It was discovered that libsndfile was incorrectly performing memory
management operations and incorrectly using buffers when executing
its FLAC codec. If a user or automated system were tricked into
processing a specially crafted sound file, an attacker could
possibly use this issue to cause a denial of service or obtain
sensitive information.
Category Archives: Advisories
USN-5408-1: Dnsmasq vulnerability
Petr Menšík and Richard Johnson discovered that Dnsmasq incorrectly handled
certain inputs. An attacker could possibly use this issue to execute
arbitrary code or expose sensitive information.
pidgin-2.14.1-4.fc34
FEDORA-2022-52777fea3c
Packages in this update:
pidgin-2.14.1-4.fc34
Update description:
Security fix for CVE-2022-26491.
pidgin-2.14.6-3.fc35
FEDORA-2022-4759ca6476
Packages in this update:
pidgin-2.14.6-3.fc35
Update description:
Security fix for CVE-2022-26491.
pidgin-2.14.8-3.fc36
FEDORA-2022-4490dce823
Packages in this update:
pidgin-2.14.8-3.fc36
Update description:
Security fix for CVE-2022-26491.
USN-5407-1: Cairo vulnerabilities
Gustavo Grieco, Alberto Garcia, Francisco Oca, Suleman Ali, and others
discovered that Cairo incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2016-9082, CVE-2017-9814, CVE-2019-6462)
Stephan Bergmann discovered that Cairo incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service,
or possibly execute arbitrary code.
(CVE-2020-35492)
Critical Patches Issued for Microsoft Products, May 10, 2022
Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
USN-5179-2: BusyBox vulnerability
USN-5179-1 fixed vulnerabilities in BusyBox. This update provides the
corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that BusyBox incorrectly handled certain malformed gzip
archives. If a user or automated system were tricked into processing a
specially crafted gzip archive, a remote attacker could use this issue to
cause BusyBox to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2021-28831)
rubygem-nokogiri-1.11.7-3.fc34
FEDORA-2022-0e5d64ce65
Packages in this update:
rubygem-nokogiri-1.11.7-3.fc34
Update description:
This rpm backports the patch for the issue for improper handling of unexpected data types, related to untrusted inputs to the SAX parsers, which is assigned as CVE-2022-29181
rubygem-nokogiri-1.13.1-3.fc35
FEDORA-2022-e9b2e1c1ac
Packages in this update:
rubygem-nokogiri-1.13.1-3.fc35
Update description:
This rpm backports the patch for the issue for improper handling of unexpected data types, related to untrusted inputs to the SAX parsers, which is assigned as CVE-2022-29181