EOL for an operating system can necessitate a shift in your security efforts, as is the case with the CentOS 7 EOL. Here’s how to navigate the process.
Monthly Archives: June 2024
Majority of Critical Open Source Projects Contain Memory Unsafe Code
A CISA analysis in collaboration with international partners concluded most critical open source projects potentially contain memory safety vulnerabilities
cups-2.4.10-1.fc39
FEDORA-2024-7c36291390
Packages in this update:
cups-2.4.10-1.fc39
Update description:
Rebase to 2.4.10, security fix for CVE-2024-35235
ghostscript-10.02.1-5.fc39
FEDORA-2024-c45c747f02
Packages in this update:
ghostscript-10.02.1-5.fc39
Update description:
Security fixes for CVE-2024-33870, CVE-2024-29510
Fix for issues in gating
Security fix for CVE-2024-33871
cups-2.4.10-1.fc40
FEDORA-2024-a3d1f80409
Packages in this update:
cups-2.4.10-1.fc40
Update description:
Rebase to 2.4.10, security fix for CVE-2024-35235
ghostscript-10.02.1-10.fc40
FEDORA-2024-f433c5c4da
Packages in this update:
ghostscript-10.02.1-10.fc40
Update description:
Security fixes for CVE-2024-33870, CVE-2024-29510
Security Analysis of the EU’s Digital Wallet
US Charges Russian Individual for Pre-Invasion Ukraine Hack
The US government is offering up to $10m for information on Amin Timovich Stigal’s location or his malicious cyber activity
USN-6857-1: Squid vulnerabilities
Joshua Rogers discovered that Squid incorrectly handled requests with the
urn: scheme. A remote attacker could possibly use this issue to cause
Squid to consume resources, leading to a denial of service. This issue
only affected Ubuntu 16.04 LTS. (CVE-2021-28651)
It was discovered that Squid incorrectly handled SSPI and SMB
authentication. A remote attacker could use this issue to cause Squid to
crash, resulting in a denial of service, or possibly obtain sensitive
information. This issue only affected Ubuntu 16.04 LTS. (CVE-2022-41318)
Joshua Rogers discovered that Squid incorrectly handled HTTP message
processing. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-49285)
Joshua Rogers discovered that Squid incorrectly handled Helper process
management. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-49286)
Joshua Rogers discovered that Squid incorrectly handled HTTP request
parsing. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service.
(CVE-2023-50269, CVE-2024-25617)
USN-6852-2: Wget vulnerability
USN-6852-1 fixed a vulnerability in Wget. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that Wget incorrectly handled semicolons in the userinfo
subcomponent of a URI. A remote attacker could possibly trick a user into
connecting to a different host than expected.