FEDORA-2023-28c182b657
Packages in this update:
skopeo-1.11.2-1.fc37
Update description:
Security fix for CVE-2022-41723
skopeo-1.11.2-1.fc37
Security fix for CVE-2022-41723
skopeo-1.11.2-1.fc38
Security fix for CVE-2022-41723
Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead to execution of malicious code and commands on the client due to improper handling of user-provided input. By inputting malicious payloads in the subdirectory searchbar or Add folder filename boxes, it is possible to execute client-side commands. For example, there is Client-Side Template Injection via subFolderPath to the ThinClient/WtmApiService.asmx/GetFileSubTree URI.
Israel-based managed cybersecurity provider Guardz has announced the general availability of its first cybersecurity offering for managed service providers (MSP) and IT professionals.
“The launch of this dedicated MSP platform brings Guardz one step closer to our goal of democratizing enterprise-grade level cybersecurity technologies,” said Dor Eisner, co-founder and CEO of Guardz. “MSPs will be able to give their clients the confidence that their business is secure from the inside out and gain complete visibility into their users’ cyber posture.”
Guardz’ namesake offering comes shortly after the company exited stealth in January with $10 million in seed funding. Company co-founder Eisner previously worked at the Israeli Military Intelligence as a cybersecurity team lead, while the other co-founder Alon Lavi was a staff sergeant at Israel Defense Forces before starting Guardz.
It was discovered that HAProxy incorrectly initialized certain connection
buffers. A remote attacker could possibly use this issue to obtain
sensitive information.
Demi Marie Obenour discovered that the Samba LDAP server incorrectly
handled certain confidential attribute values. A remote authenticated
attacker could possibly use this issue to obtain certain sensitive
information. (CVE-2023-0614)
Andrew Bartlett discovered that the Samba AD DC admin tool incorrectly
sent passwords in cleartext. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-0922)
Demi Marie Obenour discovered that ldb, when used with Samba, incorrectly
handled certain confidential attribute values. A remote authenticated
attacker could possibly use this issue to obtain certain sensitive
information.
When it’s time to put your cybersecurity roadmap into action, you might be wondering how to get started. Tony Sager has the answers.
podman-4.4.4-3.fc37
Resolves: 2183639,2183641 – use min conmon v2.1.7
Adjust tests for new Ansible
auto bump to v4.4.3
podman-4.4.4-3.fc38
Resolves: 2183639, 2183641 – use min conmon v2.1.7
Adjust tests for new Ansible
auto bump to v4.4.3