FEDORA-2022-ec3ce5fb9a
Packages in this update:
CImg-3.1.0-1.fc36
gmic-3.1.0-1.fc36
Update description:
bump version
CImg-3.1.0-1.fc36
gmic-3.1.0-1.fc36
bump version
chafa-1.2.1-7.fc34
Security fix for CVE-2022-1507
chafa-1.8.0-4.fc36
Security fix for CVE-2022-1507
chafa-1.2.1-7.fc35
Security fix for CVE-2022-1507
chafa-1.10.3-1.fc37
Automatic update for chafa-1.10.3-1.fc37.
* Fri May 6 2022 Miro Hrončok <mhroncok@redhat.com> – 1.10.3-1
– Update to 1.10.3
– Fixes: rhbz#1809122
– Contains security fix for CVE-2022-1507
– Fixes: rhbz#2080294
– Provide bundled libnsgif and lodepng
The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.
The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when an online profile picture is processed) with a malicious XMP segment. If the XMP metadata of the uploaded image is parsed, then the XXE vulnerability is triggered.
In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn’t properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.
SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.