Category Archives: Advisories

flatpak-runtime-f37-3720221117153339.5 flatpak-sdk-f37-3720221117153339.5

Read Time:10 Second

FEDORA-FLATPAK-2023-b7f75566a0

Packages in this update:

flatpak-runtime-f37-3720221117153339.5
flatpak-sdk-f37-3720221117153339.5

Update description:

Updated flatpak runtime and SDK, including latest Fedora 37 security and bug-fix errata.

Read More

CVE-2012-10003

Read Time:20 Second

A vulnerability, which was classified as problematic, has been found in ahmyi RivetTracker. This issue affects some unknown processing. The manipulation of the argument $_SERVER[‘PHP_SELF’] leads to cross site scripting. The attack may be initiated remotely. The name of the patch is f053c5cc2bc44269b0496b5f275e349928a92ef9. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217271.

Read More

qemu-6.2.0-17.fc36

Read Time:15 Second

FEDORA-2023-c8a60f6f80

Packages in this update:

qemu-6.2.0-17.fc36

Update description:

ati-vga: out-of-bounds write in ati_2d_blt (CVE-2021-3638) (rhbz#1979882)
qxl: qxl_phys2virt unsafe address translation (CVE-2022-4144) (rhbz#2148542)
linux-user: default to -cpu max (rhbz#2121700)

Read More

USN-5784-1: usbredir vulnerability

Read Time:15 Second

It was discovered that usbredir incorrectly handled memory when
serializing large amounts of data in the case of a slow or blocked
destination. An attacker could possibly use this issue to cause
applications using usbredir to crash, resulting in a denial of
service, or possibly execute arbitrary code.

Read More

CVE-2013-10007

Read Time:24 Second

A vulnerability classified as problematic has been found in ethitter WP-Print-Friendly up to 0.5.2. This affects an unknown part of the file wp-print-friendly.php. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. Upgrading to version 0.5.3 is able to address this issue. The name of the patch is 437787292670c20b4abe20160ebbe8428187f2b4. It is recommended to upgrade the affected component. The identifier VDB-217269 was assigned to this vulnerability.

Read More

CVE-2012-10002

Read Time:21 Second

A vulnerability was found in ahmyi RivetTracker. It has been declared as problematic. Affected by this vulnerability is the function changeColor of the file css.php. The manipulation of the argument set_css leads to cross site scripting. The attack can be launched remotely. The name of the patch is 45a0f33876d58cb7e4a0f17da149e58fc893b858. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217267.

Read More

CVE-2014-125035

Read Time:18 Second

A vulnerability classified as problematic was found in Jobs-Plugin. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The name of the patch is b8a56718b1d42834c6ec51d9c489c5dc20471d7b. It is recommended to apply a patch to fix this issue. The identifier VDB-217189 was assigned to this vulnerability.

Read More

golang-github-docker-22.06.0~beta.0-7.fc37 golang-github-graylog2-gelf-2.0.0-6.20201111git1550ee6.fc37

Read Time:17 Second

FEDORA-2023-6b9e2a6534

Packages in this update:

golang-github-docker-22.06.0~beta.0-7.fc37
golang-github-graylog2-gelf-2.0.0-6.20201111git1550ee6.fc37

Update description:

golang-github-graylog2-gelf-2.0.0-5.20201111git1550ee6.fc37 was not in F37 because was override with golang-github-graylog2-gelf-2.0.0-4.20190627git7ebf4f5.fc37

Read More