Fedora has released an update for opkssh version 0.16.0, fixing a security vulnerability in GQ-commitment PK Tokens, while updating dependencies and maintaining low severity due to limited exposure.
The Fedora update for perl-Mojolicious version 9.48 addresses a security flaw related to CSRF tokens, enhancing protection against BREACH attacks by masking tokens with random values per request.
Fedora 43 has released an update for the RPM package management system, rebasing it to version 6.0.2, addressing security issues like heap buffer overflow and command injection.
Fedora 44 has updated OpenPubkey SSH to version 0.16.0, which includes a security fix for GQ-commitment PK Tokens, although vulnerability risk for opkssh is low.
The Fedora update for perl-Mojolicious 9.48 addresses a security issue with CSRF tokens vulnerable to BREACH attacks by masking tokens with a fresh random value for each request.