FEDORA-2022-8c76e587f7
Packages in this update:
dokuwiki-20200729a-1.fc35
Update description:
Update to bugfix/security release 2022-07-29a. Includes security fix for CVE-2022-3123.
dokuwiki-20200729a-1.fc35
Update to bugfix/security release 2022-07-29a. Includes security fix for CVE-2022-3123.
python-lxml-4.9.1-1.fc38
Automatic update for python-lxml-4.9.1-1.fc38.
* Wed Sep 14 2022 Charalampos Stratakis <cstratak@redhat.com> – 4.9.1-1
– Update to 4.9.1
– Fix for CVE-2022-2309
– Resolves: rhbz#2107571, rhbz#2110131
dokuwiki-20200729a-1.fc36
Update to bugfix/security release 2022-07-29a. Includes security fix for CVE-2022-3123.
dokuwiki-20220731a-1.fc37
Update to new stable release, v2022-07-31a “Igor”. Includes security fix for CVE-2022-3123.
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.
Multiple security issues were discovered in Chromium, which could result
in the execution of arbitrary code, denial of service or information
disclosure.
The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys driver must first be installed by a user with administrative privileges.
zabbix-6.0.8-1.fc37
6.0.8, fixes CVE-2022-40626
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163.
java-latest-openjdk-18.0.2.0.9-1.rolling.el9
July CPU update