FEDORA-2024-bbfef02415
Packages in this update:
freeipa-4.10.3-2.fc38
Update description:
Security release: CVE-2024-1481
Resolves: rhbz#2265129
freeipa-4.10.3-2.fc38
Security release: CVE-2024-1481
Resolves: rhbz#2265129
freeipa-4.11.1-2.fc39
Security release: CVE-2024-1481
Resolves: rhbz#2265129
It was discovered that PostgreSQL incorrectly handled dropping privileges
when handling REFRESH MATERIALIZED VIEW CONCURRENTLY commands. If a user or
automatic system were tricked into running a specially crafted command, a
remote attacker could possibly use this issue to execute arbitrary SQL
functions.
edk2-20240214-2.fc39
update to edk2-stable202402
It was discovered that GNU binutils was not properly handling the logic
behind certain memory management related operations, which could lead to
an invalid memory access. An attacker could possibly use this issue to
cause a denial of service. (CVE-2022-47695)
It was discovered that GNU binutils was not properly performing bounds
checks when dealing with memory allocation operations, which could lead
to excessive memory consumption. An attacker could possibly use this issue
to cause a denial of service. (CVE-2022-48063)
It was discovered that GNU binutils incorrectly handled memory management
operations in several of its functions, which could lead to excessive
memory consumption due to memory leaks. An attacker could possibly use
these issues to cause a denial of service. (CVE-2022-48065)
chromium-122.0.6261.69-1.el8
Update to 122.0.6261.69
update to 121.0.6167.184
chromium-122.0.6261.69-1.el9
Update to 122.0.6261.69
chromium-122.0.6261.69-1.el7
Update to 122.0.6261.69
This vulnerability allows remote attackers to execute arbitrary code on affected installations of MCR VSTS CLI for Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must receive a malicious image file that is written to the local filesystem. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-42902.