ALT-BU-2022-4025-1
Branch p10 update bulletin.
Closed vulnerabilities
BDU:2022-03899
Уязвимость реализации функции SetString() класса Rat пакета math/big языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2022-23772
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
- https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ
- https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ
- [debian-lts-announce] 20220428 [SECURITY] [DLA 2985-1] golang-1.7 security update
- [debian-lts-announce] 20220428 [SECURITY] [DLA 2985-1] golang-1.7 security update
- [debian-lts-announce] 20220428 [SECURITY] [DLA 2986-1] golang-1.8 security update
- [debian-lts-announce] 20220428 [SECURITY] [DLA 2986-1] golang-1.8 security update
- GLSA-202208-02
- GLSA-202208-02
- https://security.netapp.com/advisory/ntap-20220225-0006/
- https://security.netapp.com/advisory/ntap-20220225-0006/
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
Modified: 2024-11-21
CVE-2022-23773
cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.
- https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ
- https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ
- GLSA-202208-02
- GLSA-202208-02
- https://security.netapp.com/advisory/ntap-20220225-0006/
- https://security.netapp.com/advisory/ntap-20220225-0006/
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
Modified: 2024-11-21
CVE-2022-23806
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
- https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ
- https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ
- [debian-lts-announce] 20220428 [SECURITY] [DLA 2985-1] golang-1.7 security update
- [debian-lts-announce] 20220428 [SECURITY] [DLA 2985-1] golang-1.7 security update
- [debian-lts-announce] 20220428 [SECURITY] [DLA 2986-1] golang-1.8 security update
- [debian-lts-announce] 20220428 [SECURITY] [DLA 2986-1] golang-1.8 security update
- [debian-lts-announce] 20230419 [SECURITY] [DLA 3395-1] golang-1.11 security update
- [debian-lts-announce] 20230419 [SECURITY] [DLA 3395-1] golang-1.11 security update
- GLSA-202208-02
- GLSA-202208-02
- https://security.netapp.com/advisory/ntap-20220225-0006/
- https://security.netapp.com/advisory/ntap-20220225-0006/
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
Closed bugs
В README.ALT осталось упоминание init-скрипта
Package jitsi-videobridge updated to version 2.1-alt0.7 for branch p10 in task 294023.
Closed bugs
Не работает systemctl enable jitsi-videobridge