Aggregator

salt-3007.4-3.fc42

1 week 6 days ago
FEDORA-2025-5f1e820ece Packages in this update:
  • salt-3007.4-3.fc42
Update description:
  • Resolves RHBZ#2366381
  • Resolves CVE-2024-38824 RHBZ#2372731
  • Resolves CVE-2024-38824 RHBZ#2372733
  • Resolves CVE-2025-22239 RHBZ#2372732
  • Resolves CVE-2025-22239 RHBZ#2372734
  • Resolves CVE-2025-22236 RHBZ#2372774
  • Resolves CVE-2025-22236 RHBZ#2372776
  • Resolves CVE-2025-22242 RHBZ#2372741
  • Resolves CVE-2025-22242 RHBZ#2372745
  • Resolves CVE-2025-22240 RHBZ#2372746
  • Resolves CVE-2025-22241 RHBZ#2372748
  • Resolves CVE-2025-22240 RHBZ#2372752
  • Resolves CVE-2025-22241 RHBZ#2372753

salt-3007.4-2.fc43

1 week 6 days ago
FEDORA-2025-551aed076e Packages in this update:
  • salt-3007.4-2.fc43
Update description:

Automatic update for salt-3007.4-2.fc43.

Changelog * Thu Jun 19 2025 Robby Callicotte <rcallicotte@fedoraproject.org> - 3007.4-2 - Updated sources * Thu Jun 19 2025 Robby Callicotte <rcallicotte@fedoraproject.org> - 3007.4-1 - Update to 3007.4 RHBZ#2366381 - Resolves CVE-2024-38824 RHBZ#2372731 - Resolves CVE-2024-38824 RHBZ#2372733 - Resolves CVE-2025-22239 RHBZ#2372732 - Resolves CVE-2025-22239 RHBZ#2372734 - Resolves CVE-2025-22236 RHBZ#2372774 - Resolves CVE-2025-22236 RHBZ#2372776 - Resolves CVE-2025-22242 RHBZ#2372741 - Resolves CVE-2025-22242 RHBZ#2372745 - Resolves CVE-2025-22240 RHBZ#2372746 - Resolves CVE-2025-22241 RHBZ#2372748 - Resolves CVE-2025-22240 RHBZ#2372752 - Resolves CVE-2025-22241 RHBZ#2372753

USN-7582-1: Samba vulnerabilities

1 week 6 days ago
Evgeny Legerov discovered that Samba incorrectly handled buffers in certain GSSAPI routines of Heimdal. A remote attacker could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2022-3437) Greg Hudson discovered that Samba incorrectly handled PAC parsing. On 32-bit systems, a remote attacker could use this issue to escalate privileges, or possibly execute arbitrary code. (CVE-2022-42898) Joseph Sutton discovered that Samba could be forced to issue rc4-hmac encrypted Kerberos tickets. A remote attacker could possibly use this issue to escalate privileges. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-45141) Florent Saudel discovered that Samba incorrectly handled certain Spotlight requests. A remote attacker could possibly use this issue to cause Samba to consume resources, leading to a denial of service. (CVE-2023-34966)

USN-7581-1: Express vulnerabilities

2 weeks ago
It was discovered that Express incorrectly handled certain URLs, leading to an open redirect attack. A remote attacker could possibly use this issue to perform phishing attacks. (CVE-2024-29041) Adam Korcz discovered that Express did not properly sanitize certain inputs. A remote attacker could possibly use this issue to perform cross site scripting. (CVE-2024-43796)