FEDORA-2022-cae8089f93
Packages in this update:
python3.6-3.6.15-14.fc37
Update description:
Security fix for CVE-2022-37454.
python3.6-3.6.15-14.fc37
Security fix for CVE-2022-37454.
python3.6-3.6.15-14.fc38
Security fix for CVE-2022-37454.
It was discovered that WavPack was not properly performing checks
when dealing with memory. If a user were tricked into decompressing a
specially crafted WavPack Audio File, an attacker could possibly use
this issue to cause the WavPack decompressor to crash, resulting in a
denial of service.
nginx-1.20-3620221110171337.5e5ad4a0
Backported fixes for CVE-2022-41741 and CVE-2022-41742.
nginx-1.20-3520221110171337.f27b74a8
Backported fixes for CVE-2022-41741 and CVE-2022-41742.
nginx-1.20-3720221110171337.9e842022
Backported fixes for CVE-2022-41741 and CVE-2022-41742.
nginx-1.20.1-10.el7
Backported fixes for CVE-2022-41741 and CVE-2022-41742.
USN-5709-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2022-42927,
CVE-2022-42928, CVE-2022-42929, CVE-2022-42930, CVE-2022-42932)
It was discovered that Firefox saved usernames to a plaintext file. A
local user could potentially exploit this to obtain sensitive information.
(CVE-2022-42931)