DSA-5219 webkit2gtk – security update
The following vulnerabilities have been discovered in the WebKitGTK web engine: Read More
CVE-2021-3585
A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager. Read More
CVE-2021-20260
A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission....
CVE-2021-3414
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations...
CVE-2021-3427
The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted...
CVE-2021-3563
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators...
CVE-2021-3574
A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks. Read More
CVE-2021-35939
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to...
libtar-1.2.20-25.fc35
FEDORA-2022-fe1a4e3cf0 Packages in this update: libtar-1.2.20-25.fc35 Update description: fix memory leaks through gnu_long{name,link} (CVE-2021-33645 CVE-2021-33646) fix out-of-bounds read in gnu_long{name,link} (CVE-2021-33643 CVE-2021-33644) Read More
libtar-1.2.20-25.fc36
FEDORA-2022-50e8a1b51d Packages in this update: libtar-1.2.20-25.fc36 Update description: fix memory leaks through gnu_long{name,link} (CVE-2021-33645 CVE-2021-33646) fix out-of-bounds read in gnu_long{name,link} (CVE-2021-33643 CVE-2021-33644) Read More