Aggregator

janus-1.4.2-1.fc43

4 hours 33 minutes ago
FEDORA-2026-2a6ce5b288 Packages in this update:
  • janus-1.4.2-1.fc43
Update description:

Update to upstream v1.4.2 (security release).

  • Fix AudioBridge recordings bypassing protected folders (PR #3676)
  • Fix missing protocol allowlist when using libcurl in Streaming/TextRoom plugins (PR #3677)
  • Better enforcement of max publishers in VideoRoom (PR #3678)
  • Validate list of usernames in TextRoom batch message (PR #3679)
  • Use size_t in strings replace helper (PR #3680)
  • Fix removal from wrong hashtable in SIP and NoSIP plugins (PR #3681)
  • Add cap to helper threads in Streaming and VideoRoom plugins (PR #3682)
  • Fixed memory leaks in loop allocation and ICE agent disposal (PR #3665, PR #3666)
  • Fixed rare crash in AudioBridge plugin (PR #3664)
  • Fixed one way audio after a long hold in the SIP plugin (PR #3640)
  • Bumped API version patch to 11 (JANUS_VERSION_SO 2:11:0)

janus-1.4.2-1.fc44

4 hours 34 minutes ago
FEDORA-2026-256bf09e34 Packages in this update:
  • janus-1.4.2-1.fc44
Update description:

Update to upstream v1.4.2 (security release).

  • Fix AudioBridge recordings bypassing protected folders (PR #3676)
  • Fix missing protocol allowlist when using libcurl in Streaming/TextRoom plugins (PR #3677)
  • Better enforcement of max publishers in VideoRoom (PR #3678)
  • Validate list of usernames in TextRoom batch message (PR #3679)
  • Use size_t in strings replace helper (PR #3680)
  • Fix removal from wrong hashtable in SIP and NoSIP plugins (PR #3681)
  • Add cap to helper threads in Streaming and VideoRoom plugins (PR #3682)
  • Fixed memory leaks in loop allocation and ICE agent disposal (PR #3665, PR #3666)
  • Fixed rare crash in AudioBridge plugin (PR #3664)
  • Fixed one way audio after a long hold in the SIP plugin (PR #3640)
  • Bumped API version patch to 11 (JANUS_VERSION_SO 2:11:0)

janus-1.4.2-1.fc45

4 hours 34 minutes ago
FEDORA-2026-d58d30885a Packages in this update:
  • janus-1.4.2-1.fc45
Update description:

Update to upstream v1.4.2 (security release).

  • Fix AudioBridge recordings bypassing protected folders (PR #3676)
  • Fix missing protocol allowlist when using libcurl in Streaming/TextRoom plugins (PR #3677)
  • Better enforcement of max publishers in VideoRoom (PR #3678)
  • Validate list of usernames in TextRoom batch message (PR #3679)
  • Use size_t in strings replace helper (PR #3680)
  • Fix removal from wrong hashtable in SIP and NoSIP plugins (PR #3681)
  • Add cap to helper threads in Streaming and VideoRoom plugins (PR #3682)
  • Fixed memory leaks in loop allocation and ICE agent disposal (PR #3665, PR #3666)
  • Fixed rare crash in AudioBridge plugin (PR #3664)
  • Fixed one way audio after a long hold in the SIP plugin (PR #3640)
  • Bumped API version patch to 11 (JANUS_VERSION_SO 2:11:0)

USN-8839-1: Atril vulnerabilities

7 hours 43 minutes ago
It was discovered that Atril did not properly sanitize command-line arguments in PDF /GoToR actions. If a user opened a specially crafted PDF file, an attacker could possibly use this issue to execute arbitrary code. (CVE-2026-46529) It was discovered that Atril incorrectly handled certain PDF files. An attacker could possibly use this issue to cause a denial of service or to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2019-1010006) Andy Nguyen discovered that Atril incorrectly handled certain images. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 16.04 LTS. (CVE-2019-11459)

USN-8838-1: catdoc vulnerabilities

7 hours 54 minutes ago
It was discovered that catdoc had an integer overflow when processing shared string tables in malformed spreadsheet files. An attacker could possibly use this issue to cause catdoc to crash or execute arbitrary code. (CVE-2024-48877) It was discovered that catdoc had an integer overflow when processing file allocation tables in malformed document files. An attacker could possibly use this issue to cause catdoc to crash or execute arbitrary code. (CVE-2024-52035) It was discovered that catdoc incorrectly validated sector sizes when processing malformed document files, leading to an integer underflow. An attacker could possibly use this issue to cause catdoc to crash or execute arbitrary code. (CVE-2024-54028)

USN-8835-1: Emacs vulnerability

8 hours 22 minutes ago
It was discovered that Emacs improperly handled specially crafted SVG images, resulting in memory corruption. An attacker could possibly use this issue to cause Emacs to crash, resulting in a denial of service, or obtain sensitive information.

