FEDORA-2024-40d4ab1c94
Packages in this update:
golang-github-chainguard-dev-git-urls-1.0.2-1.fc41
golang-github-task-3.40.1-1.fc41
Update description:
Bugfix to mitigate CVE-2023-46402
golang-github-chainguard-dev-git-urls-1.0.2-1.fc41
golang-github-task-3.40.1-1.fc41
Bugfix to mitigate CVE-2023-46402
Two security vulnerabilities were discovered in Smarty, a template
engine for PHP, which could result in PHP code injection or cross-site
scripting.
Brian Ristuccia discovered that in ProFTPD, a powerful modular
FTP/SFTP/FTPS server, supplemental group inheritance grants unintended
access to GID 0 because of the lack of supplemental groups from mod_sql.
It was discovered that oFono incorrectly handled decoding SMS messages
leading to a stack overflow. A remote attacker could potentially use
this issue to cause a denial of service.
(CVE-2023-2794, CVE-2023-4233, CVE-2023-4234)
python3.14-3.14.0~a2-2.fc41
Security fix for CVE-2024-12254
python3.14-3.14.0~a2-2.fc40
Security fix for CVE-2024-12254
python3.14-3.14.0~a2-2.fc42
Automatic update for python3.14-3.14.0~a2-2.fc42.
* Sun Dec 8 2024 Charalampos Stratakis <cstratak@redhat.com> – 3.14.0~a2-2
– Security fix for CVE-2024-12254
– Fixes: rhbz#2330928
icecat-115.18.0-2.rh2.fc40
Fix CVE-2024-11693 CVE-2024-11697 CVE-2024-11692
icecat-115.18.0-2.rh2.fc41
Fix CVE-2024-11693 CVE-2024-11697 CVE-2024-11692
python-nbdime-4.0.2-2.fc40
This update fixes CVE-2024-55565 by updating the vendored JavaScript to include a version of nanoid without the security issue.