Category Archives: Advisories

grub2-2.06-57.fc36

Read Time:24 Second

FEDORA-2022-f86e203baf

Packages in this update:

grub2-2.06-57.fc36

Update description:

put the font back in /boot for now

Yes, this bloats size by a couple meg. Hopefully this won’t cause problems for anyone and everyone can be okay with this CVE fix update.

Adjust the way we provide unicode.pf2 for post-CVE lockdown policy

Two font-related CVE updates (CVE-2022-2601 and CVE-2022-3775). For more information, see upstream’s disclosure or the patches themselves.

Read More

grub2-2.06-14.fc35

Read Time:24 Second

FEDORA-2022-7ce9378e90

Packages in this update:

grub2-2.06-14.fc35

Update description:

put the font back in /boot for now

Yes, this bloats size by a couple meg. Hopefully this won’t cause problems for anyone and everyone can be okay with this CVE fix update.

Adjust the way we provide unicode.pf2 for post-CVE lockdown policy

Two font-related CVE updates (CVE-2022-2601 and CVE-2022-3775). For more information, see upstream’s disclosure or the patches themselves.

Read More

CVE-2021-43258

Read Time:27 Second

CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot he ChurchInfo application. Once authenticated, a user can add names to their cart, and compose an email. Uploading an attachment for the email stores the attachment on the site in the /tmp_attach/ folder where it can be accessed with a GET request. There are no limitations on files that can be attached, allowing for malicious PHP code to be uploaded and interpreted by the server.

Read More

CVE-2022-23740

Read Time:21 Second

CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. To exploit this vulnerability, an attacker would need permission to create and build GitHub Pages using GitHub Actions. This vulnerability affected only version 3.7.0 of GitHub Enterprise Server and was fixed in version 3.7.1. This vulnerability was reported via the GitHub Bug Bounty program.

Read More

CVE-2009-1142

Read Time:12 Second

An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.

Read More

CVE-2009-1143

Read Time:11 Second

An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).

Read More

CVE-2021-35246

Read Time:13 Second

The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user’s network traffic could bypass the application’s use of SSL/TLS encryption and use the application as a platform for attacks against its users.

Read More