ALT-BU-2021-3828-1
Branch sisyphus update bulletin.
Package LibreOffice-still updated to version 7.0.5.2-alt1 for branch sisyphus in task 268574.
Closed vulnerabilities
BDU:2021-02227
Уязвимость пакета офисных программ LibreOffice, связанная с ошибками в настройках безопасности, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2021-25631
In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-20216
A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.
- https://bugzilla.redhat.com/show_bug.cgi?id=1923256
- https://bugzilla.redhat.com/show_bug.cgi?id=1923256
- GLSA-202107-16
- GLSA-202107-16
- https://www.openwall.com/lists/oss-security/2021/01/31/2
- https://www.openwall.com/lists/oss-security/2021/01/31/2
- https://www.privoxy.org/3.0.31/user-manual/whatsnew.html
- https://www.privoxy.org/3.0.31/user-manual/whatsnew.html
Modified: 2024-11-21
CVE-2021-20217
A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system availability.
Modified: 2024-11-21
CVE-2021-20272
A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash.
- https://bugzilla.redhat.com/show_bug.cgi?id=1936651
- https://bugzilla.redhat.com/show_bug.cgi?id=1936651
- [debian-lts-announce] 20210309 [SECURITY] [DLA 2587-1] privoxy security update
- [debian-lts-announce] 20210309 [SECURITY] [DLA 2587-1] privoxy security update
- GLSA-202107-16
- GLSA-202107-16
- https://www.privoxy.org/announce.txt
- https://www.privoxy.org/announce.txt
Modified: 2024-11-21
CVE-2021-20273
A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.
- https://bugzilla.redhat.com/show_bug.cgi?id=1936658
- https://bugzilla.redhat.com/show_bug.cgi?id=1936658
- [debian-lts-announce] 20210309 [SECURITY] [DLA 2587-1] privoxy security update
- [debian-lts-announce] 20210309 [SECURITY] [DLA 2587-1] privoxy security update
- GLSA-202107-16
- GLSA-202107-16
- https://www.privoxy.org/announce.txt
- https://www.privoxy.org/announce.txt
Modified: 2024-11-21
CVE-2021-20274
A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves.
Modified: 2024-11-21
CVE-2021-20275
A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.
- https://bugzilla.redhat.com/show_bug.cgi?id=1936666
- https://bugzilla.redhat.com/show_bug.cgi?id=1936666
- [debian-lts-announce] 20210309 [SECURITY] [DLA 2587-1] privoxy security update
- [debian-lts-announce] 20210309 [SECURITY] [DLA 2587-1] privoxy security update
- GLSA-202107-16
- GLSA-202107-16
- https://www.privoxy.org/announce.txt
- https://www.privoxy.org/announce.txt
Modified: 2024-11-21
CVE-2021-20276
A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service.
- https://bugzilla.redhat.com/show_bug.cgi?id=1936668
- https://bugzilla.redhat.com/show_bug.cgi?id=1936668
- [debian-lts-announce] 20210309 [SECURITY] [DLA 2587-1] privoxy security update
- [debian-lts-announce] 20210309 [SECURITY] [DLA 2587-1] privoxy security update
- GLSA-202107-16
- GLSA-202107-16
- https://www.privoxy.org/announce.txt
- https://www.privoxy.org/announce.txt
Closed bugs
Не устанавливается spotify с помощью epm play spotify