A recent survey conducted by Integrity 360 shows that data theft has overtaken ransomware as a top concern for some IT decision makers
Monthly Archives: October 2023
CVE-2023-20819 (lr11, lr12a, lr13, nr15, nr16, nr17)
In CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: MOLY01068234; Issue ID: ALPS08010003.
DSA-5512 exim4 – security update
Several vulnerabilities were discovered in Exim, a mail transport agent,
which could result in remote code execution if the EXTERNAL or SPA/NTLM
authenticators are used.
rust-aes-gcm-0.10.3-1.el9
FEDORA-EPEL-2023-1b27cb1ee9
Packages in this update:
rust-aes-gcm-0.10.3-1.el9
Update description:
Update to version 0.10.3. Addresses CVE-2023-42811.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42811
firecracker-1.4.1-3.fc37 rust-aes-gcm-0.10.3-1.fc37
FEDORA-2023-bc40c7995e
Packages in this update:
firecracker-1.4.1-3.fc37
rust-aes-gcm-0.10.3-1.fc37
Update description:
Update the aes-gcm crate to version 0.10.3. Addresses CVE-2023-42811.
Rebuild dependent packages (firecracker) for aes-gcm v0.10.3.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42811
firecracker-1.4.1-3.fc38 rust-aes-gcm-0.10.3-1.fc38
FEDORA-2023-98f44d1c4c
Packages in this update:
firecracker-1.4.1-3.fc38
rust-aes-gcm-0.10.3-1.fc38
Update description:
Update the aes-gcm crate to version 0.10.3. Addresses CVE-2023-42811.
Rebuild dependent packages (firecracker) for aes-gcm v0.10.3.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42811
firecracker-1.4.1-3.fc39 rust-aes-gcm-0.10.3-1.fc39
FEDORA-2023-17bdd59177
Packages in this update:
firecracker-1.4.1-3.fc39
rust-aes-gcm-0.10.3-1.fc39
Update description:
Update the aes-gcm crate to version 0.10.3. Addresses CVE-2023-42811.
Rebuild dependent packages (firecracker) for aes-gcm v0.10.3.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42811
firecracker-1.4.1-3.fc40 rust-aes-gcm-0.10.3-1.fc40
FEDORA-2023-377bc1b17c
Packages in this update:
firecracker-1.4.1-3.fc40
rust-aes-gcm-0.10.3-1.fc40
Update description:
Update the aes-gcm crate to version 0.10.3. Addresses CVE-2023-42811.
Rebuild dependent packages (firecracker) for aes-gcm v0.10.3.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42811
DSA-5511 mosquitto – security update
Several security vulnerabilities have been discovered in mosquitto, a MQTT
compatible message broker, which may be abused for a denial of service attack.