2017-11-24
ALT-BU-2017-3518-1
Branch sisyphus update bulletin.
Package fluidsynth updated to version 1.1.8-alt1.1 for branch sisyphus in task 195266.
Closed bugs
Молчит
Closed vulnerabilities
Published: 2017-06-17
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2015-3254
The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
Severity: MEDIUM (6.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References:
- http://grokbase.com/t/thrift/user/15c2tss3td/notice-apache-thrift-security-vulnerability-cve-2015-1774
- http://grokbase.com/t/thrift/user/15c2tss3td/notice-apache-thrift-security-vulnerability-cve-2015-1774
- 99112
- 99112
- RHSA-2017:2477
- RHSA-2017:2477
- RHSA-2017:3115
- RHSA-2017:3115
- https://issues.apache.org/jira/browse/THRIFT-3231
- https://issues.apache.org/jira/browse/THRIFT-3231
- [thrift-user] 20151210 Re: [NOTICE]: Apache Thrift Security Vulnerability CVE-2015-1774
- [thrift-user] 20151210 Re: [NOTICE]: Apache Thrift Security Vulnerability CVE-2015-1774
Published: 2018-02-12
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-5397
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
Severity: HIGH (8.8)
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
- [user] 20170113 [NOTICE]: Apache Thrift Security Vulnerability CVE-2016-5397
- [user] 20170113 [NOTICE]: Apache Thrift Security Vulnerability CVE-2016-5397
- 103025
- 103025
- RHSA-2018:2669
- RHSA-2018:2669
- RHSA-2019:3140
- RHSA-2019:3140
- https://issues.apache.org/jira/browse/THRIFT-3893
- https://issues.apache.org/jira/browse/THRIFT-3893
- [cassandra-commits] 20200604 [jira] [Created] (CASSANDRA-15856) Security vulnerabilities with dependency jars of Cassandra 3.11.6
- [cassandra-commits] 20200604 [jira] [Created] (CASSANDRA-15856) Security vulnerabilities with dependency jars of Cassandra 3.11.6