FEDORA-2022-3d7e44dbd5
Packages in this update:
python3.12-3.12.0~a3-1.fc37
Update description:
Update to 3.12.0a3
python3.12-3.12.0~a3-1.fc37
Update to 3.12.0a3
A vulnerability was found in annyshow DuxCMS 2.1. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-215116.
A vulnerability was found in annyshow DuxCMS 2.1. It has been classified as problematic. This affects an unknown part of the file admin.php&r=article/AdminContent/edit of the component Article Handler. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215115.
python3.10-3.10.9-1.fc36
python3-docs-3.10.9-1.fc36
Update to 3.10.9
python3.10-3.10.9-1.fc37
Update to 3.10.9
python3.9-3.9.16-1.fc35
Update to 3.9.16
python3.9-3.9.16-1.fc36
Update to 3.9.16
python3.9-3.9.16-1.fc37
Update to 3.9.16
Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from `xmlTextReaderExpand` in the method `Nokogiri::XML::Reader#attribute_hash`. This can lead to a null pointer exception when invalid markup is being parsed. For applications using `XML::Reader` to parse untrusted inputs, this may potentially be a vector for a denial of service attack. Users are advised to upgrade to Nokogiri `>= 1.13.10`. Users may be able to search their code for calls to either `XML::Reader#attributes` or `XML::Reader#attribute_hash` to determine if they are affected.
It was discovered that Heimdal did not properly manage memory when
normalizing Unicode. An attacker could possibly use this issue to
cause a denial of service.