FEDORA-EPEL-2022-6d6f432346
Packages in this update:
rubygem-nokogiri-1.13.6-1.el9
Update description:
1.13.6 – CVE-2022-29181 and CVE-2022-24836
rubygem-nokogiri-1.13.6-1.el9
1.13.6 – CVE-2022-29181 and CVE-2022-24836
rubygem-nokogiri-1.6.1-1.el7.2
Backport CVE-2022-24836 (#2074347), Backport CVE-2022-29181 (#2088685)
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
logrotate-3.18.1-3.fc35
fix potential DoS from unprivileged users via the state file (CVE-2022-1348)
logrotate-3.20.1-1.fc36
fix potential DoS from unprivileged users via the state file (CVE-2022-1348)
logrotate-3.18.0-4.fc34
fix potential DoS from unprivileged users via the state file (CVE-2022-1348)
Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text transmission of sensitive information when configured to use LDAP via TLS and where the domain controller returns LDAP referrals, which may allow an attacker to remotely read LDAP system credentials.
When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting.
The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prior, 3500 Rack Configuration, Part No. 129133-01 versions 6.4 and prior, and 3500/22M Firmware, Part No. 288055-01 versions 5.05 and prior) utilize a weak encryption algorithm for storage and transmission of sensitive data, which may allow an attacker to more easily obtain credentials used for access.