ALT-BU-2020-3808-1
Branch p9 update bulletin.
Package LibreOffice-still updated to version 6.3.6.2-alt1 for branch p9 in task 251141.
Closed vulnerabilities
BDU:2020-02358
Уязвимость пакета офисных программ LibreOffice, связанная с ошибками при шифровании информации, позволяющая нарушителю получить доступ к защищаемой информации
Modified: 2024-11-21
CVE-2020-12801
If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is successful, and if the file format of the recovered document was not LibreOffice's default ODF file format, then affected versions of LibreOffice default that subsequent saves of the document are unencrypted. This may lead to a user accidentally saving a MSOffice file format document unencrypted while believing it to be encrypted. This issue affects: LibreOffice 6-3 series versions prior to 6.3.6; 6-4 series versions prior to 6.4.3.
- openSUSE-SU-2020:0786
- [debian-lts-announce] 20231231 [SECURITY] [DLA 3703-1] libreoffice security update
- https://www.libreoffice.org/about-us/security/advisories/CVE-2020-12801
- openSUSE-SU-2020:0786
- https://www.libreoffice.org/about-us/security/advisories/CVE-2020-12801
- [debian-lts-announce] 20231231 [SECURITY] [DLA 3703-1] libreoffice security update
Package ldap-user-tools updated to version 0.9.5-alt1 for branch p9 in task 251333.
Closed bugs
ldap-groupmod не добавляет пользователя в группу, когда в ней есть пользователь с более коротким именем
Closed vulnerabilities
BDU:2020-03941
Уязвимость компонента master.py системы управления конфигурациями и удалённого выполнения операций SaltStack, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2020-03942
Уязвимость компонента ClearFuncs системы управления конфигурациями и удалённого выполнения операций SaltStack, позволяющая нарушителю получить доступ к конфиденциальным данным
Modified: 2025-02-07
CVE-2020-11651
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
- openSUSE-SU-2020:0564
- openSUSE-SU-2020:0564
- openSUSE-SU-2020:1074
- openSUSE-SU-2020:1074
- http://packetstormsecurity.com/files/157560/Saltstack-3000.1-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/157560/Saltstack-3000.1-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/157678/SaltStack-Salt-Master-Minion-Unauthenticated-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/157678/SaltStack-Salt-Master-Minion-Unauthenticated-Remote-Code-Execution.html
- http://www.vmware.com/security/advisories/VMSA-2020-0009.html
- http://www.vmware.com/security/advisories/VMSA-2020-0009.html
- https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
- https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
- https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst
- https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst
- [debian-lts-announce] 20200530 [SECURITY] [DLA 2223-1] salt security update
- [debian-lts-announce] 20200530 [SECURITY] [DLA 2223-1] salt security update
- 20200528 SaltStack FrameWork Vulnerabilities Affecting Cisco Products
- 20200528 SaltStack FrameWork Vulnerabilities Affecting Cisco Products
- USN-4459-1
- USN-4459-1
- DSA-4676
- DSA-4676
Modified: 2025-02-04
CVE-2020-11652
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
- openSUSE-SU-2020:0564
- openSUSE-SU-2020:1074
- http://packetstormsecurity.com/files/157560/Saltstack-3000.1-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/157678/SaltStack-Salt-Master-Minion-Unauthenticated-Remote-Code-Execution.html
- http://support.blackberry.com/kb/articleDetail?articleNumber=000063758
- http://www.vmware.com/security/advisories/VMSA-2020-0009.html
- https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
- https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst
- [debian-lts-announce] 20200530 [SECURITY] [DLA 2223-1] salt security update
- 20200528 SaltStack FrameWork Vulnerabilities Affecting Cisco Products
- USN-4459-1
- DSA-4676
- DSA-4676
- USN-4459-1
- 20200528 SaltStack FrameWork Vulnerabilities Affecting Cisco Products
- [debian-lts-announce] 20200530 [SECURITY] [DLA 2223-1] salt security update
- https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst
- https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
- http://www.vmware.com/security/advisories/VMSA-2020-0009.html
- http://support.blackberry.com/kb/articleDetail?articleNumber=000063758
- http://packetstormsecurity.com/files/157678/SaltStack-Salt-Master-Minion-Unauthenticated-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/157560/Saltstack-3000.1-Remote-Code-Execution.html
- openSUSE-SU-2020:1074
- openSUSE-SU-2020:0564