ALT-BU-2022-3457-1
Branch sisyphus_e2k update bulletin.
Package proftpd updated to version 1.3.7-alt0.1.c for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2019-04710
Уязвимость компонента main.c FTP-сервера ProFTPD, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2017-7418
ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlinks. Attackers with local access could bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link. The threat model includes an attacker who is not granted full filesystem access by a hosting provider, but can reconfigure the home directory of an FTP user.
- http://bugs.proftpd.org/show_bug.cgi?id=4295
- http://bugs.proftpd.org/show_bug.cgi?id=4295
- openSUSE-SU-2019:1836
- openSUSE-SU-2019:1836
- openSUSE-SU-2019:1870
- openSUSE-SU-2019:1870
- openSUSE-SU-2020:0031
- openSUSE-SU-2020:0031
- 97409
- 97409
- https://github.com/proftpd/proftpd/commit/ecff21e0d0e84f35c299ef91d7fda088e516d4ed
- https://github.com/proftpd/proftpd/commit/ecff21e0d0e84f35c299ef91d7fda088e516d4ed
- https://github.com/proftpd/proftpd/commit/f59593e6ff730b832dbe8754916cb5c821db579f
- https://github.com/proftpd/proftpd/commit/f59593e6ff730b832dbe8754916cb5c821db579f
- https://github.com/proftpd/proftpd/pull/444/commits/349addc3be4fcdad9bd4ec01ad1ccd916c898ed8
- https://github.com/proftpd/proftpd/pull/444/commits/349addc3be4fcdad9bd4ec01ad1ccd916c898ed8
Modified: 2024-11-21
CVE-2019-18217
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.
- openSUSE-SU-2020:0031
- openSUSE-SU-2020:0031
- https://cert-portal.siemens.com/productcert/pdf/ssa-940889.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-940889.pdf
- https://github.com/proftpd/proftpd/blob/1.3.6/NEWS
- https://github.com/proftpd/proftpd/blob/1.3.6/NEWS
- https://github.com/proftpd/proftpd/blob/1.3.6/RELEASE_NOTES
- https://github.com/proftpd/proftpd/blob/1.3.6/RELEASE_NOTES
- https://github.com/proftpd/proftpd/blob/master/NEWS
- https://github.com/proftpd/proftpd/blob/master/NEWS
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
- https://github.com/proftpd/proftpd/issues/846
- https://github.com/proftpd/proftpd/issues/846
- [debian-lts-announce] 20191027 [SECURITY] [DLA 1974-1] proftpd-dfsg security update
- [debian-lts-announce] 20191027 [SECURITY] [DLA 1974-1] proftpd-dfsg security update
- FEDORA-2019-ae019c7e9f
- FEDORA-2019-ae019c7e9f
- FEDORA-2019-7559f29ace
- FEDORA-2019-7559f29ace
- FEDORA-2019-848e410cfb
- FEDORA-2019-848e410cfb
- 20191106 [SECURITY] [DSA 4559-1] proftpd-dfsg security update
- 20191106 [SECURITY] [DSA 4559-1] proftpd-dfsg security update
- GLSA-202003-35
- GLSA-202003-35
- DSA-4559
- DSA-4559
Modified: 2024-11-21
CVE-2019-19269
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.
- openSUSE-SU-2020:0031
- openSUSE-SU-2020:0031
- https://github.com/proftpd/proftpd/issues/861
- https://github.com/proftpd/proftpd/issues/861
- [debian-lts-announce] 20191130 [SECURITY] [DLA 2018-1] proftpd-dfsg security update
- [debian-lts-announce] 20191130 [SECURITY] [DLA 2018-1] proftpd-dfsg security update
- FEDORA-2019-65a983b8b6
- FEDORA-2019-65a983b8b6
- FEDORA-2019-bfacf1e958
- FEDORA-2019-bfacf1e958
- GLSA-202003-35
- GLSA-202003-35
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
Modified: 2024-11-21
CVE-2019-19270
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken into account, and can allow clients whose certificates have been revoked to proceed with a connection to the server.
Modified: 2024-11-21
CVE-2020-9272
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
- openSUSE-SU-2020:0273
- openSUSE-SU-2020:0273
- https://cert-portal.siemens.com/productcert/pdf/ssa-679335.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-679335.pdf
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
- https://github.com/proftpd/proftpd/issues/902
- https://github.com/proftpd/proftpd/issues/902
- GLSA-202003-35
- GLSA-202003-35
Package parted updated to version 3.4-alt1 for branch sisyphus_e2k.
