FEDORA-EPEL-2024-d9102d9191
Packages in this update:
clojure-1.8.0-3.el7
Update description:
Security fix for CVE-2024-22871
clojure-1.8.0-3.el7
Security fix for CVE-2024-22871
Posted by Security Explorations on Apr 02
Hello All,
It’s been 1.5 years since Microsoft got a notification about PlayReady issues
affecting Canal+ VOD service in Poland [1].
Per information received from Microsoft back then:
1) “to maintain the integrity of the PlayReady ecosystem, the company takes
reports such as (ours) very seriously” (Oct 7, 2022),
2) the STB manufacturer committed to mitigate the incident (Nov 18, 2022).
However, as of late Mar 2024, no change…
Claudio Bozzato discovered multiple security issues in gtkwave, a file
waveform viewer for VCD (Value Change Dump) files, which may result in the
execution of arbitrary code if malformed files are opened.
Security issues were discovered in Chromium, which could result
in the execution of arbitrary code, denial of service or information
disclosure.
libdwarf-0.9.2-1.fc40
Update to latest upstream release.
Kentaro Kawane discovered that Cacti incorrectly handled user provided
input sent through request parameters to the graph_view.php script.
A remote authenticated attacker could use this issue to perform
SQL injection attacks.
dotnet7.0-7.0.117-1.fc38
This is the March 2024 update for .NET 7.
Release Notes: https://github.com/dotnet/core/blob/main/release-notes/7.0/7.0.17/7.0.17.md
dotnet7.0-7.0.117-1.fc39
This is the March 2024 update for .NET 7.
Release Notes: https://github.com/dotnet/core/blob/main/release-notes/7.0/7.0.17/7.0.17.md
python-pillow-10.3.0-1.fc39
Update to 10.3.0.
cockpit-311.2-1.fc38
sosreport: Fix command injection with crafted report names [CVE-2024-2947]