ALT-BU-2017-3471-1
Branch c7 update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2014-6060
The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.
- http://advisories.mageia.org/MGASA-2014-0334.html
- http://advisories.mageia.org/MGASA-2014-0334.html
- http://roy.marples.name/projects/dhcpcd/ci/1d2b93aa5ce25a8a710082fe2d36a6bf7f5794d5?sbs=0
- http://roy.marples.name/projects/dhcpcd/ci/1d2b93aa5ce25a8a710082fe2d36a6bf7f5794d5?sbs=0
- http://source.android.com/security/bulletin/2016-04-02.html
- http://source.android.com/security/bulletin/2016-04-02.html
- MDVSA-2014:171
- MDVSA-2014:171
- [oss-security] 20140730 CVE Request: dhcpcd DoS attack
- [oss-security] 20140730 CVE Request: dhcpcd DoS attack
- [oss-security] 20140901 CVE Request: dhcpcd DoS attack
- [oss-security] 20140901 CVE Request: dhcpcd DoS attack
- 68970
- 68970
- SSA:2014-213-02
- SSA:2014-213-02
Closed vulnerabilities
BDU:2020-04521
Уязвимость системы межпроцессорного взаимодействия D-Bus, вызванная ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2015-0245
D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds.
- http://advisories.mageia.org/MGASA-2015-0071.html
- http://advisories.mageia.org/MGASA-2015-0071.html
- openSUSE-SU-2015:0300
- openSUSE-SU-2015:0300
- DSA-3161
- DSA-3161
- MDVSA-2015:176
- MDVSA-2015:176
- [oss-security] 20150209 CVE-2015-0245: denial of service in dbus >= 1.4 systemd activation
- [oss-security] 20150209 CVE-2015-0245: denial of service in dbus >= 1.4 systemd activation
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
Closed bugs
Перезапуск dbus при обновлении много чего ломает
Closed vulnerabilities
BDU:2015-09791
Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
BDU:2016-01680
Уязвимость менеджера загрузок GNU Wget, позволяющая нарушителю изменять произвольные файлы
Modified: 2024-11-21
CVE-2014-4877
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
- http://advisories.mageia.org/MGASA-2014-0431.html
- http://advisories.mageia.org/MGASA-2014-0431.html
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=18b0979357ed7dc4e11d4f2b1d7e0f5932d82aa7
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=18b0979357ed7dc4e11d4f2b1d7e0f5932d82aa7
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=b4440d96cf8173d68ecaa07c36b8f4316ee794d0
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=b4440d96cf8173d68ecaa07c36b8f4316ee794d0
- [bug-wget] 20141027 GNU wget 1.16 released
- [bug-wget] 20141027 GNU wget 1.16 released
- SUSE-SU-2014:1366
- SUSE-SU-2014:1366
- SUSE-SU-2014:1408
- SUSE-SU-2014:1408
- openSUSE-SU-2014:1380
- openSUSE-SU-2014:1380
- RHSA-2014:1764
- RHSA-2014:1764
- RHSA-2014:1955
- RHSA-2014:1955
- GLSA-201411-05
- GLSA-201411-05
- DSA-3062
- DSA-3062
- VU#685996
- VU#685996
- MDVSA-2015:121
- MDVSA-2015:121
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- 70751
- 70751
- USN-2393-1
- USN-2393-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1139181
- https://bugzilla.redhat.com/show_bug.cgi?id=1139181
- https://community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-access
- https://community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-access
- https://github.com/rapid7/metasploit-framework/pull/4088
- https://github.com/rapid7/metasploit-framework/pull/4088
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- https://kc.mcafee.com/corporate/index?page=content&id=SB10106
- https://kc.mcafee.com/corporate/index?page=content&id=SB10106
Modified: 2024-11-21
CVE-2016-4971
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=e996e322ffd42aaa051602da182d03178d0f13e1
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=e996e322ffd42aaa051602da182d03178d0f13e1
- [info-gnu] 20160609 GNU wget 1.18 released
- [info-gnu] 20160609 GNU wget 1.18 released
- openSUSE-SU-2016:2027
- openSUSE-SU-2016:2027
- http://packetstormsecurity.com/files/162395/GNU-wget-Arbitrary-File-Upload-Code-Execution.html
- http://packetstormsecurity.com/files/162395/GNU-wget-Arbitrary-File-Upload-Code-Execution.html
- RHSA-2016:2587
- RHSA-2016:2587
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91530
- 91530
- 1036133
- 1036133
- USN-3012-1
- USN-3012-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1343666
- https://bugzilla.redhat.com/show_bug.cgi?id=1343666
- GLSA-201610-11
- GLSA-201610-11
- https://security.paloaltonetworks.com/CVE-2016-4971
- https://security.paloaltonetworks.com/CVE-2016-4971
- 40064
- 40064
Modified: 2024-11-21
CVE-2016-7098
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.
- [bug-wget] 20160814 Wget - acess list bypass / race condition PoC
- [bug-wget] 20160814 Wget - acess list bypass / race condition PoC
- [bug-wget] 20160824 Re: Wget - acess list bypass / race condition PoC
- [bug-wget] 20160824 Re: Wget - acess list bypass / race condition PoC
- openSUSE-SU-2016:2284
- openSUSE-SU-2016:2284
- openSUSE-SU-2017:0015
- openSUSE-SU-2017:0015
- [oss-security] 20160827 Re: CVE Request - Gnu Wget 1.17 - Design Error Vulnerability
- [oss-security] 20160827 Re: CVE Request - Gnu Wget 1.17 - Design Error Vulnerability
- 93157
- 93157
- [debian-lts-announce] 20200129 [SECURITY] [DLA 2086-1] wget security update
- [debian-lts-announce] 20200129 [SECURITY] [DLA 2086-1] wget security update
- 40824
- 40824
Closed bugs
Не отрабатывают скрипты autostart и environment при запуске openbox
Closed bugs
удалите поддержку /lib/udev/devices
remove unneeded /lib/tmpfiles.d/cuse.conf
Права на устройство
Предлагаю добавить fuserumount
permissions on /dev/fuse get broken and fusermount fails
Closed bugs
ошибка в open_generic()
apt-indicator и gksu