ALT-BU-2017-2885-1
Branch sisyphus update bulletin.
Package libwebkitgtk4 updated to version 2.14.3-alt1 for branch sisyphus in task 176784.
Closed vulnerabilities
BDU:2017-00394
Уязвимость операционной системы iOS, мультимедийного проигрывателя iTunes, браузера Safari, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2017-00400
Уязвимость операционной системы iOS, мультимедийного проигрывателя iTunes, браузера Safari, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2017-00404
Уязвимость браузера Safari, операционной системы iOS, мультимедийного проигрывателя iTunes, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2017-00406
Уязвимость браузера Safari, операционной системы iOS, мультимедийного проигрывателя iTunes, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2017-00410
Уязвимость браузера Safari, мультимедийного проигрывателя iTunes, операционной системы iOS, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2017-00413
Уязвимость мультимедийного проигрывателя iTunes, операционной системы iOS, браузера Safari, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2017-00467
Уязвимость браузера Safari, мультимедийного проигрывателя iTunes, операционной системы iOS, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2017-00469
Уязвимость браузера Safari, мультимедийного проигрывателя iTunes, операционной системы iOS, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2017-00478
Уязвимость операционной системы iOS, мультимедийного проигрывателя iTunes и браузера Safari, позволяющая нарушителю получить конфиденциальную информацию или обойти существующую политику ограничения доступа
BDU:2017-00484
Уязвимость операционной системы iOS, мультимедийного проигрывателя iTunes и браузера Safari , позволяющая нарушителю получить конфиденциальную информацию
BDU:2017-00486
Уязвимость операционной системы iOS, мультимедийного проигрывателя iTunes и браузера Safari, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2017-00489
Уязвимость операционной системы iOS, мультимедийного проигрывателя iTunes и браузера Safari, позволяющая нарушителю получить конфиденциальную информацию
BDU:2017-00497
Уязвимость браузера Safari и операционной системы iOS, позволяющая нарушителю получить конфиденциальную информацию
Modified: 2024-11-21
CVE-2016-7586
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a crafted web site.
- 94907
- 94907
- 1037459
- 1037459
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207421
- https://support.apple.com/HT207421
- https://support.apple.com/HT207422
- https://support.apple.com/HT207422
- https://support.apple.com/HT207424
- https://support.apple.com/HT207424
- https://support.apple.com/HT207427
- https://support.apple.com/HT207427
Modified: 2024-11-21
CVE-2016-7589
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 94908
- 94908
- 1037459
- 1037459
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207421
- https://support.apple.com/HT207421
- https://support.apple.com/HT207422
- https://support.apple.com/HT207422
- https://support.apple.com/HT207424
- https://support.apple.com/HT207424
- https://support.apple.com/HT207427
- https://support.apple.com/HT207427
- https://support.apple.com/HT207487
- https://support.apple.com/HT207487
Modified: 2024-11-21
CVE-2016-7592
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component, which allows remote attackers to obtain sensitive information via crafted JavaScript prompts on a web site.
- 94909
- 94909
- 1037459
- 1037459
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207421
- https://support.apple.com/HT207421
- https://support.apple.com/HT207422
- https://support.apple.com/HT207422
- https://support.apple.com/HT207424
- https://support.apple.com/HT207424
- https://support.apple.com/HT207427
- https://support.apple.com/HT207427
Modified: 2024-11-21
CVE-2016-7599
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that uses HTTP redirects.
- 94907
- 94907
- 1037459
- 1037459
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207421
- https://support.apple.com/HT207421
- https://support.apple.com/HT207422
- https://support.apple.com/HT207422
- https://support.apple.com/HT207424
- https://support.apple.com/HT207424
- https://support.apple.com/HT207427
- https://support.apple.com/HT207427
Modified: 2024-11-21
CVE-2016-7623
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a blob URL on a web site.
