Fedora Essential and Critical Security Patch Updates - Page 7
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and
1.37 - fix parsing of "use if ..." Fixes errors in PAR::Packer test t/90-rt59710.t - add test for _parse_libs() 1.36
Security fix for CVE-2024-52304
Backport fix for CVE-2024-9287 Update to python-3.11.0.
Update to 2.82.2, fixes CVE-2024-52533.
Update NSS to 3.106.0 Update to Firefox 133.0
Update NSS to 3.106.0 Update to Firefox 133.0
1.37 - fix parsing of "use if ..." Fixes errors in PAR::Packer test t/90-rt59710.t - add test for _parse_libs() 1.36
PHP version 8.3.14 (21 Nov 2024) CLI: Fixed bug GH-16373 (Shebang is not skipped for router script in cli-server started through shebang). (ilutov) Fixed bug GHSA-4w77-75f9-2c8w (Heap-Use-After-Free in sapi_read_post_data
Backport fixes for CVE-2024-49768 and CVE-2024-49769.
Security fix for CVE-2024-52304
Add patches to fix: CVE-2024-52530 libsoup3: HTTP request smuggling via stripping null bytes from the ends of header names (bug #2325358) CVE-2024-52532 libsoup3: infinite loop while reading websocket data (bug #2325356)
fix crash in in ogg vorbis (rhbz#2322326) (CVE-2024-50612)
Backport fix for CVE-2024-9287 Update to python-3.11.0.
Update to 2.82.2, fixes CVE-2024-52533.
Update to 131.0.6778.85 * High CVE-2024-11395: Type Confusion in V8 * High CVE-2024-11110: Inappropriate implementation in Blink * Medium CVE-2024-11111: Inappropriate implementation in Autofill * Medium CVE-2024-11112: Use after free in Media
Update to 131.0.6778.85 * High CVE-2024-11395: Type Confusion in V8 * High CVE-2024-11110: Inappropriate implementation in Blink * Medium CVE-2024-11111: Inappropriate implementation in Autofill * Medium CVE-2024-11112: Use after free in Media