ALT-BU-2022-5663-1
Branch sisyphus_mipsel update bulletin.
Package startup-rescue updated to version 0.43-alt1 for branch sisyphus_mipsel.
Closed bugs
Не находит fstab
Package rsync updated to version 3.2.5-alt0.1 for branch sisyphus_mipsel.
Closed vulnerabilities
BDU:2022-05498
Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с ошибками авторизации, позволяющая нарушителю записывать произвольные файлы
Modified: 2024-11-21
CVE-2022-29154
An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).
- [oss-security] 20220802 CVE-2022-29154: Rsync client-side arbitrary file write vulnerability.
- [oss-security] 20220802 CVE-2022-29154: Rsync client-side arbitrary file write vulnerability.
- https://github.com/WayneD/rsync/tags
- https://github.com/WayneD/rsync/tags
- FEDORA-2022-15da0cf165
- FEDORA-2022-15da0cf165
- FEDORA-2022-25e4dbedf9
- FEDORA-2022-25e4dbedf9
Package golang updated to version 1.18.5-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-32189
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.
- https://go.dev/cl/417774
- https://go.dev/cl/417774
- https://go.dev/issue/53871
- https://go.dev/issue/53871
- https://go.googlesource.com/go/+/055113ef364337607e3e72ed7d48df67fde6fc66
- https://go.googlesource.com/go/+/055113ef364337607e3e72ed7d48df67fde6fc66
- https://groups.google.com/g/golang-announce/c/YqYYG87xB10
- https://groups.google.com/g/golang-announce/c/YqYYG87xB10
- https://pkg.go.dev/vuln/GO-2022-0537
- https://pkg.go.dev/vuln/GO-2022-0537
Package gnutls30 updated to version 3.7.7-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-2509
A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.
- https://access.redhat.com/security/cve/CVE-2022-2509
- https://access.redhat.com/security/cve/CVE-2022-2509
- [debian-lts-announce] 20220812 [SECURITY] [DLA 3070-1] gnutls28 security update
- [debian-lts-announce] 20220812 [SECURITY] [DLA 3070-1] gnutls28 security update
- FEDORA-2022-5470992bfc
- FEDORA-2022-5470992bfc
- https://lists.gnupg.org/pipermail/gnutls-help/2022-July/004746.html
- https://lists.gnupg.org/pipermail/gnutls-help/2022-July/004746.html
- DSA-5203
- DSA-5203
Package docs-alt-workstation updated to version 10.1-alt2 for branch sisyphus_mipsel.
Closed bugs
Документация docs-alt-workstation - Опечатка в частице "то"
Документация docs-alt-workstation пункт 35.3. Центр приложений - Нет выделения для названия кнопки дополнительных сведений
Документация docs-alt-workstation пункт 35.3. Центр приложений - опечатки
Документация docs-alt-workstation пункт 34.2. Xsane - опечатки
Документация docs-alt-workstation пункт 34.2. Xsane - в поле "Назначение" нет значений "Файл", "Просмотр"
Package npm updated to version 8.11.0-alt2 for branch sisyphus_mipsel.
Closed vulnerabilities
BDU:2023-03309
Уязвимость пакетного менеджера npm, связанная с раскрытием информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Modified: 2024-11-21
CVE-2022-29244
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=
- https://github.com/nodejs/node/pull/43210
- https://github.com/nodejs/node/pull/43210
- https://github.com/nodejs/node/releases/tag/v16.15.1
- https://github.com/nodejs/node/releases/tag/v16.15.1
- https://github.com/nodejs/node/releases/tag/v17.9.1
- https://github.com/nodejs/node/releases/tag/v17.9.1
- https://github.com/nodejs/node/releases/tag/v18.3.0
- https://github.com/nodejs/node/releases/tag/v18.3.0
- https://github.com/npm/cli/releases/tag/v8.11.0
- https://github.com/npm/cli/releases/tag/v8.11.0
- https://github.com/npm/cli/security/advisories/GHSA-hj9c-8jmm-8c52
- https://github.com/npm/cli/security/advisories/GHSA-hj9c-8jmm-8c52
- https://github.com/npm/cli/tree/latest/workspaces/libnpmpack
- https://github.com/npm/cli/tree/latest/workspaces/libnpmpack
- https://github.com/npm/cli/tree/latest/workspaces/libnpmpublish
- https://github.com/npm/cli/tree/latest/workspaces/libnpmpublish
- https://github.com/npm/npm-packlist
- https://github.com/npm/npm-packlist
- https://security.netapp.com/advisory/ntap-20220722-0007/
- https://security.netapp.com/advisory/ntap-20220722-0007/
Closed bugs
Missing node-gyp