimization even when using a non-local transport.
(CVE-2023-22490)
Joern Schneeweisz discovered that Git incorrectly handled certain commands.
An attacker could possibly use this issue to overwrite a patch outside
the working tree. (CVE-2023-23946)
The infostealer Vidar has returned to the top 10 after an increase in ‘brandjacking’ attacks
Bahruz Jabiyev, Anthony Gavazzi, Engin Kirda, Kaan Onarlioglu, Adi Peleg,
and Harvey Tuch discovered that HAProxy incorrectly handled empty header
names. A remote attacker could possibly use this issue to manipulate
headers and bypass certain authentication checks and restrictions.