ALT-BU-2020-4128-1
Branch p9 update bulletin.
Closed vulnerabilities
BDU:2015-03488
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
Modified: 2018-10-10
CVE-2009-1382
Multiple stack-based buffer overflows in mimetex.cgi in mimeTeX, when downloaded before 20090713, allow remote attackers to execute arbitrary code via a TeX file with long (1) picture, (2) circle, or (3) input tags.
- http://scary.beasts.org/security/CESA-2009-009.html
- 35752
- ADV-2009-1875
- 35816
- http://groups.google.com/group/comp.text.tex/browse_thread/thread/5d56d3d744351578
- http://www.ocert.org/advisories/ocert-2009-010.html
- ADV-2010-0877
- FEDORA-2010-6546
- mimetex-mimetex-bo(51794)
- 20090713 [oCERT-2009-010] mimeTeX and mathTeX buffer overflows and commandinjection
Modified: 2010-04-20
CVE-2009-2459
Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have unknown impact and attack vectors related to the (1) \environ, (2) \input, and (3) \counter TeX directives.
Closed vulnerabilities
Modified: 2017-08-08
CVE-2008-4935
asciiview in aview 1.3.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/aview#####.pgm temporary file.
- http://dev.gentoo.org/~rbu/security/debiantemp/aview
- http://bugs.debian.org/496422
- [oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire
- https://bugs.gentoo.org/show_bug.cgi?id=235770
- https://bugs.gentoo.org/235808
- 33139
- 30885
- GLSA-200812-14
- aview-asciiview-symlink(44837)
Closed vulnerabilities
BDU:2021-00876
Уязвимость функции в epan/dissectors/packet-fbzero.c программного обеспечения Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-00251
Уязвимость программы для анализа трафика wireshark, связанная с неверными вычислениями, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2020-26575
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
- https://gitlab.com/wireshark/wireshark/-/commit/3ff940652962c099b73ae3233322b8697b0d10ab
- https://gitlab.com/wireshark/wireshark/-/commit/3ff940652962c099b73ae3233322b8697b0d10ab
- https://gitlab.com/wireshark/wireshark/-/issues/16887
- https://gitlab.com/wireshark/wireshark/-/issues/16887
- https://gitlab.com/wireshark/wireshark/-/merge_requests/467
- https://gitlab.com/wireshark/wireshark/-/merge_requests/467
- https://gitlab.com/wireshark/wireshark/-/merge_requests/471
- https://gitlab.com/wireshark/wireshark/-/merge_requests/471
- https://gitlab.com/wireshark/wireshark/-/merge_requests/472
- https://gitlab.com/wireshark/wireshark/-/merge_requests/472
- https://gitlab.com/wireshark/wireshark/-/merge_requests/473
- https://gitlab.com/wireshark/wireshark/-/merge_requests/473
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- FEDORA-2020-4cff262f07
- FEDORA-2020-4cff262f07
- FEDORA-2020-d4344dd12f
- FEDORA-2020-d4344dd12f
- GLSA-202011-08
- GLSA-202011-08
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.wireshark.org/security/wnpa-sec-2020-14.html
- https://www.wireshark.org/security/wnpa-sec-2020-14.html
Modified: 2024-11-21
CVE-2020-28030
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
- https://gitlab.com/wireshark/wireshark/-/commit/b287e7165e8aa89cde6ae37e7c257c5d87d16b9b
- https://gitlab.com/wireshark/wireshark/-/commit/b287e7165e8aa89cde6ae37e7c257c5d87d16b9b
- https://gitlab.com/wireshark/wireshark/-/issues/16887
- https://gitlab.com/wireshark/wireshark/-/issues/16887
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- FEDORA-2020-4cff262f07
- FEDORA-2020-4cff262f07
- FEDORA-2020-d4344dd12f
- FEDORA-2020-d4344dd12f
- https://www.wireshark.org/security/wnpa-sec-2020-15.html
- https://www.wireshark.org/security/wnpa-sec-2020-15.html