Aggregator

USN-6722-1: Django vulnerability

2 weeks 6 days ago
Simon Charette discovered that the password reset functionality in Django used a Unicode case insensitive query to retrieve accounts associated with an email address. An attacker could possibly use this to obtain password reset tokens and hijack accounts.

python-cbor2-5.6.2-1.fc41

2 weeks 6 days ago
FEDORA-2024-e63fc9eb58 Packages in this update:
  • python-cbor2-5.6.2-1.fc41
Update description:

Automatic update for python-cbor2-5.6.2-1.fc41.

Changelog * Mon Apr 8 2024 Fabian Affolter <mail@fabian-affolter.ch> - 5.6.2-1 - Update to latest upstream release (closes rhbz#2261550, closes rhbz#2245361) - Fixes CVE-2024-26134 (closes rhbz#2265036, closes rhbz#bug 2265035) * Sat Feb 3 2024 Fabian Affolter <mail@fabian-affolter.ch> - 5.6.1-1 - Update to latest upstream release 5.6.1 (closes rhbz#2245361) * Fri Jan 26 2024 Fedora Release Engineering <releng@fedoraproject.org> - 5.1.2-14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Mon Jan 22 2024 Fedora Release Engineering <releng@fedoraproject.org> - 5.1.2-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

cjson-1.7.17-1.fc41

3 weeks ago
FEDORA-2024-ef33631a3c Packages in this update:
  • cjson-1.7.17-1.fc41
Update description:

Automatic update for cjson-1.7.17-1.fc41.

Changelog * Sun Apr 7 2024 Fabian Affolter <mail@fabian-affolter.ch> - 1.7.17.-1 - Update to latest upstream version 1.7.17 (closes rhbz#2255953) - Fix rhbz#2254647

python-mechanicalsoup-1.3.0-1.fc41

3 weeks ago
FEDORA-2024-45b02f63e4 Packages in this update:
  • python-mechanicalsoup-1.3.0-1.fc41
Update description:

Automatic update for python-mechanicalsoup-1.3.0-1.fc41.

Changelog * Sun Apr 7 2024 Fabian Affolter <mail@fabian-affolter.ch> - 1.3.0-1 - Update to latest upstream version 1.3.0 (closes rhbz#2219697) - Fix rhbz#2219756, rhbz#2261581 and rhbz#2232585

chromium-123.0.6312.105-1.el7

3 weeks 3 days ago
FEDORA-EPEL-2024-3cb841c5f0 Packages in this update:
  • chromium-123.0.6312.105-1.el7
Update description:

update to 123.0.6312.105

  • High CVE-2024-3156: Inappropriate implementation in V8
  • High CVE-2024-3158: Use after free in Bookmarks
  • High CVE-2024-3159: Out of bounds memory access in V8

chromium-123.0.6312.105-1.el9

3 weeks 3 days ago
FEDORA-EPEL-2024-7bc0a1d338 Packages in this update:
  • chromium-123.0.6312.105-1.el9
Update description:

update to 123.0.6312.105

  • High CVE-2024-3156: Inappropriate implementation in V8
  • High CVE-2024-3158: Use after free in Bookmarks
  • High CVE-2024-3159: Out of bounds memory access in V8

chromium-123.0.6312.105-1.el8

3 weeks 3 days ago
FEDORA-EPEL-2024-fe061342ca Packages in this update:
  • chromium-123.0.6312.105-1.el8
Update description:

update to 123.0.6312.105

  • High CVE-2024-3156: Inappropriate implementation in V8
  • High CVE-2024-3158: Use after free in Bookmarks
  • High CVE-2024-3159: Out of bounds memory access in V8