This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker. Authentication is not required to exploit this vulnerability.
Monthly Archives: April 2023
ZDI-23-450: (Pwn2Own) Triangle MicroWorks SCADA Data Gateway Restore Workspace Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
insight-13.0.50.20220502-9.fc37
FEDORA-2023-b4d1469b54
Packages in this update:
insight-13.0.50.20220502-9.fc37
Update description:
Disable stringop-overflow warnings.
Patch “bfd-CVE-2023-1972” fixes a security issue in bfd library.
insight-13.0.50.20220502-9.fc38
FEDORA-2023-8a6a30c142
Packages in this update:
insight-13.0.50.20220502-9.fc38
Update description:
Disable stringop-overflow warnings.
Patch “bfd-CVE-2023-1972” fixes a security issue in bfd library.
insight-13.0.50.20220502-9.fc36
FEDORA-2023-5d51a42413
Packages in this update:
insight-13.0.50.20220502-9.fc36
Update description:
Disable stringop-overflow warnings.
Patch “bfd-CVE-2023-1972” fixes a security issue in bfd library.
DSA-5389 rails – security update
Two vulnerabilities were discovered in rails, the Ruby based server-side
MVC web application framework, which could lead to XSS and DOM based
cross-site scripting (CRS).
mod_security-2.9.7-1.fc38
FEDORA-2023-bc61f7a145
Packages in this update:
mod_security-2.9.7-1.fc38
Update description:
new version 2.9.7
switch to PCRE2
mod_security-2.9.7-1.fc36
FEDORA-2023-8aa264d5c5
Packages in this update:
mod_security-2.9.7-1.fc36
Update description:
new version 2.9.7
switch to PCRE2
mod_security-2.9.7-1.fc37
FEDORA-2023-09f0496e60
Packages in this update:
mod_security-2.9.7-1.fc37
Update description:
new version 2.9.7
switch to PCRE2
mingw-freeimage-3.19.0-0.14.svn1889.fc36
FEDORA-2023-2682ede2ed
Packages in this update:
mingw-freeimage-3.19.0-0.14.svn1889.fc36
Update description:
Backport proposed fix for CVE-2021-33367.