Product:

Enterprise_linux

(Redhat)
Date Id Summary Products Score Patch Annotated
2023-06-30 CVE-2023-1206 A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%. Fedora, Linux_kernel, Enterprise_linux 5.7
2023-07-10 CVE-2023-1183 A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. Fedora, Libreoffice, Enterprise_linux 5.5
2023-07-10 CVE-2023-26590 A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service. Extra_packages_for_enterprise_linux, Fedora, Enterprise_linux, Sox 5.5
2023-07-10 CVE-2023-32627 A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service. Extra_packages_for_enterprise_linux, Fedora, Enterprise_linux, Sox 5.5
2023-07-10 CVE-2023-34318 A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure. Extra_packages_for_enterprise_linux, Fedora, Enterprise_linux, Sox 7.8
2023-07-10 CVE-2023-34432 A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure. Extra_packages_for_enterprise_linux, Fedora, Enterprise_linux, Sound_exchange 7.8
2023-07-11 CVE-2023-1672 A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host. Fedora, Enterprise_linux, Tang 5.3
2023-07-11 CVE-2023-3269 A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root privileges. Fedora, Linux_kernel, Enterprise_linux 7.8
2023-07-11 CVE-2023-3354 A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service. Fedora, Qemu, Enterprise_linux, Openstack_platform 7.5
2023-07-12 CVE-2023-3618 A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service. Debian_linux, Libtiff, Enterprise_linux 6.5