ALT-BU-2021-3877-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-6624
jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
Modified: 2024-11-21
CVE-2020-6625
jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.
Modified: 2024-11-21
CVE-2021-28275
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.
Modified: 2024-11-21
CVE-2021-28276
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c.
Modified: 2024-11-21
CVE-2021-28277
A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c.
Modified: 2024-11-21
CVE-2021-28278
A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-20205
Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image.
Modified: 2024-11-21
CVE-2021-46822
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.
- https://exchange.xforce.ibmcloud.com/vulnerabilities/221567
- https://exchange.xforce.ibmcloud.com/vulnerabilities/221567
- https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f35fd27ec641c42d6b115bfa595e483ec58188d2
- https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f35fd27ec641c42d6b115bfa595e483ec58188d2
Package branding-simply-linux updated to version 9.1-alt2 for branch sisyphus in task 270719.
Closed bugs
Файловые конфликты с пакетом branding-alt-workstation-mate-settings
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-22207
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22207.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22207.json
- https://gitlab.com/wireshark/wireshark/-/issues/17331
- https://gitlab.com/wireshark/wireshark/-/issues/17331
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- FEDORA-2021-67691ad99d
- FEDORA-2021-67691ad99d
- FEDORA-2021-6e0508d69d
- FEDORA-2021-6e0508d69d
- GLSA-202107-21
- GLSA-202107-21
- DSA-5019
- DSA-5019
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.wireshark.org/security/wnpa-sec-2021-04.html
- https://www.wireshark.org/security/wnpa-sec-2021-04.html