ALT-BU-2017-3532-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-8816
The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.
- http://security.cucumberlinux.com/security/details.php?id=161
- http://security.cucumberlinux.com/security/details.php?id=161
- 101998
- 101998
- 1039896
- 1039896
- 1040608
- 1040608
- RHSA-2018:3558
- RHSA-2018:3558
- https://curl.haxx.se/docs/adv_2017-12e7.html
- https://curl.haxx.se/docs/adv_2017-12e7.html
- GLSA-201712-04
- GLSA-201712-04
- DSA-4051
- DSA-4051
Modified: 2024-11-21
CVE-2017-8817
The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.
- http://security.cucumberlinux.com/security/details.php?id=162
- http://security.cucumberlinux.com/security/details.php?id=162
- 102057
- 102057
- 1039897
- 1039897
- RHSA-2018:3558
- RHSA-2018:3558
- https://curl.haxx.se/docs/adv_2017-ae72.html
- https://curl.haxx.se/docs/adv_2017-ae72.html
- [debian-lts-announce] 20171130 [SECURITY] [DLA 1195-1] curl security update
- [debian-lts-announce] 20171130 [SECURITY] [DLA 1195-1] curl security update
- GLSA-201712-04
- GLSA-201712-04
- DSA-4051
- DSA-4051
Modified: 2024-11-21
CVE-2017-8818
curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact because too little memory is allocated for interfacing to an SSL library.
Closed bugs
При автогенерации конфигурационного файла при помощи grub-mkconfig, блок для загрузки Xen создается с синтаксической ошибкой (не хватает закрывающей фигурной скобки)
не переименован sysconfig/grub2
Closed bugs
не работает xcos
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-8819
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion services, aka TROVE-2017-009. An attacker can send many INTRODUCE2 cells to trigger this issue.
Modified: 2024-11-21
CVE-2017-8820
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory authorities via a malformed descriptor, aka TROVE-2017-010.
Modified: 2024-11-21
CVE-2017-8821
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can cause a denial of service (application hang) via crafted PEM input that signifies a public key requiring a password, which triggers an attempt by the OpenSSL library to ask the user for the password, aka TROVE-2017-011.
Modified: 2024-11-21
CVE-2017-8822
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.
- https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516
- https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516
- https://bugs.torproject.org/21534
- https://bugs.torproject.org/21534
- https://bugs.torproject.org/24333
- https://bugs.torproject.org/24333
- DSA-4054
- DSA-4054
Modified: 2024-11-21
CVE-2017-8823
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 during intro-point expiration because the expiring list is mismanaged in certain error cases, aka TROVE-2017-013.
- https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516
- https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516
- https://bugs.torproject.org/24313
- https://bugs.torproject.org/24313
- https://bugs.torproject.org/24430
- https://bugs.torproject.org/24430
- DSA-4054
- DSA-4054