Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.
Category Archives: Advisories
samba-4.16.8-0.fc36
FEDORA-2022-7f9021ead1
Packages in this update:
samba-4.16.8-0.fc36
Update description:
Security fixes for CVE-2022-37966, CVE-2022-37967 and CVE-2022-38023
libptytty-2.0-2.el8 rxvt-unicode-9.30-3.el8
FEDORA-EPEL-2022-49c3f833e1
Packages in this update:
libptytty-2.0-2.el8
rxvt-unicode-9.30-3.el8
Update description:
Update to rxvt-unicode 9.30
This mitigates CVE-2022-4170
Introduce libptytty as a dependency since upstream split it out in 9.29+
samba-4.17.4-0.fc37
FEDORA-2022-cb92b4ea21
Packages in this update:
samba-4.17.4-0.fc37
Update description:
Update to version 4.17.4
rxvt-unicode-9.30-2.el7
FEDORA-EPEL-2022-c57a51c195
Packages in this update:
rxvt-unicode-9.30-2.el7
Update description:
Update to 9.30
Strip package back to just be the -terminfo file.
This is due to CVE-2022-4170: unaffected versions of rxvt-unicode (that is, libptytty) don’t build on epel7.
rxvt-unicode-9.30-1.el7
FEDORA-EPEL-2022-e187f1231f
Packages in this update:
rxvt-unicode-9.30-1.el7
Update description:
Update to 9.30
Strip package back to just be the -terminfo file.
This is due to CVE-2022-4170: unaffected versions of rxvt-unicode (that is, libptytty) don’t build on epel7.
USN-5783-1: Linux kernel (OEM) vulnerability
Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation
in the Linux kernel contained multiple use-after-free vulnerabilities. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code.
CVE-2021-35252 (serv-u)
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
CVE-2021-28655
The improper Input Validation vulnerability in “â€�Move folder to Trashâ€� feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
mod_auth_openidc-2.4.12.2-1.fc36
FEDORA-2022-6beaa3bd0c
Packages in this update:
mod_auth_openidc-2.4.12.2-1.fc36
Update description:
CVE-2022-23527 mod_auth_openidc: Open Redirect in oidc_validate_redirect_url() using tab character