USN-5705-1: LibTIFF vulnerabilities
Chintan Shah discovered that LibTIFF incorrectly handled memory in certain conditions. An attacker could trick a user into processing a specially crafted image file and...
USN-5706-1: Linux kernel (Azure CVM) vulnerabilities
It was discovered that the BPF verifier in the Linux kernel did not properly handle internal data structures. A local attacker could use this to...
ghc-cmark-gfm-0.2.5-1.fc37
FEDORA-2022-dc6d6d9d6c Packages in this update: ghc-cmark-gfm-0.2.5-1.fc37 Update description: updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209 Read More
azure-cli-2.41.0-2.fc38
FEDORA-2022-ea9c1a9b20 Packages in this update: azure-cli-2.41.0-2.fc38 Update description: Automatic update for azure-cli-2.41.0-2.fc38. Changelog * Thu Oct 27 2022 Major Hayden <major@redhat.com> 2.41.0-2 - Fix az...
USN-5704-1: DBus vulnerabilities
It was discovered that DBus incorrectly handled messages with invalid type signatures. A local attacker could possibly use this issue to cause DBus to crash,...
python3.9-3.9.15-1.fc35
FEDORA-2022-523c1c8017 Packages in this update: python3.9-3.9.15-1.fc35 Update description: The release you're looking at is Python 3.9.15, a security bugfix release for the legacy 3.9 series....
curl-7.85.0-2.fc37
FEDORA-2022-e9d65906c4 Packages in this update: curl-7.85.0-2.fc37 Update description: url: use IDN decoded names for HSTS checks (CVE-2022-42916) http_proxy: restore the protocol pointer on error (CVE-2022-42915)...
curl-7.79.1-7.fc35
FEDORA-2022-39688a779d Packages in this update: curl-7.79.1-7.fc35 Update description: url: use IDN decoded names for HSTS checks (CVE-2022-42916) http_proxy: restore the protocol pointer on error (CVE-2022-42915)...
curl-7.82.0-9.fc36
FEDORA-2022-01ffde372c Packages in this update: curl-7.82.0-9.fc36 Update description: url: use IDN decoded names for HSTS checks (CVE-2022-42916) http_proxy: restore the protocol pointer on error (CVE-2022-42915)...
ZDI-22-1489: Delta Industrial Automation InfraSuite Device Master WriteConfiguration Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Delta Industrial Automation InfraSuite Device Master. Authentication is not required to exploit this...