Posted by KoreLogic Disclosures via Fulldisclosure on Mar 05
KL-001-2024-002: Artica Proxy Unauthenticated PHP Deserialization Vulnerability
Title: Artica Proxy Unauthenticated PHP Deserialization Vulnerability
Advisory ID: KL-001-2024-002
Publication Date: 2024.03.05
Publication URL: https://korelogic.com/Resources/Advisories/KL-001-2024-002.txt
1. Vulnerability Details
Affected Vendor: Artica
Affected Product: Artica Proxy
Affected Version: 4.50
Platform: Debian…
Posted by KoreLogic Disclosures via Fulldisclosure on Mar 05
KL-001-2024-001: Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability
Title: Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability
Advisory ID: KL-001-2024-001
Publication Date: 2024.03.05
Publication URL: https://korelogic.com/Resources/Advisories/KL-001-2024-001.txt
1. Vulnerability Details
Affected Vendor: Artica
Affected Product: Artica Proxy
Affected Version: 4.40 and 4.50
…
FEDORA-2024-d8a0e599e2
Packages in this update:
thunderbird-115.8.1-1.fc40
Update description:
Update to 115.8.1
https://www.mozilla.org/en-US/security/advisories/mfsa2024-11/
read that if you have mails with encrypted email subjects
https://www.thunderbird.net/en-US/thunderbird/115.8.1/releasenotes/
FEDORA-2024-3699706b25
Packages in this update:
thunderbird-115.8.1-1.fc39
Update description:
Update to 115.8.1
https://www.mozilla.org/en-US/security/advisories/mfsa2024-11/
read that if you have mails with encrypted email subjects
https://www.thunderbird.net/en-US/thunderbird/115.8.1/releasenotes/
FEDORA-2024-325c1d1fce
Packages in this update:
thunderbird-115.8.1-1.fc38
Update description:
Update to 115.8.1
https://www.mozilla.org/en-US/security/advisories/mfsa2024-11/
read that if you have mails with encrypted email subjects
https://www.thunderbird.net/en-US/thunderbird/115.8.1/releasenotes/
It was discovered that ImageProcessing incorrectly handled series of operations
that are coming from unsanitised inputs. If a user or an automated system were
tricked into opening a specially crafted input file, a remote attacker could
possibly use this issue to execute arbitrary code.
FEDORA-2024-09c7f715c9
Packages in this update:
python-fastapi-0.99.0-7.fc38
python-multipart-0.0.7-1.fc38
Update description:
python-multipart 0.0.7 (2024-02-03)
Refactor header option parser to use the standard library instead of a custom RegEx #75 .
Fixes a denial of service vulnerability, GHSA-qf9m-vfgh-m389 , initially reported in FastAPI but applicable to other libraries and applications.
FEDORA-2024-2e802cdb4b
Packages in this update:
python-fastapi-0.103.0-10.fc39
python-multipart-0.0.7-1.fc39
Update description:
python-multipart 0.0.7 (2024-02-03)
Refactor header option parser to use the standard library instead of a custom RegEx #75 .
Fixes a denial of service vulnerability, GHSA-qf9m-vfgh-m389 , initially reported in FastAPI but applicable to other libraries and applications.
FEDORA-2024-4115ab9959
Packages in this update:
wireshark-4.2.3-1.fc40
Update description:
New version 4.2.3
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Posts navigation
News, Advisories and much more