ALT-BU-2020-4121-1
Branch p9 update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2014-8123
Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2013-4420
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2019-5429
Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.
- [debian-lts-announce] 20220526 [SECURITY] [DLA 3026-1] filezilla security update
- [debian-lts-announce] 20220526 [SECURITY] [DLA 3026-1] filezilla security update
- FEDORA-2019-d109db9c8a
- FEDORA-2019-d109db9c8a
- GLSA-202007-51
- GLSA-202007-51
- https://svn.filezilla-project.org/filezilla?view=revision&revision=9112
- https://svn.filezilla-project.org/filezilla?view=revision&revision=9112
- https://www.tenable.com/security/research/tra-2019-14
- https://www.tenable.com/security/research/tra-2019-14
Closed vulnerabilities
BDU:2018-00035
Уязвимость функции queue_push (queue/queuepush.c) пакета yodl, позволяющая нарушителю нарушить конфиденциальность, целостность и доступность данных
Modified: 2024-11-21
CVE-2016-10375
Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c.
- https://github.com/fbb-git/yodl/commit/fd85f8c94182558ff1480d06a236d6fb927979a3
- https://github.com/fbb-git/yodl/commit/fd85f8c94182558ff1480d06a236d6fb927979a3
- https://github.com/fbb-git/yodl/issues/1
- https://github.com/fbb-git/yodl/issues/1
- [debian-lts-announce] 20200430 [SECURITY] [DLA 2194-1] yodl security update
- [debian-lts-announce] 20200430 [SECURITY] [DLA 2194-1] yodl security update
Closed vulnerabilities
BDU:2015-01947
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2013-6410
nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partial match in the authfile configuration file.
- [nbd-general] 20131201 [Nbd] 3.5 released
- [nbd-general] 20131201 [Nbd] 3.5 released
- DSA-2806
- DSA-2806
- [oss-security] 20131129 Re: CVE request: incorrect parsing of access control file in nbd-server
- [oss-security] 20131129 Re: CVE request: incorrect parsing of access control file in nbd-server
- 64002
- 64002
- USN-2676-1
- USN-2676-1
Modified: 2024-11-21
CVE-2013-7441
The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.
- openSUSE-SU-2015:0994
- openSUSE-SU-2015:0994
- [Nbd] 20130128 NBD server terminates on SIGPIPE during negotiation
- [Nbd] 20130128 NBD server terminates on SIGPIPE during negotiation
- DSA-3271
- DSA-3271
- [oss-security] 20150519 CVE Request: nbd denial of service
- [oss-security] 20150519 CVE Request: nbd denial of service
- [oss-security] 20150521 Re: CVE Request: nbd denial of service
- [oss-security] 20150521 Re: CVE Request: nbd denial of service
- 74808
- 74808
- USN-2676-1
- USN-2676-1
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=781547
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=781547
- https://github.com/yoe/nbd/commit/741495cb08503fd32a9d22648e63b64390c601f4
- https://github.com/yoe/nbd/commit/741495cb08503fd32a9d22648e63b64390c601f4
Modified: 2024-11-21
CVE-2015-0847
nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of service (deadlock) via unspecified vectors.
- openSUSE-SU-2015:0994
- openSUSE-SU-2015:0994
- [Nbd] 20150507 [PATCH] nbd-server: fix unsafe signal handling
- [Nbd] 20150507 [PATCH] nbd-server: fix unsafe signal handling
- http://sourceforge.net/projects/nbd/files/nbd/3.11/
- http://sourceforge.net/projects/nbd/files/nbd/3.11/
- DSA-3271
- DSA-3271
- [oss-security] 20150507 CVE-2015-0847 in nbd-server
- [oss-security] 20150507 CVE-2015-0847 in nbd-server
- USN-2676-1
- USN-2676-1