In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path traversal in the camera-file module.
Category Archives: Advisories
etcd-3.5.5-1.fc38~bootstrap
FEDORA-2022-28d38313c8
Packages in this update:
etcd-3.5.5-1.fc38~bootstrap
Update description:
Automatic update for etcd-3.5.5-1.fc38~bootstrap.
Changelog
* Sun Nov 6 2022 Robert-André Mauchin <zebob.m@gmail.com> 3.5.5-1
– Bootstrap
* Wed Aug 10 2022 Maxwell G <gotmax@e.email> 3.5.0-11
– Rebuild to fix FTBFS
* Wed Aug 10 2022 Maxwell G <gotmax@e.email> 3.5.0-10
– Rebuild to fix FTBFS
* Thu Jul 21 2022 Fedora Release Engineering <releng@fedoraproject.org> 3.5.0-9
– Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Tue Jul 19 2022 Maxwell G <gotmax@e.email> 3.5.0-8
– Rebuild for
CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang
* Thu Jun 23 2022 Maxwell G <gotmax@e.email> 3.5.0-7
– Rebuild to mitigate CVE-2022-21698 (rhbz#2067400).
* Sun Jun 19 2022 Robert-André Mauchin <zebob.m@gmail.com> 3.5.0-6
– Rebuilt for CVE-2022-1996, CVE-2022-24675, CVE-2022-28327,
CVE-2022-27191, CVE-2022-29526, CVE-2022-30629
* Thu Jan 20 2022 Fedora Release Engineering <releng@fedoraproject.org> 3.5.0-5
– Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
android-tools-33.0.3p1-2.fc35
FEDORA-2022-7f14b7d45e
Packages in this update:
android-tools-33.0.3p1-2.fc35
Update description:
Merge branch ‘rawhide’ into f35
Security fix for CVE-2022-20128 CVE-2022-3168
android-tools-33.0.3p1-1.fc36
FEDORA-2022-9a9a638d09
Packages in this update:
android-tools-33.0.3p1-1.fc36
Update description:
Update to 33.0.3p1
Security fix for CVE-2022-20128 CVE-2022-3168
android-tools-33.0.3p1-1.fc37
FEDORA-2022-6716cd0da2
Packages in this update:
android-tools-33.0.3p1-1.fc37
Update description:
Update to 33.0.3p1
Security fix for CVE-2022-20128 CVE-2022-3168
DSA-5272 xen – security update
Multiple vulnerabilities have been discovered in the Xen hypervisor, which
could result in privilege escalation, denial of service or information leaks.
webkitgtk-2.38.2-1.fc37
FEDORA-2022-08fdc4138a
Packages in this update:
webkitgtk-2.38.2-1.fc37
Update description:
Fix scrolling issues in some sites having fixed background.
Fix prolonged buffering during progressive live playback.
Fix several crashes and rendering issues.
Security fixes: CVE-2022-42799, CVE-2022-42823, CVE-2022-42824
DSA-5271 libxml2 – security update
Several vulnerabilities were discovered in libxml2, a library providing
support to read, modify and write XML and HTML files.
webkit2gtk3-2.38.2-1.fc36
FEDORA-2022-ce32af66d6
Packages in this update:
webkit2gtk3-2.38.2-1.fc36
Update description:
Fix scrolling issues in some sites having fixed background.
Fix prolonged buffering during progressive live playback.
Fix several crashes and rendering issues.
Security fixes: CVE-2022-42799, CVE-2022-42823, CVE-2022-42824
webkit2gtk3-2.38.2-1.fc35
FEDORA-2022-e7726761c4
Packages in this update:
webkit2gtk3-2.38.2-1.fc35
Update description:
Fix scrolling issues in some sites having fixed background.
Fix prolonged buffering during progressive live playback.
Fix several crashes and rendering issues.
Security fixes: CVE-2022-42799, CVE-2022-42823, CVE-2022-42824
Make xdg-dbus-proxy work if host session bus address is an abstract socket.
Use a single xdg-dbus-proxy process when sandbox is enabled.
Fix high resolution video playback due to unimplemented changeType operation.
Ensure GSubprocess uses posix_spawn() again and inherit file descriptors.
Fix player getting stuck in buffering (paused) state for progressive streaming.
Do not try to preconnect on link click when link preconnect setting is disabled.
Fix close status code returned when the client closes a WebSocket in some cases.
Fix media player duration calculation.
Fix several crashes and rendering issues.