Search CVE reports
31 – 40 of 35813 results
security update
1 affected package
netatalk
| Package | 24.04 LTS |
|---|---|
| netatalk | Needs evaluation |
Rsync versionĀ 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit...
1 affected package
rsync
| Package | 24.04 LTS |
|---|---|
| rsync | Fixed |
Rsync versionĀ 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to...
1 affected package
rsync
| Package | 24.04 LTS |
|---|---|
| rsync | Fixed |
The receiver's compressed-token decoder accumulated a 32-bit signed counter without overflow checking. A malicious sender can trigger an overflow that, with careful manipulation, leaks process memory contents to the attacker --...
1 affected package
rsync
| Package | 24.04 LTS |
|---|---|
| rsync | Fixed |
Rsync versionĀ 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules...
1 affected package
rsync
| Package | 24.04 LTS |
|---|---|
| rsync | Fixed |
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick...
1 affected package
unbound
| Package | 24.04 LTS |
|---|---|
| unbound | Fixed |
NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for...
1 affected package
unbound
| Package | 24.04 LTS |
|---|---|
| unbound | Fixed |
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant...
1 affected package
unbound
| Package | 24.04 LTS |
|---|---|
| unbound | Fixed |
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations...
1 affected package
unbound
| Package | 24.04 LTS |
|---|---|
| unbound | Fixed |
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running...
1 affected package
unbound
| Package | 24.04 LTS |
|---|---|
| unbound | Fixed |