It was discovered that AIOHTTP did not properly restrict file access when
the ‘follow_symlinks’ option was set to True. A remote attacker could
possibly use this issue to access unauthorized files on the system.
Category Archives: Advisories
thunderbird-128.2.0-1.fc41
FEDORA-2024-194cb0840b
Packages in this update:
thunderbird-128.2.0-1.fc41
Update description:
Update to 128.2.0
https://www.thunderbird.net/en-US/thunderbird/128.2.0esr/releasenotes/
thunderbird-128.2.0-1.fc40
FEDORA-2024-a27e8b69a0
Packages in this update:
thunderbird-128.2.0-1.fc40
Update description:
Update to 128.2.0
https://www.thunderbird.net/en-US/thunderbird/128.2.0esr/releasenotes/
thunderbird-115.15.0-1.fc39
FEDORA-2024-e77ad5f585
Packages in this update:
thunderbird-115.15.0-1.fc39
Update description:
Update to 115.15.0
https://www.thunderbird.net/en-US/thunderbird/115.15.0esr/releasenotes/
mingw-expat-2.6.3-1.fc41
FEDORA-2024-c5d55d5845
Packages in this update:
mingw-expat-2.6.3-1.fc41
Update description:
Update to expat-2.6.3.
mingw-expat-2.6.3-1.fc40
FEDORA-2024-c7b547bec5
Packages in this update:
mingw-expat-2.6.3-1.fc40
Update description:
Update to expat-2.6.3.
mingw-expat-2.6.3-1.fc39
FEDORA-2024-e86a48cd72
Packages in this update:
mingw-expat-2.6.3-1.fc39
Update description:
Update to expat-2.6.3.
clamav-1.0.7-1.fc40
FEDORA-2024-e8f7a74693
Packages in this update:
clamav-1.0.7-1.fc40
Update description:
Update to 1.0.7
CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files.
CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser that could cause a denial-of-service (DoS) condition.
clamav-1.0.7-1.el9
FEDORA-EPEL-2024-702a565078
Packages in this update:
clamav-1.0.7-1.el9
Update description:
Update to 1.0.7
CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files.
CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser that could cause a denial-of-service (DoS) condition.
clamav-1.0.7-1.fc41
FEDORA-2024-0d7eb64d90
Packages in this update:
clamav-1.0.7-1.fc41
Update description:
Update to 1.0.7
CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files.
CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser that could cause a denial-of-service (DoS) condition.