Modified: 2024-11-21
CVE-2016-7632
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 94907
- 94907
- 1037459
- 1037459
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207421
- https://support.apple.com/HT207421
- https://support.apple.com/HT207422
- https://support.apple.com/HT207422
- https://support.apple.com/HT207424
- https://support.apple.com/HT207424
- https://support.apple.com/HT207427
- https://support.apple.com/HT207427
Modified: 2024-11-21
CVE-2016-7635
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 94907
- 94907
- 1037459
- 1037459
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207421
- https://support.apple.com/HT207421
- https://support.apple.com/HT207422
- https://support.apple.com/HT207422
- https://support.apple.com/HT207424
- https://support.apple.com/HT207424
- https://support.apple.com/HT207427
- https://support.apple.com/HT207427
Modified: 2024-11-21
CVE-2016-7639
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 94907
- 94907
- 1037459
- 1037459
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207421
- https://support.apple.com/HT207421
- https://support.apple.com/HT207422
- https://support.apple.com/HT207422
- https://support.apple.com/HT207424
- https://support.apple.com/HT207424
- https://support.apple.com/HT207427
- https://support.apple.com/HT207427
Modified: 2024-11-21
CVE-2016-7641
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 94907
- 94907
- 1037459
- 1037459
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207421
- https://support.apple.com/HT207421
- https://support.apple.com/HT207422
- https://support.apple.com/HT207422
- https://support.apple.com/HT207424
- https://support.apple.com/HT207424
- https://support.apple.com/HT207427
- https://support.apple.com/HT207427
Modified: 2024-11-21
CVE-2016-7645
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 94907
- 94907
- 1037459
- 1037459
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207421
- https://support.apple.com/HT207421
- https://support.apple.com/HT207422
- https://support.apple.com/HT207422
- https://support.apple.com/HT207424
- https://support.apple.com/HT207424
- https://support.apple.com/HT207427
- https://support.apple.com/HT207427
Modified: 2024-11-21
CVE-2016-7652
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 94907
- 94907
- 1037459
- 1037459
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207421
- https://support.apple.com/HT207421
- https://support.apple.com/HT207422
- https://support.apple.com/HT207422
- https://support.apple.com/HT207424
- https://support.apple.com/HT207424
- https://support.apple.com/HT207427
- https://support.apple.com/HT207427
Modified: 2024-11-21
CVE-2016-7654
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 94907
- 94907
- 1037459
- 1037459
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207421
- https://support.apple.com/HT207421
- https://support.apple.com/HT207422
- https://support.apple.com/HT207422
- https://support.apple.com/HT207424
- https://support.apple.com/HT207424
- https://support.apple.com/HT207427
- https://support.apple.com/HT207427
Modified: 2024-11-21
CVE-2016-7656
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 94907
- 94907
- 1037459
- 1037459
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207421
- https://support.apple.com/HT207421
- https://support.apple.com/HT207422
- https://support.apple.com/HT207422
- https://support.apple.com/HT207424
- https://support.apple.com/HT207424
- https://support.apple.com/HT207427
- https://support.apple.com/HT207427
Package kernel-image-un-def updated to version 4.9.3-alt1 for branch sisyphus in task 176490.
Closed vulnerabilities
BDU:2016-02350
Уязвимость операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2016-10741
In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated with a hole) that is handled with BUG_ON instead of an I/O failure.
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=04197b341f23b908193308b8d63d17ff23232598
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=04197b341f23b908193308b8d63d17ff23232598
- 106822
- 106822
- https://bugzilla.suse.com/show_bug.cgi?id=1124010
- https://bugzilla.suse.com/show_bug.cgi?id=1124010
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.3
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.3
- https://github.com/torvalds/linux/commit/04197b341f23b908193308b8d63d17ff23232598
- https://github.com/torvalds/linux/commit/04197b341f23b908193308b8d63d17ff23232598
- [debian-lts-announce] 20190327 [SECURITY] [DLA 1731-1] linux security update
- [debian-lts-announce] 20190327 [SECURITY] [DLA 1731-1] linux security update
- [debian-lts-announce] 20190401 [SECURITY] [DLA 1731-2] linux regression update
- [debian-lts-announce] 20190401 [SECURITY] [DLA 1731-2] linux regression update
Modified: 2024-11-21
CVE-2016-9083
drivers/vfio/pci/vfio_pci.c in the Linux kernel through 4.8.11 allows local users to bypass integer overflow checks, and cause a denial of service (memory corruption) or have unspecified other impact, by leveraging access to a vfio PCI device file for a VFIO_DEVICE_SET_IRQS ioctl call, aka a "state machine confusion bug."
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=05692d7005a364add85c6e25a6c4447ce08f913a
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=05692d7005a364add85c6e25a6c4447ce08f913a
- RHSA-2017:0386
- RHSA-2017:0386
- RHSA-2017:0387
- RHSA-2017:0387
- [oss-security] 20161027 kernel: low-severity vfio driver integer overflow
- [oss-security] 20161027 kernel: low-severity vfio driver integer overflow
- 93929
- 93929
- https://bugzilla.redhat.com/show_bug.cgi?id=1389258
- https://bugzilla.redhat.com/show_bug.cgi?id=1389258
- https://github.com/torvalds/linux/commit/05692d7005a364add85c6e25a6c4447ce08f913a
- https://github.com/torvalds/linux/commit/05692d7005a364add85c6e25a6c4447ce08f913a
- https://patchwork.kernel.org/patch/9373631/
- https://patchwork.kernel.org/patch/9373631/
Modified: 2024-11-21
CVE-2016-9588
arch/x86/kvm/vmx.c in the Linux kernel through 4.9 mismanages the #BP and #OF exceptions, which allows guest OS users to cause a denial of service (guest OS crash) by declining to handle an exception thrown by an L2 guest.
