Category Archives: Advisories

galera-26.4.11-1.fc35 mariadb-10.5.15-1.fc35

Read Time:11 Second

FEDORA-2022-03350936ee

Packages in this update:

galera-26.4.11-1.fc35
mariadb-10.5.15-1.fc35

Update description:

MariaDB 10.5.15

Release notes:

https://mariadb.com/kb/en/mariadb-10515-release-notes/

Read More

USN-5394-1: WebKitGTK vulnerabilities

Read Time:16 Second

A large number of security issues were discovered in the WebKitGTK Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.

Read More

curl-7.82.0-3.fc36

Read Time:16 Second

FEDORA-2022-3517572083

Packages in this update:

curl-7.82.0-3.fc36

Update description:

fix credential leak on redirect (CVE-2022-27774)
fix auth/cookie leak on redirect (CVE-2022-27776)
fix bad local IPv6 connection reuse (CVE-2022-27775)
fix OAUTH2 bearer bypass in connection re-use (CVE-2022-22576)

Read More

curl-7.79.1-2.fc35

Read Time:16 Second

FEDORA-2022-411f088574

Packages in this update:

curl-7.79.1-2.fc35

Update description:

fix credential leak on redirect (CVE-2022-27774)
fix auth/cookie leak on redirect (CVE-2022-27776)
fix bad local IPv6 connection reuse (CVE-2022-27775)
fix OAUTH2 bearer bypass in connection re-use (CVE-2022-22576)

Read More

curl-7.76.1-14.fc34

Read Time:16 Second

FEDORA-2022-fc5776b142

Packages in this update:

curl-7.76.1-14.fc34

Update description:

fix credential leak on redirect (CVE-2022-27774)
fix auth/cookie leak on redirect (CVE-2022-27776)
fix bad local IPv6 connection reuse (CVE-2022-27775)
fix OAUTH2 bearer bypass in connection re-use (CVE-2022-22576)

Read More

CVE-2021-33436

Read Time:16 Second

NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and ultimately execute code as NT AUTHORITYSYSTEM.

Read More

USN-5392-1: Mutt vulnerabilities

Read Time:18 Second

It was discovered that Mutt incorrectly handled certain requests.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 20.04 LTS. (CVE-2021-32055)

It was discovered that Mutt incorrectly handled certain input.
An attacker could possibly use this issue to cause a crash,
or expose sensitive information. (CVE-2022-1328)

Read More