Category Archives: Advisories

rxvt-unicode-9.30-2.el7

Read Time:15 Second

FEDORA-EPEL-2022-c57a51c195

Packages in this update:

rxvt-unicode-9.30-2.el7

Update description:

Update to 9.30
Strip package back to just be the -terminfo file.
This is due to CVE-2022-4170: unaffected versions of rxvt-unicode (that is, libptytty) don’t build on epel7.

Read More

rxvt-unicode-9.30-1.el7

Read Time:15 Second

FEDORA-EPEL-2022-e187f1231f

Packages in this update:

rxvt-unicode-9.30-1.el7

Update description:

Update to 9.30
Strip package back to just be the -terminfo file.
This is due to CVE-2022-4170: unaffected versions of rxvt-unicode (that is, libptytty) don’t build on epel7.

Read More

CVE-2021-28655

Read Time:11 Second

The improper Input Validation vulnerability in “â€�Move folder to Trashâ€� feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

Read More

mod_auth_openidc-2.4.12.2-1.fc38

Read Time:22 Second

FEDORA-2022-105be2997e

Packages in this update:

mod_auth_openidc-2.4.12.2-1.fc38

Update description:

Automatic update for mod_auth_openidc-2.4.12.2-1.fc38.

Changelog

* Fri Dec 16 2022 Tomas Halman <thalman@redhat.com> – 2.4.12.2-1
Rebase to 2.4.12.2 version
– Resolves: rhbz#2153658 – CVE-2022-23527 mod_auth_openidc: Open Redirect in
oidc_validate_redirect_url() using tab character

Read More

fasterxml-oss-parent-49-2.fc38 jackson-annotations-2.14.1-3.fc38 jackson-bom-2.14.1-1.fc38 jackson-core-2.14.1-1.fc38 jackson-databind-2.14.1-1.fc38 jackson-jaxrs-providers-2.14.1-1.fc38 jackson-modules-base-2.14.1-1.fc38 jackson-parent-2.14-1.fc38

Read Time:23 Second

FEDORA-2022-6aa833b95f

Packages in this update:

fasterxml-oss-parent-49-2.fc38
jackson-annotations-2.14.1-3.fc38
jackson-bom-2.14.1-1.fc38
jackson-core-2.14.1-1.fc38
jackson-databind-2.14.1-1.fc38
jackson-jaxrs-providers-2.14.1-1.fc38
jackson-modules-base-2.14.1-1.fc38
jackson-parent-2.14-1.fc38

Update description:

Rebase Jackson packages to the latest upstream version (2.14.1)

Read More