ALT-BU-2016-2724-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2021-03-23
BDU:2019-00430
Уязвимость функции makefd_xprt() библиотеки предоставления протокола RPC libtirpc, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-14622
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.
- http://git.linux-nfs.org/?p=steved/libtirpc.git%3Ba=commit%3Bh=1c77f7a869bdea2a34799d774460d1f9983d45f0
- https://access.redhat.com/errata/RHBA-2017:1991
- https://bugzilla.novell.com/show_bug.cgi?id=968175
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14622
- https://lists.debian.org/debian-lts-announce/2018/08/msg00034.html
- https://usn.ubuntu.com/3759-1/
- https://usn.ubuntu.com/3759-2/
- http://git.linux-nfs.org/?p=steved/libtirpc.git%3Ba=commit%3Bh=1c77f7a869bdea2a34799d774460d1f9983d45f0
- https://access.redhat.com/errata/RHBA-2017:1991
- https://bugzilla.novell.com/show_bug.cgi?id=968175
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14622
- https://lists.debian.org/debian-lts-announce/2018/08/msg00034.html
- https://usn.ubuntu.com/3759-1/
- https://usn.ubuntu.com/3759-2/
Closed vulnerabilities
Modified: 2025-04-20
CVE-2016-10207
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
- http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00020.html
- http://rhn.redhat.com/errata/RHSA-2017-0630.html
- http://www.openwall.com/lists/oss-security/2017/02/02/22
- http://www.openwall.com/lists/oss-security/2017/02/05/2
- http://www.securityfocus.com/bid/96012
- https://access.redhat.com/errata/RHSA-2017:2000
- https://bugzilla.suse.com/show_bug.cgi?id=1023012
- https://github.com/TigerVNC/tigervnc/commit/8aa4bc53206c2430bbf0c8f4b642f59a379ee649
- https://security.gentoo.org/glsa/201801-13
- http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00020.html
- http://rhn.redhat.com/errata/RHSA-2017-0630.html
- http://www.openwall.com/lists/oss-security/2017/02/02/22
- http://www.openwall.com/lists/oss-security/2017/02/05/2
- http://www.securityfocus.com/bid/96012
- https://access.redhat.com/errata/RHSA-2017:2000
- https://bugzilla.suse.com/show_bug.cgi?id=1023012
- https://github.com/TigerVNC/tigervnc/commit/8aa4bc53206c2430bbf0c8f4b642f59a379ee649
- https://security.gentoo.org/glsa/201801-13
Closed bugs
Просьба собрать новую версию
Closed bugs
Package perl-Padre updated to version 1.00-alt4.df25a95 for branch sisyphus in task 163948.
Closed bugs
Не запускается с текущей версией DBD-SQLite
Closed bugs
kdm4.service not enabled
insecure core_pattern