FEDORA-2022-471e14677d
Packages in this update:
python-virtualbmc-3.0.0-1.fc37
Update description:
Security fix for CVE-2022-44020
python-virtualbmc-3.0.0-1.fc37
Security fix for CVE-2022-44020
python-slixmpp-1.7.1-1.el8
Security fix for CVE-2022-45197
varnish-6.0-3720221118143100.9e842022
New upstream release varnish-6.0.11: A security release. Includes fix for CVE-2022-45060 aka VSV00011. See https://varnish-cache.org/security/VSV00011.html for details.
varnish-6.0-3520221118143100.f27b74a8
New upstream release varnish-6.0.11: A security release. Includes fix for CVE-2022-45060 aka VSV00011. See https://varnish-cache.org/security/VSV00011.html for details.
varnish-6.0-3620221118143100.5e5ad4a0
New upstream release varnish-6.0.11: A security release. Includes fix for CVE-2022-45060 aka VSV00011. See https://varnish-cache.org/security/VSV00011.html for details.
Greg Hudson discovered integer overflow flaws in the PAC parsing in
krb5, the MIT implementation of Kerberos, which may result in remote
code execution (in a KDC, kadmin, or GSS or Kerberos application server
process), information exposure (to a cross-realm KDC acting
maliciously), or denial of service (KDC or kadmind process crash).
It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.
The SEPPmail solution is vulnerable to a Cross-Site Scripting vulnerability (XSS), because user input is not correctly encoded in HTML attributes when returned by the server.SEPPmail 11.1.10 allows XSS via a recipient address.