FEDORA-2022-7090749bf4
Packages in this update:
efl-1.26.3-1.fc37
enlightenment-0.25.4-1.fc37
Update description:
Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706
efl-1.26.3-1.fc37
enlightenment-0.25.4-1.fc37
Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706
efl-1.26.3-1.fc36
enlightenment-0.25.4-1.fc36
Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706
unbound-1.16.3-1.fc35
Fix CVE-2022-3204
unbound-1.16.3-1.fc36
Fix CVE-2022-3204
unbound-1.16.3-1.fc37
Fix CVE-2022-3204
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iCloud for Windows 11.4, iOS 14.0 and iPadOS 14.0, watchOS 7.0, tvOS 14.0, iCloud for Windows 7.21, iTunes for Windows 12.10.9. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose memory contents.
An internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. The reference count is maintained as an int; on LP64 systems this can cause the reference count to overflow if the client creates a large number of wl_shm buffer objects, or if it can coerce the server to create a large number of external references to the buffer storage. With the reference count overflowing, a use-after-free can be constructed on the wl_shm_pool tracking structure, where values may be incremented or decremented; it may also be possible to construct a limited oracle to leak 4 bytes of server-side memory to the attacking client at a time.
Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has access to the network to perform a MITM attack in order to obtain the user´s credentials.
hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.
This vulnerability allows local attackers to disclose sensitive information on affected installations of Trend Micro Deep Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.