FEDORA-2022-7e7ce7df2e
Packages in this update:
moodle-3.11.8-1.fc35
Update description:
Multiple security fixes.
moodle-3.11.8-1.fc35
Multiple security fixes.
A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown code of the file C:Program FilesFileZilla FTP Clientuninstall.exe of the component Installer. The manipulation leads to unquoted search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VMware ESXi. Authentication is not required to exploit this vulnerability.
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000005722.
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000aefe.
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000002cba.
mariadb-10.3-3520220716094844.f27b74a8
MariaDB 10.3.35 & Galera 25.3.35
Important notice:
This is the last planned update for this module stream in Fedora.
Fedora 35 will be the last Fedora release in which this module stream will be available.
mariadb-10.4-3520220717092835.f27b74a8
MariaDB 10.4.25 & Galera 26.4.11
Important notice:
This is the last planned update for this module stream in Fedora.
Fedora 35 will be the last Fedora release in which this module stream will be available.
A vulnerability, which was classified as problematic, was found in FileZilla Server up to 0.9.50. This affects an unknown part of the component PORT Handler. The manipulation leads to unintended intermediary. It is possible to initiate the attack remotely. Upgrading to version 0.9.51 is able to address this issue. It is recommended to upgrade the affected component.