ALT-BU-2014-2980-1
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2020-03812
Уязвимость программного пакета для парсинга BSON, вызванная целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2020-12135
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow via properly constructed bson input.
- https://bugs.launchpad.net/ubuntu/+source/whoopsie/+bug/1872560
- https://github.com/10gen-archive/mongo-c-driver-legacy/commit/1a1f5e26a4309480d88598913f9eebf9e9cba8ca#diff-f7d29a680148f52d6601f59ed787f577
- https://launchpadlibrarian.net/474887364/bson-fix-overflow.patch
- USN-4450-1
- https://bugs.launchpad.net/ubuntu/+source/whoopsie/+bug/1872560
- USN-4450-1
- https://launchpadlibrarian.net/474887364/bson-fix-overflow.patch
- https://github.com/10gen-archive/mongo-c-driver-legacy/commit/1a1f5e26a4309480d88598913f9eebf9e9cba8ca#diff-f7d29a680148f52d6601f59ed787f577
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-7796
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
- SUSE-SU-2016:2475
- SUSE-SU-2016:2475
- SUSE-SU-2016:2476
- SUSE-SU-2016:2476
- RHSA-2017:0003
- RHSA-2017:0003
- [oss-security] 20160930 Re: CVE Request: systemd v209+: local denial-of-service attack
- [oss-security] 20160930 Re: CVE Request: systemd v209+: local denial-of-service attack
- 93250
- 93250
- 1037320
- 1037320
- https://bugzilla.redhat.com/show_bug.cgi?id=1381911
- https://bugzilla.redhat.com/show_bug.cgi?id=1381911
- https://github.com/systemd/systemd/issues/4234#issuecomment-250441246
- https://github.com/systemd/systemd/issues/4234#issuecomment-250441246
- RHBA-2015:2092
- RHBA-2015:2092
- https://www.agwa.name/blog/post/how_to_crash_systemd_in_one_tweet
- https://www.agwa.name/blog/post/how_to_crash_systemd_in_one_tweet
Closed bugs
Не выполняет /etc/firsttime.d/ вовремя.
split zsh completions for systemd and journalctl
initscript uses obsolete kernel interface