ALT-BU-2022-3580-1
Branch sisyphus_e2k update bulletin.
Package gnupg2 updated to version 2.2.33-alt1 for branch sisyphus_e2k.
Closed bugs
gnupg2: restore setting GPG_TTY in profile.d
Package libpano13 updated to version 2.9.21-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-33293
Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c.
- https://groups.google.com/u/1/g/hugin-ptx/c/gLtz2vweD74
- https://groups.google.com/u/1/g/hugin-ptx/c/gLtz2vweD74
- [debian-lts-announce] 20220320 [SECURITY] [DLA 2957-1] libpano13 security update
- [debian-lts-announce] 20220320 [SECURITY] [DLA 2957-1] libpano13 security update
- https://sourceforge.net/p/panotools/libpano13/ci/62aa7eed8fae5d8f247a2508a757f31000de386f/
- https://sourceforge.net/p/panotools/libpano13/ci/62aa7eed8fae5d8f247a2508a757f31000de386f/
Package appstream updated to version 0.15.1-alt1 for branch sisyphus_e2k.
Closed bugs
0.15.1
Package bluefish updated to version 2.2.12-alt2 for branch sisyphus_e2k.
Closed bugs
Не выполняется команда chmod в пути с пробелами
Package mc updated to version 4.8.27-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2022-00235
Уязвимость файлового менеджера Midnight Commander, связанная с недостатками процедуры аутентификации, позволяющая нарушителю оказать воздействие на целостность данных
Modified: 2024-11-21
CVE-2021-36370
An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity.
- https://docs.ssh-mitm.at/CVE-2021-36370.html
- https://docs.ssh-mitm.at/CVE-2021-36370.html
- https://github.com/MidnightCommander/mc/blob/5c1d3c55dd15356ec7d079084d904b7b0fd58d3e/src/vfs/sftpfs/connection.c#L484
- https://github.com/MidnightCommander/mc/blob/5c1d3c55dd15356ec7d079084d904b7b0fd58d3e/src/vfs/sftpfs/connection.c#L484
- https://github.com/MidnightCommander/mc/blob/master/src/vfs/sftpfs/connection.c
- https://github.com/MidnightCommander/mc/blob/master/src/vfs/sftpfs/connection.c
- https://mail.gnome.org/archives/mc-devel/2021-August/msg00008.html
- https://mail.gnome.org/archives/mc-devel/2021-August/msg00008.html
- https://midnight-commander.org/
- https://midnight-commander.org/
- https://sourceforge.net/projects/mcwin32/files/
- https://sourceforge.net/projects/mcwin32/files/