It was discovered that Engrampa, an archive manager for the MATE
desktop environment was susceptible to path traversal when handling
CPIO archives.
Category Archives: Advisories
USN-6626-3: Linux kernel (Azure) vulnerabilities
Quentin Minster discovered that a race condition existed in the KSMBD
implementation in the Linux kernel when handling sessions operations. A
remote attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-32250, CVE-2023-32252,
CVE-2023-32257)
Marek Marczykowski-Górecki discovered that the Xen event channel
infrastructure implementation in the Linux kernel contained a race
condition. An attacker in a guest VM could possibly use this to cause a
denial of service (paravirtualized device unavailability). (CVE-2023-34324)
Zheng Wang discovered a use-after-free in the Renesas Ethernet AVB driver
in the Linux kernel during device removal. A privileged attacker could use
this to cause a denial of service (system crash). (CVE-2023-35827)
Tom Dohrmann discovered that the Secure Encrypted Virtualization (SEV)
implementation for AMD processors in the Linux kernel contained a race
condition when accessing MMIO registers. A local attacker in a SEV guest VM
could possibly use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-46813)
It was discovered that the Microchip USB Ethernet driver in the Linux
kernel contained a race condition during device removal, leading to a use-
after-free vulnerability. A physically proximate attacker could use this to
cause a denial of service (system crash). (CVE-2023-6039)
It was discovered that the TLS subsystem in the Linux kernel did not
properly perform cryptographic operations in some situations, leading to a
null pointer dereference vulnerability. A local attacker could use this to
cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2023-6176)
Xingyuan Mo discovered that the netfilter subsystem in the Linux kernel did
not properly handle dynset expressions passed from userspace, leading to a
null pointer dereference vulnerability. A local attacker could use this to
cause a denial of service (system crash). (CVE-2023-6622)
It was discovered that the TIPC protocol implementation in the Linux kernel
did not properly handle locking during tipc_crypto_key_revoke() operations.
A local attacker could use this to cause a denial of service (kernel
deadlock). (CVE-2024-0641)
mingw-qt5-qt3d-5.15.12-1.fc41 mingw-qt5-qtactiveqt-5.15.12-1.fc41 mingw-qt5-qtbase-5.15.12-2.fc41 mingw-qt5-qtcharts-5.15.12-1.fc41 mingw-qt5-qtdeclarative-5.15.12-1.fc41 mingw-qt5-qtgraphicaleffects-5.15.12-1.fc41 mingw-qt5-qtimageformats-5.15.12-1.fc41 mingw-qt5-qtlocation-5.15.12-1.fc41 mingw-qt5-qtmultimedia-5.15.12-1.fc41 mingw-qt5-qtquickcontrols-5.15.12-1.fc41 mingw-qt5-qtquickcontrols2-5.15.12-1.fc41 mingw-qt5-qtscript-5.15.12-1.fc41 mingw-qt5-qtsensors-5.15.12-1.fc41 mingw-qt5-qtserialport-5.15.12-1.fc41 mingw-qt5-qtsvg-5.15.12-1.fc41 mingw-qt5-qttools-5.15.12-1.fc41 mingw-qt5-qttranslations-5.15.12-1.fc41 mingw-qt5-qtwebchannel-5.15.12-1.fc41 mingw-qt5-qtwebsockets-5.15.12-1.fc41 mingw-qt5-qtwinextras-5.15.12-1.fc41 mingw-qt5-qtxmlpatterns-5.15.12-1.fc41
FEDORA-2024-02ccd4daed
Packages in this update:
mingw-qt5-qt3d-5.15.12-1.fc41
mingw-qt5-qtactiveqt-5.15.12-1.fc41
mingw-qt5-qtbase-5.15.12-2.fc41
mingw-qt5-qtcharts-5.15.12-1.fc41
mingw-qt5-qtdeclarative-5.15.12-1.fc41
mingw-qt5-qtgraphicaleffects-5.15.12-1.fc41
mingw-qt5-qtimageformats-5.15.12-1.fc41
mingw-qt5-qtlocation-5.15.12-1.fc41
mingw-qt5-qtmultimedia-5.15.12-1.fc41
mingw-qt5-qtquickcontrols2-5.15.12-1.fc41
mingw-qt5-qtquickcontrols-5.15.12-1.fc41
mingw-qt5-qtscript-5.15.12-1.fc41
mingw-qt5-qtsensors-5.15.12-1.fc41
mingw-qt5-qtserialport-5.15.12-1.fc41
mingw-qt5-qtsvg-5.15.12-1.fc41
mingw-qt5-qttools-5.15.12-1.fc41
mingw-qt5-qttranslations-5.15.12-1.fc41
mingw-qt5-qtwebchannel-5.15.12-1.fc41
mingw-qt5-qtwebsockets-5.15.12-1.fc41
mingw-qt5-qtwinextras-5.15.12-1.fc41
mingw-qt5-qtxmlpatterns-5.15.12-1.fc41
Update description:
Update to qt-5.15.12.
