FEDORA-2024-5c99e1d579
Packages in this update:
p7zip-16.02-31.fc40
Update description:
Fix wrapper to hide password from process history
p7zip-16.02-31.fc40
Fix wrapper to hide password from process history
p7zip-16.02-31.fc39
Fix wrapper to hide password from process history
Multiple security issues have been found in the Mozilla Firefox
web browser, which could potentially result in the execution
of arbitrary code.
Debian follows the extended support releases (ESR) of Firefox.
Starting with this update we’re now following the 128.x releases.
Between 115.x and 128.x, Firefox has seen a number of feature
updates. For more information please refer to
https://www.mozilla.org/en-US/firefox/128.0esr/releasenotes/
Fabian Vogt reported that the PAM module in oath-toolkit, a collection
of components to build one-time password authentication systems, does
not safely perform file operations in users’s home directories when
using the usersfile feature (allowing to place the OTP state in the home
directory of the to-be-authenticated user). A local user can take
advantage of this flaw for root privilege escalation.
unbound-1.21.1-3.fc39
Fixed builds on F41. Fixes CVE-2024-8508
https://github.com/NLnetLabs/unbound/releases/tag/release-1.21.1
unbound-1.21.1-3.fc40
Fixes CVE-2024-8508
https://github.com/NLnetLabs/unbound/releases/tag/release-1.21.1
unbound-1.21.1-1.fc41
Fixed builds on F41. Fixes CVE-2024-8508
https://github.com/NLnetLabs/unbound/releases/tag/release-1.21.1
The new LiteSpeed Cache flaw (CVE-2024-47374) allows unauthenticated code injection across more than six million active installations
Microsoft and the US government have collectively seized over 100 websites used by Russian nation-state actor Star Blizzard
China-aligned CeranaKeeper discovered targeting Thai govt institutions using cloud services for data exfiltration