It was discovered that PostgreSQL incorrectly handled dropping privileges
when handling REFRESH MATERIALIZED VIEW CONCURRENTLY commands. If a user or
automatic system were tricked into running a specially crafted command, a
remote attacker could possibly use this issue to execute arbitrary SQL
functions.
Category Archives: Advisories
edk2-20240214-2.fc39
FEDORA-2024-a9dead34c5
Packages in this update:
edk2-20240214-2.fc39
Update description:
update to edk2-stable202402
USN-6655-1: GNU binutils vulnerabilities
It was discovered that GNU binutils was not properly handling the logic
behind certain memory management related operations, which could lead to
an invalid memory access. An attacker could possibly use this issue to
cause a denial of service. (CVE-2022-47695)
It was discovered that GNU binutils was not properly performing bounds
checks when dealing with memory allocation operations, which could lead
to excessive memory consumption. An attacker could possibly use this issue
to cause a denial of service. (CVE-2022-48063)
It was discovered that GNU binutils incorrectly handled memory management
operations in several of its functions, which could lead to excessive
memory consumption due to memory leaks. An attacker could possibly use
these issues to cause a denial of service. (CVE-2022-48065)
chromium-122.0.6261.69-1.el8
FEDORA-EPEL-2024-eadadc9b14
Packages in this update:
chromium-122.0.6261.69-1.el8
Update description:
Update to 122.0.6261.69
update to 121.0.6167.184
chromium-122.0.6261.69-1.el9
FEDORA-EPEL-2024-c6bf47a782
Packages in this update:
chromium-122.0.6261.69-1.el9
Update description:
Update to 122.0.6261.69
chromium-122.0.6261.69-1.el7
FEDORA-EPEL-2024-5ef433f7ed
Packages in this update:
chromium-122.0.6261.69-1.el7
Update description:
Update to 122.0.6261.69
ZDI-24-208: Microsoft Azure MCR VSTS CLI vstscli Uncontrolled Search Path Element Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of MCR VSTS CLI for Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.
ZDI-24-207: Apple macOS VideoToolbox Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must receive a malicious image file that is written to the local filesystem. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-42902.
ZDI-24-206: Apple macOS ImageIO MPO Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. Interaction with the ImageIO library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2023-42888.
USN-6654-1: Roundcube Webmail vulnerability
It was discovered that Roundcube Webmail incorrectly sanitized characters
in the linkrefs text messages. An attacker could possibly use this issue to
execute a cross-site scripting (XSS) attack. (CVE-2023-43770)