[FEDORA-2023-17efd3f2cd] Fedora 38: mcrouter, fizz, fbthrift, fb303, folly & 6 more

Severity High
Affected Packages 11
CVEs 1

Update Folly stack to the latest 2023.10.16.00 tag proxygen: Security fix for
CVE-2023-44487

Package Affected Version
pkg:rpm/fedora/wdt?distro=fedora-38 < 1.32.1910230^20230711git3b52ef5.2.fc38
pkg:rpm/fedora/watchman?distro=fedora-38 < 2021.05.10.00.24.fc38
pkg:rpm/fedora/wangle?distro=fedora-38 < 2023.10.16.00.1.fc38
pkg:rpm/fedora/proxygen?distro=fedora-38 < 2023.10.16.00.1.fc38
pkg:rpm/fedora/mvfst?distro=fedora-38 < 2023.10.16.00.1.fc38
pkg:rpm/fedora/mcrouter?distro=fedora-38 < 0.41.0.20231016.1.fc38
pkg:rpm/fedora/folly?distro=fedora-38 < 2023.10.16.00.1.fc38
pkg:rpm/fedora/fizz?distro=fedora-38 < 2023.10.16.00.1.fc38
pkg:rpm/fedora/fbthrift?distro=fedora-38 < 2023.10.16.00.1.fc38
pkg:rpm/fedora/fb303?distro=fedora-38 < 2023.10.16.00.1.fc38
pkg:rpm/fedora/cachelib?distro=fedora-38 < 17^20231016.1.fc38
ID
FEDORA-2023-17efd3f2cd
Severity
high
Severity from
CVE-2023-44487
URL
https://bodhi.fedoraproject.org/updates/FEDORA-2023-17efd3f2cd
Published
2023-10-24T01:23:49
(11 months ago)
Modified
2023-10-24T01:23:49
(11 months ago)
Rights
Copyright 2023 Red Hat, Inc.
Other Advisories
Source # ID Name URL
Bugzilla 2239594 Bug #2239594 - wangle-2023.10.16.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239594
Bugzilla 2221799 Bug #2221799 - mcrouter-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2221799
Bugzilla 2239623 Bug #2239623 - fizz-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239623
Bugzilla 2239613 Bug #2239613 - fb303-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239613
Bugzilla 2239614 Bug #2239614 - fbthrift-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239614
Bugzilla 2239624 Bug #2239624 - folly-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239624
Bugzilla 2243253 Bug #2243253 - [Major Incident] CVE-2023-44487 proxygen: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2243253
Bugzilla 2239431 Bug #2239431 - proxygen-2023.10.16.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239431
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/wdt?distro=fedora-38 fedora wdt < 1.32.1910230^20230711git3b52ef5.2.fc38 fedora-38
Affected pkg:rpm/fedora/watchman?distro=fedora-38 fedora watchman < 2021.05.10.00.24.fc38 fedora-38
Affected pkg:rpm/fedora/wangle?distro=fedora-38 fedora wangle < 2023.10.16.00.1.fc38 fedora-38
Affected pkg:rpm/fedora/proxygen?distro=fedora-38 fedora proxygen < 2023.10.16.00.1.fc38 fedora-38
Affected pkg:rpm/fedora/mvfst?distro=fedora-38 fedora mvfst < 2023.10.16.00.1.fc38 fedora-38
Affected pkg:rpm/fedora/mcrouter?distro=fedora-38 fedora mcrouter < 0.41.0.20231016.1.fc38 fedora-38
Affected pkg:rpm/fedora/folly?distro=fedora-38 fedora folly < 2023.10.16.00.1.fc38 fedora-38
Affected pkg:rpm/fedora/fizz?distro=fedora-38 fedora fizz < 2023.10.16.00.1.fc38 fedora-38
Affected pkg:rpm/fedora/fbthrift?distro=fedora-38 fedora fbthrift < 2023.10.16.00.1.fc38 fedora-38
Affected pkg:rpm/fedora/fb303?distro=fedora-38 fedora fb303 < 2023.10.16.00.1.fc38 fedora-38
Affected pkg:rpm/fedora/cachelib?distro=fedora-38 fedora cachelib < 17^20231016.1.fc38 fedora-38
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...