ALT-BU-2019-3845-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-24031
In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=981404
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=981404
- https://github.com/facebook/zstd/issues/1630
- https://github.com/facebook/zstd/issues/1630
- https://www.facebook.com/security/advisories/cve-2021-24031
- https://www.facebook.com/security/advisories/cve-2021-24031
Closed vulnerabilities
BDU:2020-00724
Уязвимость программного обеспечения Samba, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2020-02775
Уязвимость программного обеспечения Samba, связанная с ошибками разыменования указателей, позволяющая нарушителю вызвать отказ в обслуживании сервера AD DC LDAP
Modified: 2024-11-21
CVE-2019-12435
Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is related to the AD DC DNS management server (dnsserver) RPC server process.
- openSUSE-SU-2019:1755
- openSUSE-SU-2019:1755
- 108825
- 108825
- FEDORA-2019-8966706e33
- FEDORA-2019-8966706e33
- FEDORA-2019-8015e5dc40
- FEDORA-2019-8015e5dc40
- USN-4018-1
- USN-4018-1
- https://www.samba.org/samba/security/CVE-2019-12435.html
- https://www.samba.org/samba/security/CVE-2019-12435.html
- https://www.synology.com/security/advisory/Synology_SA_19_27
- https://www.synology.com/security/advisory/Synology_SA_19_27
Modified: 2024-11-21
CVE-2019-12436
Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.
- 108823
- 108823
- FEDORA-2019-8015e5dc40
- FEDORA-2019-8015e5dc40
- USN-4018-1
- USN-4018-1
- https://www.samba.org/samba/security/CVE-2019-12436.html
- https://www.samba.org/samba/security/CVE-2019-12436.html
- https://www.synology.com/security/advisory/Synology_SA_19_27
- https://www.synology.com/security/advisory/Synology_SA_19_27