ALT-BU-2016-2612-1
Branch p7 update bulletin.
Closed vulnerabilities
BDU:2015-10357
Уязвимость системы управления базами данных Redis, позволяющая нарушителю выполнить произвольный Lua-байт-код
Modified: 2024-11-21
CVE-2015-4335
Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
- http://benmmurphy.github.io/blog/2015/06/04/redis-eval-lua-sandbox-escape/
- http://benmmurphy.github.io/blog/2015/06/04/redis-eval-lua-sandbox-escape/
- FEDORA-2015-9488
- FEDORA-2015-9488
- FEDORA-2015-9498
- FEDORA-2015-9498
- openSUSE-SU-2015:1687
- openSUSE-SU-2015:1687
- RHSA-2015:1676
- RHSA-2015:1676
- DSA-3279
- DSA-3279
- [oss-security] 20150604 Re: CVE Request: redis Lua sandbox escape and arbitrary code execution
- [oss-security] 20150604 Re: CVE Request: redis Lua sandbox escape and arbitrary code execution
- [oss-security] 20150604 CVE Request: redis Lua sandbox escape and arbitrary code execution
- [oss-security] 20150604 CVE Request: redis Lua sandbox escape and arbitrary code execution
- [oss-security] 20150605 Re: CVE Request: redis Lua sandbox escape and arbitrary code execution
- [oss-security] 20150605 Re: CVE Request: redis Lua sandbox escape and arbitrary code execution
- 75034
- 75034
- https://github.com/antirez/redis/commit/fdf9d455098f54f7666c702ae464e6ea21e25411
- https://github.com/antirez/redis/commit/fdf9d455098f54f7666c702ae464e6ea21e25411
- https://groups.google.com/forum/#%21msg/redis-db/4Y6OqK8gEyk/Dg-5cejl-eUJ
- https://groups.google.com/forum/#%21msg/redis-db/4Y6OqK8gEyk/Dg-5cejl-eUJ
- GLSA-201702-16
- GLSA-201702-16
Closed bugs
service redis status не показывает статус
Права на unit-файл должны быть 644
Closed vulnerabilities
BDU:2016-01052
Уязвимость программного средства мониторинга сети Xymon, позволяющая нарушителю вводить произвольные сообщения
BDU:2016-01053
Уязвимость программного средства мониторинга сети Xymon, позволяющая нарушителю выполнить произвольные команды
BDU:2016-01054
Уязвимость операционной системы Debian GNU/Linux, позволяющая нарушителю читать произвольные файлы в каталоге конфигурации
BDU:2016-01055
Уязвимости программного средства мониторинга сети Xymon, позволяющие нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2024-11-21
CVE-2016-2054
Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long filename, involving handling a "config" command.
- [Xymon] 20160208 Xymon 4.3.25 - Important Security Update
- [Xymon] 20160208 Xymon 4.3.25 - Important Security Update
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- DSA-3495
- DSA-3495
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- https://sourceforge.net/p/xymon/code/7859/
- https://sourceforge.net/p/xymon/code/7859/
- https://sourceforge.net/p/xymon/code/7860/
- https://sourceforge.net/p/xymon/code/7860/
Modified: 2024-11-21
CVE-2016-2055
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration directory via a "config" command.
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- DSA-3495
- DSA-3495
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- https://sourceforge.net/p/xymon/code/7890/
- https://sourceforge.net/p/xymon/code/7890/
Modified: 2024-11-21
CVE-2016-2056
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c.
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- http://packetstormsecurity.com/files/153620/Xymon-useradm-Command-Execution.html
- http://packetstormsecurity.com/files/153620/Xymon-useradm-Command-Execution.html
- DSA-3495
- DSA-3495
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- https://sourceforge.net/p/xymon/code/7892/
- https://sourceforge.net/p/xymon/code/7892/
Modified: 2024-11-21
CVE-2016-2057
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to that queue.
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- DSA-3495
- DSA-3495
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- https://sourceforge.net/p/xymon/code/7891/
- https://sourceforge.net/p/xymon/code/7891/
Modified: 2024-11-21
CVE-2016-2058
Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled in the "detailed status" page, or (2) remote authenticated users to inject arbitrary web script or HTML via an acknowledgement message, which is not properly handled in the "status" page.
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- DSA-3495
- DSA-3495
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- https://sourceforge.net/p/xymon/code/7892/
- https://sourceforge.net/p/xymon/code/7892/