ALT-BU-2023-2776-1
Branch sisyphus_mipsel update bulletin.
Package mate-menu updated to version 22.04.2-alt4 for branch sisyphus_mipsel.
Closed bugs
Не открывается меню настроек mate-menu
Package python3-module-avro updated to version 1.11.1-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-43045
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.
- [oss-security] 20220106 CVE-2021-43045: Apache Avro: Possible DOS vulnerabilities in C# Avro SDK
- [oss-security] 20220106 CVE-2021-43045: Apache Avro: Possible DOS vulnerabilities in C# Avro SDK
- https://lists.apache.org/thread/5fttw9vk6gd2p3b846nox7hcj5469xfd
- https://lists.apache.org/thread/5fttw9vk6gd2p3b846nox7hcj5469xfd
Package ansible-core updated to version 2.14.3-alt3 for branch sisyphus_mipsel.
Closed bugs
Требует resolvelib версии меньшей, чем в репозитории
Ошибка запуска ansible-test (модуль удалён, но бинарник всё ещё упакован)
Package strongswan updated to version 5.9.10-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
BDU:2023-02129
Уязвимость демона strongSwan, связанная с ошибками при проверке сертификата в методах EAP на основе TLS, позволяющая нарушителю выполнить отказ в обслуживании
Modified: 2025-02-08
CVE-2023-26463
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is sending an untrusted client certificate during EAP-TLS. A server is affected only if it loads plugins that implement TLS-based EAP methods (EAP-TLS, EAP-TTLS, EAP-PEAP, or EAP-TNC). This is fixed in 5.9.10.
- https://github.com/strongswan/strongswan/releases
- https://github.com/strongswan/strongswan/releases
- https://security.netapp.com/advisory/ntap-20230517-0010/
- https://security.netapp.com/advisory/ntap-20230517-0010/
- https://www.strongswan.org/blog/2023/03/02/strongswan-vulnerability-%28cve-2023-26463%29.html
- https://www.strongswan.org/blog/2023/03/02/strongswan-vulnerability-%28cve-2023-26463%29.html