The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when an online profile picture is processed) with a malicious XMP segment. If the XMP metadata of the uploaded image is parsed, then the XXE vulnerability is triggered.
Category Archives: Advisories
CVE-2019-12254
In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn’t properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.
CVE-2020-19212
SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.
CVE-2020-19213
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
CVE-2020-19215
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
CVE-2020-19216
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.
CVE-2020-19217
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
clamav-0.103.6-1.el7
FEDORA-EPEL-2022-cf82fb137a
Packages in this update:
clamav-0.103.6-1.el7
Update description:
https://blog.clamav.net/2022/05/clamav-01050-01043-01036-released.html
clamav-0.103.6-1.el8
FEDORA-EPEL-2022-334a36ba83
Packages in this update:
clamav-0.103.6-1.el8
Update description:
https://blog.clamav.net/2022/05/clamav-01050-01043-01036-released.html
clamav-0.103.6-1.el9
FEDORA-EPEL-2022-5c7d584007
Packages in this update:
clamav-0.103.6-1.el9
Update description:
https://blog.clamav.net/2022/05/clamav-01050-01043-01036-released.html