FEDORA-EPEL-2022-40b38de6f9
Packages in this update:
xfce4-settings-4.16.5-2.el8
Update description:
Fix for CVE-2022-45062 and misc other small bugfixes.
xfce4-settings-4.16.5-2.el8
Fix for CVE-2022-45062 and misc other small bugfixes.
xfce4-settings-4.16.5-1.fc35
Fixes CVE-2022-45062 and misc other bugs.
A security issue was discovered in Chromium, which could result in the
execution of arbitrary code.
Jhead, a tool for manipulating EXIF data embedded in JPEG images, allowed
attackers to execute arbitrary OS commands by placing them in a JPEG filename
and then using the regeneration -rgt50, -autorot or -ce option. In addition a
buffer overflow error in exif.c has been addressed which could lead to a denial
of service (application crash).
brotli-1.0.9-10.el7
Security fix for CVE-2020-8927
Prior to Apache Commons Net 3.9.0, Net’s FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
Posted by Egidio Romano on Dec 03
——————————————————————
Drupal H5P Module <= 2.0.0 (isValidPackage) Zip Slip Vulnerability
——————————————————————
[-] Software Link:
https://www.drupal.org/project/h5p
[-] Affected Versions:
Version 2.0.0-alpha2 and prior versions.
Version 7.x-1.50 and prior versions.
[-] Vulnerability Description:
The vulnerability is located within the…
kernel-6.0.11-300.fc37
The 6.0.11 stable kernel update contains a number of important fixes across the tree.
kernel-6.0.11-200.fc36
The 6.0.11 stable kernel update contains a number of important fixes across the tree.
kernel-6.0.11-100.fc35
The 6.0.11 stable kernel update contains a number of important fixes across the tree.