
August Linux Patch Wednesday. 658 vulnerabilities. Of these, 380 are in the Linux Kernel. About 10 have signs of exploitation in the wild. I will highlight:
Vulnerabilities of IT Asset Management system GLPI: AuthBypass (CVE-2023-35939, CVE-2023-35940) and Code Injection (CVE-2023-35924, CVE-2023-36808, CVE-2024-27096, CVE-2024-29889). Fixed in RedOS.
InfDisclosure – Minio (CVE-2023-28432). Old and trendy, but also fixes appeared only in RedOS.
DoS – PHP (CVE-2024-2757). If I were to take into account Fedora or Alpine bulletins, this would be in an earlier LPW.
2DO.
About 30 without signs of exploitation in the wild, but with exploits. I will highlight:
Command Injection – Apache HTTP Server (CVE-2024-40898)
AuthBypass – Apache HTTP Server (CVE-2024-40725)
AuthBypass – Neat VNC (CVE-2024-42458)
RCE – Calibre (CVE-2024-6782); yes, e-books software