Gerrard Tai discovered that libheif did not properly validate certain
images, leading to out-of-bounds read and write vulnerability. If a user
or automated system were tricked into opening a specially crafted file, an
attacker could possibly use this issue to cause a denial of service or to
obtain sensitive information.
Category Archives: Advisories
ZDI-24-1421: VMware HCX listExtensions SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VMware HCX. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-38814.
USN-7081-1: Go vulnerabilities
It was discovered that the Go net/http module did not properly handle
responses to requests with an “Expect: 100-continue” header under certain
circumstances. An attacker could possibly use this issue to cause a denial
of service. (CVE-2024-24791)
It was discovered that the Go parser module did not properly handle deeply
nested literal values. An attacker could possibly use this issue to cause
a panic resulting in a denial of service. (CVE-2024-34155)
It was discovered that the Go encoding/gob module did not properly handle
message decoding under certain circumstances. An attacker could possibly
use this issue to cause a panic resulting in a denial of service.
(CVE-2024-34156)
It was discovered that the Go build module did not properly handle certain
build tag lines with deeply nested expressions. An attacker could possibly
use this issue to cause a panic resulting in a denial of service.
(CVE-2024-34158)
suricata-7.0.7-1.el9
FEDORA-EPEL-2024-1f36d78e1b
Packages in this update:
suricata-7.0.7-1.el9
Update description:
Various security, performance, accuracy, and stability issues have been fixed. Note, this update is a major upgrade. Please look at the following before upgrading: https://docs.suricata.io/en/suricata-7.0.6/upgrade.html#upgrading-6-0-to-7-0
suricata-7.0.7-1.el8
FEDORA-EPEL-2024-a534fa2702
Packages in this update:
suricata-7.0.7-1.el8
Update description:
Various security, performance, accuracy, and stability issues have been fixed. Note, this update is a major upgrade. Please look at the following before upgrading: https://docs.suricata.io/en/suricata-7.0.6/upgrade.html#upgrading-6-0-to-7-0
micropython-1.23.0-1.fc39
FEDORA-2024-9c81ad492a
Packages in this update:
micropython-1.23.0-1.fc39
Update description:
Update to 1.23.0
micropython-1.23.0-1.fc40
FEDORA-2024-f9ca680ecd
Packages in this update:
micropython-1.23.0-1.fc40
Update description:
Update to 1.23.0
micropython-1.23.0-1.fc41
FEDORA-2024-cd5c1dfa94
Packages in this update:
micropython-1.23.0-1.fc41
Update description:
Update to 1.23.0
micropython-1.23.0-1.fc42
FEDORA-2024-81b8dc2197
Packages in this update:
micropython-1.23.0-1.fc42
Update description:
Automatic update for micropython-1.23.0-1.fc42.
Changelog
* Thu Oct 17 2024 Charalampos Stratakis <cstratak@redhat.com> – 1.23.0-1
– Update to 1.23.0
– Security fixes for CVE-2024-8946, CVE-2024-8947, CVE-2024-8948
Resolves: rhbz#2312926, rhbz#2312923, rhbz#2312921
USN-7080-1: Unbound vulnerability
Toshifumi Sakaguchi discovered that Unbound incorrectly handled name
compression for large RRsets, which could lead to excessive CPU usage.
An attacker could potentially use this issue to cause a denial of service
by sending specially crafted DNS responses.