ALT-BU-2022-6590-1
Branch sisyphus_e2k update bulletin.
Package python3-module-paramiko updated to version 2.11.0-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2022-01897
Уязвимость реализации протокола SSHv2 библиотеки Paramiko, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю получить доступ к конфиденциальной информации
Modified: 2024-11-21
CVE-2022-24302
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
- https://github.com/paramiko/paramiko/blob/363a28d94cada17f012c1604a3c99c71a2bda003/paramiko/pkey.py#L546
- https://github.com/paramiko/paramiko/blob/363a28d94cada17f012c1604a3c99c71a2bda003/paramiko/pkey.py#L546
- [debian-lts-announce] 20220321 [SECURITY] [DLA 2959-1] paramiko security update
- [debian-lts-announce] 20220321 [SECURITY] [DLA 2959-1] paramiko security update
- [debian-lts-announce] 20220912 [SECURITY] [DLA 3104-1] paramiko security update
- [debian-lts-announce] 20220912 [SECURITY] [DLA 3104-1] paramiko security update
- FEDORA-2022-8eb95d8611
- FEDORA-2022-8eb95d8611
- FEDORA-2022-806492f1d1
- FEDORA-2022-806492f1d1
- FEDORA-2022-bb5c461682
- FEDORA-2022-bb5c461682
- https://www.paramiko.org/changelog.html
- https://www.paramiko.org/changelog.html
Package python3-module-django updated to version 3.2.16-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-41323
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.
- https://docs.djangoproject.com/en/4.0/releases/security/
- https://docs.djangoproject.com/en/4.0/releases/security/
- https://github.com/django/django/commit/5b6b257fa7ec37ff27965358800c67e2dd11c924
- https://github.com/django/django/commit/5b6b257fa7ec37ff27965358800c67e2dd11c924
- https://groups.google.com/forum/#%21forum/django-announce
- https://groups.google.com/forum/#%21forum/django-announce
- FEDORA-2023-bde7913e5a
- FEDORA-2023-bde7913e5a
- FEDORA-2023-8fed428c5e
- FEDORA-2023-8fed428c5e
- FEDORA-2023-a53ab7c969
- FEDORA-2023-a53ab7c969
- FEDORA-2023-3d775d93be
- FEDORA-2023-3d775d93be
- FEDORA-2023-a74513bda8
- FEDORA-2023-a74513bda8
- https://security.netapp.com/advisory/ntap-20221124-0001/
- https://security.netapp.com/advisory/ntap-20221124-0001/
- https://www.djangoproject.com/weblog/2022/oct/04/security-releases/
- https://www.djangoproject.com/weblog/2022/oct/04/security-releases/
Package vim updated to version 9.0.0749-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2022-05991
Уязвимость функции utfc_ptr2len() текстового редактора Vim, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2022-05992
Уязвимость функции getcmdline_int() текстового редактора Vim, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2022-06177
Уязвимость функции win_redr_ruler() текстового редактора Vim, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2022-06178
Уязвимость функции ex_finally() текстового редактора Vim, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2022-06179
Уязвимость функции process_next_cpt_value() текстового редактора Vim, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2022-06180
Уязвимость текстового редактора Vim, связанная с ошибками разыменования указателя, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-06196
Уязвимость функции did_set_string_option() текстового редактора Vim, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2022-3234
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.
- https://github.com/vim/vim/commit/c249913edc35c0e666d783bfc21595cf9f7d9e0d
- https://github.com/vim/vim/commit/c249913edc35c0e666d783bfc21595cf9f7d9e0d
- https://huntr.dev/bounties/90fdf374-bf04-4386-8a23-38c83b88f0da
- https://huntr.dev/bounties/90fdf374-bf04-4386-8a23-38c83b88f0da
- [debian-lts-announce] 20221108 [SECURITY] [DLA 3182-1] vim security update
- [debian-lts-announce] 20221108 [SECURITY] [DLA 3182-1] vim security update
- FEDORA-2022-fff548cfab
- FEDORA-2022-fff548cfab
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-40161673a3
- FEDORA-2022-40161673a3
- GLSA-202305-16
- GLSA-202305-16
Modified: 2024-11-21
CVE-2022-3235
Use After Free in GitHub repository vim/vim prior to 9.0.0490.
- https://github.com/vim/vim/commit/1c3dd8ddcba63c1af5112e567215b3cec2de11d0
- https://github.com/vim/vim/commit/1c3dd8ddcba63c1af5112e567215b3cec2de11d0
- https://huntr.dev/bounties/96d5f7a0-a834-4571-b73b-0fe523b941af
- https://huntr.dev/bounties/96d5f7a0-a834-4571-b73b-0fe523b941af
- [debian-lts-announce] 20221124 [SECURITY] [DLA 3204-1] vim security update
- [debian-lts-announce] 20221124 [SECURITY] [DLA 3204-1] vim security update
- FEDORA-2022-fff548cfab
- FEDORA-2022-fff548cfab
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-40161673a3
- FEDORA-2022-40161673a3
- GLSA-202305-16
- GLSA-202305-16
Modified: 2024-11-21
CVE-2022-3256
Use After Free in GitHub repository vim/vim prior to 9.0.0530.
