ALT-BU-2018-3155-1
Branch sisyphus update bulletin.
Closed bugs
в спеке не указан Url:
Closed bugs
Обновление до версии 3.7.0
Closed vulnerabilities
Modified: 2024-11-21
CVE-2018-7728
An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/interfaces/MD5.cpp.
- https://bugs.freedesktop.org/show_bug.cgi?id=105205
- https://bugs.freedesktop.org/show_bug.cgi?id=105205
- https://cgit.freedesktop.org/exempi/commit/?id=e163667a06a9b656a047b0ec660b871f29a83c9f
- https://cgit.freedesktop.org/exempi/commit/?id=e163667a06a9b656a047b0ec660b871f29a83c9f
- [debian-lts-announce] 20180321 [SECURITY] [DLA 1310-1] exempi security update
- [debian-lts-announce] 20180321 [SECURITY] [DLA 1310-1] exempi security update
- FEDORA-2020-e22e9a655d
- FEDORA-2020-e22e9a655d
- USN-3668-1
- USN-3668-1
Modified: 2024-11-21
CVE-2018-7729
An issue was discovered in Exempi through 2.4.4. There is a stack-based buffer over-read in the PostScript_MetaHandler::ParsePSFile() function in XMPFiles/source/FileHandlers/PostScript_Handler.cpp.
- https://bugs.freedesktop.org/show_bug.cgi?id=105206
- https://bugs.freedesktop.org/show_bug.cgi?id=105206
- https://cgit.freedesktop.org/exempi/commit/?id=baa4b8a02c1ffab9645d13f0bfb1c0d10d311a0c
- https://cgit.freedesktop.org/exempi/commit/?id=baa4b8a02c1ffab9645d13f0bfb1c0d10d311a0c
- FEDORA-2020-e22e9a655d
- FEDORA-2020-e22e9a655d
- USN-3668-1
- USN-3668-1
Modified: 2024-11-21
CVE-2018-7730
An issue was discovered in Exempi through 2.4.4. A certain case of a 0xffffffff length is mishandled in XMPFiles/source/FormatSupport/PSIR_FileWriter.cpp, leading to a heap-based buffer over-read in the PSD_MetaHandler::CacheFileData() function.
- RHSA-2019:2048
- RHSA-2019:2048
- https://bugs.freedesktop.org/show_bug.cgi?id=105204
- https://bugs.freedesktop.org/show_bug.cgi?id=105204
- https://cgit.freedesktop.org/exempi/commit/?id=6cbd34025e5fd3ba47b29b602096e456507ce83b
- https://cgit.freedesktop.org/exempi/commit/?id=6cbd34025e5fd3ba47b29b602096e456507ce83b
- [debian-lts-announce] 20180321 [SECURITY] [DLA 1310-1] exempi security update
- [debian-lts-announce] 20180321 [SECURITY] [DLA 1310-1] exempi security update
- FEDORA-2020-e22e9a655d
- FEDORA-2020-e22e9a655d
- USN-3668-1
- USN-3668-1
Modified: 2024-11-21
CVE-2018-7731
An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FormatSupport/WEBP_Support.cpp does not check whether a bitstream has a NULL value, leading to a NULL pointer dereference in the WEBP::VP8XChunk class.
- https://bugs.freedesktop.org/show_bug.cgi?id=105247
- https://bugs.freedesktop.org/show_bug.cgi?id=105247
- https://cgit.freedesktop.org/exempi/commit/?id=aabedb5e749dd59112a3fe1e8e08f2d934f56666
- https://cgit.freedesktop.org/exempi/commit/?id=aabedb5e749dd59112a3fe1e8e08f2d934f56666
- FEDORA-2020-e22e9a655d
- FEDORA-2020-e22e9a655d
- USN-3668-1
- USN-3668-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-6173
NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.
- http://www.nlnetlabs.nl/svn/nsd/tags/NSD_4_1_11_REL/doc/RELNOTES
- http://www.nlnetlabs.nl/svn/nsd/tags/NSD_4_1_11_REL/doc/RELNOTES
- [oss-security] 20160706 Malicious primary DNS servers can crash secondaries
- [oss-security] 20160706 Malicious primary DNS servers can crash secondaries
- [oss-security] 20160706 Re: Malicious primary DNS servers can crash secondaries
- [oss-security] 20160706 Re: Malicious primary DNS servers can crash secondaries
- 91678
- 91678
- https://github.com/sischkg/xfer-limit/blob/master/README.md
- https://github.com/sischkg/xfer-limit/blob/master/README.md
- [dns-operations] 20160704 DNS activities in Japan
- [dns-operations] 20160704 DNS activities in Japan
- [nsd-users] 20160809 NSD 4.1.11
- [nsd-users] 20160809 NSD 4.1.11
- https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=790
- https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=790
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15105
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.
- 102817
- 102817
- [debian-lts-announce] 20180130 [SECURITY] [DLA 1264-1] unbound security update
- [debian-lts-announce] 20180130 [SECURITY] [DLA 1264-1] unbound security update
- [debian-lts-announce] 20190214 [SECURITY] [DLA 1676-1] unbound security update
- [debian-lts-announce] 20190214 [SECURITY] [DLA 1676-1] unbound security update
- https://unbound.net/downloads/CVE-2017-15105.txt
- https://unbound.net/downloads/CVE-2017-15105.txt
- USN-3673-1
- USN-3673-1
Closed bugs
[FR] ручка для отключения java