Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:1346

Опубликовано: 17 мар. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: gcc security update

The gcc packages provide compilers for C, C++, Java, Fortran, Objective C, and Ada 95 GNU, as well as related support libraries.

Security Fix(es):

  • jquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods (CVE-2020-11023)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
cppaarch645.el9_5cpp-11.5.0-5.el9_5.aarch64.rpm
gccaarch645.el9_5gcc-11.5.0-5.el9_5.aarch64.rpm
gcc-c++aarch645.el9_5gcc-c++-11.5.0-5.el9_5.aarch64.rpm
gcc-gfortranaarch645.el9_5gcc-gfortran-11.5.0-5.el9_5.aarch64.rpm
gcc-plugin-annobinaarch645.el9_5gcc-plugin-annobin-11.5.0-5.el9_5.aarch64.rpm
libasanaarch645.el9_5libasan-11.5.0-5.el9_5.aarch64.rpm
libgccjitaarch645.el9_5libgccjit-11.5.0-5.el9_5.aarch64.rpm
libgccjit-develaarch645.el9_5libgccjit-devel-11.5.0-5.el9_5.aarch64.rpm
libitmaarch645.el9_5libitm-11.5.0-5.el9_5.aarch64.rpm
libitm-develaarch645.el9_5libitm-devel-11.5.0-5.el9_5.aarch64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 6.9
ubuntu
больше 6 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.1
redhat
больше 6 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.9
nvd
больше 6 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.9
debian
больше 6 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, pa ...

rocky
больше 1 года назад

Moderate: gcc-toolset-14-gcc security update