ALT-BU-2020-3780-13
Branch p9 update bulletin.
Closed vulnerabilities
BDU:2020-05806
Уязвимость функции urldecode() интерпретатора языка программирования PHP, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю получить доступ к защищаемой информации
Modified: 2024-11-21
CVE-2020-7067
In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.
- https://bugs.php.net/bug.php?id=79465
- https://bugs.php.net/bug.php?id=79465
- https://security.netapp.com/advisory/ntap-20200504-0001/
- https://security.netapp.com/advisory/ntap-20200504-0001/
- DSA-4717
- DSA-4717
- DSA-4719
- DSA-4719
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Package cloud-init updated to version 20.1-alt1 for branch p9 in task 250120.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-8631
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
- openSUSE-SU-2020:0400
- openSUSE-SU-2020:0400
- https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795
- https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795
- https://github.com/canonical/cloud-init/pull/204
- https://github.com/canonical/cloud-init/pull/204
- [debian-lts-announce] 20200221 [SECURITY] [DLA 2113-1] cloud-init security update
- [debian-lts-announce] 20200221 [SECURITY] [DLA 2113-1] cloud-init security update
Modified: 2024-11-21
CVE-2020-8632
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
- openSUSE-SU-2020:0400
- openSUSE-SU-2020:0400
- https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795
- https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795
- https://github.com/canonical/cloud-init/pull/189
- https://github.com/canonical/cloud-init/pull/189
- [debian-lts-announce] 20200221 [SECURITY] [DLA 2113-1] cloud-init security update
- [debian-lts-announce] 20200221 [SECURITY] [DLA 2113-1] cloud-init security update