ALT-BU-2017-3028-1
Branch sisyphus update bulletin.
Package shim-signed updated to version 0.4-alt4 for branch sisyphus in task 181193.
Closed bugs
убрать альтовую подпись с shim-signed
Closed vulnerabilities
Modified: 2024-11-21
CVE-2012-2150
xfs_metadump in xfsprogs before 3.2.4 does not properly obfuscate file data, which allows remote attackers to obtain sensitive information by reading a generated image.
- FEDORA-2015-12435
- FEDORA-2015-12435
- FEDORA-2015-12380
- FEDORA-2015-12380
- FEDORA-2015-12406
- FEDORA-2015-12406
- openSUSE-SU-2015:1429
- openSUSE-SU-2015:1429
- openSUSE-SU-2016:0018
- openSUSE-SU-2016:0018
- [xfs] 20150729 [ANNOUNCE] xfsprogs: v3.2.4 released
- [xfs] 20150729 [ANNOUNCE] xfsprogs: v3.2.4 released
- [oss-security] 20150723 CVE-2012-2150 xfsprogs: xfs_metadump information disclosure flaw
- [oss-security] 20150723 CVE-2012-2150 xfsprogs: xfs_metadump information disclosure flaw
- [oss-security] 20150730 Re: CVE-2012-2150 xfsprogs: xfs_metadump information disclosure flaw
- [oss-security] 20150730 Re: CVE-2012-2150 xfsprogs: xfs_metadump information disclosure flaw
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- 76013
- 76013
- https://bugzilla.redhat.com/show_bug.cgi?id=817696
- https://bugzilla.redhat.com/show_bug.cgi?id=817696
Closed bugs
[FR] Обновить до актуальной версии
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-5192
When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.
- https://docs.saltstack.com/en/2016.3/topics/releases/2015.8.13.html
- https://docs.saltstack.com/en/2016.3/topics/releases/2015.8.13.html
- https://docs.saltstack.com/en/2016.3/topics/releases/2016.3.5.html
- https://docs.saltstack.com/en/2016.3/topics/releases/2016.3.5.html
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.2.html
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.2.html
Modified: 2024-11-21
CVE-2017-5200
Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.
- https://docs.saltstack.com/en/2016.3/topics/releases/2015.8.13.html
- https://docs.saltstack.com/en/2016.3/topics/releases/2015.8.13.html
- https://docs.saltstack.com/en/2016.3/topics/releases/2016.3.5.html
- https://docs.saltstack.com/en/2016.3/topics/releases/2016.3.5.html
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.2.html
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.2.html
Modified: 2024-11-21
CVE-2017-7893
In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master.