A vulnerability was found in zwczou WeChat SDK Python 0.3.0 and classified as critical. This issue affects the function validate/to_xml. The manipulation leads to xml external entity reference. The attack may be initiated remotely. Upgrading to version 0.5.5 is able to address this issue. The name of the patch is e54abadc777715b6dcb545c13214d1dea63df6c9. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-223403.
More Stories
tpm2-tools-5.7-1.fc40 tpm2-tss-4.1.0-1.fc40
FEDORA-2024-0c9d3b51d4 Packages in this update: tpm2-tools-5.7-1.fc40 tpm2-tss-4.1.0-1.fc40 Update description: tpm2-tss: Fixed CVE-2024-29040 tpm2-tools: Fixed CVE-2024-29038 Fixed CVE-2024-29039 Read More
tpm2-tools-5.5.1-1.fc39 tpm2-tss-4.0.2-1.fc39
FEDORA-2024-4512dc54af Packages in this update: tpm2-tools-5.5.1-1.fc39 tpm2-tss-4.0.2-1.fc39 Update description: tpm2-tss: Fixed CVE-2024-29040 tpm2-tools: Fixed CVE-2024-29038 Fixed CVE-2024-29039 Read More
tpm2-tools-5.5.1-1.fc38 tpm2-tss-4.0.2-1.fc38
FEDORA-2024-3265d70b61 Packages in this update: tpm2-tools-5.5.1-1.fc38 tpm2-tss-4.0.2-1.fc38 Update description: tpm2-tss: Fixed CVE-2024-29040 tpm2-tools: Fixed CVE-2024-29038 Fixed CVE-2024-29039 Read More
webkit2gtk4.0-2.44.1-1.fc40
FEDORA-2024-a1246372a4 Packages in this update: webkit2gtk4.0-2.44.1-1.fc40 Update description: Update to 2.44.1 Read More
CrushFTP VFS Sandbox Escape Vulnerability (CVE-2024-4040)
What is the vulnerability? A zero-day security vulnerability has been uncovered in an enterprise file-transfer software CrushFTP. The vulnerability tagged...
gdcm-3.0.23-5.fc39
FEDORA-2024-11821b16ac Packages in this update: gdcm-3.0.23-5.fc39 Update description: Security fixes TALOS-2024-1924, CVE-2024-22391: heap overflow TALOS-2024-1935, CVE-2024-22373: out-of-bounds write TALOS-2024-1944, CVE-2024-25569:...