ALT-BU-2016-2975-1
Branch p8 update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-5419
curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.
- openSUSE-SU-2016:2227
- openSUSE-SU-2016:2227
- openSUSE-SU-2016:2379
- openSUSE-SU-2016:2379
- RHSA-2016:2575
- RHSA-2016:2575
- RHSA-2016:2957
- RHSA-2016:2957
- DSA-3638
- DSA-3638
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 92292
- 92292
- 92319
- 92319
- 1036538
- 1036538
- 1038341
- 1038341
- SSA:2016-219-01
- SSA:2016-219-01
- USN-3048-1
- USN-3048-1
- RHSA-2018:3558
- RHSA-2018:3558
- https://curl.haxx.se/docs/adv_20160803A.html
- https://curl.haxx.se/docs/adv_20160803A.html
- FEDORA-2016-24316f1f56
- FEDORA-2016-24316f1f56
- FEDORA-2016-8354baae0f
- FEDORA-2016-8354baae0f
- GLSA-201701-47
- GLSA-201701-47
- https://source.android.com/security/bulletin/2016-12-01.html
- https://source.android.com/security/bulletin/2016-12-01.html
- https://www.tenable.com/security/tns-2016-18
- https://www.tenable.com/security/tns-2016-18
Modified: 2024-11-21
CVE-2016-5420
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.
- openSUSE-SU-2016:2227
- openSUSE-SU-2016:2227
- openSUSE-SU-2016:2379
- openSUSE-SU-2016:2379
- RHSA-2016:2575
- RHSA-2016:2575
- RHSA-2016:2957
- RHSA-2016:2957
- DSA-3638
- DSA-3638
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 92309
- 92309
- 1036537
- 1036537
- 1036739
- 1036739
- SSA:2016-219-01
- SSA:2016-219-01
- USN-3048-1
- USN-3048-1
- RHSA-2018:3558
- RHSA-2018:3558
- https://curl.haxx.se/docs/adv_20160803B.html
- https://curl.haxx.se/docs/adv_20160803B.html
- FEDORA-2016-24316f1f56
- FEDORA-2016-24316f1f56
- FEDORA-2016-8354baae0f
- FEDORA-2016-8354baae0f
- GLSA-201701-47
- GLSA-201701-47
- https://source.android.com/security/bulletin/2016-12-01.html
- https://source.android.com/security/bulletin/2016-12-01.html
- https://www.tenable.com/security/tns-2016-18
- https://www.tenable.com/security/tns-2016-18
Modified: 2024-11-21
CVE-2016-5421
Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
- openSUSE-SU-2016:2227
- openSUSE-SU-2016:2227
- openSUSE-SU-2016:2379
- openSUSE-SU-2016:2379
- DSA-3638
- DSA-3638
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 92306
- 92306
- 1036536
- 1036536
- SSA:2016-219-01
- SSA:2016-219-01
- USN-3048-1
- USN-3048-1
- RHSA-2018:3558
- RHSA-2018:3558
- https://curl.haxx.se/docs/adv_20160803C.html
- https://curl.haxx.se/docs/adv_20160803C.html
- FEDORA-2016-24316f1f56
- FEDORA-2016-24316f1f56
- FEDORA-2016-8354baae0f
- FEDORA-2016-8354baae0f
- GLSA-201701-47
- GLSA-201701-47
- https://source.android.com/security/bulletin/2016-12-01.html
- https://source.android.com/security/bulletin/2016-12-01.html
- https://www.tenable.com/security/tns-2016-18
- https://www.tenable.com/security/tns-2016-18
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-3176
Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.
Modified: 2024-11-21
CVE-2016-9639
Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
- [oss-security] 20161125 CVE Request: salt confidentiality issue
- [oss-security] 20161125 CVE Request: salt confidentiality issue
- [oss-security] 20161125 Re: CVE Request: salt confidentiality issue
- [oss-security] 20161125 Re: CVE Request: salt confidentiality issue
- 94553
- 94553
- https://docs.saltstack.com/en/2015.8/ref/configuration/master.html#rotate-aes-key
- https://docs.saltstack.com/en/2015.8/ref/configuration/master.html#rotate-aes-key
Closed bugs
Обновить версию