VYPR

Dnf5

by Rpm Software Management

Source repositories

CVEs (2)

  • CVE-2024-2746HigMay 8, 2024
    risk 0.57cvss 8.8epss 0.00

    Incomplete fix for CVE-2024-1929 The problem with CVE-2024-1929 was that the dnf5 D-Bus daemon accepted arbitrary configuration parameters from unprivileged users, which allowed a local root exploit by tricking the daemon into loading a user controlled "plugin". All of this…

  • CVE-2024-1930MedMay 8, 2024
    risk 0.42cvss 6.5epss 0.00

    No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability via No Limit on Number of Open Sessions. There is no limit on how many sessions D-Bus clients may create using the…