FEDORA-2024-0489e7ba1e
Packages in this update:
filezilla-3.67.0-1.fc38
libfilezilla-0.47.0-1.fc38
Update description:
Fix for CVE-2024-31497
filezilla-3.67.0-1.fc38
libfilezilla-0.47.0-1.fc38
Fix for CVE-2024-31497
filezilla-3.67.0-1.fc39
libfilezilla-0.47.0-1.fc39
Fix for CVE-2024-31497
filezilla-3.67.0-1.fc40
libfilezilla-0.47.0-1.fc40
Fix for CVE-2024-31497
Multiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution.
Mozilla Firefox is a web browser used to access the Internet.
Mozilla Firefox ESR is a version of the web browser intended to be deployed in large organizations.
Mozilla Thunderbird is an email client.
Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
python-pydantic-1.10.14-2.fc38
Security fix for CVE-2024-3772 (regular expression denial of service via crafted email string). Update to latest 1.10.x release: https://github.com/pydantic/pydantic/blob/v1.10.14/HISTORY.md
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2022-37434)
It was discovered that Node.js incorrectly handled the use of invalid public
keys while creating an x509 certificate. If a user or an automated system were
tricked into opening a specially crafted input file, a remote attacker could
possibly use this issue to cause a denial of service. This issue only affected
Ubuntu 23.10. (CVE-2023-30588)
It was discovered that Node.js incorrectly handled the use of CRLF sequences to
delimit HTTP requests. If a user or an automated system were tricked into
opening a specially crafted input file, a remote attacker could possibly use
this issue to obtain unauthorised access. This issue only affected
Ubuntu 23.10. (CVE-2023-30589)
It was discovered that Node.js incorrectly described the generateKeys()
function in the documentation. This inconsistency could possibly lead to
security issues in applications that use these APIs.
(CVE-2023-30590)
firefox-125.0-1.fc39
New upstream release (125.0)
firefox-125.0-1.fc38
New upstream release (125.0)
firefox-125.0-1.fc40
New upstream release (125.0)