The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token’s payload comes from valid provider, not from someone else. An attacker can provide a compromised token with custom payload. The token will pass the validation on the client side. We recommend upgrading to version 1.33.3 or above
Category Archives: Advisories
Post Title
Multiple vulnerabilities have been discovered in the Google Android operating system (OS), the most severe of which could allow for escalation of privilege. Android is an operating system developed by Google for mobile devices, including, but not limited to, smartphones, tablets, and watches. Successful exploitation of the most severe of these vulnerabilities could allow for escalation of privilege. Depending on the privileges associated with this application, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. If this application has been configured to have fewer user rights on the system, exploitation of the most severe of these vulnerabilities could have less impact than if it was configured with administrative rights.
USN-5400-1: MySQL vulnerabilities
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 8.0.29 in Ubuntu 20.04 LTS, Ubuntu 21.10, and
Ubuntu 22.04 LTS. Ubuntu 18.04 LTS has been updated to MySQL 5.7.38.
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-38.html
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-29.html
https://www.oracle.com/security-alerts/cpuapr2022.html
libxml2-2.9.14-1.fc34
FEDORA-2022-f624aad735
Packages in this update:
libxml2-2.9.14-1.fc34
Update description:
Update to 2.9.14
Fix CVE-2022-29824: Integer overflow in xmlBuf and xmlBuffer
mingw-freetype-2.12.1-1.fc36
FEDORA-2022-7ece4f6d74
Packages in this update:
mingw-freetype-2.12.1-1.fc36
Update description:
Update to 2.12.1.
Backport fixes for CVE-2022-27404, CVE-2022-27405, CVE-2022-27406
libxml2-2.9.14-1.fc35
FEDORA-2022-be6d83642a
Packages in this update:
libxml2-2.9.14-1.fc35
Update description:
Update to 2.9.14
Fix CVE-2022-29824: Integer overflow in xmlBuf and xmlBuffer
libxml2-2.9.14-1.fc36
FEDORA-2022-9136d646e4
Packages in this update:
libxml2-2.9.14-1.fc36
Update description:
Update to 2.9.14
Fix CVE-2022-29824: Integer overflow in xmlBuf and xmlBuffer
firefox-100.0-2.fc36
FEDORA-2022-2c4ed935d1
Packages in this update:
firefox-100.0-2.fc36
Update description:
New upstream version (100.0)
Fix mozbz#1759137 (ffmpeg crash)
firefox-100.0-1.fc35
FEDORA-2022-63b1344b6d
Packages in this update:
firefox-100.0-1.fc35
Update description:
New upstream version (100.0)
firefox-100.0-1.fc34
FEDORA-2022-d2d1fd90df
Packages in this update:
firefox-100.0-1.fc34
Update description:
New upstream version (100.0)