Post Content
Category Archives: Advisories
USN-5686-1: Git vulnerabilities
Cory Snider discovered that Git incorrectly handled certain symbolic links.
An attacker could possibly use this issue to cause an unexpected behaviour.
(CVE-2022-39253)
Kevin Backhouse discovered that Git incorrectly handled certain command strings.
An attacker could possibly use this issue to arbitrary code execution.
(CVE-2022-39260)
jhead-3.06.0.1-5.el7
FEDORA-EPEL-2022-204b242845
Packages in this update:
jhead-3.06.0.1-5.el7
Update description:
added patches to fix CVE-2022-41751
jhead-3.06.0.1-5.el8
FEDORA-EPEL-2022-6cfebbe90a
Packages in this update:
jhead-3.06.0.1-5.el8
Update description:
added patches to fix CVE-2022-41751
jhead-3.06.0.1-5.el9
FEDORA-EPEL-2022-5761039b36
Packages in this update:
jhead-3.06.0.1-5.el9
Update description:
added patches to fix CVE-2022-41751
jhead-3.06.0.1-5.fc35
FEDORA-2022-1d9133bc8e
Packages in this update:
jhead-3.06.0.1-5.fc35
Update description:
added patches to fix CVE-2022-41751
CVE-2020-15853
supybot-fedora implements the command ‘refresh’, that refreshes the cache of all users from FAS. This takes quite a while to run, and zodbot stops responding to requests during this time.
USN-5685-1: FRR vulnerabilities
It was discovered that FRR incorrectly handled parsing certain BGP
messages. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service. (CVE-2022-37032)
It was discovered that FRR incorrectly handled processing certain BGP
messages. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service, obtain sensitive information,
or execute arbitrary code. (CVE-2022-37035)
jhead-3.06.0.1-5.fc36
FEDORA-2022-61ec901852
Packages in this update:
jhead-3.06.0.1-5.fc36
Update description:
added patches to fix CVE-2022-41751
CVE-2021-3305 (feishu)
Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.