Mageia alert MGASA-2024-0067 (jupyter-notebook)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2024-0067: Updated jupyter-notebook packages fix security vulnerabilities | |
Date: | Sat, 16 Mar 2024 02:43:42 +0100 | |
Message-ID: | <20240316014342.1CEC69FD49@duvel.mageia.org> | |
Archive-link: | Article |
MGASA-2024-0067 - Updated jupyter-notebook packages fix security vulnerabilities Publication date: 16 Mar 2024 URL: https://advisories.mageia.org/MGASA-2024-0067.html Type: security Affected Mageia releases: 9 CVE: CVE-2022-24785, CVE-2022-31129 Description: Path traversal in moment.locale. (CVE-2022-24785) Inefficient parsing algorithim resulting in DoS. (CVE-2022-31129) References: - https://bugs.mageia.org/show_bug.cgi?id=30664 - https://lists.fedoraproject.org/archives/list/package-ann... - https://ubuntu.com/security/notices/USN-5559-1 - https://www.debian.org/lts/security/2023/dla-3295 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3... SRPMS: - 9/core/jupyter-notebook-6.4.12-1.1.mga9