dotnet6.0-6.0.113-1.fc36

Read Time:14 Second

FEDORA-2023-4d5f7e5cb0

Packages in this update:

dotnet6.0-6.0.113-1.fc36

Update description:

This updates .NET 6 to the January 2023 security release.

The updated versions are SDK 6.0.113 and Runtime 6.0.13

This include a fix for CVE-2023-21538

Read More

dotnet6.0-6.0.113-1.fc37

Read Time:14 Second

FEDORA-2023-f9368f7fea

Packages in this update:

dotnet6.0-6.0.113-1.fc37

Update description:

This updates .NET 6 to the January 2023 security release.

The updated versions are SDK 6.0.113 and Runtime 6.0.13

This include a fix for CVE-2023-21538

Read More

USN-5801-1: Vim vulnerabilities

Read Time:24 Second

It was discovered that Vim makes illegal memory calls when pasting
brackets in Ex mode. An attacker could possibly use this to crash Vim,
access or modify memory, or execute arbitrary commands. This issue
affected only Ubuntu 20.04 and 22.04 (CVE-2022-0392)

It was discovered that Vim makes illegal memory calls when making
certain retab calls. An attacker could possibly use this to crash Vim,
access or modify memory, or execute arbitrary commands. (CVE-2022-0417)

Read More

USN-5802-1: Linux kernel vulnerabilities

Read Time:50 Second

It was discovered that the NFSD implementation in the Linux kernel did not
properly handle some RPC messages, leading to a buffer overflow. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2022-43945)

Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation
in the Linux kernel contained multiple use-after-free vulnerabilities. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2022-42896)

It was discovered that the Xen netback driver in the Linux kernel did not
properly handle packets structured in certain ways. An attacker in a guest
VM could possibly use this to cause a denial of service (host NIC
availability). (CVE-2022-3643)

It was discovered that an integer overflow vulnerability existed in the
Bluetooth subsystem in the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (system crash).
(CVE-2022-45934)

Read More