ZDI-24-1643: (Pwn2Own) iXsystems TrueNAS tarfile.extractall Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of iXsystems TrueNAS devices. Authentication is not required to exploit this vulnerability. The...
DSA-5825-1 ceph – security update
Sage McTaggart discovered an authentication bypass in radosgw, the RADOS REST gateway of Ceph, a distributed storage and file system. https://security-tracker.debian.org/tracker/DSA-5825-1 Read More
DSA-5824-1 chromium – security update
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-5824-1 Read More
python-virtualenv-20.21.1-14.el9
FEDORA-EPEL-2024-08d8c17c5d Packages in this update: python-virtualenv-20.21.1-14.el9 Update description: Security fix for CVE-2024-53899 Fix for virtualenv --seeder pip --python=python3.12 Read More
USN-7117-3: needrestart regression
USN-7117-1 fixed vulnerabilities in needrestart. The update introduced a regression in needrestart. This update fixes the problem for LXC containers. We apologize for the inconvenience....
python3.13-3.13.1-1.fc40
FEDORA-2024-be6ea1ce44 Packages in this update: python3.13-3.13.1-1.fc40 Update description: This is the first maintenance release of Python 3.13 Python 3.13 is the newest major release of...
python3-docs-3.13.1-1.fc41 python3.13-3.13.1-1.fc41
FEDORA-2024-3c18fe0d93 Packages in this update: python3.13-3.13.1-1.fc41 python3-docs-3.13.1-1.fc41 Update description: This is the first maintenance release of Python 3.13 Python 3.13 is the newest major release...
USN-7139-1: Apache Shiro vulnerability
It was discovered that Apache Shiro used a static cipher within the "Remember Me" feature inside authentication by default. An attacker could possibly use this...
USN-7138-1: Ghostscript vulnerabilities
It was discovered that Ghostscript incorrectly handled parsing certain PS files. An attacker could use this issue to cause Ghostscript to crash, resulting in a...
python3.10-3.10.16-1.fc41
FEDORA-2024-cae0bcc133 Packages in this update: python3.10-3.10.16-1.fc41 Update description: Python 3.10.16 security release. Security content in this release gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to consistently use the...