ALT-BU-2017-3230-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2025-04-20
CVE-2017-7529
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
- http://mailman.nginx.org/pipermail/nginx-announce/2017/000200.html
- http://seclists.org/fulldisclosure/2021/Sep/36
- http://www.securityfocus.com/bid/99534
- http://www.securitytracker.com/id/1039238
- https://access.redhat.com/errata/RHSA-2017:2538
- https://puppet.com/security/cve/cve-2017-7529
- https://support.apple.com/kb/HT212818
- http://mailman.nginx.org/pipermail/nginx-announce/2017/000200.html
- http://seclists.org/fulldisclosure/2021/Sep/36
- http://www.securityfocus.com/bid/99534
- http://www.securitytracker.com/id/1039238
- https://access.redhat.com/errata/RHSA-2017:2538
- https://puppet.com/security/cve/cve-2017-7529
- https://support.apple.com/kb/HT212818
Package libva-driver-intel updated to version 1.8.3-alt2.S1 for branch sisyphus in task 185275.
Closed bugs
wrong package summary
Closed vulnerabilities
Modified: 2025-04-20
CVE-2017-9772
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable.
- http://www.securityfocus.com/bid/99277
- https://caml.inria.fr/mantis/view.php?id=7557
- https://security.gentoo.org/glsa/201710-07
- https://sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.html
- http://www.securityfocus.com/bid/99277
- https://caml.inria.fr/mantis/view.php?id=7557
- https://security.gentoo.org/glsa/201710-07
- https://sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.html
Modified: 2025-04-20
CVE-2017-9779
OCaml compiler allows attackers to have unspecified impact via unknown vectors, a similar issue to CVE-2017-9772 "but with much less impact."
