ALT-BU-2018-3123-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2018-8098
Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an attacker to cause a denial of service (out-of-bounds read) via a crafted repository index file.
- https://github.com/libgit2/libgit2/commit/3207ddb0103543da8ad2139ec6539f590f9900c1
- https://github.com/libgit2/libgit2/commit/3207ddb0103543da8ad2139ec6539f590f9900c1
- https://github.com/libgit2/libgit2/commit/3db1af1f370295ad5355b8f64b865a2a357bcac0
- https://github.com/libgit2/libgit2/commit/3db1af1f370295ad5355b8f64b865a2a357bcac0
- https://libgit2.github.com/security/
- https://libgit2.github.com/security/
- [debian-lts-announce] 20220321 [SECURITY] [DLA 2936-1] libgit2 security update
- [debian-lts-announce] 20220321 [SECURITY] [DLA 2936-1] libgit2 security update
Modified: 2024-11-21
CVE-2018-8099
Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an attacker to cause a denial of service via a crafted repository index file.
- https://github.com/libgit2/libgit2/commit/58a6fe94cb851f71214dbefac3f9bffee437d6fe
- https://github.com/libgit2/libgit2/commit/58a6fe94cb851f71214dbefac3f9bffee437d6fe
- https://libgit2.github.com/security/
- https://libgit2.github.com/security/
- [debian-lts-announce] 20220321 [SECURITY] [DLA 2936-1] libgit2 security update
- [debian-lts-announce] 20220321 [SECURITY] [DLA 2936-1] libgit2 security update
Package kernel-image-std-def updated to version 4.9.86-alt1 for branch sisyphus in task 201508.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2018-1000028
Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This attack appear to be exploitable via NFS server must export a filesystem with the "rootsquash" options enabled. This vulnerability appears to have been fixed in after commit 1995266727fa.
Package firefox-esr updated to version 52.7.0-alt1 for branch sisyphus in task 201647.
Closed vulnerabilities
BDU:2023-01886
Уязвимость браузера Mozilla Firefox ESR и почтового клиента Thunderbird, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2018-5144
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
- 103384
- 103384
- 1040514
- 1040514
- RHSA-2018:0526
- RHSA-2018:0526
- RHSA-2018:0527
- RHSA-2018:0527
- RHSA-2018:0647
- RHSA-2018:0647
- RHSA-2018:0648
- RHSA-2018:0648
- https://bugzilla.mozilla.org/show_bug.cgi?id=1440926
- https://bugzilla.mozilla.org/show_bug.cgi?id=1440926
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- GLSA-201810-01
- GLSA-201810-01
- GLSA-201811-13
- GLSA-201811-13
- USN-3545-1
- USN-3545-1
- DSA-4139
- DSA-4139
- DSA-4155
- DSA-4155
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
Modified: 2024-11-21
CVE-2018-5145
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
- 103384
- 103384
- 1040514
- 1040514
- RHSA-2018:0526
- RHSA-2018:0526
- RHSA-2018:0527
- RHSA-2018:0527
- RHSA-2018:0647
- RHSA-2018:0647
- RHSA-2018:0648
- RHSA-2018:0648
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1261175%2C1348955
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1261175%2C1348955
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- GLSA-201811-13
- GLSA-201811-13
- USN-3545-1
- USN-3545-1
- DSA-4139
- DSA-4139
- DSA-4155
- DSA-4155
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
- https://www.mozilla.org/security/advisories/mfsa2018-09/