USN-6594-1: Squid vulnerabilities

Read Time:29 Second

Joshua Rogers discovered that Squid incorrectly handled HTTP message
processing. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-49285)

Joshua Rogers discovered that Squid incorrectly handled Helper process
management. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-49286)

Joshua Rogers discovered that Squid incorrectly handled HTTP request
parsing. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-50269)

Read More

systemd-253.15-2.fc38

Read Time:21 Second

FEDORA-2024-c79658eedf

Packages in this update:

systemd-253.15-2.fc38

Update description:

A bunch of fixes for various components: systemd, systemctl, hostnamectl, bootctl, systemd-networkd, systemd-network-generator, systemd-analyze, systemd-dissect, man pages.
Also has a patch for CVE-2023-7008 (rhbz#2222260)
Add missing %postun scriptlets for systemd-{resolved,networkd} so that they are restarted on package updates.

No need to restart or log out.

Read More

systemd-254.8-2.fc39

Read Time:22 Second

FEDORA-2024-b8312ca5b3

Packages in this update:

systemd-254.8-2.fc39

Update description:

A bunch of fixes for various components: systemd, systemctl, systemd-firstboot, systemd-repart, bootctl, systemd-networkd, systemd-network-generator, systemd-analyze, systemd-dissect, ukify, man pages.
Also has a patch for CVE-2023-7008 (rhbz#2222260)
Add missing %postun scriptlets for systemd-{resolved,networkd} so that they are restarted on package updates.

No need to log out or reboot.

Read More

USN-6593-1: GnuTLS vulnerabilities

Read Time:26 Second

It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker could
possibly use this issue to recover sensitive information. (CVE-2024-0553)

It was discovered that GnuTLS incorrectly handled certain certificate
chains with a cross-signing loop. A remote attacker could possibly use this
issue to cause GnuTLS to crash, resulting in a denial of service. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 23.04, and Ubuntu 23.10.
(CVE-2024-0567)

Read More