ALT-BU-2019-4021-1
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2019-03696
Уязвимость программы системного администрирования Sudo, существующая из-за недостаточной проверки входных данных, выполнить произвольные команды с привилегиями root
Modified: 2024-11-21
CVE-2019-14287
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
- openSUSE-SU-2019:2316
- openSUSE-SU-2019:2316
- openSUSE-SU-2019:2333
- openSUSE-SU-2019:2333
- http://packetstormsecurity.com/files/154853/Slackware-Security-Advisory-sudo-Updates.html
- http://packetstormsecurity.com/files/154853/Slackware-Security-Advisory-sudo-Updates.html
- [oss-security] 20191014 Sudo: CVE-2019-14287
- [oss-security] 20191014 Sudo: CVE-2019-14287
- [oss-security] 20191023 Membership application for linux-distros - VMware
- [oss-security] 20191023 Membership application for linux-distros - VMware
- [oss-security] 20191029 Re: Membership application for linux-distros - VMware
- [oss-security] 20191029 Re: Membership application for linux-distros - VMware
- [oss-security] 20210914 Re: Oracle Solaris membership in the distros list
- [oss-security] 20210914 Re: Oracle Solaris membership in the distros list
- RHBA-2019:3248
- RHBA-2019:3248
- RHSA-2019:3197
- RHSA-2019:3197
- RHSA-2019:3204
- RHSA-2019:3204
- RHSA-2019:3205
- RHSA-2019:3205
- RHSA-2019:3209
- RHSA-2019:3209
- RHSA-2019:3219
- RHSA-2019:3219
- RHSA-2019:3278
- RHSA-2019:3278
- RHSA-2019:3694
- RHSA-2019:3694
- RHSA-2019:3754
- RHSA-2019:3754
- RHSA-2019:3755
- RHSA-2019:3755
- RHSA-2019:3895
- RHSA-2019:3895
- RHSA-2019:3916
- RHSA-2019:3916
- RHSA-2019:3941
- RHSA-2019:3941
- RHSA-2019:4191
- RHSA-2019:4191
- RHSA-2020:0388
- RHSA-2020:0388
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1964-1] sudo security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1964-1] sudo security update
- FEDORA-2019-9cb221f2be
- FEDORA-2019-9cb221f2be
- FEDORA-2019-72755db9c7
- FEDORA-2019-72755db9c7
- FEDORA-2019-67998e9f7e
- FEDORA-2019-67998e9f7e
- https://resources.whitesourcesoftware.com/blog-whitesource/new-vulnerability-in-sudo-cve-2019-14287
- https://resources.whitesourcesoftware.com/blog-whitesource/new-vulnerability-in-sudo-cve-2019-14287
- 20191015 [slackware-security] sudo (SSA:2019-287-01)
- 20191015 [slackware-security] sudo (SSA:2019-287-01)
- 20191015 [SECURITY] [DSA 4543-1] sudo security update
- 20191015 [SECURITY] [DSA 4543-1] sudo security update
- GLSA-202003-12
- GLSA-202003-12
- https://security.netapp.com/advisory/ntap-20191017-0003/
- https://security.netapp.com/advisory/ntap-20191017-0003/
- https://support.f5.com/csp/article/K53746212?utm_source=f5support&%3Butm_medium=RSS
- https://support.f5.com/csp/article/K53746212?utm_source=f5support&%3Butm_medium=RSS
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03976en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03976en_us
- USN-4154-1
- USN-4154-1
- DSA-4543
- DSA-4543
- [oss-security] 20191015 Re: Sudo: CVE-2019-14287
- [oss-security] 20191015 Re: Sudo: CVE-2019-14287
- https://www.sudo.ws/alerts/minus_1_uid.html
- https://www.sudo.ws/alerts/minus_1_uid.html
Closed bugs
CVE-2019-14287 в sudo < 1.8.28
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-declarative updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-xmlpatterns updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-websockets updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-multimedia updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-serialport updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-location updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-sensors updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-webchannel updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-quickcontrols updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-script updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-x11extras updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-imageformats updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-quickcontrols2 updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-connectivity updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-serialbus updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-translations updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-graphicaleffects updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-wayland updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-webengine updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-virtualkeyboard updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-charts updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-speech updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-datavis3d updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-gamepad updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-webview updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package qt5-networkauth updated to version 5.12.5-alt1 for branch sisyphus in task 239023.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
Package f2fs-tools updated to version 1.13.0-alt1 for branch sisyphus in task 239228.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-6070
An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code execution. An attacker can provide a malicious file to trigger this vulnerability.