2019-02-08
ALT-BU-2019-3477-1
Branch sisyphus update bulletin.
Closed bugs
cmake update to 3.13.3-alt1 broke build of many packages
Package parcellite updated to version 1.1.9-alt2 for branch sisyphus in task 220844.
Closed bugs
Добавить автозапуск для Mate
Package matrix-synapse updated to version 0.34.1.1-alt1 for branch sisyphus in task 220890.
Closed vulnerabilities
Published: 2019-03-21
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-5885
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
Severity: HIGH (7.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
References:
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/32Y6KD3OAHCG5P33HC2QEX3NUZOSXCGZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/32Y6KD3OAHCG5P33HC2QEX3NUZOSXCGZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMCLO5PUPBA756UKY72PKUWL4RRM4W6K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMCLO5PUPBA756UKY72PKUWL4RRM4W6K/
- https://matrix.org/blog/2019/01/10/critical-security-update-synapse-0-34-0-1-synapse-0-34-1-1/
- https://matrix.org/blog/2019/01/10/critical-security-update-synapse-0-34-0-1-synapse-0-34-1-1/
- https://matrix.org/blog/2019/01/15/further-details-on-critical-security-update-in-synapse-affecting-all-versions-prior-to-0-34-1-cve-2019-5885/
- https://matrix.org/blog/2019/01/15/further-details-on-critical-security-update-in-synapse-affecting-all-versions-prior-to-0-34-1-cve-2019-5885/
Package libtool_2.4 updated to version 2.4.2-alt8 for branch sisyphus in task 220900.
Closed bugs
-export-symbols and -export-symbols-regex are not implemented properly for C++ code
Closed bugs
Не запускается