Category Archives: Advisories

xen-4.15.4-1.fc35

Read Time:13 Second

FEDORA-2022-53a4a5dd11

Packages in this update:

xen-4.15.4-1.fc35

Update description:

update to xen-4.15.4
adjust xen.canonicalize.patch
remove or adjust patches now included or superceded upstream
x86: Multiple speculative security issues [XSA-422, CVE-2022-23824]

Read More

thunderbird-102.5.0-1.fc35

Read Time:25 Second

FEDORA-2022-927df621df

Packages in this update:

thunderbird-102.5.0-1.fc35

Update description:

Update to 102.5.0 ;
https://www.mozilla.org/en-US/security/advisories/mfsa2022-49/ ;
https://www.thunderbird.net/en-US/thunderbird/102.5.0/releasenotes/ ;
https://www.thunderbird.net/en-US/thunderbird/102.4.2/releasenotes/

Update to 102.4.1 ; https://www.thunderbird.net/en-US/thunderbird/102.4.1/releasenotes/

Update to 102.4.0 ; https://www.thunderbird.net/en-US/thunderbird/102.4.0/releasenotes/

Read More

heimdal-7.7.1-1.el7

Read Time:34 Second

FEDORA-EPEL-2022-30fd5a80a8

Packages in this update:

heimdal-7.7.1-1.el7

Update description:

This release fixes the following Security Vulnerabilities:

CVE-2022-42898 PAC parse integer overflows
CVE-2022-3437 Overflows and non-constant time leaks in DES{,3} and arcfour
CVE-2022-41916 Fix Unicode normalization read of 1 bytes past end of array
CVE-2021-44758 NULL dereference DoS in SPNEGO acceptors
CVE-2021-3671 A null pointer de-reference when handling missing sname in TGS-REQ
CVE-2022-44640 Heimdal KDC: invalid free in ASN.1 codec

Note that CVE-2022-44640 is a severe vulnerability, possibly a 10.0 on the Common Vulnerability Scoring System (CVSS) v3.

Read More

heimdal-7.7.1-1.el8

Read Time:34 Second

FEDORA-EPEL-2022-be3947859f

Packages in this update:

heimdal-7.7.1-1.el8

Update description:

This release fixes the following Security Vulnerabilities:

CVE-2022-42898 PAC parse integer overflows
CVE-2022-3437 Overflows and non-constant time leaks in DES{,3} and arcfour
CVE-2022-41916 Fix Unicode normalization read of 1 bytes past end of array
CVE-2021-44758 NULL dereference DoS in SPNEGO acceptors
CVE-2021-3671 A null pointer de-reference when handling missing sname in TGS-REQ
CVE-2022-44640 Heimdal KDC: invalid free in ASN.1 codec

Note that CVE-2022-44640 is a severe vulnerability, possibly a 10.0 on the Common Vulnerability Scoring System (CVSS) v3.

Read More

heimdal-7.7.1-1.fc35

Read Time:34 Second

FEDORA-2022-c6e50d409b

Packages in this update:

heimdal-7.7.1-1.fc35

Update description:

This release fixes the following Security Vulnerabilities:

CVE-2022-42898 PAC parse integer overflows
CVE-2022-3437 Overflows and non-constant time leaks in DES{,3} and arcfour
CVE-2022-41916 Fix Unicode normalization read of 1 bytes past end of array
CVE-2021-44758 NULL dereference DoS in SPNEGO acceptors
CVE-2021-3671 A null pointer de-reference when handling missing sname in TGS-REQ
CVE-2022-44640 Heimdal KDC: invalid free in ASN.1 codec

Note that CVE-2022-44640 is a severe vulnerability, possibly a 10.0 on the Common Vulnerability Scoring System (CVSS) v3.

Read More

heimdal-7.7.1-1.fc36

Read Time:34 Second

FEDORA-2022-fbca84b938

Packages in this update:

heimdal-7.7.1-1.fc36

Update description:

This release fixes the following Security Vulnerabilities:

CVE-2022-42898 PAC parse integer overflows
CVE-2022-3437 Overflows and non-constant time leaks in DES{,3} and arcfour
CVE-2022-41916 Fix Unicode normalization read of 1 bytes past end of array
CVE-2021-44758 NULL dereference DoS in SPNEGO acceptors
CVE-2021-3671 A null pointer de-reference when handling missing sname in TGS-REQ
CVE-2022-44640 Heimdal KDC: invalid free in ASN.1 codec

Note that CVE-2022-44640 is a severe vulnerability, possibly a 10.0 on the Common Vulnerability Scoring System (CVSS) v3.

Read More

heimdal-7.7.1-1.fc37

Read Time:34 Second

FEDORA-2022-ea403b373f

Packages in this update:

heimdal-7.7.1-1.fc37

Update description:

This release fixes the following Security Vulnerabilities:

CVE-2022-42898 PAC parse integer overflows
CVE-2022-3437 Overflows and non-constant time leaks in DES{,3} and arcfour
CVE-2022-41916 Fix Unicode normalization read of 1 bytes past end of array
CVE-2021-44758 NULL dereference DoS in SPNEGO acceptors
CVE-2021-3671 A null pointer de-reference when handling missing sname in TGS-REQ
CVE-2022-44640 Heimdal KDC: invalid free in ASN.1 codec

Note that CVE-2022-44640 is a severe vulnerability, possibly a 10.0 on the Common Vulnerability Scoring System (CVSS) v3.

Read More