FEDORA-2022-ed0eeb6a20
Packages in this update:
python-lxml-4.7.1-3.fc36
Update description:
Security fix for CVE-2022-2309
python-lxml-4.7.1-3.fc36
Security fix for CVE-2022-2309
python-lxml-4.9.1-1.fc37
Update to 4.9.1
python-engineio-4.3.4-2.fc38
Automatic update for python-engineio-4.3.4-2.fc38.
* Thu Sep 15 2022 Benjamin A. Beasley <code@musicinmybrain.net> 4.3.4-2
– Don’t ship package-lock.json files with the examples
– This keeps from having automated bugs filed for irrelevant CVE’s in NPM
packages that are mentioned there. See RHBZ#2127005.
dokuwiki-20200729a-1.fc35
Update to bugfix/security release 2022-07-29a. Includes security fix for CVE-2022-3123.
python-lxml-4.9.1-1.fc38
Automatic update for python-lxml-4.9.1-1.fc38.
* Wed Sep 14 2022 Charalampos Stratakis <cstratak@redhat.com> – 4.9.1-1
– Update to 4.9.1
– Fix for CVE-2022-2309
– Resolves: rhbz#2107571, rhbz#2110131
dokuwiki-20200729a-1.fc36
Update to bugfix/security release 2022-07-29a. Includes security fix for CVE-2022-3123.
dokuwiki-20220731a-1.fc37
Update to new stable release, v2022-07-31a “Igor”. Includes security fix for CVE-2022-3123.
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.
Multiple security issues were discovered in Chromium, which could result
in the execution of arbitrary code, denial of service or information
disclosure.
The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys driver must first be installed by a user with administrative privileges.