ALT-BU-2022-5654-1
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2022-05498
Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с ошибками авторизации, позволяющая нарушителю записывать произвольные файлы
Modified: 2024-11-21
CVE-2022-29154
An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).
- [oss-security] 20220802 CVE-2022-29154: Rsync client-side arbitrary file write vulnerability.
- [oss-security] 20220802 CVE-2022-29154: Rsync client-side arbitrary file write vulnerability.
- https://github.com/WayneD/rsync/tags
- https://github.com/WayneD/rsync/tags
- FEDORA-2022-15da0cf165
- FEDORA-2022-15da0cf165
- FEDORA-2022-25e4dbedf9
- FEDORA-2022-25e4dbedf9
Package simplescreenrecorder updated to version 0.4.4-alt3 for branch sisyphus in task 304650.
Closed bugs
При запуске записи основное окно не сворачиваетсяв в системный трей simplescreenrecorder
Closed vulnerabilities
BDU:2022-00594
Уязвимость функции stab_xcoff_builtin_type (stabs.c) набора инструментального программного обеспечения GNU Binary Utilities, связанная с записью за границами буфера, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2021-45078
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
- FEDORA-2021-3614c0b466
- FEDORA-2021-3614c0b466
- FEDORA-2021-f2c6802743
- FEDORA-2021-f2c6802743
- GLSA-202208-30
- GLSA-202208-30
- https://security.netapp.com/advisory/ntap-20220107-0002/
- https://security.netapp.com/advisory/ntap-20220107-0002/
- https://sourceware.org/bugzilla/show_bug.cgi?id=28694
- https://sourceware.org/bugzilla/show_bug.cgi?id=28694
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=161e87d12167b1e36193385485c1f6ce92f74f02
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=161e87d12167b1e36193385485c1f6ce92f74f02
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-32189
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.
- https://go.dev/cl/417774
- https://go.dev/cl/417774
- https://go.dev/issue/53871
- https://go.dev/issue/53871
- https://go.googlesource.com/go/+/055113ef364337607e3e72ed7d48df67fde6fc66
- https://go.googlesource.com/go/+/055113ef364337607e3e72ed7d48df67fde6fc66
- https://groups.google.com/g/golang-announce/c/YqYYG87xB10
- https://groups.google.com/g/golang-announce/c/YqYYG87xB10
- https://pkg.go.dev/vuln/GO-2022-0537
- https://pkg.go.dev/vuln/GO-2022-0537
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-2509
A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.
- https://access.redhat.com/security/cve/CVE-2022-2509
- https://access.redhat.com/security/cve/CVE-2022-2509
- [debian-lts-announce] 20220812 [SECURITY] [DLA 3070-1] gnutls28 security update
- [debian-lts-announce] 20220812 [SECURITY] [DLA 3070-1] gnutls28 security update
- FEDORA-2022-5470992bfc
- FEDORA-2022-5470992bfc
- https://lists.gnupg.org/pipermail/gnutls-help/2022-July/004746.html
- https://lists.gnupg.org/pipermail/gnutls-help/2022-July/004746.html
- DSA-5203
- DSA-5203