Multiple vulnerabilities have been discovered in the Xen hypervisor, which
could result in privilege escalation, denial of service or information leaks.
Category Archives: Advisories
webkitgtk-2.38.2-1.fc37
FEDORA-2022-08fdc4138a
Packages in this update:
webkitgtk-2.38.2-1.fc37
Update description:
Fix scrolling issues in some sites having fixed background.
Fix prolonged buffering during progressive live playback.
Fix several crashes and rendering issues.
Security fixes: CVE-2022-42799, CVE-2022-42823, CVE-2022-42824
DSA-5271 libxml2 – security update
Several vulnerabilities were discovered in libxml2, a library providing
support to read, modify and write XML and HTML files.
webkit2gtk3-2.38.2-1.fc36
FEDORA-2022-ce32af66d6
Packages in this update:
webkit2gtk3-2.38.2-1.fc36
Update description:
Fix scrolling issues in some sites having fixed background.
Fix prolonged buffering during progressive live playback.
Fix several crashes and rendering issues.
Security fixes: CVE-2022-42799, CVE-2022-42823, CVE-2022-42824
webkit2gtk3-2.38.2-1.fc35
FEDORA-2022-e7726761c4
Packages in this update:
webkit2gtk3-2.38.2-1.fc35
Update description:
Fix scrolling issues in some sites having fixed background.
Fix prolonged buffering during progressive live playback.
Fix several crashes and rendering issues.
Security fixes: CVE-2022-42799, CVE-2022-42823, CVE-2022-42824
Make xdg-dbus-proxy work if host session bus address is an abstract socket.
Use a single xdg-dbus-proxy process when sandbox is enabled.
Fix high resolution video playback due to unimplemented changeType operation.
Ensure GSubprocess uses posix_spawn() again and inherit file descriptors.
Fix player getting stuck in buffering (paused) state for progressive streaming.
Do not try to preconnect on link click when link preconnect setting is disabled.
Fix close status code returned when the client closes a WebSocket in some cases.
Fix media player duration calculation.
Fix several crashes and rendering issues.
CVE-2021-39473 (hotelmanager)
Saibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and contact fields.
systemd-249.13-6.fc35
FEDORA-2022-8ac4104a02
Packages in this update:
systemd-249.13-6.fc35
Update description:
Latest stable release (various small fixes all over: #2085481, #2086166)
2139355, CVE-2022-3821
No need to log out or reboot.
CVE-2021-34055
jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
CVE-2021-39432 (diplib)
vim-9.0.828-1.fc35
FEDORA-2022-3d354ef0fb
Packages in this update:
vim-9.0.828-1.fc35
Update description:
Security fix for CVE-2022-3705
2139842 – vim upgrade broke :! for displaying terminal output