This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-26158.
Monthly Archives: April 2024
ZDI-24-364: Arista NG Firewall ReportEntry SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-27889.
yyjson-0.9.0-1.fc38
FEDORA-2024-4691d60717
Packages in this update:
yyjson-0.9.0-1.fc38
Update description:
Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791; Security fix for CVE-2024-25713
yyjson-0.9.0-1.fc39
FEDORA-2024-ef2e551fab
Packages in this update:
yyjson-0.9.0-1.fc39
Update description:
Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791; Security fix for CVE-2024-25713
yyjson-0.9.0-1.fc40
FEDORA-2024-8c48a81cb9
Packages in this update:
yyjson-0.9.0-1.fc40
Update description:
Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791; Security fix for CVE-2024-25713
yyjson-0.9.0-1.fc41
FEDORA-2024-2a0f7e9e97
Packages in this update:
yyjson-0.9.0-1.fc41
Update description:
Automatic update for yyjson-0.9.0-1.fc41.
Changelog
* Tue Apr 9 2024 topazus <topazus@outlook.com> – 0.9.0-1
– Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791
python-django-4.2.11-1.fc39
FEDORA-2024-2ec03ca8cb
Packages in this update:
python-django-4.2.11-1.fc39
Update description:
Security fix for CVE-2024-24680 and CVE-2024-27351
python-django-4.2.11-1.fc40
FEDORA-2024-5c7fb64c74
Packages in this update:
python-django-4.2.11-1.fc40
Update description:
Security fix for CVE-2024-24680 and CVE-2024-27351
python-django-4.2.11-1.fc41
FEDORA-2024-c5c5671edb
Packages in this update:
python-django-4.2.11-1.fc41
Update description:
Automatic update for python-django-4.2.11-1.fc41.
Changelog
* Mon Apr 8 2024 Michel Lind <salimma@fedoraproject.org> – 4.2.11-1
– Update to 4.2.11
– Resolves CVE-2024-24680 (rhbz#2263505)
– Resolves CVE-2024-27351 (rhbz#2267654)
US Federal Data Privacy Law Introduced by Legislators
Two US lawmakers have published a draft federal data privacy law, dubbed the American Privacy Rights Act, which aims to provide protections for the personal information of all US citizens