ALT-BU-2017-3250-1
Branch sisyphus update bulletin.
Package php5-fpm-fcgi updated to version 5.6.31.20170607-alt1.S1.2 for branch sisyphus in task 185644.
Closed bugs
Не ротейтятся корректно логи
Closed vulnerabilities
BDU:2020-03954
Уязвимость реализации функции function box_blur_line библиотеки отрисовки векторной графики librsvg, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2017-11464
A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.
- 99956
- 99956
- https://bugzilla.gnome.org/show_bug.cgi?id=783835
- https://bugzilla.gnome.org/show_bug.cgi?id=783835
- https://git.gnome.org/browse/librsvg/commit/?id=ecf9267a24b2c3c0cd211dbdfa9ef2232511972a
- https://git.gnome.org/browse/librsvg/commit/?id=ecf9267a24b2c3c0cd211dbdfa9ef2232511972a
- https://github.com/GNOME/librsvg/commit/ecf9267a24b2c3c0cd211dbdfa9ef2232511972a
- https://github.com/GNOME/librsvg/commit/ecf9267a24b2c3c0cd211dbdfa9ef2232511972a
- [debian-lts-announce] 20200722 [SECURITY] [DLA 2285-1] librsvg security update
- [debian-lts-announce] 20200722 [SECURITY] [DLA 2285-1] librsvg security update
- USN-4436-1
- USN-4436-1
Closed vulnerabilities
BDU:2018-00019
Уязвимость функции try_read_command (memcached.c) программного средства кэширования данных memcached, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2018-01496
Уязвимость программного средства кэширования данных memcached, связанная с переполнением целых чисел, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2017-9951
The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.
- 99874
- 99874
- https://github.com/memcached/memcached/wiki/ReleaseNotes1439
- https://github.com/memcached/memcached/wiki/ReleaseNotes1439
- https://groups.google.com/forum/message/raw?msg=memcached/ubGWrkmrr4E/nrm1SeVJAQAJ
- https://groups.google.com/forum/message/raw?msg=memcached/ubGWrkmrr4E/nrm1SeVJAQAJ
- USN-3588-1
- USN-3588-1
- DSA-4218
- DSA-4218
- https://www.twistlock.com/2017/07/13/cve-2017-9951-heap-overflow-memcached-server-1-4-38-twistlock-vulnerability-report/
- https://www.twistlock.com/2017/07/13/cve-2017-9951-heap-overflow-memcached-server-1-4-38-twistlock-vulnerability-report/
Modified: 2024-11-21
CVE-2018-1000127
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.
- RHSA-2018:2290
- RHSA-2018:2290
- https://github.com/memcached/memcached/commit/a8c4a82787b8b6c256d61bd5c42fb7f92d1bae00
- https://github.com/memcached/memcached/commit/a8c4a82787b8b6c256d61bd5c42fb7f92d1bae00
- https://github.com/memcached/memcached/issues/271
- https://github.com/memcached/memcached/issues/271
- https://github.com/memcached/memcached/wiki/ReleaseNotes1437
- https://github.com/memcached/memcached/wiki/ReleaseNotes1437
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1329-1] memcached security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1329-1] memcached security update
- USN-3601-1
- USN-3601-1
- DSA-4218
- DSA-4218
Package kf5-plasma-desktop updated to version 5.10.4-alt1.S1 for branch sisyphus in task 185627.
Closed bugs
Не сохраняются настройки QT4