ALT-BU-2020-3817-1
Branch sisyphus update bulletin.
Package openconnect updated to version 8.10-alt1 for branch sisyphus in task 251779.
Closed vulnerabilities
BDU:2020-04472
Уязвимость функции get_cert_name (gnutls.c) приложения для подключения к виртуальным частным сетям OpenConnect, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2024-11-21
CVE-2020-12823
OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.
- openSUSE-SU-2020:0997
- openSUSE-SU-2020:1027
- https://bugs.gentoo.org/721570
- https://gitlab.com/openconnect/openconnect/-/merge_requests/108
- [debian-lts-announce] 20200516 [SECURITY] [DLA 2212-1] openconnect security update
- FEDORA-2020-bc22f06aa3
- FEDORA-2020-143735a624
- FEDORA-2020-2af15c566e
- GLSA-202006-15
- openSUSE-SU-2020:0997
- GLSA-202006-15
- FEDORA-2020-2af15c566e
- FEDORA-2020-143735a624
- FEDORA-2020-bc22f06aa3
- [debian-lts-announce] 20200516 [SECURITY] [DLA 2212-1] openconnect security update
- https://gitlab.com/openconnect/openconnect/-/merge_requests/108
- https://bugs.gentoo.org/721570
- openSUSE-SU-2020:1027
Package edk2-tools updated to version 20200229-alt1 for branch sisyphus in task 251783.
Closed vulnerabilities
BDU:2020-04779
Уязвимость микропрограммного обеспечения BIOS процессоров Intel, связанная с ошибками управления привилегиями, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-14558
Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable denial of service via adjacent access.
- [debian-lts-announce] 20210429 [SECURITY] [DLA 2645-1] edk2 security update
- [debian-lts-announce] 20210429 [SECURITY] [DLA 2645-1] edk2 security update
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00356.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00356.html
Modified: 2024-11-21
CVE-2019-14559
Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.
Modified: 2024-11-21
CVE-2019-14563
Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
Modified: 2024-11-21
CVE-2019-14575
Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
Modified: 2024-11-21
CVE-2019-14586
Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.
Modified: 2024-11-21
CVE-2019-14587
Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Closed vulnerabilities
BDU:2020-04779
Уязвимость микропрограммного обеспечения BIOS процессоров Intel, связанная с ошибками управления привилегиями, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-14558
Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable denial of service via adjacent access.
- [debian-lts-announce] 20210429 [SECURITY] [DLA 2645-1] edk2 security update
- [debian-lts-announce] 20210429 [SECURITY] [DLA 2645-1] edk2 security update
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00356.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00356.html
Modified: 2024-11-21
CVE-2019-14559
Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.
Modified: 2024-11-21
CVE-2019-14563
Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
Modified: 2024-11-21
CVE-2019-14575
Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
Modified: 2024-11-21
CVE-2019-14586
Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.
Modified: 2024-11-21
CVE-2019-14587
Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Closed vulnerabilities
BDU:2020-01963
Уязвимость браузера Tor, связанная с неконтролируемым расходом ресурса, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2020-10592
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.
Modified: 2024-11-21
CVE-2020-10593
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negotiated twice on the same circuit.
Package LibreOffice-still updated to version 6.3.6.2-alt2 for branch sisyphus in task 251766.
Closed bugs
В программной группе LibreOffice Сalc отображается с той же иконкой, что и у калькулятора