Dan Smith, Julia Kreger and Jay Faulkner discovered that in
image processing for Ironic, a specially crafted image
could be used by an authenticated user to exploit undesired behaviors
in qemu-img, including possible unauthorized access to potentially
sensitive data.
Category Archives: Advisories
aardvark-dns-1.12.2-1.fc39
FEDORA-2024-0ce77b8571
Packages in this update:
aardvark-dns-1.12.2-1.fc39
Update description:
Security fix for CVE-2024-8418
aardvark-dns-1.12.2-1.fc40
FEDORA-2024-141d029304
Packages in this update:
aardvark-dns-1.12.2-1.fc40
Update description:
Security fix for CVE-2024-8418
aardvark-dns-1.12.2-1.fc41
FEDORA-2024-30ed35ba86
Packages in this update:
aardvark-dns-1.12.2-1.fc41
Update description:
Security fix for CVE-2024-8418
USN-6985-1: ImageMagick vulnerabilities
It was discovered that ImageMagick incorrectly handled certain malformed
image files. If a user or automated system using ImageMagick were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service or execute code with the privileges of the user
invoking the program.
ruby-3.3.5-14.fc42
FEDORA-2024-8a931e76d2
Packages in this update:
ruby-3.3.5-14.fc42
Update description:
Update to Ruby 3.3.5
USN-6988-1: Twisted vulnerabilities
It was discovered that Twisted incorrectly handled response order when
processing multiple HTTP requests. A remote attacker could possibly use
this issue to delay and manipulate responses.
This issue only affected Ubuntu 24.04 LTS. (CVE-2024-41671)
It was discovered that Twisted did not properly sanitize certain input.
An attacker could use this vulnerability to possibly execute an HTML
injection leading to a cross-site scripting (XSS) attack.
(CVE-2024-41810)
osc-1.9.1-420.1.1.el9
FEDORA-EPEL-2024-ebc9668713
Packages in this update:
osc-1.9.1-420.1.1.el9
Update description:
New upstream release 1.9.1, fixes CVE-2024-22034
osc-1.9.1-420.1.1.fc39
FEDORA-2024-18d9a6ba14
Packages in this update:
osc-1.9.1-420.1.1.fc39
Update description:
New upstream release 1.9.1, fixes CVE-2024-22034
osc-1.9.1-420.1.1.fc40
FEDORA-2024-b11026f492
Packages in this update:
osc-1.9.1-420.1.1.fc40
Update description:
New upstream release 1.9.1, fixes CVE-2024-22034