Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary system command, disrupt system or terminate service.
More Stories
mingw-binutils-2.39-6.fc38
FEDORA-2023-15c6e4be28 Packages in this update: mingw-binutils-2.39-6.fc38 Update description: Backport fix for CVE-2023-1579. Read More
USN-5966-2: amanda regression
USN-5966-1 fixed vulnerabilities in amanda. Unfortunately it introduced a regression in GNUTAR-based backups. This update reverts all of the changes...
ImageMagick-7.1.1.4-2.fc38
FEDORA-2023-f992309b7e Packages in this update: ImageMagick-7.1.1.4-2.fc38 Update description: Fix missing epoch in ImageMagick-heic requires (#2181176) Update ImageMagick to 7.1.1.4 (#2176749)...
python-flask-restx-1.1.0-1.fc38
FEDORA-2023-354467acba Packages in this update: python-flask-restx-1.1.0-1.fc38 Update description: New upstream release Read More
CVE-2018-25048
The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to...
USN-5966-1: amanda vulnerabilities
Maher Azzouzi discovered an information disclosure vulnerability in the calcsize binary within amanda. calcsize is a suid binary owned by...