ALT-BU-2020-3872-1
Branch sisyphus update bulletin.
Closed bugs
Конфликт 0.73 с 0.72
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-13898
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NULL pointer dereference.
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/sdp.c#L120
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/sdp.c#L123
- https://github.com/meetecho/janus-gateway/pull/2214
- https://github.com/merrychap/CVEs/tree/master/janus-webrtc/CVE-2020-13898
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/sdp.c#L120
- https://github.com/merrychap/CVEs/tree/master/janus-webrtc/CVE-2020-13898
- https://github.com/meetecho/janus-gateway/pull/2214
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/sdp.c#L123
Modified: 2024-11-21
CVE-2020-13899
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in janus.c discloses information from uninitialized stack memory.
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/janus.c#L1326
- https://github.com/meetecho/janus-gateway/pull/2214
- https://github.com/merrychap/poc_exploits/tree/master/janus-webrtc/CVE-2020-13899
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/janus.c#L1326
- https://github.com/merrychap/poc_exploits/tree/master/janus-webrtc/CVE-2020-13899
- https://github.com/meetecho/janus-gateway/pull/2214
Modified: 2024-11-21
CVE-2020-13900
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_preparse in sdp.c has a NULL pointer dereference.
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/sdp.c#L64
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/sdp.c#L74
- https://github.com/meetecho/janus-gateway/pull/2214
- https://github.com/merrychap/poc_exploits/tree/master/janus-webrtc/CVE-2020-13900
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/sdp.c#L64
- https://github.com/merrychap/poc_exploits/tree/master/janus-webrtc/CVE-2020-13900
- https://github.com/meetecho/janus-gateway/pull/2214
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/sdp.c#L74
Modified: 2024-11-21
CVE-2020-13901
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow.
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/sdp.c#L1248
- https://github.com/meetecho/janus-gateway/pull/2214
- https://github.com/merrychap/poc_exploits/tree/master/janus-webrtc/CVE-2020-13901
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/sdp.c#L1248
- https://github.com/merrychap/poc_exploits/tree/master/janus-webrtc/CVE-2020-13901
- https://github.com/meetecho/janus-gateway/pull/2214
Modified: 2024-11-21
CVE-2020-14033
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plugins/janus_streaming.c has a Buffer Overflow via a crafted RTSP server.
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/plugins/janus_streaming.c#L6117
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/plugins/janus_streaming.c#L6166
- https://github.com/meetecho/janus-gateway/pull/2229
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/plugins/janus_streaming.c#L6117
- https://github.com/meetecho/janus-gateway/pull/2229
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/plugins/janus_streaming.c#L6166
Modified: 2024-11-21
CVE-2020-14034
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/utils.c#L381
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/utils.c#L401
- https://github.com/meetecho/janus-gateway/pull/2229
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/utils.c#L381
- https://github.com/meetecho/janus-gateway/pull/2229
- https://github.com/meetecho/janus-gateway/blob/v0.10.0/utils.c#L401
Package kernel-image-rt updated to version 4.19.127-alt1.rt54 for branch sisyphus in task 253484.
Closed vulnerabilities
BDU:2021-03057
Уязвимость функции fill_thread_core_info() ядра операционной системы Linux, позволяющая нарушителю раскрыть защищаемую информацию и вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2020-10732
A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.
- openSUSE-SU-2020:0801
- openSUSE-SU-2020:0935
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10732
- https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=aca969cacf07f41070d788ce2b8ca71f09d5207d
- https://github.com/google/kmsan/issues/76
- https://github.com/ruscur/linux/commit/a95cdec9fa0c08e6eeb410d461c03af8fd1fef0a
- https://lore.kernel.org/lkml/CAG_fn=VZZ7yUxtOGzuTLkr7wmfXWtKK9BHHYawj=rt9XWnCYvg%40mail.gmail.com/
- https://security.netapp.com/advisory/ntap-20210129-0005/
- https://twitter.com/grsecurity/status/1252558055629299712
- USN-4411-1
- USN-4427-1
- USN-4439-1
- USN-4440-1
- USN-4485-1
- openSUSE-SU-2020:0801
- USN-4485-1
- USN-4440-1
- USN-4439-1
- USN-4427-1
- USN-4411-1
- https://twitter.com/grsecurity/status/1252558055629299712
- https://security.netapp.com/advisory/ntap-20210129-0005/
- https://lore.kernel.org/lkml/CAG_fn=VZZ7yUxtOGzuTLkr7wmfXWtKK9BHHYawj=rt9XWnCYvg%40mail.gmail.com/
- https://github.com/ruscur/linux/commit/a95cdec9fa0c08e6eeb410d461c03af8fd1fef0a
- https://github.com/google/kmsan/issues/76
- https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=aca969cacf07f41070d788ce2b8ca71f09d5207d
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10732
- openSUSE-SU-2020:0935
Closed bugs
Ошибка osec: getgrgid_r: No such file or directory