Several vulnerabilities were discovered in libxml2, a library providing
support to read, modify and write XML and HTML files.
Category Archives: Advisories
webkit2gtk3-2.38.2-1.fc36
FEDORA-2022-ce32af66d6
Packages in this update:
webkit2gtk3-2.38.2-1.fc36
Update description:
Fix scrolling issues in some sites having fixed background.
Fix prolonged buffering during progressive live playback.
Fix several crashes and rendering issues.
Security fixes: CVE-2022-42799, CVE-2022-42823, CVE-2022-42824
webkit2gtk3-2.38.2-1.fc35
FEDORA-2022-e7726761c4
Packages in this update:
webkit2gtk3-2.38.2-1.fc35
Update description:
Fix scrolling issues in some sites having fixed background.
Fix prolonged buffering during progressive live playback.
Fix several crashes and rendering issues.
Security fixes: CVE-2022-42799, CVE-2022-42823, CVE-2022-42824
Make xdg-dbus-proxy work if host session bus address is an abstract socket.
Use a single xdg-dbus-proxy process when sandbox is enabled.
Fix high resolution video playback due to unimplemented changeType operation.
Ensure GSubprocess uses posix_spawn() again and inherit file descriptors.
Fix player getting stuck in buffering (paused) state for progressive streaming.
Do not try to preconnect on link click when link preconnect setting is disabled.
Fix close status code returned when the client closes a WebSocket in some cases.
Fix media player duration calculation.
Fix several crashes and rendering issues.
CVE-2021-39473 (hotelmanager)
Saibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and contact fields.
systemd-249.13-6.fc35
FEDORA-2022-8ac4104a02
Packages in this update:
systemd-249.13-6.fc35
Update description:
Latest stable release (various small fixes all over: #2085481, #2086166)
2139355, CVE-2022-3821
No need to log out or reboot.
CVE-2021-34055
jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
CVE-2021-39432 (diplib)
vim-9.0.828-1.fc35
FEDORA-2022-3d354ef0fb
Packages in this update:
vim-9.0.828-1.fc35
Update description:
Security fix for CVE-2022-3705
2139842 – vim upgrade broke :! for displaying terminal output
CVE-2021-41574
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further investigation showed that it was not a vulnerability. Notes: none.
CVE-2021-34686
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further investigation showed that it was not a vulnerability. Notes: none.