[SECURITY] CVE-2023-30576: Apache Guacamole: Use-after-free in handling of RDP audio input buffer

2023-06-06 Thread Michael Jumper
Severity: moderate Base CVSS Score: 6.8 (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N) Affected versions: - Apache Guacamole 0.9.10 through 1.5.1 Description: Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an

[SECURITY] CVE-2023-30575: Apache Guacamole: Incorrect calculation of Guacamole protocol element lengths

2023-06-06 Thread Michael Jumper
Severity: moderate Base CVSS Score: 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N) Affected versions: - Apache Guacamole through 1.5.1 Description: Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake,

[ANNOUNCE] Apache Qpid Proton 0.39.0 released

2023-06-06 Thread Robbie Gemmell
The Apache Qpid (https://qpid.apache.org) community is pleased to announce the immediate availability of Apache Qpid Proton 0.39.0. Apache Qpid Proton is a messaging library for the Advanced Message Queuing Protocol 1.0 (AMQP 1.0, ISO/IEC 19464, https://www.amqp.org). It can be used in a wide

[ANNOUNCE] Apache Pulsar Client Python 3.2.0 released

2023-06-06 Thread Yunze Xu
The Apache Pulsar team is proud to announce Apache Pulsar Client Python version 3.2.0. Pulsar is a highly scalable, low latency messaging platform running on commodity hardware. It provides simple pub-sub semantics over topics, guaranteed at-least-once delivery of messages, automatic cursor

[ANNOUNCE] Apache MINA 2.2.2, 2.1.7 and 2.0.24 released

2023-06-06 Thread Emmanuel Lecharny
The Apache MINA project is pleased to announce the release of Apache MINA 2.2.2, 2.1.7 and 2.0.24 Those versions are fixing some SSL/TLS issues and bring some added features: * DIRMINA-1122: support for endpoint identification algorithm (thanks to Marcin L) * DIRMINA-1157: A fix for a sporadic