ALT-BU-2020-3812-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-10737
A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.
Closed bugs
Не находит каталогов
Package firefox-esr updated to version 68.8.0-alt2 for branch sisyphus in task 251630.
Closed bugs
Добавить название дистрибутива в строку User-Agent браузера
Package alterator-datetime updated to version 4.5.0-alt1 for branch sisyphus in task 251654.
Closed bugs
Не указан номер часового пояса
Не сохраняется адрес NTP-сервера
Closed vulnerabilities
BDU:2019-02904
Уязвимость эмулятора DOSBox, связанная с недостатками контроля доступа, позволяющая нарушителю оказать воздействие на целостность данных, получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
BDU:2019-02905
Уязвимость эмулятора DOSBox, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю оказать воздействие на целостность данных, получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-12594
DOSBox 0.74-2 has Incorrect Access Control.
- openSUSE-SU-2019:1905
- openSUSE-SU-2019:1905
- openSUSE-SU-2019:1920
- openSUSE-SU-2019:1920
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931222
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931222
- [debian-lts-announce] 20190707 [SECURITY] [DLA 1845-1] dosbox security update
- [debian-lts-announce] 20190707 [SECURITY] [DLA 1845-1] dosbox security update
- FEDORA-2019-6b86d0f1c0
- FEDORA-2019-6b86d0f1c0
- 20190712 [SECURITY] [DSA 4478-1] dosbox security update
- 20190712 [SECURITY] [DSA 4478-1] dosbox security update
- https://security-tracker.debian.org/tracker/CVE-2019-12594
- https://security-tracker.debian.org/tracker/CVE-2019-12594
- DSA-4478
- DSA-4478
- https://www.dosbox.com/crew.php
- https://www.dosbox.com/crew.php
Modified: 2024-11-21
CVE-2019-7165
A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.
- openSUSE-SU-2019:1905
- openSUSE-SU-2019:1920
- [debian-lts-announce] 20190707 [SECURITY] [DLA 1845-1] dosbox security update
- FEDORA-2019-6b86d0f1c0
- 20190712 [SECURITY] [DSA 4478-1] dosbox security update
- https://security-tracker.debian.org/tracker/CVE-2019-7165
- DSA-4478
- https://www.dosbox.com
- openSUSE-SU-2019:1905
- https://www.dosbox.com
- DSA-4478
- https://security-tracker.debian.org/tracker/CVE-2019-7165
- 20190712 [SECURITY] [DSA 4478-1] dosbox security update
- FEDORA-2019-6b86d0f1c0
- [debian-lts-announce] 20190707 [SECURITY] [DLA 1845-1] dosbox security update
- openSUSE-SU-2019:1920