Two cross-site scripting vulnerabilities were discovered in the Django
Rest Framework, a toolkit to build web APIs.
Category Archives: Advisories
DSA-5188 openjdk-11 – security update
Several vulnerabilities have been discovered in the OpenJDK Java runtime,
which may result in the execution of arbitrary Java bytecode or the
bypass of the Java sandbox.
DSA-5187 chromium – security update
Multiple security issues were discovered in Chromium, which could result
in the execution of arbitrary code, denial of service or information
disclosure.
Multiple Vulnerabilities in Apple Products Could Allow for Arbitrary Code Execution
Multiple vulnerabilities have been discovered in Apple Products, the most severe of which could allow for arbitrary code execution.
iOS is a mobile operating system for mobile devices, including the iPhone, iPad, and iPod touch.
iPadOS is the successor to iOS 12 and is a mobile operating system for iPads.
macOS Catalina is the 16th major release of macOS
macOS Big Sur is the 17th release of macOS.
macOS Monterey is the 18th and current major release of macOS.
Safari is a graphical web browser developed by Apple.
tvOS is an operating system for fourth-generation Apple TV digital media player.
watchOS is the mobile operating system for Apple Watch and is based on the iOS operating system.
Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
mingw-poppler-22.01.0-6.fc36
FEDORA-2022-ce08b1c643
Packages in this update:
mingw-poppler-22.01.0-6.fc36
Update description:
Backport fix for CVE-2022-27337.
giflib-5.2.1-14.fc36
FEDORA-2022-964883b2a5
Packages in this update:
giflib-5.2.1-14.fc36
Update description:
Apply proposed patch for CVE-2022-28506.
giflib-5.2.1-9.fc35 mingw-giflib-5.2.1-7.fc35
FEDORA-2022-91f353b8be
Packages in this update:
giflib-5.2.1-9.fc35
mingw-giflib-5.2.1-7.fc35
Update description:
Apply proposed patch for CVE-2022-28506.
mingw-harfbuzz-3.3.2-2.fc36
FEDORA-2022-ced8f872b1
Packages in this update:
mingw-harfbuzz-3.3.2-2.fc36
Update description:
Backport fix for CVE-2022-33068.
mingw-harfbuzz-2.9.1-2.fc35
FEDORA-2022-ac58de6e98
Packages in this update:
mingw-harfbuzz-2.9.1-2.fc35
Update description:
Backport fix for CVE-2022-33068.
CVE-2020-36557
A race condition in the Linux kernel before 5.6.2 between the VT_DISALLOCATE ioctl and closing/opening of ttys could lead to a use-after-free.