FEDORA-2022-17bc21cf38
Packages in this update:
python3.6-3.6.15-14.fc38
Update description:
Security fix for CVE-2022-37454.
python3.6-3.6.15-14.fc38
Security fix for CVE-2022-37454.
It was discovered that WavPack was not properly performing checks
when dealing with memory. If a user were tricked into decompressing a
specially crafted WavPack Audio File, an attacker could possibly use
this issue to cause the WavPack decompressor to crash, resulting in a
denial of service.
nginx-1.20-3620221110171337.5e5ad4a0
Backported fixes for CVE-2022-41741 and CVE-2022-41742.
nginx-1.20-3520221110171337.f27b74a8
Backported fixes for CVE-2022-41741 and CVE-2022-41742.
nginx-1.20-3720221110171337.9e842022
Backported fixes for CVE-2022-41741 and CVE-2022-41742.
nginx-1.20.1-10.el7
Backported fixes for CVE-2022-41741 and CVE-2022-41742.
USN-5709-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2022-42927,
CVE-2022-42928, CVE-2022-42929, CVE-2022-42930, CVE-2022-42932)
It was discovered that Firefox saved usernames to a plaintext file. A
local user could potentially exploit this to obtain sensitive information.
(CVE-2022-42931)
Multiple vulnerabilities have been discovered in Apple Products, the most severe of which could allow for arbitrary code execution.
macOS Ventura is the 19th and current major release of macOS
iOS is a mobile operating system for mobile devices, including the iPhone, iPad, and iPod touch.
iPadOS is the successor to iOS 12 and is a mobile operating system for iPads.
Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.