In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.
Category Archives: Advisories
python3.10-3.10.8-2.fc37
FEDORA-2022-a7cad6bd22
Packages in this update:
python3.10-3.10.8-2.fc37
Update description:
Security fix for CVE-2022-42919
python3.10-3.10.8-2.fc38
FEDORA-2022-bd02afca8c
Packages in this update:
python3.10-3.10.8-2.fc38
Update description:
Automatic update for python3.10-3.10.8-2.fc38.
Changelog
* Wed Nov 9 2022 Lumír Balhar <lbalhar@redhat.com> – 3.10.8-2
– Fix CVE-2022-42919
Resolves: rhbz#2138709
python3.9-3.9.15-2.fc38
FEDORA-2022-6728f16289
Packages in this update:
python3.9-3.9.15-2.fc38
Update description:
Automatic update for python3.9-3.9.15-2.fc38.
Changelog
* Wed Nov 9 2022 Lumír Balhar <lbalhar@redhat.com> – 3.9.15-2
– Fix for CVE-2022-42919
Resolves: rhbz#2138711
sysstat-12.6.0-4.fc37
FEDORA-2022-9f3af921a5
Packages in this update:
sysstat-12.6.0-4.fc37
Update description:
Security fix for CVE-2022-39377 – arithmetic overflow in allocate_structures() on 32 bit systems
sysstat-12.5.6-2.fc36
FEDORA-2022-dbe48a4bc7
Packages in this update:
sysstat-12.5.6-2.fc36
Update description:
Security fix for CVE-2022-39377 – arithmetic overflow in allocate_structures() on 32 bit systems
sysstat-12.5.6-2.fc35
FEDORA-2022-5adda2d05f
Packages in this update:
sysstat-12.5.6-2.fc35
Update description:
Security fix for CVE-2022-39377 – arithmetic overflow in allocate_structures() on 32 bit systems
USN-5720-1: Zstandard vulnerabilities
It was discovered that Zstandard was not properly managing file
permissions when generating output files. A local attacker could
possibly use this issue to cause a race condition and gain
unauthorized access to sensitive data.
USN-5719-1: OpenJDK vulnerabilities
It was discovered that OpenJDK incorrectly handled long client hostnames.
An attacker could possibly use this issue to cause the corruption of
sensitive information. (CVE-2022-21619)
It was discovered that OpenJDK incorrectly randomized DNS port numbers. A
remote attacker could possibly use this issue to perform spoofing attacks.
(CVE-2022-21624)
It was discovered that OpenJDK did not limit the number of connections
accepted from HTTP clients. An attacker could possibly use this issue to
cause a denial of service. (CVE-2022-21628)
It was discovered that OpenJDK incorrectly handled X.509 certificates. An
attacker could possibly use this issue to cause a denial of service. This
issue only affected OpenJDK 8 and OpenJDK 11. (CVE-2022-21626)
It was discovered that OpenJDK incorrectly handled cached server
connections. An attacker could possibly use this issue to perform spoofing
attacks. This issue only affected OpenJDK 11, OpenJDK 17 and OpenJDK 19.
(CVE-2022-39399)
It was discovered that OpenJDK incorrectly handled byte conversions. An
attacker could possibly use this issue to obtain sensitive information.
This issue only affected OpenJDK 11, OpenJDK 17 and OpenJDK 19.
(CVE-2022-21618)
Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Google Chrome is a web browser used to access the internet. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.