2022-12-07
ALT-BU-2022-7343-1
Branch sisyphus_e2k update bulletin.
Package libopenh264 updated to version 2.3.1-alt1.1 for branch sisyphus_e2k.
Closed bugs
недостаёт Provides:/Obsoletes:
Package modsecurity updated to version 3.0.8-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Published: 2023-01-20
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-48279
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References:
- https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-covering-several-cves/
- https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-covering-several-cves/
- https://github.com/SpiderLabs/ModSecurity/pull/2795
- https://github.com/SpiderLabs/ModSecurity/pull/2795
- https://github.com/SpiderLabs/ModSecurity/pull/2797
- https://github.com/SpiderLabs/ModSecurity/pull/2797
- https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.9.6
- https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.9.6
- https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.0.8
- https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.0.8
- [debian-lts-announce] 20230126 [SECURITY] [DLA 3283-1] modsecurity-apache security update
- [debian-lts-announce] 20230126 [SECURITY] [DLA 3283-1] modsecurity-apache security update
- FEDORA-2023-09f0496e60
- FEDORA-2023-09f0496e60
- FEDORA-2023-bc61f7a145
- FEDORA-2023-bc61f7a145
- FEDORA-2023-8aa264d5c5
- FEDORA-2023-8aa264d5c5
Package zabbix updated to version 6.0.12-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Published: 2022-12-05
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-43516
A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI)
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References: