Category Archives: Advisories

chromium-131.0.6778.85-1.el8

Read Time:30 Second

FEDORA-EPEL-2024-09b0f49aa6

Packages in this update:

chromium-131.0.6778.85-1.el8

Update description:

Update to 131.0.6778.85

High CVE-2024-11395: Type Confusion in V8
High CVE-2024-11110: Inappropriate implementation in Blink
Medium CVE-2024-11111: Inappropriate implementation in Autofill
Medium CVE-2024-11112: Use after free in Media
Medium CVE-2024-11113: Use after free in Accessibility
Medium CVE-2024-11114: Inappropriate implementation in Views
Medium CVE-2024-11115: Insufficient policy enforcement in Navigation
Medium CVE-2024-11116: Inappropriate implementation in Paint
Low CVE-2024-11117: Inappropriate implementation in FileSystem

Read More

chromium-131.0.6778.85-2.fc40

Read Time:29 Second

FEDORA-2024-292aa2c246

Packages in this update:

chromium-131.0.6778.85-2.fc40

Update description:

Update to 131.0.6778.85

* High CVE-2024-11395: Type Confusion in V8
* High CVE-2024-11110: Inappropriate implementation in Blink
* Medium CVE-2024-11111: Inappropriate implementation in Autofill
* Medium CVE-2024-11112: Use after free in Media
* Medium CVE-2024-11113: Use after free in Accessibility
* Medium CVE-2024-11114: Inappropriate implementation in Views
* Medium CVE-2024-11115: Insufficient policy enforcement in Navigation
* Medium CVE-2024-11116: Inappropriate implementation in Paint
* Low CVE-2024-11117: Inappropriate implementation in FileSystem

Read More

chromium-131.0.6778.85-1.el10_0

Read Time:30 Second

FEDORA-EPEL-2024-63b3a88151

Packages in this update:

chromium-131.0.6778.85-1.el10_0

Update description:

Update to 131.0.6778.85

* High CVE-2024-11395: Type Confusion in V8
* High CVE-2024-11110: Inappropriate implementation in Blink
* Medium CVE-2024-11111: Inappropriate implementation in Autofill
* Medium CVE-2024-11112: Use after free in Media
* Medium CVE-2024-11113: Use after free in Accessibility
* Medium CVE-2024-11114: Inappropriate implementation in Views
* Medium CVE-2024-11115: Insufficient policy enforcement in Navigation
* Medium CVE-2024-11116: Inappropriate implementation in Paint
* Low CVE-2024-11117: Inappropriate implementation in FileSystem

Read More

chromium-131.0.6778.85-1.el9

Read Time:30 Second

FEDORA-EPEL-2024-7a7d342b23

Packages in this update:

chromium-131.0.6778.85-1.el9

Update description:

Update to 131.0.6778.85

* High CVE-2024-11395: Type Confusion in V8
* High CVE-2024-11110: Inappropriate implementation in Blink
* Medium CVE-2024-11111: Inappropriate implementation in Autofill
* Medium CVE-2024-11112: Use after free in Media
* Medium CVE-2024-11113: Use after free in Accessibility
* Medium CVE-2024-11114: Inappropriate implementation in Views
* Medium CVE-2024-11115: Insufficient policy enforcement in Navigation
* Medium CVE-2024-11116: Inappropriate implementation in Paint
* Low CVE-2024-11117: Inappropriate implementation in FileSystem

Read More

chromium-131.0.6778.85-2.fc41

Read Time:29 Second

FEDORA-2024-582d2a7648

Packages in this update:

chromium-131.0.6778.85-2.fc41

Update description:

Update to 131.0.6778.85

* High CVE-2024-11395: Type Confusion in V8
* High CVE-2024-11110: Inappropriate implementation in Blink
* Medium CVE-2024-11111: Inappropriate implementation in Autofill
* Medium CVE-2024-11112: Use after free in Media
* Medium CVE-2024-11113: Use after free in Accessibility
* Medium CVE-2024-11114: Inappropriate implementation in Views
* Medium CVE-2024-11115: Insufficient policy enforcement in Navigation
* Medium CVE-2024-11116: Inappropriate implementation in Paint
* Low CVE-2024-11117: Inappropriate implementation in FileSystem

Read More

chromium-131.0.6778.85-1.fc39

Read Time:29 Second

FEDORA-2024-ecfbcfce86

Packages in this update:

chromium-131.0.6778.85-1.fc39

Update description:

Update to 131.0.6778.85

* High CVE-2024-11395: Type Confusion in V8
* High CVE-2024-11110: Inappropriate implementation in Blink
* Medium CVE-2024-11111: Inappropriate implementation in Autofill
* Medium CVE-2024-11112: Use after free in Media
* Medium CVE-2024-11113: Use after free in Accessibility
* Medium CVE-2024-11114: Inappropriate implementation in Views
* Medium CVE-2024-11115: Insufficient policy enforcement in Navigation
* Medium CVE-2024-11116: Inappropriate implementation in Paint
* Low CVE-2024-11117: Inappropriate implementation in FileSystem

Read More

USN-7015-6: Python regressions

Read Time:1 Minute, 1 Second

USN-7015-5 fixed vulnerabilities in python2.7. The update introduced
several minor regressions. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)

It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)

It was discovered that the Python email module incorrectly quoted newlines
for email headers. A remote attacker could possibly use this issue to
perform header injection. (CVE-2024-6923)

It was discovered that the Python http.cookies module incorrectly handled
parsing cookies that contained backslashes for quoted characters. A remote
attacker could possibly use this issue to cause Python to consume
resources, leading to a denial of service. (CVE-2024-7592)

It was discovered that the Python zipfile module incorrectly handled
certain malformed zip files. A remote attacker could possibly use this
issue to cause Python to stop responding, resulting in a denial of
service. (CVE-2024-8088)

Read More