ALT-BU-2023-2728-1
Branch sisyphus_mipsel update bulletin.
Package podman updated to version 4.4.2-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
Modified: 2025-02-24
CVE-2023-0778
A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.
Package sudo updated to version 1.9.13p2-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
BDU:2023-01183
Уязвимость функции set_cmnd_path() программы системного администрирования Sudo, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-03-22
CVE-2023-27320
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
- [oss-security] 20230301 Re: sudo: double free with per-command chroot sudoers rules
- [oss-security] 20230301 Re: sudo: double free with per-command chroot sudoers rules
- FEDORA-2023-cb5df36beb
- FEDORA-2023-cb5df36beb
- FEDORA-2023-d2d6ec2a32
- FEDORA-2023-d2d6ec2a32
- FEDORA-2023-11c9d868ca
- FEDORA-2023-11c9d868ca
- GLSA-202309-12
- GLSA-202309-12
- https://security.netapp.com/advisory/ntap-20230413-0009/
- https://security.netapp.com/advisory/ntap-20230413-0009/
- https://www.openwall.com/lists/oss-security/2023/02/28/1
- https://www.openwall.com/lists/oss-security/2023/02/28/1
- https://www.sudo.ws/releases/stable/#1.9.13p2
- https://www.sudo.ws/releases/stable/#1.9.13p2
Modified: 2024-11-21
CVE-2023-28486
Sudo before 1.9.13 does not escape control characters in log messages.
- https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13
- [debian-lts-announce] 20240203 [SECURITY] [DLA 3732-1] sudo security update
- GLSA-202309-12
- https://security.netapp.com/advisory/ntap-20230420-0002/
- https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca
- https://security.netapp.com/advisory/ntap-20230420-0002/
- GLSA-202309-12
- [debian-lts-announce] 20240203 [SECURITY] [DLA 3732-1] sudo security update
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13
Modified: 2024-11-21
CVE-2023-28487
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
- https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13
- [debian-lts-announce] 20240203 [SECURITY] [DLA 3732-1] sudo security update
- GLSA-202309-12
- https://security.netapp.com/advisory/ntap-20230420-0002/
- https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca
- https://security.netapp.com/advisory/ntap-20230420-0002/
- GLSA-202309-12
- [debian-lts-announce] 20240203 [SECURITY] [DLA 3732-1] sudo security update
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13