FEDORA-2022-6813a0eb99
Packages in this update:
autotrace-0.31.9-1.fc36
Update description:
AutoTrace ver. 0.31.9
autotrace-0.31.9-1.fc36
AutoTrace ver. 0.31.9
autotrace-0.31.9-1.fc37
AutoTrace ver. 0.31.9
IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 206089
exim-4.96-2.fc35
This is update of exim to fix CVE-2022-37451.
exim-4.96-2.fc36
This is update of exim to fix CVE-2022-37451.
mingw-jasper-3.0.6-2.fc37
Backport fix for CVE-2022-2963.
insight-13.0.50.20220502-1.fc35
New upstream snapshot.
Fixes CVE-2021-3826.
Disable deprecated declaration warnings/errors.
Disable nonnull-compare warnings.
Patch “symtab_no_format_overflow” to avoid a false positive format overflow
detection.
A buffer overflow was discovered in the vhost code of DPDK,
a set of libraries for fast packet processing, which could result
in denial of service or the execution of arbitrary code by malicious
guests/containers.
In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern (“[a-zA-Z][a-zA-Z0-9+.-]+:”) before making a redirection. This allows a malicious client to pass an XSS payload through the redirect_uri parameter while making an authorization request. NOTE: this vulnerability is similar to CVE-2020-7741.