ALT-BU-2021-4053-1
Branch sisyphus update bulletin.
Package telegram-desktop updated to version 2.8.11-alt1 for branch sisyphus in task 279728.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-36769
A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop before 2.8.8. An attacker can cause the server to receive messages in a different order than they were sent a client.
Closed bugs
deepin: не работает обзор сети
Closed bugs
Сломался mcopy после обновления до версии 4.0.33-alt1
Closed bugs
python3-module-nss FTBFS on ppc64le
Package pve-backup updated to version 1.0.5-alt2 for branch sisyphus in task 279768.
Closed bugs
pve-backup FTBFS
Package secure_delete updated to version 3.1-alt3 for branch sisyphus in task 279773.
Closed bugs
конфликтует по файлам с srm
Package kernel-image-std-def updated to version 5.10.51-alt1 for branch sisyphus in task 279783.
Closed vulnerabilities
BDU:2023-01796
Уязвимость функции seq_buf_putmem_hex() ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании.
Modified: 2024-11-21
CVE-2023-28772
An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow.
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.3
- https://github.com/torvalds/linux/commit/d3b16034a24a112bb83aeb669ac5b9b01f744bb7
- https://lkml.kernel.org/r/20210626032156.47889-1-yun.zhou%40windriver.com
- https://lore.kernel.org/lkml/20210625122453.5e2fe304%40oasis.local.home/
- https://security.netapp.com/advisory/ntap-20230427-0005/
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.3
- https://security.netapp.com/advisory/ntap-20230427-0005/
- https://lore.kernel.org/lkml/20210625122453.5e2fe304%40oasis.local.home/
- https://lkml.kernel.org/r/20210626032156.47889-1-yun.zhou%40windriver.com
- https://github.com/torvalds/linux/commit/d3b16034a24a112bb83aeb669ac5b9b01f744bb7
Package kernel-image-un-def updated to version 5.12.18-alt1 for branch sisyphus in task 279792.
Closed vulnerabilities
BDU:2023-01796
Уязвимость функции seq_buf_putmem_hex() ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании.
Modified: 2024-11-21
CVE-2023-28772
An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow.
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.3
- https://github.com/torvalds/linux/commit/d3b16034a24a112bb83aeb669ac5b9b01f744bb7
- https://lkml.kernel.org/r/20210626032156.47889-1-yun.zhou%40windriver.com
- https://lore.kernel.org/lkml/20210625122453.5e2fe304%40oasis.local.home/
- https://security.netapp.com/advisory/ntap-20230427-0005/
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.3
- https://security.netapp.com/advisory/ntap-20230427-0005/
- https://lore.kernel.org/lkml/20210625122453.5e2fe304%40oasis.local.home/
- https://lkml.kernel.org/r/20210626032156.47889-1-yun.zhou%40windriver.com
- https://github.com/torvalds/linux/commit/d3b16034a24a112bb83aeb669ac5b9b01f744bb7
Closed vulnerabilities
BDU:2022-05822
Уязвимость функции udp6_input() библиотеки TCP-IP эмулятора Libslirp, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Modified: 2024-11-21
CVE-2021-3592
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
- https://bugzilla.redhat.com/show_bug.cgi?id=1970484
- https://bugzilla.redhat.com/show_bug.cgi?id=1970484
- [debian-lts-announce] 20210902 [SECURITY] [DLA 2753-1] qemu security update
- [debian-lts-announce] 20210902 [SECURITY] [DLA 2753-1] qemu security update
- [debian-lts-announce] 20210911 [SECURITY] [DLA 2753-2] qemu regression update
- [debian-lts-announce] 20210911 [SECURITY] [DLA 2753-2] qemu regression update
- [debian-lts-announce] 20230314 [SECURITY] [DLA 3362-1] qemu security update
- [debian-lts-announce] 20230314 [SECURITY] [DLA 3362-1] qemu security update