- https://github.com/vim/vim/commit/8ecfa2c56b4992c7f067b92488aa9acea5a454ad
- https://github.com/vim/vim/commit/8ecfa2c56b4992c7f067b92488aa9acea5a454ad
- https://huntr.dev/bounties/8336a3df-212a-4f8d-ae34-76ef1f936bb3
- https://huntr.dev/bounties/8336a3df-212a-4f8d-ae34-76ef1f936bb3
- [debian-lts-announce] 20221124 [SECURITY] [DLA 3204-1] vim security update
- [debian-lts-announce] 20221124 [SECURITY] [DLA 3204-1] vim security update
- FEDORA-2022-fff548cfab
- FEDORA-2022-fff548cfab
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-40161673a3
- FEDORA-2022-40161673a3
- GLSA-202305-16
- GLSA-202305-16
Modified: 2024-11-21
CVE-2022-3278
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.
- https://github.com/vim/vim/commit/69082916c8b5d321545d60b9f5facad0a2dd5a4e
- https://github.com/vim/vim/commit/69082916c8b5d321545d60b9f5facad0a2dd5a4e
- https://huntr.dev/bounties/a9fad77e-f245-4ce9-ba15-c7d4c86c4612
- https://huntr.dev/bounties/a9fad77e-f245-4ce9-ba15-c7d4c86c4612
- FEDORA-2022-fff548cfab
- FEDORA-2022-fff548cfab
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-40161673a3
- FEDORA-2022-40161673a3
- GLSA-202305-16
- GLSA-202305-16
Modified: 2024-11-21
CVE-2022-3296
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
- https://github.com/vim/vim/commit/96b9bf8f74af8abf1e30054f996708db7dc285be
- https://github.com/vim/vim/commit/96b9bf8f74af8abf1e30054f996708db7dc285be
- https://huntr.dev/bounties/958866b8-526a-4979-9471-39392e0c9077
- https://huntr.dev/bounties/958866b8-526a-4979-9471-39392e0c9077
- FEDORA-2022-fff548cfab
- FEDORA-2022-fff548cfab
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-40161673a3
- FEDORA-2022-40161673a3
- GLSA-202305-16
- GLSA-202305-16
Modified: 2024-11-21
CVE-2022-3297
Use After Free in GitHub repository vim/vim prior to 9.0.0579.
- https://github.com/vim/vim/commit/0ff01835a40f549c5c4a550502f62a2ac9ac447c
- https://github.com/vim/vim/commit/0ff01835a40f549c5c4a550502f62a2ac9ac447c
- https://huntr.dev/bounties/1aa9ec92-0355-4710-bf85-5bce9effa01c
- https://huntr.dev/bounties/1aa9ec92-0355-4710-bf85-5bce9effa01c
- FEDORA-2022-fff548cfab
- FEDORA-2022-fff548cfab
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-40161673a3
- FEDORA-2022-40161673a3
- GLSA-202305-16
- GLSA-202305-16
Modified: 2024-11-21
CVE-2022-3324
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
- https://github.com/vim/vim/commit/8279af514ca7e5fd3c31cf13b0864163d1a0bfeb
- https://github.com/vim/vim/commit/8279af514ca7e5fd3c31cf13b0864163d1a0bfeb
- https://huntr.dev/bounties/e414e55b-f332-491f-863b-c18dca97403c
- https://huntr.dev/bounties/e414e55b-f332-491f-863b-c18dca97403c
- [debian-lts-announce] 20221108 [SECURITY] [DLA 3182-1] vim security update
- [debian-lts-announce] 20221108 [SECURITY] [DLA 3182-1] vim security update
- FEDORA-2022-fff548cfab
- FEDORA-2022-fff548cfab
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-40161673a3
- FEDORA-2022-40161673a3
- GLSA-202305-16
- GLSA-202305-16
Modified: 2024-11-21
CVE-2022-3352
Use After Free in GitHub repository vim/vim prior to 9.0.0614.
- https://github.com/vim/vim/commit/ef976323e770315b5fca544efb6b2faa25674d15
- https://github.com/vim/vim/commit/ef976323e770315b5fca544efb6b2faa25674d15
- https://huntr.dev/bounties/d058f182-a49b-40c7-9234-43d4c5a29f60
- https://huntr.dev/bounties/d058f182-a49b-40c7-9234-43d4c5a29f60
- [debian-lts-announce] 20221124 [SECURITY] [DLA 3204-1] vim security update
- [debian-lts-announce] 20221124 [SECURITY] [DLA 3204-1] vim security update
- FEDORA-2022-fff548cfab
- FEDORA-2022-fff548cfab
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-4bc60c32a2
- FEDORA-2022-40161673a3
- FEDORA-2022-40161673a3
- GLSA-202305-16
- GLSA-202305-16
Modified: 2024-11-21
CVE-2022-3491
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.
- https://github.com/vim/vim/commit/3558afe9e9e904cabb8475392d859f2d2fc21041
- https://github.com/vim/vim/commit/3558afe9e9e904cabb8475392d859f2d2fc21041
- https://huntr.dev/bounties/6e6e05c2-2cf7-4aa5-a817-a62007bf92cb
- https://huntr.dev/bounties/6e6e05c2-2cf7-4aa5-a817-a62007bf92cb
- GLSA-202305-16
- GLSA-202305-16
Closed bugs
vim Игнорирует ~/.vimrc