Category Archives: Advisories

yarnpkg-1.22.22-4.fc41

Read Time:7 Second

FEDORA-2024-b0fc600c3c

Packages in this update:

yarnpkg-1.22.22-4.fc41

Update description:

Update bundled elliptic to fix CVE-2024-48949.

Read More

USN-7020-4: Linux kernel vulnerabilities

Read Time:18 Second

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
– GPU drivers;
– Network drivers;
– SCSI drivers;
– F2FS file system;
– BPF subsystem;
– IPv4 networking;
(CVE-2024-42228, CVE-2024-42154, CVE-2024-42160, CVE-2024-42159,
CVE-2024-41009, CVE-2024-42224)

Read More

ZDI-24-1335: SonicWALL Connect Tunnel Link Following Denial-of-Service Vulnerability

Read Time:18 Second

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of SonicWALL Connect Tunnel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2024-45315.

Read More

ZDI-24-1334: SonicWALL Connect Tunnel Link Following Local Privilege Escalation Vulnerability

Read Time:17 Second

This vulnerability allows local attackers to escalate privileges on affected installations of SonicWALL Connect Tunnel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-45316.

Read More

rust-hyper-rustls-0.27.3-1.fc39 rust-reqwest-0.12.8-1.fc39 rust-rustls-native-certs-0.8.0-1.fc39 rust-rustls-native-certs0.7-0.7.3-1.fc39 rust-tonic-0.12.3-1.fc39 rust-tonic-build-0.12.3-1.fc39 rust-tonic-types-0.12.3-1.fc39 rust-tower-0.5.1-1.fc39 rust-tower-http-0.6.1-1.fc39 rust-tower-http0.5-0.5.2-1.fc39 rust-tower0.4-0.4.13-1.fc39

Read Time:57 Second

FEDORA-2024-ff98facbc6

Packages in this update:

rust-hyper-rustls-0.27.3-1.fc39
rust-reqwest-0.12.8-1.fc39
rust-rustls-native-certs0.7-0.7.3-1.fc39
rust-rustls-native-certs-0.8.0-1.fc39
rust-tonic-0.12.3-1.fc39
rust-tonic-build-0.12.3-1.fc39
rust-tonic-types-0.12.3-1.fc39
rust-tower0.4-0.4.13-1.fc39
rust-tower-0.5.1-1.fc39
rust-tower-http0.5-0.5.2-1.fc39
rust-tower-http-0.6.1-1.fc39

Update description:

Update the hyper-rustls crate to version 0.27.3.
Update the reqwest crate to version 0.12.8.
Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7.
Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.
Update the tower crate to version 0.5.1 and add a compat package for version 0.4.
Update the tower-http crate to version 0.6.1 and add a compat package for version 0.5.

Read More