It was discovered that Cockpit, a web console for Linux servers, was
susceptible to arbitrary command execution if an administrative user
was tricked into opening an sosreport file with a malformed filename.
Monthly Archives: April 2024
xorg-x11-server-Xwayland-23.2.5-1.fc39
FEDORA-2024-a1d440af5c
Packages in this update:
xorg-x11-server-Xwayland-23.2.5-1.fc39
Update description:
CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and CVE-2024-31083
trafficserver-9.2.4-1.fc38
FEDORA-2024-d0acf8d109
Packages in this update:
trafficserver-9.2.4-1.fc38
Update description:
Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)
trafficserver-9.2.4-1.fc39
FEDORA-2024-b1e16b4335
Packages in this update:
trafficserver-9.2.4-1.fc39
Update description:
Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)
trafficserver-9.2.4-1.fc40
FEDORA-2024-111a8a624b
Packages in this update:
trafficserver-9.2.4-1.fc40
Update description:
Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)
trafficserver-9.2.4-1.el8
FEDORA-EPEL-2024-57848161af
Packages in this update:
trafficserver-9.2.4-1.el8
Update description:
Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)
trafficserver-9.2.4-1.el9
FEDORA-EPEL-2024-0cbb770fdc
Packages in this update:
trafficserver-9.2.4-1.el9
Update description:
Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)
trafficserver-9.2.4-1.el7
FEDORA-EPEL-2024-1f6e851537
Packages in this update:
trafficserver-9.2.4-1.el7
Update description:
Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)
xorg-x11-server-Xwayland-23.2.5-1.fc40
FEDORA-2024-852d7faa63
Packages in this update:
xorg-x11-server-Xwayland-23.2.5-1.fc40
Update description:
CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and CVE-2024-31083
Smashing Security podcast #366: Money-making bots, and Incognito isn’t private
Google says it is deleting the your Google Chrome Incognito private-browsing data that it should never have collected anyway. Can a zero-risk millionaire-making bot be trusted? And what countries are banned from buying your sensitive data?
All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown’s Thom Langford.