ALT-BU-2021-3973-1
Branch sisyphus update bulletin.
Package lxde-lxsession updated to version 0.5.5-alt3 for branch sisyphus in task 274486.
Closed bugs
Падает сессия LXDE при запуске после пересборки с новым libgtk+2
Package firmware-intel-ucode updated to version 16-alt1.20210608 for branch sisyphus in task 274527.
Closed vulnerabilities
BDU:2021-03383
Уязвимость микропрограммного обеспечения процессоров Intel, связанная с раскрытием информации через несоответствие, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2021-03384
Уязвимость микропрограммного обеспечения процессоров Intel, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2021-03385
Уязвимость микропрограммного обеспечения процессоров Intel, связанная с ошибками в настройках безопасности, позволяющая нарушителю раскрыть защищаемую информацию
Modified: 2024-11-21
CVE-2020-24511
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf
- [debian-lts-announce] 20210726 [SECURITY] [DLA 2718-1] intel-microcode security update
- [debian-lts-announce] 20210726 [SECURITY] [DLA 2718-1] intel-microcode security update
- https://security.netapp.com/advisory/ntap-20210611-0005/
- https://security.netapp.com/advisory/ntap-20210611-0005/
- DSA-4934
- DSA-4934
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00464.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00464.html
Modified: 2024-11-21
CVE-2020-24512
Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf
- [debian-lts-announce] 20210726 [SECURITY] [DLA 2718-1] intel-microcode security update
- [debian-lts-announce] 20210726 [SECURITY] [DLA 2718-1] intel-microcode security update
- https://security.netapp.com/advisory/ntap-20210611-0005/
- https://security.netapp.com/advisory/ntap-20210611-0005/
- DSA-4934
- DSA-4934
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00464.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00464.html
Modified: 2024-11-21
CVE-2020-24513
Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf
- [debian-lts-announce] 20210726 [SECURITY] [DLA 2718-1] intel-microcode security update
- [debian-lts-announce] 20210726 [SECURITY] [DLA 2718-1] intel-microcode security update
- DSA-4934
- DSA-4934
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00465.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00465.html
Modified: 2024-11-21
CVE-2021-24489
The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.