This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-26158.
Category Archives: Advisories
ZDI-24-362: Microsoft Azure Private 5G Core InitialUEMessage Improper Input Validation Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Microsoft Azure Private 5G Core. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.9. The following CVEs are assigned: CVE-2024-20685.
ZDI-24-361: Microsoft Windows Internet Shortcut SmartScreen Bypass Vulnerability
This vulnerability allows remote attackers to bypass the SmartScreen security feature to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-29988.
yyjson-0.9.0-1.fc38
FEDORA-2024-4691d60717
Packages in this update:
yyjson-0.9.0-1.fc38
Update description:
Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791; Security fix for CVE-2024-25713
yyjson-0.9.0-1.fc39
FEDORA-2024-ef2e551fab
Packages in this update:
yyjson-0.9.0-1.fc39
Update description:
Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791; Security fix for CVE-2024-25713
yyjson-0.9.0-1.fc40
FEDORA-2024-8c48a81cb9
Packages in this update:
yyjson-0.9.0-1.fc40
Update description:
Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791; Security fix for CVE-2024-25713
yyjson-0.9.0-1.fc41
FEDORA-2024-2a0f7e9e97
Packages in this update:
yyjson-0.9.0-1.fc41
Update description:
Automatic update for yyjson-0.9.0-1.fc41.
Changelog
* Tue Apr 9 2024 topazus <topazus@outlook.com> – 0.9.0-1
– Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791
python-django-4.2.11-1.fc40
FEDORA-2024-5c7fb64c74
Packages in this update:
python-django-4.2.11-1.fc40
Update description:
Security fix for CVE-2024-24680 and CVE-2024-27351
python-django-4.2.11-1.fc39
FEDORA-2024-2ec03ca8cb
Packages in this update:
python-django-4.2.11-1.fc39
Update description:
Security fix for CVE-2024-24680 and CVE-2024-27351
python-django-4.2.11-1.fc41
FEDORA-2024-c5c5671edb
Packages in this update:
python-django-4.2.11-1.fc41
Update description:
Automatic update for python-django-4.2.11-1.fc41.
Changelog
* Mon Apr 8 2024 Michel Lind <salimma@fedoraproject.org> – 4.2.11-1
– Update to 4.2.11
– Resolves CVE-2024-24680 (rhbz#2263505)
– Resolves CVE-2024-27351 (rhbz#2267654)