ALT-BU-2019-3945-1
Branch p9 update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2019-13273
In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.
Modified: 2024-11-21
CVE-2019-13274
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
Modified: 2024-11-21
CVE-2019-13451
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/history.c
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/history.c
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.xymon.com/archive/2019-July/046570.html
- https://lists.xymon.com/archive/2019-July/046570.html
Modified: 2024-11-21
CVE-2019-13452
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/reportlog.c
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/reportlog.c
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.xymon.com/archive/2019-July/046570.html
- https://lists.xymon.com/archive/2019-July/046570.html
Modified: 2024-11-21
CVE-2019-13455
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion in acknowledge.c.
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/acknowledge.c
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/acknowledge.c
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.xymon.com/archive/2019-July/046570.html
- https://lists.xymon.com/archive/2019-July/046570.html
Modified: 2024-11-21
CVE-2019-13473
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have an undocumented TELNET service within the BusyBox subsystem, leading to root access.
- http://packetstormsecurity.com/files/154416/Dabman-And-Imperial-Web-Radio-Devices-Undocumented-Telnet-Backdoor.html
- http://packetstormsecurity.com/files/154416/Dabman-And-Imperial-Web-Radio-Devices-Undocumented-Telnet-Backdoor.html
- http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProto-DoS-XSS-Missing-Authentication.html
- http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProto-DoS-XSS-Missing-Authentication.html
- 20230904 Vulnerabilities in Internet Radio auna IR-160 SE (UIProto)
- 20230904 Vulnerabilities in Internet Radio auna IR-160 SE (UIProto)
- https://www.vulnerability-lab.com/get_content.php?id=2183
- https://www.vulnerability-lab.com/get_content.php?id=2183
Modified: 2024-11-21
CVE-2019-13474
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have insufficient access control for the /set_dname, /mylogo, /LocalPlay, /irdevice.xml, /Sendkey, /setvol, /hotkeylist, /init, /playlogo.jpg, /stop, /exit, /back, and /playinfo commands.
- http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProto-DoS-XSS-Missing-Authentication.html
- http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProto-DoS-XSS-Missing-Authentication.html
- http://seclists.org/fulldisclosure/2019/Sep/12
- http://seclists.org/fulldisclosure/2019/Sep/12
- 20230904 Vulnerabilities in Internet Radio auna IR-160 SE (UIProto)
- 20230904 Vulnerabilities in Internet Radio auna IR-160 SE (UIProto)
- https://www.vulnerability-lab.com/get_content.php?id=2183
- https://www.vulnerability-lab.com/get_content.php?id=2183
Modified: 2024-11-21
CVE-2019-13484
In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/appfeed.c
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/appfeed.c
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.xymon.com/archive/2019-July/046570.html
- https://lists.xymon.com/archive/2019-July/046570.html
Modified: 2024-11-21
CVE-2019-13485
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c.
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/history.c
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/history.c
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.xymon.com/archive/2019-July/046570.html
- https://lists.xymon.com/archive/2019-July/046570.html
Modified: 2024-11-21
CVE-2019-13486
In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/svcstatus.c
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/svcstatus.c
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.xymon.com/archive/2019-July/046570.html
- https://lists.xymon.com/archive/2019-July/046570.html
Closed vulnerabilities
BDU:2019-02871
Уязвимость функции pango_log2vis_get_embedding_levels библиотеки Pango, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2019-1010238
Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like pango_itemize.
- RHBA-2019:2824
- RHBA-2019:2824
- RHSA-2019:2571
- RHSA-2019:2571
- RHSA-2019:2582
- RHSA-2019:2582
- RHSA-2019:2594
- RHSA-2019:2594
- RHSA-2019:3234
- RHSA-2019:3234
- https://gitlab.gnome.org/GNOME/pango/-/commits/main/pango/pango-bidi-type.c
- https://gitlab.gnome.org/GNOME/pango/-/commits/main/pango/pango-bidi-type.c
- https://gitlab.gnome.org/GNOME/pango/-/issues/342
- https://gitlab.gnome.org/GNOME/pango/-/issues/342
- FEDORA-2019-547be4a683
- FEDORA-2019-547be4a683
- FEDORA-2019-155e34df5a
- FEDORA-2019-155e34df5a
- 20190812 [SECURITY] [DSA 4496-1] pango1.0 security update
- 20190812 [SECURITY] [DSA 4496-1] pango1.0 security update
- GLSA-201909-03
- GLSA-201909-03
- USN-4081-1
- USN-4081-1
- DSA-4496
- DSA-4496
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
Package alterator-sysconfig updated to version 1.3.0-alt1 for branch p9 in task 237503.
Closed bugs
Добавить галочку «Не использовать прокси для локальных адресов»