ALT-BU-2018-3254-1
Branch p8 update bulletin.
Closed vulnerabilities
BDU:2018-00916
Уязвимость программного средства для взаимодействия с серверами cURL, вызванная переполнением буфера в памяти, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2018-01424
Уязвимость программного средства для взаимодействия с серверами curl, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-1000300
curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when closing down an FTP connection with very long server command replies.. This vulnerability appears to have been fixed in curl < 7.54.1 and curl >= 7.60.0.
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 104207
- 104207
- 1040933
- 1040933
- https://curl.haxx.se/docs/adv_2018-82c2.html
- https://curl.haxx.se/docs/adv_2018-82c2.html
- GLSA-201806-05
- GLSA-201806-05
- USN-3648-1
- USN-3648-1
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
Modified: 2024-11-21
CVE-2018-1000301
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl < 7.20.0 and curl >= 7.60.0.
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 104225
- 104225
- 1040931
- 1040931
- RHBA-2019:0327
- RHBA-2019:0327
- RHSA-2018:3157
- RHSA-2018:3157
- RHSA-2018:3558
- RHSA-2018:3558
- RHSA-2020:0544
- RHSA-2020:0544
- RHSA-2020:0594
- RHSA-2020:0594
- https://curl.haxx.se/docs/adv_2018-b138.html
- https://curl.haxx.se/docs/adv_2018-b138.html
- [debian-lts-announce] 20180516 [SECURITY] [DLA 1379-1] curl security update
- [debian-lts-announce] 20180516 [SECURITY] [DLA 1379-1] curl security update
- GLSA-201806-05
- GLSA-201806-05
- USN-3598-2
- USN-3598-2
- USN-3648-1
- USN-3648-1
- DSA-4202
- DSA-4202
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Package glusterfs3 updated to version 3.12.9-alt0.M80P.1 for branch p8 in task 206538.
Closed vulnerabilities
BDU:2021-04142
Уязвимость функции gluster_shared_storage платформы хранения для физических, виртуальных и облачных сред gluster, позволяющая нарушителю повысить свои привилегии
Modified: 2024-11-21
CVE-2018-1088
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
- openSUSE-SU-2020:0079
- openSUSE-SU-2020:0079
- RHSA-2018:1136
- RHSA-2018:1136
- RHSA-2018:1137
- RHSA-2018:1137
- RHSA-2018:1275
- RHSA-2018:1275
- RHSA-2018:1524
- RHSA-2018:1524
- https://bugzilla.redhat.com/show_bug.cgi?id=1558721
- https://bugzilla.redhat.com/show_bug.cgi?id=1558721
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- [debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
- GLSA-201904-06
- GLSA-201904-06