ALT-BU-2019-3678-1
Branch sisyphus update bulletin.
Closed bugs
Два значка запуска
Closed vulnerabilities
BDU:2021-00100
Уязвимость набора криптографических библиотек NSS, связанная с неправильным подтверждением подлинности сертификата, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-17007
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1533216
- https://bugzilla.mozilla.org/show_bug.cgi?id=1533216
- https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.44_release_notes
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.44_release_notes
- https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04
- https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04
Closed vulnerabilities
BDU:2020-01339
Уязвимость компонента RFC3490 библиотеки Libidn2, позволяющая нарушителю создать вредоносный домен, который соответствует целевому домену
Modified: 2024-11-21
CVE-2019-12290
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.
- openSUSE-SU-2019:2613
- openSUSE-SU-2019:2613
- openSUSE-SU-2019:2611
- openSUSE-SU-2019:2611
- https://gitlab.com/libidn/libidn2/commit/241e8f486134793cb0f4a5b0e5817a97883401f5
- https://gitlab.com/libidn/libidn2/commit/241e8f486134793cb0f4a5b0e5817a97883401f5
- https://gitlab.com/libidn/libidn2/commit/614117ef6e4c60e1950d742e3edf0a0ef8d389de
- https://gitlab.com/libidn/libidn2/commit/614117ef6e4c60e1950d742e3edf0a0ef8d389de
- https://gitlab.com/libidn/libidn2/merge_requests/71
- https://gitlab.com/libidn/libidn2/merge_requests/71
- FEDORA-2019-20e9736c97
- FEDORA-2019-20e9736c97
- FEDORA-2019-28d3cd20c0
- FEDORA-2019-28d3cd20c0
- FEDORA-2019-160303ebeb
- FEDORA-2019-160303ebeb
- FEDORA-2019-1ebb5c928e
- FEDORA-2019-1ebb5c928e
- FEDORA-2019-f454c7a118
- FEDORA-2019-f454c7a118
- GLSA-202003-63
- GLSA-202003-63
- USN-4168-1
- USN-4168-1