It was discovered that ImageMagick incorrectly handled certain malformed
image files. If a user or automated system using ImageMagick were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service or potentially leak sensitive information.
These vulnerabilities included heap and stack-based buffer overflows,
memory leaks, and improper handling of uninitialized values.
Category Archives: Advisories
USN-7054-1: unzip vulnerability
It was discovered that unzip did not properly handle unicode strings under
certain circumstances. If a user were tricked into opening a specially
crafted zip file, an attacker could possibly use this issue to cause unzip
to crash, resulting in a denial of service, or possibly execute arbitrary
code.
mosquitto-2.0.19-1.fc39
FEDORA-2024-f71b7dad10
Packages in this update:
mosquitto-2.0.19-1.fc39
Update description:
Update to 2.0.19
mosquitto-2.0.19-1.fc40
FEDORA-2024-e36b567b66
Packages in this update:
mosquitto-2.0.19-1.fc40
Update description:
Update to 2.0.19
mosquitto-2.0.19-1.fc41
FEDORA-2024-0078a55acf
Packages in this update:
mosquitto-2.0.19-1.fc41
Update description:
Update to 2.0.19
Fix FTBFS (closes rhbz#2300978)
USN-7021-4: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
– GPU drivers;
– BTRFS file system;
– F2FS file system;
– GFS2 file system;
– BPF subsystem;
– Netfilter;
– RxRPC session sockets;
– Integrity Measurement Architecture(IMA) framework;
(CVE-2024-41009, CVE-2024-26677, CVE-2024-42160, CVE-2024-39494,
CVE-2024-39496, CVE-2024-38570, CVE-2024-27012, CVE-2024-42228)
redis-7.2.6-1.fc39
FEDORA-2024-68f9c0741f
Packages in this update:
redis-7.2.6-1.fc39
Update description:
Redis Community Edition 7.2.6 Released Wed 02 Oct 2024 20:17:04 IDT
Upgrade urgency SECURITY: See security fixes below.
Security fixes
CVE-2024-31449 Lua library commands may lead to stack overflow and potential RCE.
CVE-2024-31227 Potential Denial-of-service due to malformed ACL selectors.
CVE-2024-31228 Potential Denial-of-service due to unbounded pattern matching.
redis-7.2.6-1.fc40
FEDORA-2024-5d4eb04e76
Packages in this update:
redis-7.2.6-1.fc40
Update description:
Redis Community Edition 7.2.6 Released Wed 02 Oct 2024 20:17:04 IDT
Upgrade urgency SECURITY: See security fixes below.
Security fixes
CVE-2024-31449 Lua library commands may lead to stack overflow and potential RCE.
CVE-2024-31227 Potential Denial-of-service due to malformed ACL selectors.
CVE-2024-31228 Potential Denial-of-service due to unbounded pattern matching.
USN-7052-1: GNOME Shell vulnerabilities
It was discovered that GNOME Shell mishandled extensions that fail to
reload, possibly leading to extensions staying enabled on the lock screen.
An attacker could possibly use this issue to launch applications, view
sensitive information, or execute arbitrary commands. (CVE-2017-8288)
It was discovered that the GNOME Shell incorrectly handled certain
keyboard inputs. An attacker could possibly use this issue to invoke
keyboard shortcuts, and potentially other actions while the workstation
was locked. (CVE-2019-3820)
DSA-5781-1 chromium – security update
Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.