FEDORA-2024-3bede83c58
Packages in this update:
znc-1.9.1-4.fc42
znc-clientbuffer-0-0.28.20190129git9766a4a.fc42
znc-push-2.0.0-10.20210311git4243934.fc42
Update description:
Changes from 1.8.2 / New in 1.9.x
Fix CVE-2024-39844
znc-1.9.1-4.fc42
znc-clientbuffer-0-0.28.20190129git9766a4a.fc42
znc-push-2.0.0-10.20210311git4243934.fc42
Fix CVE-2024-39844
vim-9.1.719-1.fc39
Security fix for CVE-2024-45306
patchlevel 703
Security fixes for CVE-2024-43374, CVE-2024-43802
vim-9.1.719-1.fc40
Security fix for CVE-2024-45306
vim-9.1.719-1.fc41
Security fix for CVE-2024-45306
ruby-3.3.5-14.fc41
Upgrade to Ruby 3.3.5.
openjpeg-2.5.2-4.fc41
Backport fix for CVE-2023-39327.
clamav-1.0.7-1.el8
Update to 1.0.7
CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files.
CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser that could cause a denial-of-service (DoS) condition.
Posted by Matthias Deeg via Fulldisclosure on Sep 05
Advisory ID: SYSS-2024-030
Product: C-MOR Video Surveillance
Manufacturer: za-internet GmbH
Affected Version(s): 5.2401, 6.00PL01
Tested Version(s): 5.2401, 6.00PL01
Vulnerability Type: OS Command Injection (CWE-78)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2024-04-05
Solution Date: –
Public Disclosure: 2024-09-04…
Posted by Matthias Deeg via Fulldisclosure on Sep 05
Advisory ID: SYSS-2024-029
Product: C-MOR Video Surveillance
Manufacturer: za-internet GmbH
Affected Version(s): 5.2401
Tested Version(s): 5.2401
Vulnerability Type: Dependency on Vulnerable Third-Party
Component (CWE-1395)
Use of Unmaintained Third Party Components
(CWE-1104)
Risk Level: High
Solution Status: Fixed…
Posted by Matthias Deeg via Fulldisclosure on Sep 05
Advisory ID: SYSS-2024-028
Product: C-MOR Video Surveillance
Manufacturer: za-internet GmbH
Affected Version(s): 5.2401, 6.00PL01
Tested Version(s): 5.2401, 6.00PL01
Vulnerability Type: Cleartext Storage of Sensitive Information
(CWE-312)
Risk Level: Medium
Solution Status: Open
Manufacturer Notification: 2024-04-05
Solution Date: –
Public…