This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, product implements a registration mechanism that can be used to create a user with a sufficient privilege level. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-22505.
Category Archives: Advisories
ZDI-24-105: Allegra loadFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, product implements a registration mechanism that can be used to create a user with a sufficient privilege level. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-22506.
ZDI-24-104: Allegra saveFile Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, product implements a registration mechanism that can be used to create a user with a sufficient privilege level. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-22548.
GLSA 202402-11: libxml2: Multiple Vulnerabilities
DSA-5619-1 libgit2 – security update
Two vulnerabilities were discovered in libgit2, a low-level Git library,
which may result in denial of service or potentially the execution of
arbitrary code.
clamav-1.0.5-1.el9
FEDORA-EPEL-2024-471565274b
Packages in this update:
clamav-1.0.5-1.el9
Update description:
Update to 1.0.5
clamav-1.0.5-1.fc39
FEDORA-2024-3439911df6
Packages in this update:
clamav-1.0.5-1.fc39
Update description:
Update to 1.0.5
clamav-1.0.5-1.fc38
FEDORA-2024-c42cf0e576
Packages in this update:
clamav-1.0.5-1.fc38
Update description:
Update to 1.0.5
USN-6625-2: Linux kernel (GCP) vulnerabilities
Marek Marczykowski-Górecki discovered that the Xen event channel
infrastructure implementation in the Linux kernel contained a race
condition. An attacker in a guest VM could possibly use this to cause a
denial of service (paravirtualized device unavailability). (CVE-2023-34324)
Zheng Wang discovered a use-after-free in the Renesas Ethernet AVB driver
in the Linux kernel during device removal. A privileged attacker could use
this to cause a denial of service (system crash). (CVE-2023-35827)
It was discovered that a race condition existed in the Linux kernel when
performing operations with kernel objects, leading to an out-of-bounds
write. A local attacker could use this to cause a denial of service (system
crash) or execute arbitrary code. (CVE-2023-45863)
黄思聪 discovered that the NFC Controller Interface (NCI) implementation in
the Linux kernel did not properly handle certain memory allocation failure
conditions, leading to a null pointer dereference vulnerability. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2023-46343)
gitleaks-8.18.2-1.fc40
FEDORA-2024-4901258366
Packages in this update:
gitleaks-8.18.2-1.fc40
Update description:
Automatic update for gitleaks-8.18.2-1.fc40.
Changelog
* Thu Feb 8 2024 Mikel Olasagasti Uranga <mikel@olasagasti.info> – 8.18.2-1
– Update to 8.18.2 – Closes rhbz#2250439 rhbz#2248275