A look into CISA’s Known Exploited Vulnerability Catalogue is on our minds this week, plus we look at vulnerability updates for gdb, Ansible, CUPS, libheif, Roundcube, the Linux kernel and more.
175 unique CVEs addressed
tower_callback
(nowadays is called aap_callback
-
Ansible Automation Platform) parameter appropriatelyunsafe
- in that they may come from an external,
untrusted source - won’t get evaluated/expanded when used to avoid possible
info leaks etc - various issues where ansible would fail to respect this and
essentially forget they were tagged as unsafe and end up exposing secrets as a
resultFoomaticRIPCommandLine
then can run arbitrary commands
as rootAF_PACKET
, tty, ptrace, futex and
others