This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Monthly Archives: June 2023
ZDI-23-880: Microsoft Azure Machine Learning Service DSIMountAgent Missing Authentication Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on Microsoft Azure. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
libX11-1.8.6-1.fc38
FEDORA-2023-7503ce855c
Packages in this update:
libX11-1.8.6-1.fc38
Update description:
libX11 1.8.6 (CVE-2023-3138)
DSA-5430 openjdk-17 – security update
Several vulnerabilities have been discovered in the OpenJDK Java runtime,
which may result in denial of service, information disclosure or bypass
of sandbox restrictions.
DSA-5431 sofia-sip – security update
Xu Biang discovered that missing input sanitising in Sofia-SIP, a SIP
User-Agent library could result in denial of service.
dotnet7.0-7.0.107-1.fc37
FEDORA-2023-e6d5cb11bb
Packages in this update:
dotnet7.0-7.0.107-1.fc37
Update description:
This is the June 2023 monthly update for .NET 7. It includes fixes for several CVEs.
Release Notes:
– Runtime: https://github.com/dotnet/core/blob/main/release-notes/7.0/7.0.7/7.0.7.md
– SDK: https://github.com/dotnet/core/blob/main/release-notes/7.0/7.0.7/7.0.107.md
dotnet7.0-7.0.107-1.fc38
FEDORA-2023-ee819d655b
Packages in this update:
dotnet7.0-7.0.107-1.fc38
Update description:
This is the June 2023 monthly update for .NET 7. It includes fixes for several CVEs.
Release Notes:
– Runtime: https://github.com/dotnet/core/blob/main/release-notes/7.0/7.0.7/7.0.7.md
– SDK: https://github.com/dotnet/core/blob/main/release-notes/7.0/7.0.7/7.0.107.md
dotnet6.0-6.0.118-1.fc37
FEDORA-2023-edb993aeaf
Packages in this update:
dotnet6.0-6.0.118-1.fc37
Update description:
This is the June 2023 monthly update for .NET 6. It includes fixes for several CVEs.
Release Notes:
– Runtime: https://github.com/dotnet/core/blob/main/release-notes/6.0/6.0.18/6.0.18.md
– SDK: https://github.com/dotnet/core/blob/main/release-notes/6.0/6.0.18/6.0.118.md
dotnet6.0-6.0.118-1.fc38
FEDORA-2023-401e38c388
Packages in this update:
dotnet6.0-6.0.118-1.fc38
Update description:
This is the June 2023 monthly update for .NET 6. It includes fixes for several CVEs.
Release Notes:
– Runtime: https://github.com/dotnet/core/blob/main/release-notes/6.0/6.0.18/6.0.18.md
– SDK: https://github.com/dotnet/core/blob/main/release-notes/6.0/6.0.18/6.0.118.md
USN-6169-1: GNU SASL vulnerability
It was discovered that GNU SASL’s GSSAPI server could make an
out-of-bounds reads if given specially crafted GSS-API authentication
data. A remote attacker could possibly use this issue to cause a
denial of service or to expose sensitive information.