Closed bugs
Обновить parted
Package propagator updated to version 20211007-alt1 for branch sisyphus_e2k.
Closed bugs
propagator: не работает автоматическая загрузка по сети при наличии >= 2 интерфейсов
propagator: занудный ramdisk_size
udev: тупит при загрузке (init == propagator)
propagator: загрузка по http с нераспакованной ISO
propagator: load_ramdisk_fd: sloppy error handling
propagator: загрузка по http не всегда срабатывает
Package odfpy updated to version 1.4.1-alt1 for branch sisyphus_e2k.
Closed bugs
python3-module-odf and python3-module-odfpy both provide python3(odf)
Package screen updated to version 4.8.0-alt2 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2021-03746
Уязвимость компонента encoding.c оконного менеджера GNU Screen, связанная с внедрением или модификацией аргумента, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2021-26937
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
- [oss-security] 20210210 Re: screen crash processing combining characters
- [oss-security] 20210210 Re: screen crash processing combining characters
- https://ftp.gnu.org/gnu/screen/
- https://ftp.gnu.org/gnu/screen/
- [debian-lts-announce] 20210219 [SECURITY] [DLA 2570-1] screen security update
- [debian-lts-announce] 20210219 [SECURITY] [DLA 2570-1] screen security update
- FEDORA-2021-9107eeb95c
- FEDORA-2021-9107eeb95c
- FEDORA-2021-5e9894a0c5
- FEDORA-2021-5e9894a0c5
- https://lists.gnu.org/archive/html/screen-devel/2021-02/msg00000.html
- https://lists.gnu.org/archive/html/screen-devel/2021-02/msg00000.html
- GLSA-202105-11
- GLSA-202105-11
- DSA-4861
- DSA-4861
- https://www.openwall.com/lists/oss-security/2021/02/09/3
- https://www.openwall.com/lists/oss-security/2021/02/09/3
Package privoxy updated to version 3.0.33-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-44540
A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.
Modified: 2024-11-21
CVE-2021-44541
A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.
Modified: 2024-11-21
CVE-2021-44542
A memory leak vulnerability was found in Privoxy when handling errors.
Modified: 2024-11-21
CVE-2021-44543
An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Privoxy is configured to servce the user-manual itself.
Package phoronix-test-suite updated to version 10.8.0-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-0157
phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- https://github.com/phoronix-test-suite/phoronix-test-suite/commit/56fd0a3b69fb33c1c90a6017ed735889aaa59486
- https://github.com/phoronix-test-suite/phoronix-test-suite/commit/56fd0a3b69fb33c1c90a6017ed735889aaa59486
- https://huntr.dev/bounties/2c0fe81b-0977-4e1e-b5d8-7646c9a7ebbd
- https://huntr.dev/bounties/2c0fe81b-0977-4e1e-b5d8-7646c9a7ebbd
- FEDORA-2022-8f968eea82
- FEDORA-2022-8f968eea82
- FEDORA-2022-43f11039b2
- FEDORA-2022-43f11039b2
Modified: 2024-11-21
CVE-2022-0196
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- https://github.com/phoronix-test-suite/phoronix-test-suite/commit/4f18296a1862fe54a4c58701a1f5ec6bd62a4d94
- https://github.com/phoronix-test-suite/phoronix-test-suite/commit/4f18296a1862fe54a4c58701a1f5ec6bd62a4d94
- https://huntr.dev/bounties/3675eec7-bbce-4dfd-a2d3-d6862dce9ea6
- https://huntr.dev/bounties/3675eec7-bbce-4dfd-a2d3-d6862dce9ea6
- FEDORA-2022-8f968eea82
- FEDORA-2022-8f968eea82
- FEDORA-2022-43f11039b2
- FEDORA-2022-43f11039b2
Modified: 2024-11-21
CVE-2022-0197
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- https://github.com/phoronix-test-suite/phoronix-test-suite/commit/4f18296a1862fe54a4c58701a1f5ec6bd62a4d94
- https://github.com/phoronix-test-suite/phoronix-test-suite/commit/4f18296a1862fe54a4c58701a1f5ec6bd62a4d94
- https://huntr.dev/bounties/5abb7915-32f4-4fb1-afa7-bb6d8c4c5ad2
- https://huntr.dev/bounties/5abb7915-32f4-4fb1-afa7-bb6d8c4c5ad2
- FEDORA-2022-8f968eea82
- FEDORA-2022-8f968eea82
- FEDORA-2022-43f11039b2
- FEDORA-2022-43f11039b2