FEDORA-2022-a7cad6bd22
Packages in this update:
python3.10-3.10.8-2.fc37
Update description:
Security fix for CVE-2022-42919
python3.10-3.10.8-2.fc37
Security fix for CVE-2022-42919
python3.10-3.10.8-2.fc38
Automatic update for python3.10-3.10.8-2.fc38.
* Wed Nov 9 2022 Lumír Balhar <lbalhar@redhat.com> – 3.10.8-2
– Fix CVE-2022-42919
Resolves: rhbz#2138709
python3.9-3.9.15-2.fc38
Automatic update for python3.9-3.9.15-2.fc38.
* Wed Nov 9 2022 Lumír Balhar <lbalhar@redhat.com> – 3.9.15-2
– Fix for CVE-2022-42919
Resolves: rhbz#2138711
sysstat-12.6.0-4.fc37
Security fix for CVE-2022-39377 – arithmetic overflow in allocate_structures() on 32 bit systems
sysstat-12.5.6-2.fc36
Security fix for CVE-2022-39377 – arithmetic overflow in allocate_structures() on 32 bit systems
sysstat-12.5.6-2.fc35
Security fix for CVE-2022-39377 – arithmetic overflow in allocate_structures() on 32 bit systems
It was discovered that Zstandard was not properly managing file
permissions when generating output files. A local attacker could
possibly use this issue to cause a race condition and gain
unauthorized access to sensitive data.
It was discovered that OpenJDK incorrectly handled long client hostnames.
An attacker could possibly use this issue to cause the corruption of
sensitive information. (CVE-2022-21619)
It was discovered that OpenJDK incorrectly randomized DNS port numbers. A
remote attacker could possibly use this issue to perform spoofing attacks.
(CVE-2022-21624)
It was discovered that OpenJDK did not limit the number of connections
accepted from HTTP clients. An attacker could possibly use this issue to
cause a denial of service. (CVE-2022-21628)
It was discovered that OpenJDK incorrectly handled X.509 certificates. An
attacker could possibly use this issue to cause a denial of service. This
issue only affected OpenJDK 8 and OpenJDK 11. (CVE-2022-21626)
It was discovered that OpenJDK incorrectly handled cached server
connections. An attacker could possibly use this issue to perform spoofing
attacks. This issue only affected OpenJDK 11, OpenJDK 17 and OpenJDK 19.
(CVE-2022-39399)
It was discovered that OpenJDK incorrectly handled byte conversions. An
attacker could possibly use this issue to obtain sensitive information.
This issue only affected OpenJDK 11, OpenJDK 17 and OpenJDK 19.
(CVE-2022-21618)
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Google Chrome is a web browser used to access the internet. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
flatpak-runtime-f37-3720221025175532.3
flatpak-sdk-f37-3720221025175532.3
Updated flatpak runtime and SDK, including latest Fedora 37 security and bug-fix errata.