Category Archives: Advisories

nodejs20-20.12.1-3.fc39

Read Time:21 Second

FEDORA-2024-91bb4ed803

Packages in this update:

nodejs20-20.12.1-3.fc39

Update description:

2024-04-03, Version 20.12.1 ‘Iron’ (LTS), @RafaelGSS

This is a security release

Notable Changes

CVE-2024-27983 – Assertion failed in node::http2::Http2Session::~Http2Session() leads to HTTP/2 server crash- (High)
CVE-2024-27982 – HTTP Request Smuggling via Content Length Obfuscation – (Medium)
llhttp version 9.2.1
undici version 5.28.4

Read More

USN-6722-1: Django vulnerability

Read Time:12 Second

Simon Charette discovered that the password reset functionality in
Django used a Unicode case insensitive query to retrieve accounts
associated with an email address. An attacker could possibly use this
to obtain password reset tokens and hijack accounts.

Read More

python-cbor2-5.6.2-1.fc41

Read Time:43 Second

FEDORA-2024-e63fc9eb58

Packages in this update:

python-cbor2-5.6.2-1.fc41

Update description:

Automatic update for python-cbor2-5.6.2-1.fc41.

Changelog

* Mon Apr 8 2024 Fabian Affolter <mail@fabian-affolter.ch> – 5.6.2-1
– Update to latest upstream release (closes rhbz#2261550, closes rhbz#2245361)
– Fixes CVE-2024-26134 (closes rhbz#2265036, closes rhbz#bug 2265035)
* Sat Feb 3 2024 Fabian Affolter <mail@fabian-affolter.ch> – 5.6.1-1
– Update to latest upstream release 5.6.1 (closes rhbz#2245361)
* Fri Jan 26 2024 Fedora Release Engineering <releng@fedoraproject.org> – 5.1.2-14
– Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Mon Jan 22 2024 Fedora Release Engineering <releng@fedoraproject.org> – 5.1.2-13
– Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

Read More