ALT-BU-2023-2728-1
Branch sisyphus_mipsel update bulletin.
Package podman updated to version 4.4.2-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
Modified: 2025-02-24
CVE-2023-0778
A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.
Package sudo updated to version 1.9.13p2-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
Modified: 2024-09-13
BDU:2023-01183
Уязвимость функции set_cmnd_path() программы системного администрирования Sudo, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-03-21
CVE-2023-27320
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
- http://www.openwall.com/lists/oss-security/2023/03/01/8
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/332KN4QI6QXB7NI7SWSJ2EQJKWIILFN6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLXMRAMXC3BYL4DNKVTK3V6JDMUXZ7B/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6VW24YGXJYI4NZ5HZPQCF4MCE7766AU/
- https://security.gentoo.org/glsa/202309-12
- https://security.netapp.com/advisory/ntap-20230413-0009/
- https://www.openwall.com/lists/oss-security/2023/02/28/1
- https://www.sudo.ws/releases/stable/#1.9.13p2
- http://www.openwall.com/lists/oss-security/2023/03/01/8
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/332KN4QI6QXB7NI7SWSJ2EQJKWIILFN6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLXMRAMXC3BYL4DNKVTK3V6JDMUXZ7B/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6VW24YGXJYI4NZ5HZPQCF4MCE7766AU/
- https://security.gentoo.org/glsa/202309-12
- https://security.netapp.com/advisory/ntap-20230413-0009/
- https://www.openwall.com/lists/oss-security/2023/02/28/1
- https://www.sudo.ws/releases/stable/#1.9.13p2
Modified: 2024-11-21
CVE-2023-28486
Sudo before 1.9.13 does not escape control characters in log messages.
- https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13
- https://lists.debian.org/debian-lts-announce/2024/02/msg00002.html
- https://security.gentoo.org/glsa/202309-12
- https://security.netapp.com/advisory/ntap-20230420-0002/
- https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13
- https://lists.debian.org/debian-lts-announce/2024/02/msg00002.html
- https://security.gentoo.org/glsa/202309-12
- https://security.netapp.com/advisory/ntap-20230420-0002/
Modified: 2024-11-21
CVE-2023-28487
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
- https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13
- https://lists.debian.org/debian-lts-announce/2024/02/msg00002.html
- https://security.gentoo.org/glsa/202309-12
- https://security.netapp.com/advisory/ntap-20230420-0002/
- https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13
- https://lists.debian.org/debian-lts-announce/2024/02/msg00002.html
- https://security.gentoo.org/glsa/202309-12
- https://security.netapp.com/advisory/ntap-20230420-0002/