ALT-BU-2023-2848-1
Branch sisyphus_riscv64 update bulletin.
Package python3-module-avro updated to version 1.11.1-alt2 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-43045
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.
- [oss-security] 20220106 CVE-2021-43045: Apache Avro: Possible DOS vulnerabilities in C# Avro SDK
- [oss-security] 20220106 CVE-2021-43045: Apache Avro: Possible DOS vulnerabilities in C# Avro SDK
- https://lists.apache.org/thread/5fttw9vk6gd2p3b846nox7hcj5469xfd
- https://lists.apache.org/thread/5fttw9vk6gd2p3b846nox7hcj5469xfd
Package alien updated to version 8.95.6-alt1 for branch sisyphus_riscv64.
Closed bugs
Неверная версия
Package sleuthkit updated to version 4.12.0-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2025-04-02
CVE-2022-45639
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
- http://packetstormsecurity.com/files/171649/Sleuthkit-4.11.1-Command-Injection.html
- http://www.binaryworld.it/
- https://www.binaryworld.it/guidepoc.asp#CVE-2022-45639
- http://packetstormsecurity.com/files/171649/Sleuthkit-4.11.1-Command-Injection.html
- https://www.binaryworld.it/guidepoc.asp#CVE-2022-45639
- http://www.binaryworld.it/
Package liferea updated to version 1.14.1-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2023-1350
A vulnerability was found in liferea. It has been rated as critical. Affected by this issue is the function update_job_run of the file src/update.c of the component Feed Enrichment. The manipulation of the argument source with the input |date >/tmp/bad-item-link.txt leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 8d8b5b963fa64c7a2122d1bbfbb0bed46e813e59. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-222848.
Package eepm updated to version 3.34.0-alt1 for branch sisyphus_riscv64.
Closed bugs
Не собирает zoom
Package nerdctl updated to version 1.2.1-alt2 for branch sisyphus_riscv64.
Closed bugs
Не запускается контейнер без root