The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user’s network traffic could bypass the application’s use of SSL/TLS encryption and use the application as a platform for attacks against its users.
Category Archives: Advisories
USN-5739-1: MariaDB vulnerabilities
Several security issues were discovered in MariaDB and this update
includes new upstream MariaDB versions to fix these issues.
MariaDB has been updated to 10.3.37 in Ubuntu 20.04 LTS and to 10.6.11
in Ubuntu 22.04 LTS and Ubuntu 22.10.
In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.
USN-5638-3: Expat vulnerability
USN-5638-1 fixed a vulnerability in Expat. This update provides
the corresponding updates for Ubuntu 16.04 ESM, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-43680)
This update also fixes a minor regression introduced in
Ubuntu 18.04 LTS.
We apologize for the inconvenience.
Original advisory details:
Rhodri James discovered that Expat incorrectly handled memory when
processing certain malformed XML files. An attacker could possibly
use this issue to cause a crash or execute arbitrary code.
mariadb-10.5-3620221121091939.5e5ad4a0
FEDORA-MODULAR-2022-d8e8a4ba1e
Packages in this update:
mariadb-10.5-3620221121091939.5e5ad4a0
Update description:
MariaDB 10.5.18 & Galera 26.4.13
Release notes:
mariadb-10.5-3720221121091939.9e842022
FEDORA-MODULAR-2022-5bfccade30
Packages in this update:
mariadb-10.5-3720221121091939.9e842022
Update description:
MariaDB 10.5.18 & Galera 26.4.13
Release notes:
mariadb-10.5-3520221121091939.f27b74a8
FEDORA-MODULAR-2022-87965d9e1f
Packages in this update:
mariadb-10.5-3520221121091939.f27b74a8
Update description:
MariaDB 10.5.18 & Galera 26.4.13
Release notes:
USN-5737-1: APR-util vulnerability
It was discovered that APR-util did not properly handle memory when using
SDBM database files. A local attacker with write access to the database
can make a program or process using these functions crash, and cause a
denial of service.
firefox-107.0-3.fc37
FEDORA-2022-b95f6a2db1
Packages in this update:
firefox-107.0-3.fc37
Update description:
New upstream version (107.0)
firefox-107.0-3.fc35
FEDORA-2022-269b27bdbc
Packages in this update:
firefox-107.0-3.fc35
Update description:
New upstream version (107.0)
firefox-107.0-3.fc36
FEDORA-2022-2321894a60
Packages in this update:
firefox-107.0-3.fc36
Update description:
New upstream version (107.0)