ALT-BU-2016-3236-2
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2023-11-13
BDU:2022-05945
Уязвимость функций fillin_rpath, decompose_rpath системной библиотеки GNU C Library, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2025-04-20
CVE-2016-5417
Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures.
- http://www.openwall.com/lists/oss-security/2016/08/02/5
- http://www.securityfocus.com/bid/92257
- https://sourceware.org/bugzilla/show_bug.cgi?id=19257
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=2212c1420c92a33b0e0bd9a34938c9814a56c0f7
- https://www.sourceware.org/ml/libc-alpha/2016-08/msg00212.html
- http://www.openwall.com/lists/oss-security/2016/08/02/5
- http://www.securityfocus.com/bid/92257
- https://sourceware.org/bugzilla/show_bug.cgi?id=19257
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=2212c1420c92a33b0e0bd9a34938c9814a56c0f7
- https://www.sourceware.org/ml/libc-alpha/2016-08/msg00212.html
Modified: 2025-04-20
CVE-2017-16997
elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to gain privileges via a Trojan horse library in the current working directory, related to the fillin_rpath and decompose_rpath functions. This is associated with misinterpretion of an empty RPATH/RUNPATH token as the "./" directory. NOTE: this configuration of RPATH/RUNPATH for a privileged program is apparently very uncommon; most likely, no such program is shipped with any common Linux distribution.
- http://www.securityfocus.com/bid/102228
- https://access.redhat.com/errata/RHBA-2019:0327
- https://access.redhat.com/errata/RHSA-2018:3092
- https://bugs.debian.org/884615
- https://sourceware.org/bugzilla/show_bug.cgi?id=22625
- https://sourceware.org/ml/libc-alpha/2017-12/msg00528.html
- http://www.securityfocus.com/bid/102228
- https://access.redhat.com/errata/RHBA-2019:0327
- https://access.redhat.com/errata/RHSA-2018:3092
- https://bugs.debian.org/884615
- https://sourceware.org/bugzilla/show_bug.cgi?id=22625
- https://sourceware.org/ml/libc-alpha/2017-12/msg00528.html
Closed bugs
Обновление версии dovecot
Package dovecot-pigeonhole updated to version 0.4.16-alt1 for branch sisyphus in task 175515.
Closed bugs
Обновление версии dovecot-pigeonhole
Package alterator-sslkey updated to version 0.2.4-alt1 for branch sisyphus in task 175522.
Closed bugs
Не создаются ключи
Package make-initrd updated to version 0.8.13-alt1 for branch sisyphus in task 175523.
Closed bugs
guess-kbd: команда не найдена
Closed bugs
Зависит от xterm
