The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE
Category Archives: Advisories
USN-5421-1: LibTIFF vulnerabilities
It was discovered that LibTIFF incorrectly handled certain images.
An attacker could possibly use this issue to cause a crash,
resulting in a denial of service. This issue only affects
Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-35522)
Chintan Shah discovered that LibTIFF incorrectly handled memory when
handling certain images. An attacker could possibly use this issue to
cause a crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2022-0561, CVE-2022-0562, CVE-2022-0891)
It was discovered that LibTIFF incorrectly handled certain images.
An attacker could possibly use this issue to cause a crash,
resulting in a denial of service. This issue only affects
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 21.10. (CVE-2022-0865)
plantuml-1.2022.5-1.el9
FEDORA-EPEL-2022-a0a3d90422
Packages in this update:
plantuml-1.2022.5-1.el9
Update description:
Security fix for CVE-2022-1379
Updated version to 1.2022.4
plantuml-1.2022.5-1.fc36
FEDORA-2022-e6c09a89eb
Packages in this update:
plantuml-1.2022.5-1.fc36
Update description:
Security fix for CVE-2022-1379
plib-1.8.5-30.fc36
FEDORA-2022-08022e9452
Packages in this update:
plib-1.8.5-30.fc36
Update description:
Security fix for CVE-2021-38714
plib-1.8.5-30.fc34
FEDORA-2022-1cf3c9578f
Packages in this update:
plib-1.8.5-30.fc34
Update description:
Security fix for CVE-2021-38714
plib-1.8.5-30.fc35
FEDORA-2022-bcc0df5180
Packages in this update:
plib-1.8.5-30.fc35
Update description:
Security fix for CVE-2021-38714
plantuml-1.2022.5-1.fc35
FEDORA-2022-fda9f1f7bd
Packages in this update:
plantuml-1.2022.5-1.fc35
Update description:
Security fix for CVE-2022-1379
plantuml-1.2022.5-1.fc37
FEDORA-2022-ddfd750ade
Packages in this update:
plantuml-1.2022.5-1.fc37
Update description:
Automatic update for plantuml-1.2022.5-1.fc37.
Changelog
* Mon May 16 2022 Sandipan Roy <bytehackr@fedoraproject.org> – 1:1.2022.5-1
– Updated version to 1.2022.5
– Added fix for rhbz#2086392
Multiple Vulnerabilities in SonicWall SSLVPN SMA1000 Series Could Allow for Authentication Bypass
Multiple vulnerabilities in SonicWall SMA 1000 Series could allow for authentication bypass. Successful exploitation could allow an attacker to have unauthorized access to internal resources and even redirect potential victims to malicious websites. The SonicWall SMA 1000 Series is a unified secure access gateway that enables organizations to provide access to any application, anytime, from anywhere and any devices, including managed and unmanaged.