An implementation flaw was discovered in multiple cryptographic libraries that allows a side-channel based attacker to recover ECDSA or DSA private keys. When these cryptographic libraries use the private key to create a signature, such as for a TLS or SSH connection, they inadvertently leak information through memory caches. An unprivileged attacker running on the same machine can collect the information from a few thousand signatures and recover the value of the private key.
External References:
https://www.nccgroup.trust/us/our-research/technical-advisory-return-of-the-hidden-number-problem/
Catastrophic backtracking vulnerability was found in Python. Exploitation of a regular expression in difflib.ISLINEJUNK method in servers that use difflib can lead to denial of service.
Upstream issue:
https://bugs.python.org/issue32981
Catastrophic backtracking vulnerability was found in Python. Exploitation of a regular expression in pop3lib's apop() method although limited by 2048 chars, can lead to denial of service.
Upstream issue:
https://bugs.python.org/issue32981
A flaw was found in git which allows an attacker to execute arbitrary code by crafting a malicious .gitmodules file in a project cloned with --recurse-submodules.
References: https://bugzilla.novell.com/showbug.cgi?id=1110949 https://groups.google.com/forum/#!topic/git-packagers/fNLXf6LQC08
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. ...
Last updated 25 August 2025
Last updated 25 August 2025
Last updated 25 August 2025
Last updated 25 August 2025
XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow.