https://bugzilla.redhat.com/show_bug.cgi?id=2292348
Bug ID: 2292348
Summary: CVE-2024-36587 dnscrypt-proxy: escalate privileges to
root via overwriting the binary dnscrypt-proxy
[fedora-all]
Product: Fedora
Version: 40
Status: NEW
Component: dnscrypt-proxy
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: davide(a)cavalca.name
Reporter: rkeshri(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: davide(a)cavalca.name,
epel-packagers-sig(a)lists.fedoraproject.org,
go-sig(a)lists.fedoraproject.org, zebob.m(a)gmail.com
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
http://bugzilla.redhat.com/show_bug.cgi?id=2292346
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2292348
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2281507
Bug ID: 2281507
Summary: CVE-2024-34083 python-aiosmtpd: aiosmtpd: servers
based on aiosmtpd accept extra unencrypted commands
[fedora-all]
Product: Fedora
Version: 40
Status: NEW
Component: python-aiosmtpd
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: aurelien(a)bompard.org
Reporter: ybuenos(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: aurelien(a)bompard.org,
epel-packagers-sig(a)lists.fedoraproject.org,
michel(a)michel-slm.name, psimovec(a)redhat.com
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
http://bugzilla.redhat.com/show_bug.cgi?id=2281505
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2281507
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2281497
Bug ID: 2281497
Summary: CVE-2024-35190 asterisk: wrongly matches ALL
unauthorized SIP requests [fedora-all]
Product: Fedora
Version: 40
Status: NEW
Component: asterisk
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: jsmith.fedora(a)gmail.com
Reporter: ybuenos(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: bennie.joubert(a)jsdaav.com,
epel-packagers-sig(a)lists.fedoraproject.org,
jsmith.fedora(a)gmail.com, rbryant(a)redhat.com
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
http://bugzilla.redhat.com/show_bug.cgi?id=2281495
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2281497
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2283271
Bug ID: 2283271
Summary: [abrt] gnome-calendar:
gcal_date_chooser_day_get_date(): gnome-calendar
killed by SIGSEGV
Product: Fedora
Version: rawhide
Hardware: x86_64
Status: NEW
Whiteboard: abrt_hash:844fb481027285f020859b86186f23f850c81a94;VAR
IANT_ID=workstation;
Component: gnome-calendar
Assignee: gnome-sig(a)lists.fedoraproject.org
Reporter: derekenz(a)gmail.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
gnome-sig(a)lists.fedoraproject.org,
igor.raits(a)gmail.com, klember(a)redhat.com
Target Milestone: ---
Classification: Fedora
Description of problem:
Launched the Calendar app from the dock. After clicking the X on the right to
close the app, a few seconds later a message apears saying gnome-calendar quit
unexpectedly.
Version-Release number of selected component:
gnome-calendar-46.1-1.fc41
Additional info:
reporter: libreport-2.17.15
type: CCpp
reason: gnome-calendar killed by SIGSEGV
journald_cursor:
s=d2a3c695abd4492abe4b1780b3a1b25a;i=2cc9;b=11fc1bdfbfdb412d81d3872386799a70;m=a9ea39b9;t=619513d5a5fba;x=bb64d8ab08fdaf7e
executable: /usr/bin/gnome-calendar
cmdline: /usr/bin/gnome-calendar --gapplication-service
cgroup:
0::/user.slice/user-1000.slice/user@1000.service/app.slice/dbus-:1.2-org.gnome.Calendar@2.service
rootdir: /
uid: 1000
kernel: 6.9.0-64.fc41.x86_64
package: gnome-calendar-46.1-1.fc41
runlevel: N 5
dso_list: /usr/bin/gnome-calendar gnome-calendar-46.1-1.fc41.x86_64
(Fedora Project) 1716621885
comment: Launched the Calendar app from the dock. After clicking the X
on the right to close the app, a few seconds later a message apears saying
gnome-calendar quit unexpectedly.
backtrace_rating: 4
crash_function: gcal_date_chooser_day_get_date
Truncated backtrace:
Thread no. 1 (7 frames)
#0 gcal_date_chooser_day_get_date at
../src/gui/event-editor/gcal-date-chooser-day.c:203
#1 update_event_indicators at ../src/gui/event-editor/gcal-date-chooser.c:452
#2 update_event_indicators_in_idle_cb at
../src/gui/event-editor/gcal-date-chooser.c:493
#5 g_main_context_dispatch_unlocked at ../glib/gmain.c:4152
#6 g_main_context_iterate_unlocked.isra.0 at ../glib/gmain.c:4217
#7 g_main_context_iteration at ../glib/gmain.c:4282
#8 g_application_run at ../gio/gapplication.c:2712
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2283271
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2280535
Bug ID: 2280535
Summary: CVE-2024-34459 mingw-libxml2: libxml2: buffer
over-read in xmlHTMLPrintFileContext in xmllint.c
[fedora-all]
Product: Fedora
Version: 40
Status: NEW
Component: mingw-libxml2
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: rjones(a)redhat.com
Reporter: rkeshri(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
rjones(a)redhat.com
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
http://bugzilla.redhat.com/show_bug.cgi?id=2280532
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2280535
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2280175
Bug ID: 2280175
Summary: [abrt] cinnamon: std::__atomic_base<unsigned
long>::load(): cinnamon killed by SIGSEGV
Product: Fedora
Version: 40
Hardware: x86_64
Status: NEW
Whiteboard: abrt_hash:1f9c07ff4becff90a3617fc3ccc8c2aa8cb814d4;VAR
IANT_ID=workstation;
Component: cinnamon
Assignee: leigh123linux(a)googlemail.com
Reporter: aauzi(a)free.fr
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
leigh123linux(a)googlemail.com, miketwebster(a)gmail.com,
riehecky(a)fnal.gov
Target Milestone: ---
Classification: Fedora
Description of problem:
It happended on an attempt to wake the PC from deep sleep or, maybe,
hibernation.
I first used the mouse, the screen backlight went on... then nothing more.
After few seconds, despite my efforts to mouse the mouse, use the keyboard, the
screen backlight went off.
At this stage, I had to force the power off.
Version-Release number of selected component:
cinnamon-6.0.4-6.fc40
Additional info:
reporter: libreport-2.17.15
crash_function: std::__atomic_base<unsigned long>::load
type: CCpp
dso_list: /usr/bin/cinnamon cinnamon-6.0.4-6.fc40.x86_64 (Fedora Project)
1714659458
rootdir: /
uid: 1000
kernel: 6.8.9-300.fc40.x86_64
backtrace_rating: 4
cmdline: cinnamon --replace
reason: cinnamon killed by SIGSEGV
package: cinnamon-6.0.4-6.fc40
journald_cursor:
s=4b82b3d0656a4445b058dd19f0d529a3;i=58bb30;b=2379fa2430584f3aa087a1b7fae4e280;m=1e8cf274ac;t=61849a7845b2b;x=dc2ef7597513be0c
executable: /usr/bin/cinnamon
cgroup: 0::/user.slice/user-1000.slice/session-2.scope
runlevel: N 5
Truncated backtrace:
Thread no. 1 (2 frames)
#0 std::__atomic_base<unsigned long>::load at
/usr/include/c++/14/bits/atomic_base.h:499
#1 mozilla::detail::IntrinsicMemoryOps<unsigned long,
(mozilla::MemoryOrdering)0>::load at
/usr/src/debug/mozjs102-102.15.1-5.fc40.x86_64/dist/include/mozilla/Atomics.h:195
Potential duplicate: bug 2222870
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2280175
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…