Multiple vulnerabilities have been discovered within VMware Aria Operations for Networks, the most severe of which could allow for remote code execution. VMware Aria Operations for Networks is a network monitoring tool that collects and analyzes metrics, APIs, configurations, metadata, integrations, telemetry netflow, sFlow, and IPFIX flow traffic, which traverses the infrastructure. Successful exploitation of these vulnerabilities could allow for remote code execution in the context of the administrator account. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Daily Archives: August 30, 2023
python-jupyter-server-2.7.2-1.fc39
FEDORA-2023-3d77cfc654
Packages in this update:
python-jupyter-server-2.7.2-1.fc39
Update description:
Security update with fixes for CVE-2023-39968 and CVE-2023-40170
Cloud Security and Functionality: Don’t Settle for Just One
CIS is testing its CIS Hardened Images with Azure Update Manager and Amazon EC2 Image Builder. Here’s what this means for your cloud security.
python3-docs-3.11.5-1.fc37 python3.11-3.11.5-1.fc37
FEDORA-2023-aeb32a843f
Packages in this update:
python3.11-3.11.5-1.fc37
python3-docs-3.11.5-1.fc37
Update description:
Update to 3.11.5
python3-docs-3.11.5-1.fc38 python3.11-3.11.5-1.fc38
FEDORA-2023-3d13b093d2
Packages in this update:
python3.11-3.11.5-1.fc38
python3-docs-3.11.5-1.fc38
Update description:
Update to 3.11.5
python3.11-3.11.5-1.fc39
FEDORA-2023-4953fc03b9
Packages in this update:
python3.11-3.11.5-1.fc39
Update description:
Update to 3.11.5
kernel-6.4.13-100.fc37
FEDORA-2023-a1ca0ef4d6
Packages in this update:
kernel-6.4.13-100.fc37
Update description:
The 6.4.13 stable kernel updates contain a number of important fixes across the tree.
kernel-6.4.13-200.fc38
FEDORA-2023-da8b7c1ca3
Packages in this update:
kernel-6.4.13-200.fc38
Update description:
The 6.4.13 stable kernel updates contain a number of important fixes across the tree.
Flaw Exposes WP Migration Plugin to Hacks
The vulnerable code was identified by the security research team at PatchStack
USN-6322-1: elfutils vulnerabilities
It was discovered that elfutils incorrectly handled certain malformed
files. If a user or automated system were tricked into processing a
specially crafted file, elfutils could be made to crash or consume
resources, resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-16062, CVE-2018-16403, CVE-2018-18310,
CVE-2018-18520, CVE-2018-18521, CVE-2019-7149, CVE-2019-7150,
CVE-2019-7665)
It was discovered that elfutils incorrectly handled bounds checks in
certain functions when processing malformed files. If a user or automated
system were tricked into processing a specially crafted file, elfutils
could be made to crash or consume resources, resulting in a denial of
service. (CVE-2020-21047, CVE-2021-33294)