ALT-BU-2022-4586-1
Branch sisyphus_riscv64 update bulletin.
Package clickhouse-cpp updated to version 1.2.2-alt2 for branch sisyphus_riscv64.
Closed bugs
Файловый конфликт с пакетом libclickhouse-cpp-devel
Package fuse updated to version 2.9.9-alt4 for branch sisyphus_riscv64.
Closed bugs
libfuse depends on fuse
Package golang updated to version 1.17.9-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-24675
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8
- FEDORA-2022-a49babed75
- FEDORA-2022-a49babed75
- FEDORA-2022-c0f780ecf1
- FEDORA-2022-c0f780ecf1
- FEDORA-2022-e46e6e8317
- FEDORA-2022-e46e6e8317
- FEDORA-2022-30c5ed5625
- FEDORA-2022-30c5ed5625
- FEDORA-2022-ba365d3703
- FEDORA-2022-ba365d3703
- FEDORA-2022-fae3ecee19
- FEDORA-2022-fae3ecee19
- GLSA-202208-02
- GLSA-202208-02
- https://security.netapp.com/advisory/ntap-20220915-0010/
- https://security.netapp.com/advisory/ntap-20220915-0010/
Modified: 2024-11-21
CVE-2022-27536
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8
- GLSA-202208-02
- GLSA-202208-02
- https://security.netapp.com/advisory/ntap-20230309-0001/
- https://security.netapp.com/advisory/ntap-20230309-0001/
Modified: 2024-11-21
CVE-2022-28327
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8
- FEDORA-2022-a49babed75
- FEDORA-2022-a49babed75
- FEDORA-2022-c0f780ecf1
- FEDORA-2022-c0f780ecf1
- FEDORA-2022-53f0c619c5
- FEDORA-2022-53f0c619c5
- FEDORA-2022-e46e6e8317
- FEDORA-2022-e46e6e8317
- FEDORA-2022-30c5ed5625
- FEDORA-2022-30c5ed5625
- FEDORA-2022-ba365d3703
- FEDORA-2022-ba365d3703
- FEDORA-2022-fae3ecee19
- FEDORA-2022-fae3ecee19
- GLSA-202208-02
- GLSA-202208-02
- https://security.netapp.com/advisory/ntap-20220915-0010/
- https://security.netapp.com/advisory/ntap-20220915-0010/
Package alterator-osec updated to version 0.2.2-alt1 for branch sisyphus_riscv64.
Closed bugs
Не обновляет статус выполнения в Веб-интерфейсе
Неясно применение функции Отправлять отчёт
Не уменьшает значение количество хранимых файлов журнала
Отпечатка в справке (фалов -> файлов)
Package update-kernel updated to version 1.2.1-alt1 for branch sisyphus_riscv64.
Closed bugs
При наличии в репо свежей версии ядра предлагается переход на другой флейвор