It was discovered that Exim did not enforce STARTTLS sync point on client
side. An attacker could possibly use this issue to perform response
injection during MTA SMTP sending.
Category Archives: Advisories
qt6-qtbase-6.7.2-3.fc40
FEDORA-2024-9bf3ff4133
Packages in this update:
qt6-qtbase-6.7.2-3.fc40
Update description:
Fix CVE-2024-39936.
golang-1.21.12-1.fc39
FEDORA-2024-5b06c85574
Packages in this update:
golang-1.21.12-1.fc39
Update description:
This update fixes CVE-2024-24791
golang-1.22.5-1.fc40
FEDORA-2024-96a7a68962
Packages in this update:
golang-1.22.5-1.fc40
Update description:
This update fixes CVE-2024-24791
erlang-jose-1.11.10-1.fc40
FEDORA-2024-a8d7972ef6
Packages in this update:
erlang-jose-1.11.10-1.fc40
Update description:
Re-reviewed Jose ver. 1.11.10
erlang-jose-1.11.10-1.fc39
FEDORA-2024-9484b6915b
Packages in this update:
erlang-jose-1.11.10-1.fc39
Update description:
Re-reviewed Jose ver. 1.11.10
jpegxl-0.8.3-1.fc40
FEDORA-2024-d1c276c860
Packages in this update:
jpegxl-0.8.3-1.fc40
Update description:
update to 0.8.3
jpegxl-0.8.3-1.fc39
FEDORA-2024-35ce4d5a74
Packages in this update:
jpegxl-0.8.3-1.fc39
Update description:
update to 0.8.3
mingw-python-certifi-2024.7.4-1.fc40
FEDORA-2024-599bb2cb73
Packages in this update:
mingw-python-certifi-2024.7.4-1.fc40
Update description:
Update to 2024.7.4.
caddy-2.8.4-1.fc41
FEDORA-2024-bd8fe42929
Packages in this update:
caddy-2.8.4-1.fc41
Update description:
Automatic update for caddy-2.8.4-1.fc41.
Changelog
* Fri Jul 5 2024 Carl George <carlwgeorge@fedoraproject.org> – 2.8.4-1
– Update to version 2.8.4 rhbz#2278549
– Resolves CVE-2023-49295 rhbz#2257829
– Resolves CVE-2024-27304 rhbz#2268278
– Resolves CVE-2024-27289 rhbz#2268468
– Resolves CVE-2024-28180 rhbz#2268877
– Resolves CVE-2024-22189 rhbz#2273517
– Remove LimitNPROC from systemd unit files