Rory McNamara discovered that wpa_supplicant could be made to load
arbitrary shared objects by unprivileged users that have access to
the control interface. An attacker could use this to escalate privileges
to root.
Category Archives: Advisories
Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution
Multiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Firefox ESR is a version of the web browser intended to be deployed in large organizations. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
tor-0.4.8.12-2.el8
FEDORA-EPEL-2024-2d8a766d53
Packages in this update:
tor-0.4.8.12-2.el8
Update description:
Re-add systemd-devel as build dependency so the daemon knows how to notify systemd that it was started – fixes bz#2302910
tor-0.4.8.12-2.el9
FEDORA-EPEL-2024-4188096f1c
Packages in this update:
tor-0.4.8.12-2.el9
Update description:
Re-add systemd-devel as build dependency so the daemon knows how to notify systemd that it was started – fixes bz#2302910
tor-0.4.8.12-2.fc39
FEDORA-2024-c2da7f4de7
Packages in this update:
tor-0.4.8.12-2.fc39
Update description:
Re-add systemd-devel as build dependency so the daemon knows how to notify systemd that it was started – fixes bz#2302910
tor-0.4.8.12-2.fc40
FEDORA-2024-3f9eb3c86c
Packages in this update:
tor-0.4.8.12-2.fc40
Update description:
Re-add systemd-devel as build dependency so the daemon knows how to notify systemd that it was started – fixes bz#2302910
ZDI-24-1099: Apache OFBiz resolveURI Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Apache OFBiz. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-38856.
ZDI-24-1098: (0Day) Microsoft Windows Error Reporting Service Missing Authorization Arbitrary Process Termination Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5.
ZDI-24-1097: (0Day) Microsoft GitHub Dev-Containers Improper Privilege Management Privilege Escalation Vulnerability
This vulnerability allows remote attackers to escalate privileges on Microsoft GitHub. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9.
ZDI-24-1096: (0Day) Microsoft Office Visio EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office Visio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3.