This vulnerability allows remote attackers to bypass authentication on affected installations of Progress Software WhatsUp Gold. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-7763.
Category Archives: Advisories
USN-7108-1: AsyncSSH vulnerabilities
Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk discovered that AsyncSSH
did not properly handle the extension info message. An attacker able to
intercept communications could possibly use this issue to downgrade
the algorithm used for client authentication. (CVE-2023-46445)
Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk discovered that AsyncSSH
did not properly handle the user authentication request message. An
attacker could possibly use this issue to control the remote end of an SSH
client session via packet injection/removal and shell emulation.
(CVE-2023-46446)
cobbler3.2-3.2.3-1.el8
FEDORA-EPEL-2024-375a09fd04
Packages in this update:
cobbler3.2-3.2.3-1.el8
Update description:
Update to 3.2.3 – CVE-2024-47533
cobbler3.2-3.2.3-1.el9
FEDORA-EPEL-2024-1fa5fbde17
Packages in this update:
cobbler3.2-3.2.3-1.el9
Update description:
Update to 3.2.3 – CVE-2024-47533
cobbler-3.3.7-1.el9
FEDORA-EPEL-2024-97fdc539e2
Packages in this update:
cobbler-3.3.7-1.el9
Update description:
Update to 3.3.7 – CVE-2024-47533
cobbler-3.3.7-1.fc40
FEDORA-2024-76d8603c78
Packages in this update:
cobbler-3.3.7-1.fc40
Update description:
Update to 3.3.7 – CVE-2024-47533
cobbler-3.3.7-1.fc39
FEDORA-2024-a6f0ade1d3
Packages in this update:
cobbler-3.3.7-1.fc39
Update description:
Update to 3.3.7 – CVE-2024-47533
cobbler-3.3.7-1.fc41
FEDORA-2024-4f04edd1e7
Packages in this update:
cobbler-3.3.7-1.fc41
Update description:
Update to 3.3.7 – CVE-2024-47533