ALT-BU-2020-3792-1
Branch sisyphus update bulletin.
Package altmediawriter updated to version 0.4.4-alt1 for branch sisyphus in task 250931.
Closed bugs
Не хватает зависимости на qt5-quickcontrols
Package openconnect updated to version 8.09-alt1 for branch sisyphus in task 250947.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-12105
OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.
Closed vulnerabilities
BDU:2021-01723
Уязвимость механизма хранения nonce дайджест-аутентификации прокси-сервера Squid, связанная с целочисленным переполнением значения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01747
Уязвимость функции ESIExpression:: Evaluate прокси-сервера Squid, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-12519
An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack won't overflow.
- openSUSE-SU-2020:0623
- openSUSE-SU-2020:0623
- [oss-security] 20200423 [ADVISORY] SQUID-2019:12 Multiple issues in ESI Response processing
- [oss-security] 20200423 [ADVISORY] SQUID-2019:12 Multiple issues in ESI Response processing
- https://gitlab.com/jeriko.one/security/-/blob/master/squid/CVEs/CVE-2019-12519.txt
- https://gitlab.com/jeriko.one/security/-/blob/master/squid/CVEs/CVE-2019-12519.txt
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- GLSA-202005-05
- GLSA-202005-05
- https://security.netapp.com/advisory/ntap-20210205-0006/
- https://security.netapp.com/advisory/ntap-20210205-0006/
- USN-4356-1
- USN-4356-1
- DSA-4682
- DSA-4682
Modified: 2024-11-21
CVE-2020-11945
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).
- openSUSE-SU-2020:0623
- http://master.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patch
- http://www.openwall.com/lists/oss-security/2020/04/23/2
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patch
- https://bugzilla.suse.com/show_bug.cgi?id=1170313
- https://github.com/squid-cache/squid/commit/eeebf0f37a72a2de08348e85ae34b02c34e9a811
- https://github.com/squid-cache/squid/pull/585
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- FEDORA-2020-848065cc4c
- FEDORA-2020-56e809930e
- FEDORA-2020-a6a921a591
- GLSA-202005-05
- https://security.netapp.com/advisory/ntap-20210304-0004/
- USN-4356-1
- DSA-4682
- openSUSE-SU-2020:0623
- DSA-4682
- USN-4356-1
- https://security.netapp.com/advisory/ntap-20210304-0004/
- GLSA-202005-05
- FEDORA-2020-a6a921a591
- FEDORA-2020-56e809930e
- FEDORA-2020-848065cc4c
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- https://github.com/squid-cache/squid/pull/585
- https://github.com/squid-cache/squid/commit/eeebf0f37a72a2de08348e85ae34b02c34e9a811
- https://bugzilla.suse.com/show_bug.cgi?id=1170313
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patch
- http://www.openwall.com/lists/oss-security/2020/04/23/2
- http://master.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patch
Closed bugs
FR: new version SeaMonkey 2.53.1