ALT-BU-2019-4078-1
Branch p9 update bulletin.
Closed vulnerabilities
BDU:2020-00739
Уязвимость функции __zzip_parse_root_directory библиотеки архивирования ZZIPlib, связанная с неосвобождением ресурса после истечения действительного срока его эксплуатирования, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-16548
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack.
- openSUSE-SU-2019:2396
- openSUSE-SU-2019:2396
- openSUSE-SU-2019:2394
- openSUSE-SU-2019:2394
- RHSA-2019:2196
- RHSA-2019:2196
- https://github.com/gdraheim/zziplib/issues/58
- https://github.com/gdraheim/zziplib/issues/58
- [debian-lts-announce] 20200628 [SECURITY] [DLA 2258-1] zziplib security update
- [debian-lts-announce] 20200628 [SECURITY] [DLA 2258-1] zziplib security update
Modified: 2024-11-21
CVE-2018-17828
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
Package cyrus-imapd updated to version 3.0.12-alt1 for branch p9 in task 240896.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2019-18928
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
- [debian-lts-announce] 20220619 [SECURITY] [DLA 3052-1] cyrus-imapd security update
- [debian-lts-announce] 20220619 [SECURITY] [DLA 3052-1] cyrus-imapd security update
- FEDORA-2019-03be160f9c
- FEDORA-2019-03be160f9c
- FEDORA-2019-393e1cef4d
- FEDORA-2019-393e1cef4d
- https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.14.html
- https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.14.html
- https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.12.html
- https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.12.html