ALT-BU-2020-4187-1
Branch p9 update bulletin.
Closed vulnerabilities
BDU:2020-02852
Уязвимость функции check_file_actlst (sa_common.c) утилиты измерения и анализа производительности системы sysstat, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2022-06244
Уязвимость функции remap_struct() компонента sa_common.c утилиты для измерения и анализа производительности системы Sysstat, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-16167
sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00067.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00068.html
- https://github.com/sysstat/sysstat/compare/v12.1.5...v12.1.6
- https://github.com/sysstat/sysstat/issues/230
- https://lists.debian.org/debian-lts-announce/2022/11/msg00014.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVSMKUPWIGQYX4G5LZXL7ZBJN3KY6RM3/
- https://usn.ubuntu.com/4242-1/
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00067.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00068.html
- https://github.com/sysstat/sysstat/compare/v12.1.5...v12.1.6
- https://github.com/sysstat/sysstat/issues/230
- https://lists.debian.org/debian-lts-announce/2022/11/msg00014.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVSMKUPWIGQYX4G5LZXL7ZBJN3KY6RM3/
- https://usn.ubuntu.com/4242-1/
Modified: 2024-11-21
CVE-2019-19725
sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
- https://github.com/sysstat/sysstat/issues/242
- https://lists.debian.org/debian-lts-announce/2022/11/msg00014.html
- https://security.gentoo.org/glsa/202007-22
- https://usn.ubuntu.com/4242-1/
- https://github.com/sysstat/sysstat/issues/242
- https://lists.debian.org/debian-lts-announce/2022/11/msg00014.html
- https://security.gentoo.org/glsa/202007-22
- https://usn.ubuntu.com/4242-1/
Closed bugs
Ошибка запуска hplip, hp-toolbox error: dBus initialization error
Closed vulnerabilities
BDU:2020-01486
Уязвимость брокера сообщений Eclipse Mosquitto, связанная с недостаточной проверкой исключительных состояний, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11778
If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, sets a will delay interval, sets a session expiry interval, and the will delay interval is set longer than the session expiry interval, then a use after free error occurs, which has the potential to cause a crash in some situations.
Modified: 2024-11-21
CVE-2019-11779
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00077.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00008.html
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=551160
- https://lists.debian.org/debian-lts-announce/2019/10/msg00035.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4WMHIM64Q35NGTR6R3ILZUL4MA4ANB5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HFWQBNFTAVHPUYNGYO2TCPF5PCSWC2Z7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWNVTFA2CKXERXRYPYE2YFTZP4GNBGYY/
- https://seclists.org/bugtraq/2019/Nov/25
- https://usn.ubuntu.com/4137-1/
- https://www.debian.org/security/2019/dsa-4570
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00077.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00008.html
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=551160
- https://lists.debian.org/debian-lts-announce/2019/10/msg00035.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4WMHIM64Q35NGTR6R3ILZUL4MA4ANB5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HFWQBNFTAVHPUYNGYO2TCPF5PCSWC2Z7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWNVTFA2CKXERXRYPYE2YFTZP4GNBGYY/
- https://seclists.org/bugtraq/2019/Nov/25
- https://usn.ubuntu.com/4137-1/
- https://www.debian.org/security/2019/dsa-4570
Package eiskaltdcpp updated to version 2.4.0-alt1 for branch p9 in task 263083.
Closed bugs
[DEAD BUG] Вылетает
прошу обновить с включением коммита 93944747