- FEDORA-2021-71de23bedd
- FEDORA-2021-71de23bedd
- FEDORA-2021-7cd749f133
- FEDORA-2021-7cd749f133
- GLSA-202107-44
- GLSA-202107-44
- https://security.netapp.com/advisory/ntap-20210805-0004/
- https://security.netapp.com/advisory/ntap-20210805-0004/
Modified: 2024-11-21
CVE-2021-3593
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
- https://bugzilla.redhat.com/show_bug.cgi?id=1970487
- https://bugzilla.redhat.com/show_bug.cgi?id=1970487
- [debian-lts-announce] 20220404 [SECURITY] [DLA 2970-1] qemu security update
- [debian-lts-announce] 20220404 [SECURITY] [DLA 2970-1] qemu security update
- [debian-lts-announce] 20230314 [SECURITY] [DLA 3362-1] qemu security update
- [debian-lts-announce] 20230314 [SECURITY] [DLA 3362-1] qemu security update
- FEDORA-2021-71de23bedd
- FEDORA-2021-71de23bedd
- FEDORA-2021-7cd749f133
- FEDORA-2021-7cd749f133
- GLSA-202107-44
- GLSA-202107-44
- https://security.netapp.com/advisory/ntap-20210805-0004/
- https://security.netapp.com/advisory/ntap-20210805-0004/
Modified: 2024-11-21
CVE-2021-3594
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
- https://bugzilla.redhat.com/show_bug.cgi?id=1970491
- https://bugzilla.redhat.com/show_bug.cgi?id=1970491
- [debian-lts-announce] 20210902 [SECURITY] [DLA 2753-1] qemu security update
- [debian-lts-announce] 20210902 [SECURITY] [DLA 2753-1] qemu security update
- [debian-lts-announce] 20230314 [SECURITY] [DLA 3362-1] qemu security update
- [debian-lts-announce] 20230314 [SECURITY] [DLA 3362-1] qemu security update
- FEDORA-2021-71de23bedd
- FEDORA-2021-71de23bedd
- FEDORA-2021-7cd749f133
- FEDORA-2021-7cd749f133
- GLSA-202107-44
- GLSA-202107-44
- https://security.netapp.com/advisory/ntap-20210805-0004/
- https://security.netapp.com/advisory/ntap-20210805-0004/
Modified: 2024-11-21
CVE-2021-3595
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
- https://bugzilla.redhat.com/show_bug.cgi?id=1970489
- https://bugzilla.redhat.com/show_bug.cgi?id=1970489
- [debian-lts-announce] 20210902 [SECURITY] [DLA 2753-1] qemu security update
- [debian-lts-announce] 20210902 [SECURITY] [DLA 2753-1] qemu security update
- [debian-lts-announce] 20230314 [SECURITY] [DLA 3362-1] qemu security update
- [debian-lts-announce] 20230314 [SECURITY] [DLA 3362-1] qemu security update
- FEDORA-2021-71de23bedd
- FEDORA-2021-71de23bedd
- FEDORA-2021-7cd749f133
- FEDORA-2021-7cd749f133
- GLSA-202107-44
- GLSA-202107-44
- https://security.netapp.com/advisory/ntap-20210805-0004/
- https://security.netapp.com/advisory/ntap-20210805-0004/
Closed vulnerabilities
BDU:2021-03561
Уязвимость функции wordexp() библиотеки, обеспечивающей системные вызовы и основные функции glibc, позволяющая нарушителю читать произвольные файлы
Modified: 2024-11-21
CVE-2021-35942
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.
- [debian-lts-announce] 20221017 [SECURITY] [DLA 3152-1] glibc security update
- [debian-lts-announce] 20221017 [SECURITY] [DLA 3152-1] glibc security update
- GLSA-202208-24
- GLSA-202208-24
- https://security.netapp.com/advisory/ntap-20210827-0005/
- https://security.netapp.com/advisory/ntap-20210827-0005/
- https://sourceware.org/bugzilla/show_bug.cgi?id=28011
- https://sourceware.org/bugzilla/show_bug.cgi?id=28011
- https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=5adda61f62b77384718b4c0d8336ade8f2b4b35c
- https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=5adda61f62b77384718b4c0d8336ade8f2b4b35c
- https://sourceware.org/glibc/wiki/Security%20Exceptions
- https://sourceware.org/glibc/wiki/Security%20Exceptions
Closed bugs
valgrind FTBFS on armh