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ef85b67385436ddc1998f45f1d6a210f935b3388
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ef85b67385436ddc1998f45f1d6a210f935b3388
- DSA-3804
- DSA-3804
- [oss-security] 20161215 CVE-2016-9588 Kernel: kvm: nVMX: uncaught software exceptions in L1 guest lead to DoS
- [oss-security] 20161215 CVE-2016-9588 Kernel: kvm: nVMX: uncaught software exceptions in L1 guest lead to DoS
- 94933
- 94933
- RHSA-2017:1842
- RHSA-2017:1842
- RHSA-2017:2077
- RHSA-2017:2077
- https://bugzilla.redhat.com/show_bug.cgi?id=1404924
- https://bugzilla.redhat.com/show_bug.cgi?id=1404924
- https://github.com/torvalds/linux/commit/ef85b67385436ddc1998f45f1d6a210f935b3388
- https://github.com/torvalds/linux/commit/ef85b67385436ddc1998f45f1d6a210f935b3388
- USN-3822-1
- USN-3822-1
- USN-3822-2
- USN-3822-2
Modified: 2024-11-21
CVE-2016-9919
The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79dc7e3f1cd323be4c81aa1a94faa1b3ed987fb2
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79dc7e3f1cd323be4c81aa1a94faa1b3ed987fb2
- [oss-security] 20161208 CVE request: Linux panic on fragemented IPv6 traffic (icmp6_send)
- [oss-security] 20161208 CVE request: Linux panic on fragemented IPv6 traffic (icmp6_send)
- 94824
- 94824
- https://github.com/torvalds/linux/commit/79dc7e3f1cd323be4c81aa1a94faa1b3ed987fb2
- https://github.com/torvalds/linux/commit/79dc7e3f1cd323be4c81aa1a94faa1b3ed987fb2
Closed vulnerabilities
BDU:2022-02560
Уязвимость модулей интерпретатора языка программирования Perl , связанная с ошибками управления привилегиями, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2016-1238
(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan/IO-Compress/bin/zipdetails, (13) cpan/JSON-PP/bin/json_pp, (14) cpan/Test-Harness/bin/prove, (15) dist/ExtUtils-ParseXS/lib/ExtUtils/xsubpp, (16) dist/Module-CoreList/corelist, (17) ext/Pod-Html/bin/pod2html, (18) utils/c2ph.PL, (19) utils/h2ph.PL, (20) utils/h2xs.PL, (21) utils/libnetcfg.PL, (22) utils/perlbug.PL, (23) utils/perldoc.PL, (24) utils/perlivp.PL, and (25) utils/splain.PL in Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working directory.
- openSUSE-SU-2019:1831
- openSUSE-SU-2019:1831
- http://perl5.git.perl.org/perl.git/commit/cee96d52c39b1e7b36e1c62d38bcd8d86e9a41ab
- http://perl5.git.perl.org/perl.git/commit/cee96d52c39b1e7b36e1c62d38bcd8d86e9a41ab
- DSA-3628
- DSA-3628
- [perl.perl5.porters] 20160725 CVE-2016-1238: Important unsafe module load path flaw
- [perl.perl5.porters] 20160725 CVE-2016-1238: Important unsafe module load path flaw
- 92136
- 92136
- 1036440
- 1036440
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731
- [announce] 20180916 [SECURITY] Apache SpamAssassin 3.4.2 resolves CVE-2017-15705, CVE-2016-1238, CVE-2018-11780 & CVE-2018-11781
- [announce] 20180916 [SECURITY] Apache SpamAssassin 3.4.2 resolves CVE-2017-15705, CVE-2016-1238, CVE-2018-11780 & CVE-2018-11781
- [debian-lts-announce] 20181113 [SECURITY] [DLA 1578-1] spamassassin security update
- [debian-lts-announce] 20181113 [SECURITY] [DLA 1578-1] spamassassin security update
- FEDORA-2016-e9e5c081d4
- FEDORA-2016-e9e5c081d4
- FEDORA-2016-dd20a4631a
- FEDORA-2016-dd20a4631a
- FEDORA-2016-6ec2009080
- FEDORA-2016-6ec2009080
- https://rt.perl.org/Public/Bug/Display.html?id=127834
- https://rt.perl.org/Public/Bug/Display.html?id=127834
- GLSA-201701-75
- GLSA-201701-75
- GLSA-201812-07
- GLSA-201812-07