Multiple vulnerabilities have been discovered in Google Chrome, which could allow for remote code execution. Successful exploitation of these vulnerabilities could allow for remote code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
Category Archives: Advisories
grub2-2.06-118.fc38
FEDORA-2024-01f402fae5
Packages in this update:
grub2-2.06-118.fc38
Update description:
Security fix for CVE-2023-4692
Security fix for CVE-2023-4693
Fri Mar 08 2024 Nicolas Frayer nfrayer@redhat.com – 2.06-118
fs/xfs: Handle non-continuous data blocks in directory extents
Related: #2254370
Fri Mar 08 2024 Nicolas Frayer nfrayer@redhat.com – 2.06-117
GRUB2 NTFS driver vulnerabilities
(CVE-2023-4692)
(CVE-2023-4693)
Resolves: #2236613
Resolves: #2241978
Resolves: #2241976
Resolves: #2238343
grub2-2.06-120.fc39
FEDORA-2024-d09797f550
Packages in this update:
grub2-2.06-120.fc39
Update description:
Security fix for CVE-2023-4692
Security fix for CVE-2023-4693
Fri Apr 12 2024 Nicolas Frayer nfrayer@redhat.com – 2.06-120
fs/xfs: Handle non-continuous data blocks in directory extents
Related: #2254370
Fri Mar 08 2024 Nicolas Frayer nfrayer@redhat.com – 2.06-119
GRUB2 NTFS driver vulnerabilities
(CVE-2023-4692)
(CVE-2023-4693)
Resolves: #2236613
Resolves: #2241978
Resolves: #2241976
Resolves: #2238343
grub2-2.06-121.fc40
FEDORA-2024-2b545d3085
Packages in this update:
grub2-2.06-121.fc40
Update description:
Security fix for CVE-2023-4692
Security fix for CVE-2023-4693
Fri Apr 12 2024 Nicolas Frayer nfrayer@redhat.com – 2.06-121
fs/xfs: Handle non-continuous data blocks in directory extents
Related: #2254370
Fri Mar 08 2024 Nicolas Frayer nfrayer@redhat.com – 2.06-120
GRUB2 NTFS driver vulnerabilities
(CVE-2023-4692)
(CVE-2023-4693)
Resolves: #2236613
Resolves: #2241978
Resolves: #2241976
Resolves: #2238343
freerdp-3.5.0-1.fc40
FEDORA-2024-050266dc33
Packages in this update:
freerdp-3.5.0-1.fc40
Update description:
Update to 3.5.0 (CVE-2024-32039, CVE-2024-32040, CVE-2024-32041, CVE-2024-32458, CVE-2024-32459, CVE-2024-32460)
squid-6.9-1.fc39
FEDORA-2024-bd8c6c6926
Packages in this update:
squid-6.9-1.fc39
Update description:
New squid 6.9
security update
squid-6.9-1.fc38
FEDORA-2024-a414a81d47
Packages in this update:
squid-6.9-1.fc38
Update description:
New squid 6.9
security update
DSA-5663-1 firefox-esr – security update
Multiple security issues have been found in the Mozilla Firefox web
browser, which could potentially result in the execution of arbitrary
code or clickjacking.
DSA-5665-1 tomcat10 – security update
Several security vulnerabilities have been discovered in the Tomcat
servlet and JSP engine.
CVE-2023-46589
Tomcat 10 did not correctly parse HTTP trailer headers. A trailer header
that exceeded the header size limit could cause Tomcat to treat a single
request as multiple requests leading to the possibility of request
smuggling when behind a reverse proxy.
CVE-2024-24549
Denial of Service due to improper input validation vulnerability for
HTTP/2. When processing an HTTP/2 request, if the request exceeded any of
the configured limits for headers, the associated HTTP/2 stream was not
reset until after all of the headers had been processed.
CVE-2024-23672
Denial of Service via incomplete cleanup vulnerability. It was possible
for WebSocket clients to keep WebSocket connections open leading to
increased resource consumption.
DSA-5664-1 jetty9 – security update
Jetty 9 is a Java based web server and servlet engine. It was discovered that
remote attackers may leave many HTTP/2 connections in ESTABLISHED state (not
closed), TCP congested and idle. Eventually the server will stop accepting new
connections from valid clients which can cause a denial of service.