ALT-BU-2019-3891-1
Branch sisyphus update bulletin.
Package cryptsetup updated to version 2.2.0-alt1 for branch sisyphus in task 236388.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-4484
The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password.
- http://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetup_initrd_shell.html
- http://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetup_initrd_shell.html
- [oss-security] 20161114 CVE-2016-4484: - Cryptsetup Initrd root Shell
- [oss-security] 20161114 CVE-2016-4484: - Cryptsetup Initrd root Shell
- [oss-security] 20161115 Re: CVE-2016-4484: - Cryptsetup Initrd root Shell - Update: Dracut is also vulnerable
- [oss-security] 20161115 Re: CVE-2016-4484: - Cryptsetup Initrd root Shell - Update: Dracut is also vulnerable
- [oss-security] 20161115 Re: [FD] CVE-2016-4484: - Cryptsetup Initrd root Shell
- [oss-security] 20161115 Re: [FD] CVE-2016-4484: - Cryptsetup Initrd root Shell
- [oss-security] 20161116 Re: CVE-2016-4484: - Cryptsetup Initrd root Shell
- [oss-security] 20161116 Re: CVE-2016-4484: - Cryptsetup Initrd root Shell
- 94315
- 94315
- https://gitlab.com/cryptsetup/cryptsetup/commit/ef8a7d82d8d3716ae9b58179590f7908981fa0cb
- https://gitlab.com/cryptsetup/cryptsetup/commit/ef8a7d82d8d3716ae9b58179590f7908981fa0cb
Closed vulnerabilities
BDU:2020-00739
Уязвимость функции __zzip_parse_root_directory библиотеки архивирования ZZIPlib, связанная с неосвобождением ресурса после истечения действительного срока его эксплуатирования, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-16548
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack.
- openSUSE-SU-2019:2396
- openSUSE-SU-2019:2396
- openSUSE-SU-2019:2394
- openSUSE-SU-2019:2394
- RHSA-2019:2196
- RHSA-2019:2196
- https://github.com/gdraheim/zziplib/issues/58
- https://github.com/gdraheim/zziplib/issues/58
- [debian-lts-announce] 20200628 [SECURITY] [DLA 2258-1] zziplib security update
- [debian-lts-announce] 20200628 [SECURITY] [DLA 2258-1] zziplib security update
Modified: 2024-11-21
CVE-2018-17828
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.