FEDORA-2023-ec02e360af
Packages in this update:
tigervnc-1.13.1-9.fc38
xorg-x11-server-1.20.14-28.fc38
Update description:
CVE fix for: CVE-2023-6377, CVE-2023-6478
tigervnc-1.13.1-9.fc38
xorg-x11-server-1.20.14-28.fc38
CVE fix for: CVE-2023-6377, CVE-2023-6478
tigervnc-1.13.1-9.fc39
xorg-x11-server-1.20.14-28.fc39
CVE fix for: CVE-2023-6377, CVE-2023-6478
Zygmunt Krynicki discovered that GNOME Settings did not accurately reflect
the SSH remote login status when the system was configured to use systemd
socket activation for OpenSSH. Remote SSH access may be unknowingly
enabled, contrary to expectation.
Multiple security issues were discovered in Chromium, which could result
in the execution of arbitrary code, denial of service or information
disclosure.
Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server,
which may result in privilege escalation if the X server is running
privileged.
Posted by SEC Consult Vulnerability Lab, Research via Fulldisclosure on Dec 12
SEC Consult Vulnerability Lab Security Advisory < 20231211-0 >
=======================================================================
title: Local Privilege Escalation via MSI installer
product: PDF24 Creator (geek Software GmbH)
vulnerable version: <=11.15.1
fixed version: 11.15.2
CVE number: CVE-2023-49147
impact: High
homepage:…
Posted by SEC Consult Vulnerability Lab, Research via Fulldisclosure on Dec 12
SEC Consult Vulnerability Lab Security Advisory < 20231206-0 >
=======================================================================
title: Kiosk Escape Privilege Escalation
product: One Identity Password Manager Secure Password Extension
vulnerable version: <5.13.1
fixed version: 5.13.1
CVE number: CVE-2023-48654
impact: critical
homepage:…
Posted by SEC Consult Vulnerability Lab, Research via Fulldisclosure on Dec 12
SEC Consult Vulnerability Lab Security Advisory < 20231205-0 >
=======================================================================
title: Argument injection leading to unauthenticated RCE and
authentication bypass
product: Atos Unify OpenScape Session Border Controller (SBC)
Atos Unify OpenScape Branch
Atos Unify OpenScape BCF
vulnerable…
Posted by SEC Consult Vulnerability Lab, Research via Fulldisclosure on Dec 12
SEC Consult Vulnerability Lab Security Advisory < 20231128-0 >
=======================================================================
title: Missing Certificate Validation & User Enumeration
product: Anveo Mobile App and Server
vulnerable version: Mobile App: 10.0.0.359 / 2016-07-13; Server: 11.0.0.5
fixed version: –
CVE number: –
impact: Medium
homepage:…
Posted by Marco Ivaldi on Dec 12
Hi,
Please find attached a security advisory that describes some buffer
overflow vulnerabilities we discovered in TinyDir.
* Title: Buffer overflow vulnerabilities with long path names in TinyDir
* Product: TinyDir <= 1.2.5
* Author: Marco Ivaldi <marco.ivaldi () hnsecurity it>
* Date: 2023-12-04
* CVE ID: CVE-2023-49287
* Severity: High – 7.7 – CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
* Vendor URL: https://github.com/cxong/tinydir…