ALT-BU-2022-7061-1
Branch p10 update bulletin.
Closed vulnerabilities
BDU:2022-06694
Уязвимость функции asn1_encode_simple_der() библиотеки Libtasn1, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2021-46848
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
- https://bugs.gentoo.org/866237
- https://bugs.gentoo.org/866237
- https://gitlab.com/gnutls/libtasn1/-/commit/44a700d2051a666235748970c2df047ff207aeb5
- https://gitlab.com/gnutls/libtasn1/-/commit/44a700d2051a666235748970c2df047ff207aeb5
- https://gitlab.com/gnutls/libtasn1/-/issues/32
- https://gitlab.com/gnutls/libtasn1/-/issues/32
- [debian-lts-announce] 20230109 [SECURITY] [DLA 3263-1] libtasn1-6 security update
- [debian-lts-announce] 20230109 [SECURITY] [DLA 3263-1] libtasn1-6 security update
- FEDORA-2022-3c933ffaca
- FEDORA-2022-3c933ffaca
- FEDORA-2022-3f9ee1ad91
- FEDORA-2022-3f9ee1ad91
- FEDORA-2022-061f857481
- FEDORA-2022-061f857481
- FEDORA-2022-19056934a7
- FEDORA-2022-19056934a7
- https://security.netapp.com/advisory/ntap-20221118-0006/
- https://security.netapp.com/advisory/ntap-20221118-0006/
Closed vulnerabilities
BDU:2022-05968
Уязвимость функции usbredirparser_serialize() компонента usbredirparser/usbredirparser.c протокола перенаправления USB-трафика Usbredir, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2021-3700
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.
- https://bugzilla.redhat.com/show_bug.cgi?id=1992830
- https://bugzilla.redhat.com/show_bug.cgi?id=1992830
- https://gitlab.freedesktop.org/spice/usbredir/-/commit/03c519ff5831ba
- https://gitlab.freedesktop.org/spice/usbredir/-/commit/03c519ff5831ba
- [debian-lts-announce] 20220320 [SECURITY] [DLA 2958-1] usbredir security update
- [debian-lts-announce] 20220320 [SECURITY] [DLA 2958-1] usbredir security update