Publish Advisories

GHSA-6wvf-f2vw-3425
GHSA-vg57-hwh2-c85p
GHSA-27jf-22p2-6vq4
GHSA-mh66-32q9-mpj8
GHSA-c4ch-cv96-r58v
GHSA-9f68-5hcg-8ww5
GHSA-4qww-pqq9-xrw5
GHSA-7555-3222-qmcm
GHSA-fg4m-w584-q5x8
GHSA-fmxj-97w3-xq3m
GHSA-p79g-j2j8-9wqw
GHSA-qh7m-p5jw-2wvg
GHSA-3qhf-rfv2-rc83
GHSA-ccfh-v7cp-3943
GHSA-fr4c-ch83-r968
GHSA-p43x-m8vx-c7fm
This commit is contained in:
advisory-database[bot]
2024-10-03 15:32:01 +00:00
parent f3ea0c29ce
commit e3f7d2776f
16 changed files with 173 additions and 18 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6wvf-f2vw-3425",
"modified": "2024-10-02T12:30:31Z",
"modified": "2024-10-03T15:30:47Z",
"published": "2024-05-14T18:30:52Z",
"aliases": [
"CVE-2024-3727"
@@ -142,6 +142,10 @@
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-3727"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:7187"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:7182"
@@ -40,6 +40,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122",
"CWE-787"
],
"severity": "CRITICAL",
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-248",
"CWE-703",
"CWE-755"
],
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -61,7 +61,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-113"
],
"severity": null,
"github_reviewed": false,
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-918",
"CWE-94"
],
"severity": "CRITICAL",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4qww-pqq9-xrw5",
"modified": "2024-09-04T21:30:32Z",
"modified": "2024-10-03T15:30:47Z",
"published": "2024-09-04T21:30:32Z",
"aliases": [
"CVE-2024-44970"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: SHAMPO, Fix invalid WQ linked list unlink\n\nWhen all the strides in a WQE have been consumed, the WQE is unlinked\nfrom the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possible\nto receive CQEs with 0 consumed strides for the same WQE even after the\nWQE is fully consumed and unlinked. This triggers an additional unlink\nfor the same wqe which corrupts the linked list.\n\nFix this scenario by accepting 0 sized consumed strides without\nunlinking the WQE again.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T19:15:31Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7555-3222-qmcm",
"modified": "2024-09-27T15:30:34Z",
"modified": "2024-10-03T15:30:50Z",
"published": "2024-09-27T15:30:34Z",
"aliases": [
"CVE-2024-46864"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/hyperv: fix kexec crash due to VP assist page corruption\n\ncommit 9636be85cc5b (\"x86/hyperv: Fix hyperv_pcpu_input_arg handling when\nCPUs go online/offline\") introduces a new cpuhp state for hyperv\ninitialization.\n\ncpuhp_setup_state() returns the state number if state is\nCPUHP_AP_ONLINE_DYN or CPUHP_BP_PREPARE_DYN and 0 for all other states.\nFor the hyperv case, since a new cpuhp state was introduced it would\nreturn 0. However, in hv_machine_shutdown(), the cpuhp_remove_state() call\nis conditioned upon \"hyperv_init_cpuhp > 0\". This will never be true and\nso hv_cpu_die() won't be called on all CPUs. This means the VP assist page\nwon't be reset. When the kexec kernel tries to setup the VP assist page\nagain, the hypervisor corrupts the memory region of the old VP assist page\ncausing a panic in case the kexec kernel is using that memory elsewhere.\nThis was originally fixed in commit dfe94d4086e4 (\"x86/hyperv: Fix kexec\npanic/hang issues\").\n\nGet rid of hyperv_init_cpuhp entirely since we are no longer using a\ndynamic cpuhp state and use CPUHP_AP_HYPERV_ONLINE directly with\ncpuhp_remove_state().",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-27T13:15:17Z"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p79g-j2j8-9wqw",
"modified": "2024-09-04T21:30:32Z",
"modified": "2024-10-03T15:30:47Z",
"published": "2024-09-04T21:30:32Z",
"aliases": [
"CVE-2024-44973"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm, slub: do not call do_slab_free for kfence object\n\nIn 782f8906f805 the freeing of kfence objects was moved from deep\ninside do_slab_free to the wrapper functions outside. This is a nice\nchange, but unfortunately it missed one spot in __kmem_cache_free_bulk.\n\nThis results in a crash like this:\n\nBUG skbuff_head_cache (Tainted: G S B E ): Padding overwritten. 0xffff88907fea0f00-0xffff88907fea0fff @offset=3840\n\nslab_err (mm/slub.c:1129)\nfree_to_partial_list (mm/slub.c:? mm/slub.c:4036)\nslab_pad_check (mm/slub.c:864 mm/slub.c:1290)\ncheck_slab (mm/slub.c:?)\nfree_to_partial_list (mm/slub.c:3171 mm/slub.c:4036)\nkmem_cache_alloc_bulk (mm/slub.c:? mm/slub.c:4495 mm/slub.c:4586 mm/slub.c:4635)\nnapi_build_skb (net/core/skbuff.c:348 net/core/skbuff.c:527 net/core/skbuff.c:549)\n\nAll the other callers to do_slab_free appear to be ok.\n\nAdd a kfence_free check in __kmem_cache_free_bulk to avoid the crash.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T19:15:31Z"
File diff suppressed because one or more lines are too long
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qhf-rfv2-rc83",
"modified": "2024-10-03T15:30:50Z",
"published": "2024-10-03T15:30:50Z",
"aliases": [
"CVE-2024-9100"
],
"details": "Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9100"
},
{
"type": "WEB",
"url": "https://www.manageengine.com/analytics-plus/CVE-2024-9100.html"
},
{
"type": "WEB",
"url": "https://www.zoho.com/analytics/onpremise/CVE-2024-9100.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-03T15:15:15Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ccfh-v7cp-3943",
"modified": "2024-10-03T15:30:50Z",
"published": "2024-10-03T15:30:50Z",
"aliases": [
"CVE-2024-5803"
],
"details": "The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5803"
},
{
"type": "WEB",
"url": "https://support.norton.com/sp/static/external/tools/security-advisories.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-367"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-03T15:15:15Z"
}
}
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p43x-m8vx-c7fm",
"modified": "2024-10-03T15:30:50Z",
"published": "2024-10-03T15:30:50Z",
"aliases": [
"CVE-2024-9460"
],
"details": "A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9460"
},
{
"type": "WEB",
"url": "https://github.com/ppp-src/CVE/issues/8"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.279132"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.279132"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.417052"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-03T15:15:15Z"
}
}