ALT-BU-2019-3540-1
Branch p8 update bulletin.
Closed bugs
Просьба обновить до последней версии
Closed vulnerabilities
BDU:2021-01319
Уязвимость множества функций из mercurial/subrepo.py программного средства управления версиями Mercurial, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-3902
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3902
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3902
- [debian-lts-announce] 20190425 [SECURITY] [DLA 1764-1] mercurial security update
- [debian-lts-announce] 20190425 [SECURITY] [DLA 1764-1] mercurial security update
- [debian-lts-announce] 20200731 [SECURITY] [DLA 2293-1] mercurial security update
- [debian-lts-announce] 20200731 [SECURITY] [DLA 2293-1] mercurial security update
- USN-4086-1
- USN-4086-1
- https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.9_.282019-02-01.29
- https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.9_.282019-02-01.29
Closed vulnerabilities
BDU:2018-00028
Уязвимость библиотеки spice, связанная с переполнением буфера, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2019-00441
Уязвимость функции write_validate_array_item() («demarshal.py») системы рендеринга удаленного виртуального «рабочего стола» SPICE (the Simple Protocol for Independent Computing Environments), связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю получить доступ к конфиденциальной информации или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2016-9577
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
Modified: 2024-11-21
CVE-2016-9578
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
Modified: 2024-11-21
CVE-2017-7506
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.
- DSA-3907
- DSA-3907
- [oss-security] 20170714 CVE-2017-7506 spice: Possible buffer overflow via invalid monitor configurations
- [oss-security] 20170714 CVE-2017-7506 spice: Possible buffer overflow via invalid monitor configurations
- 99583
- 99583
- RHSA-2017:2471
- RHSA-2017:2471
- RHSA-2018:3522
- RHSA-2018:3522
- https://bugzilla.redhat.com/show_bug.cgi?id=1452606
- https://bugzilla.redhat.com/show_bug.cgi?id=1452606
Modified: 2024-11-21
CVE-2018-10873
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
- 105152
- 105152
- RHSA-2018:2731
- RHSA-2018:2731
- RHSA-2018:2732
- RHSA-2018:2732
- RHSA-2018:3470
- RHSA-2018:3470
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10873
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10873
- https://gitlab.freedesktop.org/spice/spice-common/commit/bb15d4815ab586b4c4a20f4a565970a44824c42c
- https://gitlab.freedesktop.org/spice/spice-common/commit/bb15d4815ab586b4c4a20f4a565970a44824c42c
- [debian-lts-announce] 20180831 [SECURITY] [DLA 1488-1] spice security update
- [debian-lts-announce] 20180831 [SECURITY] [DLA 1488-1] spice security update
- [debian-lts-announce] 20180831 [SECURITY] [DLA 1486-1] spice security update
- [debian-lts-announce] 20180831 [SECURITY] [DLA 1486-1] spice security update
- [debian-lts-announce] 20180831 [SECURITY] [DLA 1489-1] spice-gtk security update
- [debian-lts-announce] 20180831 [SECURITY] [DLA 1489-1] spice-gtk security update
- USN-3751-1
- USN-3751-1
- DSA-4319
- DSA-4319