FEDORA-2023-df375d0634
Packages in this update:
open-vm-tools-12.3.0-1.fc38
Update description:
Package new upstream version of open-vm-tools-12.3.0-22234872.
Security fix for CVE-2023-20900, CVE-2023-20867
open-vm-tools-12.3.0-1.fc38
Package new upstream version of open-vm-tools-12.3.0-22234872.
Security fix for CVE-2023-20900, CVE-2023-20867
open-vm-tools-12.3.0-1.fc39
Package new upstream version of open-vm-tools-12.3.0-22234872.
Security fix for CVE-2023-20900, CVE-2023-20867
This vulnerability allows remote attackers to disclose sensitive information on affected installations of ManageEngine ADManager Plus. Authentication is required to exploit this vulnerability.
This vulnerability allows remote attackers to bypass authentication on affected installations of Hewlett Packard Enterprise OneView. Authentication is not required to exploit this vulnerability.
Multiple vulnerabilities were discovered in frr, the FRRouting suite of
internet protocols, while processing malformed requests and packets the BGP
daemon may have reachable assertions, NULL pointer dereference, out-of-bounds
memory access, which may lead to denial of service attack.
Two security issues have been discovered in the Open VMware Tools, which
may result in a man-in-the-middle attack or authentication bypass.
Several NULL pointer dereference flaws were discovered in Mutt, a
text-based mailreader supporting MIME, GPG, PGP and threading, which may
result in denial of service (application crash) when viewing a specially
crafted email or when composing from a specially crafted draft message.
borgbackup-1.1.18-2.el8
fix for CVE-2023-36811: spoofed archive leads to data loss
This version contains additional patches on top of 1.1.18 to fix the CVE mentioned above. The release notes for borgbackup 1.2.5+ regarding TAM authentication apply to this version as well: https://github.com/borgbackup/borg/blob/1.2.6/docs/changes.rst#pre-125-archives-spoofing-vulnerability-cve-2023-36811
borgbackup-1.1.18-2.el7
fix for CVE-2023-36811: spoofed archive leads to data loss
This version contains additional patches on top of 1.1.18 to fix the CVE mentioned above. The release notes for borgbackup 1.2.5+ regarding TAM authentication apply to this version as well: https://github.com/borgbackup/borg/blob/1.2.6/docs/changes.rst#pre-125-archives-spoofing-vulnerability-cve-2023-36811
matrix-synapse-1.80.0-5.fc37
python-matrix-common-1.3.0-7.fc37
rust-pythonize-0.19.0-1.fc37
Update matrix-synapse to v1.80.0 to fix CVE-2022-39374, CVE-2023-32323