ALT-BU-2014-2980-1
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2020-03812
Уязвимость программного пакета для парсинга BSON, вызванная целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2020-12135
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow via properly constructed bson input.
- https://bugs.launchpad.net/ubuntu/+source/whoopsie/+bug/1872560
- https://github.com/10gen-archive/mongo-c-driver-legacy/commit/1a1f5e26a4309480d88598913f9eebf9e9cba8ca#diff-f7d29a680148f52d6601f59ed787f577
- https://launchpadlibrarian.net/474887364/bson-fix-overflow.patch
- https://usn.ubuntu.com/4450-1/
- https://bugs.launchpad.net/ubuntu/+source/whoopsie/+bug/1872560
- https://github.com/10gen-archive/mongo-c-driver-legacy/commit/1a1f5e26a4309480d88598913f9eebf9e9cba8ca#diff-f7d29a680148f52d6601f59ed787f577
- https://launchpadlibrarian.net/474887364/bson-fix-overflow.patch
- https://usn.ubuntu.com/4450-1/
Closed vulnerabilities
Modified: 2025-04-12
CVE-2016-7796
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00016.html
- http://rhn.redhat.com/errata/RHSA-2017-0003.html
- http://www.openwall.com/lists/oss-security/2016/09/30/1
- http://www.securityfocus.com/bid/93250
- http://www.securitytracker.com/id/1037320
- https://bugzilla.redhat.com/show_bug.cgi?id=1381911
- https://github.com/systemd/systemd/issues/4234#issuecomment-250441246
- https://rhn.redhat.com/errata/RHBA-2015-2092.html
- https://www.agwa.name/blog/post/how_to_crash_systemd_in_one_tweet
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00016.html
- http://rhn.redhat.com/errata/RHSA-2017-0003.html
- http://www.openwall.com/lists/oss-security/2016/09/30/1
- http://www.securityfocus.com/bid/93250
- http://www.securitytracker.com/id/1037320
- https://bugzilla.redhat.com/show_bug.cgi?id=1381911
- https://github.com/systemd/systemd/issues/4234#issuecomment-250441246
- https://rhn.redhat.com/errata/RHBA-2015-2092.html
- https://www.agwa.name/blog/post/how_to_crash_systemd_in_one_tweet
Closed bugs
Не выполняет /etc/firsttime.d/ вовремя.
split zsh completions for systemd and journalctl
initscript uses obsolete kernel interface