mingw-qt5-qt3d-5.15.12-1.fc40 mingw-qt5-qtactiveqt-5.15.12-1.fc40 mingw-qt5-qtbase-5.15.12-2.fc40 mingw-qt5-qtcharts-5.15.12-1.fc40 mingw-qt5-qtdeclarative-5.15.12-1.fc40 mingw-qt5-qtgraphicaleffects-5.15.12-1.fc40 mingw-qt5-qtimageformats-5.15.12-1.fc40 mingw-qt5-qtlocation-5.15.12-1.fc40 mingw-qt5-qtmultimedia-5.15.12-1.fc40 mingw-qt5-qtquickcontrols-5.15.12-1.fc40 mingw-qt5-qtquickcontrols2-5.15.12-1.fc40 mingw-qt5-qtscript-5.15.12-1.fc40 mingw-qt5-qtsensors-5.15.12-1.fc40 mingw-qt5-qtserialport-5.15.12-1.fc40 mingw-qt5-qtsvg-5.15.12-1.fc40 mingw-qt5-qttools-5.15.12-1.fc40 mingw-qt5-qttranslations-5.15.12-1.fc40 mingw-qt5-qtwebchannel-5.15.12-1.fc40 mingw-qt5-qtwebsockets-5.15.12-1.fc40 mingw-qt5-qtwinextras-5.15.12-1.fc40 mingw-qt5-qtxmlpatterns-5.15.12-1.fc40
FEDORA-2024-58c67dbb21
Packages in this update:
mingw-qt5-qt3d-5.15.12-1.fc40
mingw-qt5-qtactiveqt-5.15.12-1.fc40
mingw-qt5-qtbase-5.15.12-2.fc40
mingw-qt5-qtcharts-5.15.12-1.fc40
mingw-qt5-qtdeclarative-5.15.12-1.fc40
mingw-qt5-qtgraphicaleffects-5.15.12-1.fc40
mingw-qt5-qtimageformats-5.15.12-1.fc40
mingw-qt5-qtlocation-5.15.12-1.fc40
mingw-qt5-qtmultimedia-5.15.12-1.fc40
mingw-qt5-qtquickcontrols2-5.15.12-1.fc40
mingw-qt5-qtquickcontrols-5.15.12-1.fc40
mingw-qt5-qtscript-5.15.12-1.fc40
mingw-qt5-qtsensors-5.15.12-1.fc40
mingw-qt5-qtserialport-5.15.12-1.fc40
mingw-qt5-qtsvg-5.15.12-1.fc40
mingw-qt5-qttools-5.15.12-1.fc40
mingw-qt5-qttranslations-5.15.12-1.fc40
mingw-qt5-qtwebchannel-5.15.12-1.fc40
mingw-qt5-qtwebsockets-5.15.12-1.fc40
mingw-qt5-qtwinextras-5.15.12-1.fc40
mingw-qt5-qtxmlpatterns-5.15.12-1.fc40
Update description:
Update to qt-5.15.12.
