This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Monthly Archives: March 2023
ZDI-23-206: Siemens Solid Edge Viewer DXF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
ZDI-23-207: Siemens Solid Edge Viewer DWG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
ZDI-23-208: Siemens Solid Edge Viewer DWG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
duktape-2.2.0-6.el8
FEDORA-EPEL-2023-5f230957f1
Packages in this update:
duktape-2.2.0-6.el8
Update description:
Backport upstream fix for CVE-2021-46322.
caddy-2.4.6-6.el9
FEDORA-EPEL-2023-0d642b2dde
Packages in this update:
caddy-2.4.6-6.el9
Update description:
Backport of upstream fix for CVE-2022-29718.
caddy-2.4.6-6.fc36
FEDORA-2023-a258bed79b
Packages in this update:
caddy-2.4.6-6.fc36
Update description:
Backport of upstream fix for CVE-2022-29718.
DSA-5366 multipath-tools – security update
The Qualys Research Labs reported an authorization bypass
(CVE-2022-41974)
and a symlink attack
(CVE-2022-41973)
in multipath-tools, a set of tools to drive the Device Mapper multipathing
driver, which may result in local privilege escalation.