Johannes Kuhn (DasBrain) discovered that znc incorrectly handled
user input under certain operations. An attacker could possibly
use this issue to execute arbitrary code on a user’s system if
the user was tricked into joining a malicious server.
Category Archives: Advisories
python-django4.2-4.2.16-1.fc41
FEDORA-2024-b08735561c
Packages in this update:
python-django4.2-4.2.16-1.fc41
Update description:
urlize and urlizetrunc were subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
python-django4.2-4.2.16-1.fc40
FEDORA-2024-865828665c
Packages in this update:
python-django4.2-4.2.16-1.fc40
Update description:
urlize and urlizetrunc were subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
python-django4.2-4.2.16-1.el9
FEDORA-EPEL-2024-92f7377188
Packages in this update:
python-django4.2-4.2.16-1.el9
Update description:
urlize and urlizetrunc were subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
python-django4.2-4.2.16-1.fc39
FEDORA-2024-28892f7c8f
Packages in this update:
python-django4.2-4.2.16-1.fc39
Update description:
urlize and urlizetrunc were subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
USN-6989-1: OpenStack vulnerability
Dan Smith, Julia Kreger and Jay Faulkner discovered that in
image processing for Ironic, a specially crafted image
could be used by an authenticated user to exploit undesired behaviors
in qemu-img, including possible unauthorized access to potentially
sensitive data.
aardvark-dns-1.12.2-1.fc39
FEDORA-2024-0ce77b8571
Packages in this update:
aardvark-dns-1.12.2-1.fc39
Update description:
Security fix for CVE-2024-8418
aardvark-dns-1.12.2-1.fc40
FEDORA-2024-141d029304
Packages in this update:
aardvark-dns-1.12.2-1.fc40
Update description:
Security fix for CVE-2024-8418
aardvark-dns-1.12.2-1.fc41
FEDORA-2024-30ed35ba86
Packages in this update:
aardvark-dns-1.12.2-1.fc41
Update description:
Security fix for CVE-2024-8418
USN-6985-1: ImageMagick vulnerabilities
It was discovered that ImageMagick incorrectly handled certain malformed
image files. If a user or automated system using ImageMagick were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service or execute code with the privileges of the user
invoking the program.