A buffer overflow was discovered in libndp, a library implementing the
IPv6 Neighbor Discovery Protocol (NDP), which could result in denial of
service or potentially the execution of arbitrary code if malformed
IPv6 router advertisements are processed.
Category Archives: Advisories
python-PyMySQL-1.1.1-1.fc40
FEDORA-2024-b26f07d27b
Packages in this update:
python-PyMySQL-1.1.1-1.fc40
Update description:
Update to 1.1.1 to fix CVE CVE-2024-36039
python-PyMySQL-1.1.1-1.fc39
FEDORA-2024-e7141ab284
Packages in this update:
python-PyMySQL-1.1.1-1.fc39
Update description:
Update to 1.1.1 to fix CVE CVE-2024-36039
DSA-5711-1 thunderbird – security update
Multiple security issues were discovered in Thunderbird, which could
result inthe execution of arbitrary code.
DSA-5712-1 ffmpeg – security update
Several vulnerabilities have been discovered in the FFmpeg multimedia
framework, which could result in denial of service or potentially the
execution of arbitrary code if malformed files/streams are processed.
thunderbird-115.12.0-2.fc39
FEDORA-2024-25da59ef4e
Packages in this update:
thunderbird-115.12.0-2.fc39
Update description:
Update to 115.12.0
https://www.mozilla.org/en-US/security/advisories/mfsa2024-28/
https://www.thunderbird.net/en-US/thunderbird/115.12.0/releasenotes/
thunderbird-115.12.0-2.fc40
FEDORA-2024-748bedc96c
Packages in this update:
thunderbird-115.12.0-2.fc40
Update description:
Update to 115.12.0
https://www.mozilla.org/en-US/security/advisories/mfsa2024-28/
https://www.thunderbird.net/en-US/thunderbird/115.12.0/releasenotes/
vte-0.28.2-42.el7
FEDORA-EPEL-2024-29630d7094
Packages in this update:
vte-0.28.2-42.el7
Update description:
Update patches.
ghostscript-10.02.1-3.fc39
FEDORA-2024-029fa02f7a
Packages in this update:
ghostscript-10.02.1-3.fc39
Update description:
Security fix for CVE-2024-33871
ZDI-24-778: Linux Kernel USB Core Out-Of-Bounds Read Local Privilege Escalation Vulnerability
This vulnerability allows physically present attackers to escalate privileges on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1.