ALT-BU-2022-5616-1
Branch sisyphus update bulletin.
Package python-module-anytree updated to version 2.8.0-alt2 for branch sisyphus in task 304413.
Closed bugs
Не хватает зависимостей для mlx_fs_dump
Суть проблемы в том, что в части исполняемых файлов указан интерпретатор python3
Package mlnx-tools updated to version 5.1.3-alt3 for branch sisyphus in task 304413.
Closed bugs
Суть проблемы в том, что в части исполняемых файлов указан интерпретатор python3
Closed bugs
dhcpcd не отправляет DHCPREQUEST после получения DHCPOFFER
Closed vulnerabilities
BDU:2022-05522
Уязвимость пакета compress/gzip языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-06492
Уязвимость компонента Decoder.Skip языка программирования Go, связанная с неконтролируемой рекурсией, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2022-1705
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.
- https://go.dev/cl/409874
- https://go.dev/cl/409874
- https://go.dev/cl/410714
- https://go.dev/cl/410714
- https://go.dev/issue/53188
- https://go.dev/issue/53188
- https://go.googlesource.com/go/+/e5017a93fcde94f09836200bca55324af037ee5f
- https://go.googlesource.com/go/+/e5017a93fcde94f09836200bca55324af037ee5f
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://pkg.go.dev/vuln/GO-2022-0525
- https://pkg.go.dev/vuln/GO-2022-0525
Modified: 2024-11-21
CVE-2022-1962
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.
- https://go.dev/cl/417063
- https://go.dev/cl/417063
- https://go.dev/issue/53616
- https://go.dev/issue/53616
- https://go.googlesource.com/go/+/695be961d57508da5a82217f7415200a11845879
- https://go.googlesource.com/go/+/695be961d57508da5a82217f7415200a11845879
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://pkg.go.dev/vuln/GO-2022-0515
- https://pkg.go.dev/vuln/GO-2022-0515
Modified: 2024-11-21
CVE-2022-28131
Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.
- https://go.dev/cl/417062
- https://go.dev/cl/417062
- https://go.dev/issue/53614
- https://go.dev/issue/53614
- https://go.googlesource.com/go/+/08c46ed43d80bbb67cb904944ea3417989be4af3
- https://go.googlesource.com/go/+/08c46ed43d80bbb67cb904944ea3417989be4af3
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://pkg.go.dev/vuln/GO-2022-0521
- https://pkg.go.dev/vuln/GO-2022-0521
Modified: 2024-11-21
CVE-2022-30630
Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.
- https://go.dev/cl/417065
- https://go.dev/cl/417065
- https://go.dev/issue/53415
- https://go.dev/issue/53415
- https://go.googlesource.com/go/+/fa2d41d0ca736f3ad6b200b2a4e134364e9acc59
- https://go.googlesource.com/go/+/fa2d41d0ca736f3ad6b200b2a4e134364e9acc59
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://pkg.go.dev/vuln/GO-2022-0527
- https://pkg.go.dev/vuln/GO-2022-0527
Modified: 2024-11-21
CVE-2022-30631
Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files.
- https://go.dev/cl/417067
- https://go.dev/cl/417067
- https://go.dev/issue/53168
- https://go.dev/issue/53168
- https://go.googlesource.com/go/+/b2b8872c876201eac2d0707276c6999ff3eb185e
- https://go.googlesource.com/go/+/b2b8872c876201eac2d0707276c6999ff3eb185e
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://pkg.go.dev/vuln/GO-2022-0524
- https://pkg.go.dev/vuln/GO-2022-0524
Modified: 2024-11-21
CVE-2022-30632
Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path containing a large number of path separators.
- https://go.dev/cl/417066
- https://go.dev/cl/417066
- https://go.dev/issue/53416
- https://go.dev/issue/53416
- https://go.googlesource.com/go/+/ac68c6c683409f98250d34ad282b9e1b0c9095ef
- https://go.googlesource.com/go/+/ac68c6c683409f98250d34ad282b9e1b0c9095ef
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://pkg.go.dev/vuln/GO-2022-0522
- https://pkg.go.dev/vuln/GO-2022-0522
Modified: 2024-11-21
CVE-2022-30633
Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag.
- https://go.dev/cl/417061
- https://go.dev/cl/417061
- https://go.dev/issue/53611
- https://go.dev/issue/53611
- https://go.googlesource.com/go/+/c4c1993fd2a5b26fe45c09592af6d3388a3b2e08
- https://go.googlesource.com/go/+/c4c1993fd2a5b26fe45c09592af6d3388a3b2e08
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://pkg.go.dev/vuln/GO-2022-0523
- https://pkg.go.dev/vuln/GO-2022-0523
Modified: 2024-11-21
CVE-2022-30635
Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.
- https://go.dev/cl/417064
- https://go.dev/cl/417064
- https://go.dev/issue/53615
- https://go.dev/issue/53615
- https://go.googlesource.com/go/+/6fa37e98ea4382bf881428ee0c150ce591500eb7
- https://go.googlesource.com/go/+/6fa37e98ea4382bf881428ee0c150ce591500eb7
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://pkg.go.dev/vuln/GO-2022-0526
- https://pkg.go.dev/vuln/GO-2022-0526
Modified: 2024-11-21
CVE-2022-32148
Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header.
- https://go.dev/cl/412857
- https://go.dev/cl/412857
- https://go.dev/issue/53423
- https://go.dev/issue/53423
- https://go.googlesource.com/go/+/b2cc0fecc2ccd80e6d5d16542cc684f97b3a9c8a
- https://go.googlesource.com/go/+/b2cc0fecc2ccd80e6d5d16542cc684f97b3a9c8a
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
- https://pkg.go.dev/vuln/GO-2022-0520
- https://pkg.go.dev/vuln/GO-2022-0520
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-1928
Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.
- https://github.com/go-gitea/gitea/commit/65e0688a5c9dacad50e71024b7529fdf0e3c2e9c
- https://github.com/go-gitea/gitea/commit/65e0688a5c9dacad50e71024b7529fdf0e3c2e9c
- https://huntr.dev/bounties/6336ec42-5c4d-4f61-ae38-2bb539f433d2
- https://huntr.dev/bounties/6336ec42-5c4d-4f61-ae38-2bb539f433d2
- GLSA-202210-14
- GLSA-202210-14
Modified: 2024-11-21
CVE-2022-38183
In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to private issue titles.