Alexander Lakhin discovered that PostgreSQL incorrectly handled the
security restricted operation sandbox when a privileged user is maintaining
another user’s objects. An attacker having permission to create non-temp
objects can use this issue to execute arbitrary commands as the superuser.
Category Archives: Advisories
pypy3.9-7.3.9-4.3.9.fc36
FEDORA-2022-4ac2e16969
Packages in this update:
pypy3.9-7.3.9-4.3.9.fc36
Update description:
Backport fix for CVE-2021-28861
CVE-2020-26839
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.
CVE-2020-26840
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.
CVE-2020-26841
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.
CVE-2020-26842
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.
CVE-2020-26843
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.
CVE-2020-26844
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.
CVE-2020-26845
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.
python-m2r-0.2.1-12.20190604git66f4a5a.fc37 python-mistune-2.0.4-1.fc37 python-mistune08-0.8.4-7.fc37 python-sphinx-typlog-theme-0.8.0-1.fc37
FEDORA-2022-e4f5866111
Packages in this update:
python-m2r-0.2.1-12.20190604git66f4a5a.fc37
python-mistune08-0.8.4-7.fc37
python-mistune-2.0.4-1.fc37
python-sphinx-typlog-theme-0.8.0-1.fc37
Update description:
updates mistune to 2.0.4
m2r updated to pin dependency to mistune < 2
new package: python-mistune08 compatibility package, to be used by dependents that cannot use the new mistune (namely nbconvert)
new package: python-sphinx-typlog-theme, needed to build mistune 2.x documentation
Compatibility package for mistune 0.8, so we can update mistune to 2x without breaking unported dependents like nbconvert