In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service and an limited out-of-bounds read.
Category Archives: Advisories
CVE-2021-34566
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.
python3.10-3.10.8-2.fc37
FEDORA-2022-a7cad6bd22
Packages in this update:
python3.10-3.10.8-2.fc37
Update description:
Security fix for CVE-2022-42919
python3.10-3.10.8-2.fc38
FEDORA-2022-bd02afca8c
Packages in this update:
python3.10-3.10.8-2.fc38
Update description:
Automatic update for python3.10-3.10.8-2.fc38.
Changelog
* Wed Nov 9 2022 Lumír Balhar <lbalhar@redhat.com> – 3.10.8-2
– Fix CVE-2022-42919
Resolves: rhbz#2138709
python3.9-3.9.15-2.fc38
FEDORA-2022-6728f16289
Packages in this update:
python3.9-3.9.15-2.fc38
Update description:
Automatic update for python3.9-3.9.15-2.fc38.
Changelog
* Wed Nov 9 2022 Lumír Balhar <lbalhar@redhat.com> – 3.9.15-2
– Fix for CVE-2022-42919
Resolves: rhbz#2138711
sysstat-12.6.0-4.fc37
FEDORA-2022-9f3af921a5
Packages in this update:
sysstat-12.6.0-4.fc37
Update description:
Security fix for CVE-2022-39377 – arithmetic overflow in allocate_structures() on 32 bit systems
sysstat-12.5.6-2.fc36
FEDORA-2022-dbe48a4bc7
Packages in this update:
sysstat-12.5.6-2.fc36
Update description:
Security fix for CVE-2022-39377 – arithmetic overflow in allocate_structures() on 32 bit systems
sysstat-12.5.6-2.fc35
FEDORA-2022-5adda2d05f
Packages in this update:
sysstat-12.5.6-2.fc35
Update description:
Security fix for CVE-2022-39377 – arithmetic overflow in allocate_structures() on 32 bit systems
USN-5720-1: Zstandard vulnerabilities
It was discovered that Zstandard was not properly managing file
permissions when generating output files. A local attacker could
possibly use this issue to cause a race condition and gain
unauthorized access to sensitive data.
USN-5719-1: OpenJDK vulnerabilities
It was discovered that OpenJDK incorrectly handled long client hostnames.
An attacker could possibly use this issue to cause the corruption of
sensitive information. (CVE-2022-21619)
It was discovered that OpenJDK incorrectly randomized DNS port numbers. A
remote attacker could possibly use this issue to perform spoofing attacks.
(CVE-2022-21624)
It was discovered that OpenJDK did not limit the number of connections
accepted from HTTP clients. An attacker could possibly use this issue to
cause a denial of service. (CVE-2022-21628)
It was discovered that OpenJDK incorrectly handled X.509 certificates. An
attacker could possibly use this issue to cause a denial of service. This
issue only affected OpenJDK 8 and OpenJDK 11. (CVE-2022-21626)
It was discovered that OpenJDK incorrectly handled cached server
connections. An attacker could possibly use this issue to perform spoofing
attacks. This issue only affected OpenJDK 11, OpenJDK 17 and OpenJDK 19.
(CVE-2022-39399)
It was discovered that OpenJDK incorrectly handled byte conversions. An
attacker could possibly use this issue to obtain sensitive information.
This issue only affected OpenJDK 11, OpenJDK 17 and OpenJDK 19.
(CVE-2022-21618)