ALT-BU-2018-3024-1
Branch sisyphus update bulletin.
Package libwebkitgtk4 updated to version 2.18.6-alt1 for branch sisyphus in task 198511.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-13884
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- https://support.apple.com/HT208324
- https://support.apple.com/HT208324
- https://support.apple.com/HT208325
- https://support.apple.com/HT208325
- https://support.apple.com/HT208326
- https://support.apple.com/HT208326
- https://support.apple.com/HT208327
- https://support.apple.com/HT208327
- https://support.apple.com/HT208328
- https://support.apple.com/HT208328
- https://support.apple.com/HT208334
- https://support.apple.com/HT208334
- USN-3551-1
- USN-3551-1
Modified: 2024-11-21
CVE-2017-13885
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- https://support.apple.com/HT208324
- https://support.apple.com/HT208324
- https://support.apple.com/HT208326
- https://support.apple.com/HT208326
- https://support.apple.com/HT208327
- https://support.apple.com/HT208327
- https://support.apple.com/HT208328
- https://support.apple.com/HT208328
- https://support.apple.com/HT208334
- https://support.apple.com/HT208334
- USN-3551-1
- USN-3551-1
Modified: 2024-11-21
CVE-2017-7153
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof user-interface information (about whether the entire content is derived from a valid TLS session) via a crafted web site that sends a 401 Unauthorized redirect.
- https://support.apple.com/HT208324
- https://support.apple.com/HT208324
- https://support.apple.com/HT208325
- https://support.apple.com/HT208325
- https://support.apple.com/HT208326
- https://support.apple.com/HT208326
- https://support.apple.com/HT208327
- https://support.apple.com/HT208327
- https://support.apple.com/HT208328
- https://support.apple.com/HT208328
- https://support.apple.com/HT208334
- https://support.apple.com/HT208334
- USN-3551-1
- USN-3551-1
Modified: 2024-11-21
CVE-2017-7160
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- https://support.apple.com/HT208324
- https://support.apple.com/HT208324
- https://support.apple.com/HT208326
- https://support.apple.com/HT208326
- https://support.apple.com/HT208327
- https://support.apple.com/HT208327
- https://support.apple.com/HT208328
- https://support.apple.com/HT208328
- https://support.apple.com/HT208334
- https://support.apple.com/HT208334
- USN-3551-1
- USN-3551-1
Modified: 2024-11-21
CVE-2017-7161
An issue was discovered in certain Apple products. Safari before 11.0.2 is affected. The issue involves the "WebKit Web Inspector" component. It allows remote attackers to execute arbitrary code via special characters that trigger command injection.
Modified: 2024-11-21
CVE-2017-7165
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- https://support.apple.com/HT208324
- https://support.apple.com/HT208324
- https://support.apple.com/HT208325
- https://support.apple.com/HT208325
- https://support.apple.com/HT208326
- https://support.apple.com/HT208326
- https://support.apple.com/HT208327
- https://support.apple.com/HT208327
- https://support.apple.com/HT208328
- https://support.apple.com/HT208328
- https://support.apple.com/HT208334
- https://support.apple.com/HT208334
- USN-3551-1
- USN-3551-1
Modified: 2024-11-21
CVE-2018-4088
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected. iCloud before 7.3 on Windows is affected. iTunes before 12.7.3 on Windows is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 102775
- 102775
- 1040265
- 1040265
- 1040266
- 1040266
- 1040267
- 1040267
- https://support.apple.com/HT208462
- https://support.apple.com/HT208462
- https://support.apple.com/HT208463
- https://support.apple.com/HT208463
- https://support.apple.com/HT208464
- https://support.apple.com/HT208464
- https://support.apple.com/HT208465
- https://support.apple.com/HT208465
- https://support.apple.com/HT208473
- https://support.apple.com/HT208473
- https://support.apple.com/HT208474
- https://support.apple.com/HT208474
- https://support.apple.com/HT208475
- https://support.apple.com/HT208475
- USN-3551-1
- USN-3551-1
Modified: 2024-11-21
CVE-2018-4096
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected. iCloud before 7.3 on Windows is affected. iTunes before 12.7.3 on Windows is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 102775
- 102775
- 1040265
- 1040265
- 1040266
- 1040266
- 1040267
- 1040267
- https://support.apple.com/HT208462
- https://support.apple.com/HT208462
- https://support.apple.com/HT208463
- https://support.apple.com/HT208463
- https://support.apple.com/HT208464
- https://support.apple.com/HT208464
- https://support.apple.com/HT208465
- https://support.apple.com/HT208465
- https://support.apple.com/HT208473
- https://support.apple.com/HT208473
- https://support.apple.com/HT208474
- https://support.apple.com/HT208474
- https://support.apple.com/HT208475
- https://support.apple.com/HT208475
- USN-3551-1
- USN-3551-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-9868
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
Closed bugs
Не присваивается IPv6 адрес через Router Advertisement
Package phpMyAdmin updated to version 4.7.7-alt1 for branch sisyphus in task 198577.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-1000499
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.
- http://cyberworldmirror.com/vulnerability-phpmyadmin-lets-attacker-perform-drop-table-single-click/
- http://cyberworldmirror.com/vulnerability-phpmyadmin-lets-attacker-perform-drop-table-single-click/
- 1040163
- 1040163
- 45284
- 45284
- https://www.phpmyadmin.net/security/PMASA-2017-9/
- https://www.phpmyadmin.net/security/PMASA-2017-9/
Modified: 2024-11-21
CVE-2018-19969
phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.
Closed vulnerabilities
BDU:2018-00014
Уязвимость функции asn1_check_identifier библиотеки libtasn1, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2017-10790
The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1_node structure. It may lead to a remote denial of service attack.
- https://bugzilla.redhat.com/show_bug.cgi?id=1464141
- https://bugzilla.redhat.com/show_bug.cgi?id=1464141
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [debian-lts-announce] 20200628 [SECURITY] [DLA 2255-1] libtasn1-6 security update
- [debian-lts-announce] 20200628 [SECURITY] [DLA 2255-1] libtasn1-6 security update
- GLSA-201710-11
- GLSA-201710-11
- USN-3547-1
- USN-3547-1
- DSA-4106
- DSA-4106
Modified: 2024-11-21
CVE-2018-6003
An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.
- http://git.savannah.nongnu.org/cgit/libtasn1.git/commit/?id=c593ae84cfcde8fea45787e53950e0ac71e9ca97
- http://git.savannah.nongnu.org/cgit/libtasn1.git/commit/?id=c593ae84cfcde8fea45787e53950e0ac71e9ca97
- https://bugzilla.redhat.com/show_bug.cgi?id=1535926
- https://bugzilla.redhat.com/show_bug.cgi?id=1535926
- https://bugzilla.suse.com/show_bug.cgi?id=1076832
- https://bugzilla.suse.com/show_bug.cgi?id=1076832
- https://gitlab.com/gnutls/libtasn1/commit/946565d8eb05fbf7970ea366e817581bb5a90910
- https://gitlab.com/gnutls/libtasn1/commit/946565d8eb05fbf7970ea366e817581bb5a90910
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- DSA-4106
- DSA-4106