ALT-BU-2022-6249-1
Branch sisyphus_riscv64 update bulletin.
Package python3-module-joblib updated to version 1.2.0-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-21797
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
- https://github.com/joblib/joblib/commit/b90f10efeb670a2cc877fb88ebb3f2019189e059
- https://github.com/joblib/joblib/commit/b90f10efeb670a2cc877fb88ebb3f2019189e059
- https://github.com/joblib/joblib/issues/1128
- https://github.com/joblib/joblib/issues/1128
- https://github.com/joblib/joblib/pull/1321
- https://github.com/joblib/joblib/pull/1321
- [debian-lts-announce] 20221117 [SECURITY] [DLA 3193-1] joblib security update
- [debian-lts-announce] 20221117 [SECURITY] [DLA 3193-1] joblib security update
- [debian-lts-announce] 20230330 [SECURITY] [DLA 3193-2] joblib security update
- [debian-lts-announce] 20230330 [SECURITY] [DLA 3193-2] joblib security update
- FEDORA-2022-c0bfe37ae5
- FEDORA-2022-c0bfe37ae5
- FEDORA-2022-c83ce1c000
- FEDORA-2022-c83ce1c000
- GLSA-202401-01
- GLSA-202401-01
- https://security.snyk.io/vuln/SNYK-PYTHON-JOBLIB-3027033
- https://security.snyk.io/vuln/SNYK-PYTHON-JOBLIB-3027033
Package pdns updated to version 4.6.3-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-17482
An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory.
Modified: 2024-11-21
CVE-2020-24696
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can trigger a race condition leading to a crash, or possibly arbitrary code execution, by sending crafted queries with a GSS-TSIG signature.
Modified: 2024-11-21
CVE-2020-24697
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can cause a denial of service by sending crafted queries with a GSS-TSIG signature.
Modified: 2024-11-21
CVE-2020-24698
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might be able to cause a double-free, leading to a crash or possibly arbitrary code execution. by sending crafted queries with a GSS-TSIG signature.
Modified: 2024-11-21
CVE-2021-36754
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception.
- [oss-security] 20210726 security advisory 2021-01 for PowerDNS Authoritative Server 4.5.0
- [oss-security] 20210726 security advisory 2021-01 for PowerDNS Authoritative Server 4.5.0
- https://doc.powerdns.com/authoritative/security-advisories/index.html
- https://doc.powerdns.com/authoritative/security-advisories/index.html
- https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2021-01.html
- https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2021-01.html
Modified: 2024-11-21
CVE-2022-27227
In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition causes incomplete zone transfers to be handled as successful transfers.
- [oss-security] 20220325 Security Advisory 2022-01 for PowerDNS Authoritative Server 4.4.2, 4.5.3, 4.6.0 and PowerDNS Recursor 4.4.7, 4.5.7, 4.6.0
- [oss-security] 20220325 Security Advisory 2022-01 for PowerDNS Authoritative Server 4.4.2, 4.5.3, 4.6.0 and PowerDNS Recursor 4.4.7, 4.5.7, 4.6.0
- https://doc.powerdns.com/authoritative/security-advisories/index.html
- https://doc.powerdns.com/authoritative/security-advisories/index.html
- https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2022-01.html
- https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2022-01.html
- https://docs.powerdns.com/recursor/security-advisories/index.html
- https://docs.powerdns.com/recursor/security-advisories/index.html
- https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2022-01.html
- https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2022-01.html
- FEDORA-2022-8367cefdea
- FEDORA-2022-8367cefdea
- FEDORA-2022-6e19acf414
- FEDORA-2022-6e19acf414
- FEDORA-2022-ccfd5d1045
- FEDORA-2022-ccfd5d1045
- FEDORA-2022-1df2a841e4
- FEDORA-2022-1df2a841e4
Package nautilus updated to version 42.5-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-37290
GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.
- https://gitlab.gnome.org/GNOME/nautilus/-/issues/2376
- https://gitlab.gnome.org/GNOME/nautilus/-/merge_requests/1001
- https://gitlab.gnome.org/GNOME/nautilus/-/tree/master
- FEDORA-2023-dbe1157188
- FEDORA-2023-f81ad89b81
- https://gitlab.gnome.org/GNOME/nautilus/-/issues/2376
- FEDORA-2023-f81ad89b81
- FEDORA-2023-dbe1157188
- https://gitlab.gnome.org/GNOME/nautilus/-/tree/master
- https://gitlab.gnome.org/GNOME/nautilus/-/merge_requests/1001
Package eepm updated to version 3.26.10-alt1 for branch sisyphus_riscv64.
Closed bugs
pycharm не устанавливается
epm play spotify: отсутствует иконка приложения
WPS Office создаёт лишний раздел в меню
Package wxGTK3.2 updated to version 3.2.1-alt2 for branch sisyphus_riscv64.
Closed bugs
Файловый конфликт с libwxBase3.1-devel