ALT-BU-2018-3117-1
Branch p8 update bulletin.
Package lxqt-panel updated to version 0.12.0-alt3.M80P.1 for branch p8 in task 201480.
Closed bugs
поддержка pulseaudio
Package kernel-image-un-def updated to version 4.14.24-alt0.M80P.1 for branch p8 in task 201432.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2018-1000028
Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This attack appear to be exploitable via NFS server must export a filesystem with the "rootsquash" options enabled. This vulnerability appears to have been fixed in after commit 1995266727fa.
Closed bugs
не запускается без /etc/os-release
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-16818
RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, related to rgw/rgw_iam_policy.cc, rgw/rgw_basic_types.h, and rgw/rgw_iam_types.h.
- https://bugzilla.redhat.com/show_bug.cgi?id=1515872
- https://bugzilla.redhat.com/show_bug.cgi?id=1515872
- https://github.com/ceph/ceph/commit/b3118cabb8060a8cc6a01c4e8264cb18e7b1745a
- https://github.com/ceph/ceph/commit/b3118cabb8060a8cc6a01c4e8264cb18e7b1745a
- FEDORA-2017-97b730736f
- FEDORA-2017-97b730736f
Modified: 2024-11-21
CVE-2018-7262
In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service.
- http://tracker.ceph.com/issues/23039
- http://tracker.ceph.com/issues/23039
- RHSA-2018:0546
- RHSA-2018:0546
- RHSA-2018:0548
- RHSA-2018:0548
- https://bugzilla.redhat.com/show_bug.cgi?id=1546611
- https://bugzilla.redhat.com/show_bug.cgi?id=1546611
- https://github.com/ceph/ceph/pull/20488
- https://github.com/ceph/ceph/pull/20488
- FEDORA-2018-ed907ef9a0
- FEDORA-2018-ed907ef9a0