mingw-qt5-qt3d-5.15.12-1.fc39 mingw-qt5-qtactiveqt-5.15.12-1.fc39 mingw-qt5-qtbase-5.15.12-2.fc39 mingw-qt5-qtcharts-5.15.12-1.fc39 mingw-qt5-qtdeclarative-5.15.12-1.fc39 mingw-qt5-qtgraphicaleffects-5.15.12-1.fc39 mingw-qt5-qtimageformats-5.15.12-1.fc39 mingw-qt5-qtlocation-5.15.12-1.fc39 mingw-qt5-qtmultimedia-5.15.12-1.fc39 mingw-qt5-qtquickcontrols-5.15.12-1.fc39 mingw-qt5-qtquickcontrols2-5.15.12-1.fc39 mingw-qt5-qtscript-5.15.12-1.fc39 mingw-qt5-qtsensors-5.15.12-1.fc39 mingw-qt5-qtserialport-5.15.12-1.fc39 mingw-qt5-qtsvg-5.15.12-1.fc39 mingw-qt5-qttools-5.15.12-1.fc39 mingw-qt5-qttranslations-5.15.12-1.fc39 mingw-qt5-qtwebchannel-5.15.12-1.fc39 mingw-qt5-qtwebsockets-5.15.12-1.fc39 mingw-qt5-qtwinextras-5.15.12-1.fc39 mingw-qt5-qtxmlpatterns-5.15.12-1.fc39
FEDORA-2024-a8cdce27ac
Packages in this update:
mingw-qt5-qt3d-5.15.12-1.fc39
mingw-qt5-qtactiveqt-5.15.12-1.fc39
mingw-qt5-qtbase-5.15.12-2.fc39
mingw-qt5-qtcharts-5.15.12-1.fc39
mingw-qt5-qtdeclarative-5.15.12-1.fc39
mingw-qt5-qtgraphicaleffects-5.15.12-1.fc39
mingw-qt5-qtimageformats-5.15.12-1.fc39
mingw-qt5-qtlocation-5.15.12-1.fc39
mingw-qt5-qtmultimedia-5.15.12-1.fc39
mingw-qt5-qtquickcontrols2-5.15.12-1.fc39
mingw-qt5-qtquickcontrols-5.15.12-1.fc39
mingw-qt5-qtscript-5.15.12-1.fc39
mingw-qt5-qtsensors-5.15.12-1.fc39
mingw-qt5-qtserialport-5.15.12-1.fc39
mingw-qt5-qtsvg-5.15.12-1.fc39
mingw-qt5-qttools-5.15.12-1.fc39
mingw-qt5-qttranslations-5.15.12-1.fc39
mingw-qt5-qtwebchannel-5.15.12-1.fc39
mingw-qt5-qtwebsockets-5.15.12-1.fc39
mingw-qt5-qtwinextras-5.15.12-1.fc39
mingw-qt5-qtxmlpatterns-5.15.12-1.fc39
Update description:
Update to qt-5.15.12.
qt5-qtbase-5.15.12-5.fc39
FEDORA-2024-d9be3edddb
Packages in this update:
qt5-qtbase-5.15.12-5.fc39
Update description:
Fix CVE-2024-25580: potential buffer overflow when reading KTX images.
FEDORA-2024-7424b57c59
FEDORA-2024-7424b57c59
Packages in this update:
Update description:
Fix CVE-2024-25580: potential buffer overflow when reading KTX images.
USN-6640-1: shadow vulnerability
It was discovered that shadow was not properly sanitizing memory when
running the password utility. An attacker could possibly use this issue
to retrieve a password from memory, exposing sensitive information.
44CON 2024 September 18th – 20th CFP
Posted by Florent Daigniere via Fulldisclosure on Feb 15
44CON is the UK’s largest combined annual Security Conference and
Training event. Taking place 18,19,20 of September at the
Novotel London West near Hammersmith, London. We will have a fully
dedicated conference facility, including catering, private bar, amazing
coffee and a daily Gin O’Clock break.
_ _
/_//_// / // / | 18th – 20th September 2024
/ //_,/_// / | Novotel London West, London
-=-…
qemu-8.1.3-3.fc39
FEDORA-2024-c601293124
Packages in this update:
qemu-8.1.3-3.fc39
Update description:
Stack buffer overflow in virtio_net_flush_tx (CVE-2023-6693) (rhbz#2256436)