FEDORA-2022-ff2aa5643d
Packages in this update:
rizin-0.4.1-1.fc36
Update description:
Rebase to upstream version 0.4.1 to fix some security issues
rizin-0.4.1-1.fc36
Rebase to upstream version 0.4.1 to fix some security issues
rizin-0.4.1-1.fc37
Rebase to upstream version 0.4.1 to fix some security issues
containerd-1.6.8-4.fc37
Fix FTBFS
moby-engine-20.10.18-1.fc36
Update to 20.10.18.
Mitigates CVE-2022-36109 / GHSA-rc4r-wh2q-q6c4
Several vulnerabilities were discovered in gdk-pixbuf, the GDK
Pixbuf library.
containerd-1.6.8-2.fc37
moby-engine-20.10.18-1.fc37
Update to 1.6.8. Fixes rhbz#2094144.
Update to 20.10.18.
Mitigates CVE-2022-36109 / GHSA-rc4r-wh2q-q6c4
PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java.
An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanitized. This causes SQL injection.
In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn’t aligned correctly. In version before GLIBC version 2.29 and aligned correctly, it allows arbitrary write anywhere in the programs memory.
In man2html 1.6g, a filename can be created to overwrite the previous size parameter of the next chunk and the fd, bk, fd_nextsize, bk_nextsize of the current chunk. The next chunk is then freed later on, causing a freeing of an arbitrary amount of memory.