ALT-BU-2020-4187-1
Branch p9 update bulletin.
Closed vulnerabilities
BDU:2020-02852
Уязвимость функции check_file_actlst (sa_common.c) утилиты измерения и анализа производительности системы sysstat, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2022-06244
Уязвимость функции remap_struct() компонента sa_common.c утилиты для измерения и анализа производительности системы Sysstat, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-16167
sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.
- openSUSE-SU-2019:2395
- openSUSE-SU-2019:2395
- openSUSE-SU-2019:2397
- openSUSE-SU-2019:2397
- https://github.com/sysstat/sysstat/compare/v12.1.5...v12.1.6
- https://github.com/sysstat/sysstat/compare/v12.1.5...v12.1.6
- https://github.com/sysstat/sysstat/issues/230
- https://github.com/sysstat/sysstat/issues/230
- [debian-lts-announce] 20221113 [SECURITY] [DLA 3188-1] sysstat security update
- [debian-lts-announce] 20221113 [SECURITY] [DLA 3188-1] sysstat security update
- FEDORA-2020-9ced76e631
- FEDORA-2020-9ced76e631
- USN-4242-1
- USN-4242-1
Modified: 2024-11-21
CVE-2019-19725
sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
- https://github.com/sysstat/sysstat/issues/242
- https://github.com/sysstat/sysstat/issues/242
- [debian-lts-announce] 20221113 [SECURITY] [DLA 3188-1] sysstat security update
- [debian-lts-announce] 20221113 [SECURITY] [DLA 3188-1] sysstat security update
- GLSA-202007-22
- GLSA-202007-22
- USN-4242-1
- USN-4242-1
Closed bugs
Ошибка запуска hplip, hp-toolbox error: dBus initialization error
Closed vulnerabilities
BDU:2020-01486
Уязвимость брокера сообщений Eclipse Mosquitto, связанная с недостаточной проверкой исключительных состояний, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11778
If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, sets a will delay interval, sets a session expiry interval, and the will delay interval is set longer than the session expiry interval, then a use after free error occurs, which has the potential to cause a crash in some situations.
Modified: 2024-11-21
CVE-2019-11779
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
- openSUSE-SU-2019:2206
- openSUSE-SU-2019:2206
- openSUSE-SU-2019:2247
- openSUSE-SU-2019:2247
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=551160
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=551160
- [debian-lts-announce] 20191026 [SECURITY] [DLA 1972-1] mosquitto security update
- [debian-lts-announce] 20191026 [SECURITY] [DLA 1972-1] mosquitto security update
- FEDORA-2019-d99e2329cb
- FEDORA-2019-d99e2329cb
- FEDORA-2019-4c69fb4cd7
- FEDORA-2019-4c69fb4cd7
- FEDORA-2019-8b83c261dd
- FEDORA-2019-8b83c261dd
- 20191118 [SECURITY] [DSA 4570-1] mosquitto security update
- 20191118 [SECURITY] [DSA 4570-1] mosquitto security update
- USN-4137-1
- USN-4137-1
- DSA-4570
- DSA-4570
Package eiskaltdcpp updated to version 2.4.0-alt1 for branch p9 in task 263083.
Closed bugs
[DEAD BUG] Вылетает
прошу обновить с включением коммита 93944747