Category Archives: Advisories

golang-github-cloudflare-circl-1.3.7-1.fc41

Read Time:31 Second

FEDORA-2024-97fd10b49f

Packages in this update:

golang-github-cloudflare-circl-1.3.7-1.fc41

Update description:

Automatic update for golang-github-cloudflare-circl-1.3.7-1.fc41.

Changelog

* Thu Mar 7 2024 Mikel Olasagasti Uranga <mikel@olasagasti.info> – 1.3.7-1
– Update to 1.3.7 – Closes rhbz#2165786 rhbz#2203758
* Sun Feb 11 2024 Maxwell G <maxwell@gtmx.me> – 1.3.1-6
– Rebuild for golang 1.22.0
* Wed Jan 24 2024 Fedora Release Engineering <releng@fedoraproject.org> – 1.3.1-5
– Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

Read More

USN-6682-1: Puma vulnerabilities

Read Time:55 Second

ZeddYu Lu discovered that Puma incorrectly handled parsing certain headers.
A remote attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue only affected Ubuntu 20.04 LTS.
(CVE-2020-11076)

It was discovered that Puma incorrectly handled parsing certain headers.
A remote attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue only affected Ubuntu 20.04 LTS.
(CVE-2020-11077)

Jean Boussier discovered that Puma might not always release resources
properly after handling HTTP requests. A remote attacker could possibly
use this issue to read sensitive information. (CVE-2022-23634)

It was discovered that Puma incorrectly handled certain malformed headers.
A remote attacker could use this issue to perform an HTTP Request Smuggling
attack. (CVE-2022-24790)

Ben Kallus discovered that Puma incorrectly handled parsing certain headers.
A remote attacker could use this issue to perform an HTTP Request Smuggling
attack. (CVE-2023-40175)

Bartek Nowotarski discovered that Puma incorrectly handled parsing certain
encoded content. A remote attacker could possibly use this to cause a
denial of service. (CVE-2024-21647)

Read More

openvswitch-3.3.0-1.fc40

Read Time:15 Second

FEDORA-2024-1f26ce7731

Packages in this update:

openvswitch-3.3.0-1.fc40

Update description:

Update to 3.3.0
Remove network-scripts subpackage starting from Fedora 40
Backport a simple fix to avoid “SSL db: implementation” test to fail
It also indirectly fix CVE-2023-3966 and CVE-2023-5366

Read More