USN-8830-1: phpseclib vulnerabilities

9 hours ago
It was discovered that phpseclib did not perform constant-time padding validation when using AES in CBC mode. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-32935) It was discovered that phpseclib did not use a constant-time comparison when validating SSH packet authentication codes. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-40194) It was discovered that phpseclib did not properly limit object identifier lengths when parsing ASN.1 data. An attacker could possibly use this issue to cause phpseclib to use excessive resources, leading to a denial of service. (CVE-2026-44167)

USN-8828-1: dracut vulnerabilities

9 hours 22 minutes ago
It was discovered that dracut created initramfs images with overly permissive permissions under certain circumstances. A local attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-8637) It was discovered that dracut did not properly sanitize DHCP options before writing them to shell scripts under certain circumstances. A remote attacker controlling a DHCP server on the local network could possibly use this issue to execute arbitrary code as root during system boot. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-6893) It was discovered that dracut did not properly quote error messages written to shell scripts under certain circumstances. A remote attacker controlling a DHCP server on the local network could possibly use this issue to execute arbitrary code as root during system boot. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-15816) It was discovered that dracut did not properly sanitize network configuration data before writing it to a temporary shell script under certain circumstances. A remote attacker controlling DHCP on the local network could possibly use this issue to execute arbitrary code as root during system boot. This issue only affected Ubuntu 22.04 LTS. (CVE-2026-16445)

USN-8827-1: Erlang vulnerabilities

9 hours 34 minutes ago
It was discovered that the Erlang Port Mapper Daemon did not properly handle slow connections. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-42792) It was discovered that Erlang incorrectly handled certain external term format data, leading to heap corruption. An attacker could possibly use this issue to cause Erlang to crash, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-55737) It was discovered that Erlang incorrectly handled invalid external term format data. An attacker could possibly use this issue to cause Erlang to crash, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-54890) It was discovered that Erlang incorrectly handled certain packet lengths, leading to a buffer overflow. A remote attacker could possibly use this issue to cause Erlang to crash or execute arbitrary code. (CVE-2026-75538) It was discovered that the Erlang Megaco flex scanner incorrectly handled certain input, leading to a buffer overflow. A remote attacker could possibly use this issue to cause Erlang to crash or execute arbitrary code. (CVE-2026-59250) It was discovered that Erlang TLS clients incorrectly accepted cipher suites that they had not offered. A remote attacker could possibly use this issue to intercept and modify TLS communications. (CVE-2026-55953) It was discovered that Erlang incorrectly handled certain certificate chains. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58227) It was discovered that Erlang incorrectly handled certain certificate policies. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-59251) It was discovered that the Erlang HTTP server incorrectly handled certain conflicting HTTP framing headers. A remote attacker could possibly use this issue to smuggle HTTP requests. (CVE-2026-23941, CVE-2026-73812) It was discovered that the Erlang HTTP server incorrectly handled certain malformed chunk sizes. A remote attacker could possibly use this issue to cause Erlang to crash, resulting in a denial of service. (CVE-2026-69664) It was discovered that the Erlang HTTP server did not properly limit the size of chunked request bodies. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-74835) It was discovered that the Erlang HTTP server incorrectly handled certain equivalent request paths and differences in character case. A remote attacker could possibly use this issue to bypass authentication and gain unauthorized access. (CVE-2026-66835, CVE-2026-73270) It was discovered that the Erlang HTTP server did not properly limit simultaneous connections. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-70399) It was discovered that the Erlang HTTP server incorrectly handled header continuation lines. A remote attacker could possibly use this issue to smuggle HTTP requests. (CVE-2026-66357) It was discovered that the Erlang HTTP server incorrectly handled certain malformed header names. A remote attacker could possibly use this issue to smuggle HTTP requests. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-73276) It was discovered that the Erlang HTTP server incorrectly handled incomplete request bodies. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-71380) It was discovered that the Erlang HTTP client did not properly limit the size of HTTP response headers. A malicious HTTP server could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-55951) It was discovered that Erlang did not properly limit the length of port numbers when parsing URIs. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-59696) It was discovered that the Erlang SNMP application did not properly limit the size of certain integer values. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-70405) It was discovered that the Erlang LDAP client did not properly limit the length of port numbers in referral URLs. A malicious LDAP server could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-70409)