SUSE SLED15 / SLES15 Security Update : python-M2Crypto (SUSE-SU-2022:2691-1)

The remote SUSE Linux SLED15 / SLES15 host has a package installed that is affected by a vulnerability as referenced in the SUSE-SU-2022:2691-1 advisory. - A flaw was found in all released versions ...

Continue Reading
DSpace ItemImportService API Vulnerable to Path Traversal in Simple Archive Format Package Import

### Impact ItemImportServiceImpl is vulnerable to a path traversal vulnerability. This means a malicious SAF (simple archive format) package could cause a file/directory to be created anywhere the Tom ...

Continue Reading
DSpace ItemImportService API Vulnerable to Path Traversal in Simple Archive Format Package Import

### Impact ItemImportServiceImpl is vulnerable to a path traversal vulnerability. This means a malicious SAF (simple archive format) package could cause a file/directory to be created anywhere the Tom ...

Continue Reading
Rust-WebSocket memory allocation based on untrusted length

## Impact Untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the issue is during dataframe parsing. Affected versions would allo ...

Continue Reading
Rust-WebSocket memory allocation based on untrusted length

## Impact Untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the issue is during dataframe parsing. Affected versions would alloc ...

Continue Reading
Updated python-m2crypto packages fix security vulnerability

Bleichenbacher timing attacks in the RSA decryption API (CVE-2020-25657)Read More ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Security update for python-M2Crypto (important)

An update that fixes one vulnerability is now available. Description: This update for python-M2Crypto fixes the following issues: - CVE-2020-25657: Fixed Bleichenbacher timing attacks in the RS ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2022-33201

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading

Back to Main

Subscribe for the latest news: