FEDORA-EPEL-2024-01755f0acd
Packages in this update:
composer-2.7.7-1.el9
Update description:
Version 2.7.7 2024-06-10
Security: Fixed command injection via malicious git branch name (GHSA-47f6-5gq3-vx9c / CVE-2024-35241)
Security: Fixed multiple command injections via malicious git/hg branch names (GHSA-v9qv-c7wm-wgmf / CVE-2024-35242)
Fixed PSR violations for classes not matching the namespace of a rule being hidden, this may lead to new violations being shown (#11957)
Fixed UX when a plugin is still in vendor dir but is not required nor allowed anymore after changing branches (#12000)
Fixed new platform requirements from composer.json not being checked if the lock file is outdated (#12001)
Fixed secure-http checks that could be bypassed by using malformed URL formats (fa3b9582c)
Fixed Filesystem::isLocalPath including windows-specific checks on linux (3c37a67c)
Fixed perforce argument escaping (3773f775)
Fixed handling of zip bombs when extracting archives (de5f7e32)
Fixed Windows command parameter escaping to prevent abuse of unicode characters with best fit encoding conversion (3130a7455, 04a63b324)
Fixed ability for config command to remove autoload keys (#11967)
Fixed empty type support in init command (#11999)
Fixed git clone errors when safe.bareRepository is set to strict in the git config (#11969)
Fixed regression showing network errors on PHP <8.1 (#11974)
Fixed some color bleed from a few warnings (#11972)
More Stories
libxml2-2.12.10-1.fc40
FEDORA-2025-adbb0031f7 Packages in this update: libxml2-2.12.10-1.fc40 Update description: Update to 2.12.10 Read More
libxml2-2.12.10-1.fc41
FEDORA-2025-65790c11eb Packages in this update: libxml2-2.12.10-1.fc41 Update description: Update to 2.12.10 Fix CVE-2024-56171 and CVE-2025-24928. Read More
libxml2-2.12.10-1.fc42
FEDORA-2025-b9170cd464 Packages in this update: libxml2-2.12.10-1.fc42 Update description: Update to 2.12.10 Fix CVE-2024-56171 and CVE-2025-24928. Read More
kitty-0.40.0-2.fc40
FEDORA-2025-2fe21e3da5 Packages in this update: kitty-0.40.0-2.fc40 Update description: Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes Read More
USN-7351-1: RESTEasy vulnerabilities
Nikos Papadopoulos discovered that RESTEasy improperly handled URL encoding when certain errors occur. An attacker could possibly use this issue...
USN-7344-2: Linux kernel vulnerabilities
Chenyuan Yang discovered that the CEC driver driver in the Linux kernel contained a use-after-free vulnerability. A local attacker could...