ALT-BU-2022-5235-1
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2022-03725
Уязвимость функции mysqlnd/pdo (mysqlnd_wireprotocol.c) интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код
BDU:2022-05351
Уязвимость функции pg_query_params() интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2022-31625
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.
- https://bugs.php.net/bug.php?id=81720
- https://bugs.php.net/bug.php?id=81720
- [debian-lts-announce] 20221215 [SECURITY] [DLA 3243-1] php7.3 security update
- [debian-lts-announce] 20221215 [SECURITY] [DLA 3243-1] php7.3 security update
- FEDORA-2022-f3fc52428e
- FEDORA-2022-f3fc52428e
- FEDORA-2022-0a96e5b9b1
- FEDORA-2022-0a96e5b9b1
- GLSA-202209-20
- GLSA-202209-20
- https://security.netapp.com/advisory/ntap-20220722-0005/
- https://security.netapp.com/advisory/ntap-20220722-0005/
- DSA-5179
- DSA-5179
Modified: 2024-11-21
CVE-2022-31626
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.
- https://bugs.php.net/bug.php?id=81719
- https://bugs.php.net/bug.php?id=81719
- [debian-lts-announce] 20221215 [SECURITY] [DLA 3243-1] php7.3 security update
- [debian-lts-announce] 20221215 [SECURITY] [DLA 3243-1] php7.3 security update
- FEDORA-2022-f3fc52428e
- FEDORA-2022-f3fc52428e
- FEDORA-2022-0a96e5b9b1
- FEDORA-2022-0a96e5b9b1
- GLSA-202209-20
- GLSA-202209-20
- https://security.netapp.com/advisory/ntap-20220722-0005/
- https://security.netapp.com/advisory/ntap-20220722-0005/
- DSA-5179
- DSA-5179
Closed vulnerabilities
BDU:2022-03725
Уязвимость функции mysqlnd/pdo (mysqlnd_wireprotocol.c) интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код
BDU:2022-05351
Уязвимость функции pg_query_params() интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2022-31625
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.
- https://bugs.php.net/bug.php?id=81720
- https://bugs.php.net/bug.php?id=81720
- [debian-lts-announce] 20221215 [SECURITY] [DLA 3243-1] php7.3 security update
- [debian-lts-announce] 20221215 [SECURITY] [DLA 3243-1] php7.3 security update
- FEDORA-2022-f3fc52428e
- FEDORA-2022-f3fc52428e
- FEDORA-2022-0a96e5b9b1
- FEDORA-2022-0a96e5b9b1
- GLSA-202209-20
- GLSA-202209-20
- https://security.netapp.com/advisory/ntap-20220722-0005/
- https://security.netapp.com/advisory/ntap-20220722-0005/
- DSA-5179
- DSA-5179
Modified: 2024-11-21
CVE-2022-31626
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.
- https://bugs.php.net/bug.php?id=81719
- https://bugs.php.net/bug.php?id=81719
- [debian-lts-announce] 20221215 [SECURITY] [DLA 3243-1] php7.3 security update
- [debian-lts-announce] 20221215 [SECURITY] [DLA 3243-1] php7.3 security update
- FEDORA-2022-f3fc52428e
- FEDORA-2022-f3fc52428e
- FEDORA-2022-0a96e5b9b1
- FEDORA-2022-0a96e5b9b1
- GLSA-202209-20
- GLSA-202209-20
- https://security.netapp.com/advisory/ntap-20220722-0005/
- https://security.netapp.com/advisory/ntap-20220722-0005/
- DSA-5179
- DSA-5179
Closed vulnerabilities
BDU:2022-03962
Уязвимость модуля mailcap интерпретатора языка программирования Python, позволяющая нарушителю выполнить произвольную команду
Modified: 2024-11-21
CVE-2015-20107
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
- https://bugs.python.org/issue24778
- https://bugs.python.org/issue24778
- https://github.com/python/cpython/issues/68966
- https://github.com/python/cpython/issues/68966
- [debian-lts-announce] 20230524 [SECURITY] [DLA 3432-1] python2.7 security update
- [debian-lts-announce] 20230524 [SECURITY] [DLA 3432-1] python2.7 security update
- [debian-lts-announce] 20230630 [SECURITY] [DLA 3477-1] python3.7 security update
- [debian-lts-announce] 20230630 [SECURITY] [DLA 3477-1] python3.7 security update
- FEDORA-2022-4b0dfda810
- FEDORA-2022-4b0dfda810
- FEDORA-2022-b499f2a9c6
- FEDORA-2022-b499f2a9c6
- FEDORA-2022-d157a91e10
- FEDORA-2022-d157a91e10
- FEDORA-2022-dbe9a8f9ac
- FEDORA-2022-dbe9a8f9ac
- FEDORA-2022-20e87fb0d1
- FEDORA-2022-20e87fb0d1
- FEDORA-2022-9cd41b6709
- FEDORA-2022-9cd41b6709
- FEDORA-2022-cece1d07d9
- FEDORA-2022-cece1d07d9
- FEDORA-2022-ec74ac4079
- FEDORA-2022-ec74ac4079
- FEDORA-2022-5ad25e3d3c
- FEDORA-2022-5ad25e3d3c
- FEDORA-2022-2e1d1205cf
- FEDORA-2022-2e1d1205cf
- FEDORA-2022-17a1bb7e78
- FEDORA-2022-17a1bb7e78
- FEDORA-2022-9dd70781cb
- FEDORA-2022-9dd70781cb
- FEDORA-2022-79843dfb3c
- FEDORA-2022-79843dfb3c
- FEDORA-2022-5ea8aa7518
- FEDORA-2022-5ea8aa7518
- FEDORA-2022-0be85556b4
- FEDORA-2022-0be85556b4
- FEDORA-2022-1358cedf2d
- FEDORA-2022-1358cedf2d
- FEDORA-2022-ce55d01569
- FEDORA-2022-ce55d01569
- FEDORA-2022-4a69d20cf4
- FEDORA-2022-4a69d20cf4
- FEDORA-2022-9da5703d22
- FEDORA-2022-9da5703d22
- FEDORA-2022-d1682fef04
- FEDORA-2022-d1682fef04
- FEDORA-2022-4c788bdc40
- FEDORA-2022-4c788bdc40
- FEDORA-2022-a8e50dc83e
- FEDORA-2022-a8e50dc83e
- https://python-security.readthedocs.io/vuln/mailcap-shell-injection.html
- https://python-security.readthedocs.io/vuln/mailcap-shell-injection.html
- GLSA-202305-02
- GLSA-202305-02
- https://security.netapp.com/advisory/ntap-20220616-0001/
- https://security.netapp.com/advisory/ntap-20220616-0001/
Package bootloader-utils updated to version 0.5.4-alt1 for branch sisyphus in task 299892.
Closed bugs
Не поддерживается загрузка с /boot на отдельном разделе при загрузке с extlinux.conf