ALT-BU-2021-4579-1
Branch sisyphus_mipsel update bulletin.
Package cpio updated to version 2.13-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
BDU:2020-01329
Уязвимость утилиты архивирования Сpio, связанная с ошибками при проверке заголовка TAR-файла, позволяющая нарушителю повысить свои привилегии
Modified: 2024-11-21
CVE-2019-14866
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14866
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14866
- https://lists.debian.org/debian-lts-announce/2023/06/msg00007.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00007.html
- https://lists.gnu.org/archive/html/bug-cpio/2019-08/msg00003.html
- https://lists.gnu.org/archive/html/bug-cpio/2019-08/msg00003.html
- https://lists.gnu.org/archive/html/bug-cpio/2019-11/msg00000.html
- https://lists.gnu.org/archive/html/bug-cpio/2019-11/msg00000.html
Package calibre updated to version 5.33.2-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-44686
calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.
- https://bugs.launchpad.net/calibre/+bug/1951979
- https://bugs.launchpad.net/calibre/+bug/1951979
- https://github.com/dwisiswant0/advisory/issues/18
- https://github.com/dwisiswant0/advisory/issues/18
- https://github.com/kovidgoyal/calibre/compare/v5.31.1...v5.32.0
- https://github.com/kovidgoyal/calibre/compare/v5.31.1...v5.32.0
- FEDORA-2021-e42fadbcc3
- FEDORA-2021-e42fadbcc3
Package python3-module-cvxopt updated to version 1.2.7-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-41500
Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.