ALT-BU-2019-3746-1
Branch p9 update bulletin.
Package firefox-esr updated to version 60.7.1-alt1 for branch p9 in task 232565.
Closed vulnerabilities
BDU:2019-03613
Уязвимость метода Array.pop почтового клиента Thunderbird и браузеров Firefox и Firefox ESR, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-04-04
CVE-2019-11707
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1544386
- https://bugzilla.mozilla.org/show_bug.cgi?id=1544386
- GLSA-201908-12
- GLSA-201908-12
- https://www.mozilla.org/security/advisories/mfsa2019-18/
- https://www.mozilla.org/security/advisories/mfsa2019-18/
- https://www.mozilla.org/security/advisories/mfsa2019-20/
- https://www.mozilla.org/security/advisories/mfsa2019-20/
Package xorg-drv-intel updated to version 2.99.917-alt10 for branch p9 in task 232594.
Closed bugs
Broadwell GT2 Gen8 сваливается в UXA
Closed vulnerabilities
Modified: 2024-11-21
CVE-2019-10133
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
Modified: 2024-11-21
CVE-2019-10134
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
Modified: 2024-11-21
CVE-2019-10154
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
Closed vulnerabilities
BDU:2021-01915
Уязвимость библиотек crypto/x509 и golang.org/x/crypto/cryptobyte языка программирования GO, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2020-7919
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.
- https://groups.google.com/forum/#%21forum/golang-announce
- https://groups.google.com/forum/#%21forum/golang-announce
- https://groups.google.com/forum/#%21topic/golang-announce/Hsw4mHYc470
- https://groups.google.com/forum/#%21topic/golang-announce/Hsw4mHYc470
- https://groups.google.com/forum/#%21topic/golang-announce/-sdUB4VEQkA
- https://groups.google.com/forum/#%21topic/golang-announce/-sdUB4VEQkA
- FEDORA-2020-12bc5b5597
- FEDORA-2020-12bc5b5597
- https://security.netapp.com/advisory/ntap-20200327-0001/
- https://security.netapp.com/advisory/ntap-20200327-0001/
- DSA-4848
- DSA-4848
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html