Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
Category Archives: Advisories
chromium-100.0.4896.127-1.fc34
FEDORA-2022-17aa1c62da
Packages in this update:
chromium-100.0.4896.127-1.fc34
Update description:
100 Chromium releases! Of course, at the rate they release now, we’ll probably be at 150 before the end of the year. Anyway, here’s the update.
Fixes:
CVE-2022-1232 CVE-2022-1305 CVE-2022-1306 CVE-2022-1307 CVE-2022-1308 CVE-2022-1309 CVE-2022-1310 CVE-2022-1311 CVE-2022-1312 CVE-2022-1313 CVE-2022-1314 CVE-2022-1364
chromium-100.0.4896.127-1.fc35
FEDORA-2022-0f14e2308e
Packages in this update:
chromium-100.0.4896.127-1.fc35
Update description:
100 Chromium releases! Of course, at the rate they release now, we’ll probably be at 150 before the end of the year. Anyway, here’s the update.
Fixes:
CVE-2022-1232 CVE-2022-1305 CVE-2022-1306 CVE-2022-1307 CVE-2022-1308 CVE-2022-1309 CVE-2022-1310 CVE-2022-1311 CVE-2022-1312 CVE-2022-1313 CVE-2022-1314 CVE-2022-1364
chromium-100.0.4896.127-1.fc36
FEDORA-2022-59297c8fcd
Packages in this update:
chromium-100.0.4896.127-1.fc36
Update description:
100 Chromium releases! Of course, at the rate they release now, we’ll probably be at 150 before the end of the year. Anyway, here’s the update.
Fixes:
CVE-2022-1232 CVE-2022-1305 CVE-2022-1306 CVE-2022-1307 CVE-2022-1308 CVE-2022-1309 CVE-2022-1310 CVE-2022-1311 CVE-2022-1312 CVE-2022-1313 CVE-2022-1314 CVE-2022-1364
DSA-5124 ffmpeg – security update
Several vulnerabilities have been discovered in the FFmpeg multimedia
framework, which could result in denial of service or potentially the
execution of arbitrary code if malformed files/streams are processed.
zxing-cpp-1.2.0-4.fc36
FEDORA-2022-e22f1a8c17
Packages in this update:
zxing-cpp-1.2.0-4.fc36
Update description:
rebuild for CVE-2022-28041
CuraEngine-4.13.1-2.fc35
FEDORA-2022-bc606b86f4
Packages in this update:
CuraEngine-4.13.1-2.fc35
Update description:
Security fix for CVE-2022-28041
CuraEngine-4.13.1-2.fc36
FEDORA-2022-0125d9cd29
Packages in this update:
CuraEngine-4.13.1-2.fc36
Update description:
Security fix for CVE-2022-28041
CuraEngine-4.13.1-2.fc34
FEDORA-2022-cc64b21327
Packages in this update:
CuraEngine-4.13.1-2.fc34
Update description:
Security fix for CVE-2022-28041
[AIT-SA-20220208-01] SexyPolling SQL Injection
Posted by sec-advisory on Apr 22
SexyPolling SQL Injection
====================
| Identifier: | AIT-SA-20220208-01|
| Target: | Sexy Polling ( Joomla Extension) |
| Vendor: | 2glux |
| Version: | all versions below version 2.1.8 |
| CVE: | Not yet |
| Accessibility: | Remote |
| Severity: | Critical |
| Author: | Wolfgang Hotwagner (AIT Austrian Institute of Technology) |
Summary
========
[Sexy Polling is a Joomla Extension for votes.](https://2glux.com/projects/sexypolling…