Aggregator

USN-7968-1: Apache HTTP Server vulnerabilities

9 hours 14 minutes ago
It was discovered that the Apache HTTP Server incorrectly handled failed ACME certificate renewals. This could result in renewal attempts to be repeated without delays, possibly leading to a denial of service. (CVE-2025-55753) Anthony Parfenov discovered that the Apache HTTP Server would pass the query string to cmd directives when configured with Server Side Includes (SSI) enabled and mod_cgid. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-58098) Mattias Åsander discovered that the Apache HTTP Server incorrectly neutralized certain environment variables. This could result in unexpectedly superseding variables calculated by the server for CGI programs. (CVE-2025-65082) Mattias Åsander discovered that the Apache HTTP Server incorrectly handled AllowOverride FileInfo configurations when using mod_userdir with suexec. An attacker with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. (CVE-2025-66200)

USN-7966-2: Telegraf vulnerabilities

11 hours 31 minutes ago
USN-7966-1 fixed vulnerabilities in Snowflake. This update provides the corresponding updates for Telegraf. Original advisory details: It was discovered that Pion DTLS, vendored in Telegraf, did not impose a limit on the amount of data that was buffered during the handshake. An attacker could possibly use the issue to cause a denial of service. (CVE-2022-29189) It was discovered that Pion DTLS, vendored in Telegraf, did not prevent the fragmentBuffer from processing zero length fragments. An attacker could possibly use the issue to cause a denial of service. (CVE-2022-29190) It was discovered that Pion DTLS, vendored in Telegraf, did not require CertificateVerify when Client Cert was sent. An attacker could possibly use the issue to cause a denial of service. (CVE-2022-29222)

USN-7967-1: Avahi vulnerabilities

11 hours 43 minutes ago
It was discovered that Avahi incorrectly terminated when processing browser records with wide-area disabled. An attacker could possibly use this issue to cause Avahi to crash, resulting in a denial of service. (CVE-2025-68276) It was discovered that Avahi incorrectly terminated when processing unsolicited CNAME records pointing to resource records with short TTLs. An attacker could possibly use this issue to cause Avahi to crash, resulting in a denial of service. (CVE-2025-68468) It was discovered that Avahi incorrectly terminated when processing unsolicited CNAME records in quick succession. An attacker could possibly use this issue to cause Avahi to crash, resulting in a denial of service. (CVE-2025-68471)

USN-7955-2: urllib3 regression

12 hours 16 minutes ago
USN-7955-1 fixed vulnerabilities in urllib3. The update introduced a regression in response streaming on Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that urllib3 incorrectly handled decompression during HTTP redirects. An attacker could possibly use this issue to cause urllib3 to use excessive resources, causing a denial of service.

USN-7966-1: Snowflake vulnerabilities

13 hours 38 minutes ago
It was discovered that Pion DTLS, vendored in Snowflake, did not impose a limit on the amount of data that was buffered during the handshake. An attacker could possibly use the issue to cause a denial of service. (CVE-2022-29189) It was discovered that Pion DTLS, vendored in Snowflake, did not prevent the fragmentBuffer from processing zero length fragments. An attacker could possibly use the issue to cause a denial of service. (CVE-2022-29190) It was discovered that Pion DTLS, vendored in Snowflake, did not require CertificateVerify when Client Cert was sent. An attacker could possibly use the issue to cause a denial of service. (CVE-2022-29222)