This vulnerability allows remote attackers to execute arbitrary code on affected installations of VMware HCX. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-38814.
Category Archives: Advisories
USN-7081-1: Go vulnerabilities
It was discovered that the Go net/http module did not properly handle
responses to requests with an “Expect: 100-continue” header under certain
circumstances. An attacker could possibly use this issue to cause a denial
of service. (CVE-2024-24791)
It was discovered that the Go parser module did not properly handle deeply
nested literal values. An attacker could possibly use this issue to cause
a panic resulting in a denial of service. (CVE-2024-34155)
It was discovered that the Go encoding/gob module did not properly handle
message decoding under certain circumstances. An attacker could possibly
use this issue to cause a panic resulting in a denial of service.
(CVE-2024-34156)
It was discovered that the Go build module did not properly handle certain
build tag lines with deeply nested expressions. An attacker could possibly
use this issue to cause a panic resulting in a denial of service.
(CVE-2024-34158)
suricata-7.0.7-1.el9
FEDORA-EPEL-2024-1f36d78e1b
Packages in this update:
suricata-7.0.7-1.el9
Update description:
Various security, performance, accuracy, and stability issues have been fixed. Note, this update is a major upgrade. Please look at the following before upgrading: https://docs.suricata.io/en/suricata-7.0.6/upgrade.html#upgrading-6-0-to-7-0
suricata-7.0.7-1.el8
FEDORA-EPEL-2024-a534fa2702
Packages in this update:
suricata-7.0.7-1.el8
Update description:
Various security, performance, accuracy, and stability issues have been fixed. Note, this update is a major upgrade. Please look at the following before upgrading: https://docs.suricata.io/en/suricata-7.0.6/upgrade.html#upgrading-6-0-to-7-0
micropython-1.23.0-1.fc39
FEDORA-2024-9c81ad492a
Packages in this update:
micropython-1.23.0-1.fc39
Update description:
Update to 1.23.0
micropython-1.23.0-1.fc40
FEDORA-2024-f9ca680ecd
Packages in this update:
micropython-1.23.0-1.fc40
Update description:
Update to 1.23.0
micropython-1.23.0-1.fc41
FEDORA-2024-cd5c1dfa94
Packages in this update:
micropython-1.23.0-1.fc41
Update description:
Update to 1.23.0
micropython-1.23.0-1.fc42
FEDORA-2024-81b8dc2197
Packages in this update:
micropython-1.23.0-1.fc42
Update description:
Automatic update for micropython-1.23.0-1.fc42.
Changelog
* Thu Oct 17 2024 Charalampos Stratakis <cstratak@redhat.com> – 1.23.0-1
– Update to 1.23.0
– Security fixes for CVE-2024-8946, CVE-2024-8947, CVE-2024-8948
Resolves: rhbz#2312926, rhbz#2312923, rhbz#2312921
USN-7080-1: Unbound vulnerability
Toshifumi Sakaguchi discovered that Unbound incorrectly handled name
compression for large RRsets, which could lead to excessive CPU usage.
An attacker could potentially use this issue to cause a denial of service
by sending specially crafted DNS responses.
NetworkManager-libreswan-1.2.24-1.fc39
FEDORA-2024-d20b38c63f
Packages in this update:
NetworkManager-libreswan-1.2.24-1.fc39
Update description:
This is an update to 1.2.24 release of NetworkManager-libreswan, the IPSec VPN plugin for NetworkManager. It fixes a local privilege escalation bug due to improper escaping of Libreswan configuration. (CVE-2024-9050)