ALT-BU-2023-3030-1
Branch sisyphus_mipsel update bulletin.
Package alterator-x11 updated to version 1.98.15-alt1 for branch sisyphus_mipsel.
Closed bugs
video_scan -s drivers завершается ошибкой
Package python3-module-poetry-core updated to version 1.5.2-alt1 for branch sisyphus_mipsel.
Closed bugs
poetry-core: new version
Package libmicrohttpd updated to version 0.9.76-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2023-27371
GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field, which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function.
- https://git.gnunet.org/libmicrohttpd.git/commit/?id=6d6846e20bfdf4b3eb1b592c97520a532f724238
- https://git.gnunet.org/libmicrohttpd.git/commit/?id=6d6846e20bfdf4b3eb1b592c97520a532f724238
- https://github.com/0xhebi/CVEs/tree/main/GNU%20Libmicrohttpd
- https://github.com/0xhebi/CVEs/tree/main/GNU%20Libmicrohttpd
- [debian-lts-announce] 20230330 [SECURITY] [DLA 3374-1] libmicrohttpd security update
- [debian-lts-announce] 20230330 [SECURITY] [DLA 3374-1] libmicrohttpd security update
- https://lists.gnu.org/archive/html/libmicrohttpd/2023-02/msg00000.html
- https://lists.gnu.org/archive/html/libmicrohttpd/2023-02/msg00000.html
Package faad updated to version 2.10.1-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
BDU:2022-01663
Уязвимость функции ftypin компонента mp4read.c аудио декодера Freeware Advanced Audio Decoder 2 (FAAD2), позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2022-01666
Уязвимость функции sbr_qmf_analysis_32 компонента sbr_qmf.c аудио декодера Freeware Advanced Audio Decoder 2 (FAAD2), позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2022-01667
Уязвимость функции lt_prediction компонента lt_predict.c аудио декодера Freeware Advanced Audio Decoder 2 (FAAD2), позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2022-01813
Уязвимость функции get_sample() компонента output.c аудио декодера Freeware Advanced Audio Decoder 2 (FAAD2), позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-01814
Уязвимость функции sbr_qmf_synthesis_64 компонента sbr_qmf.c аудио декодера Freeware Advanced Audio Decoder 2 (FAAD2), позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2021-32273
An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4read.c. It allows an attacker to cause Code Execution.
Modified: 2024-11-21
CVE-2021-32274
An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 located in sbr_qmf.c. It allows an attacker to cause code Execution.
Modified: 2024-11-21
CVE-2021-32276
An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It allows an attacker to cause Denial of Service.
Modified: 2024-11-21
CVE-2021-32277
An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_analysis_32 located in sbr_qmf.c. It allows an attacker to cause code Execution.
Modified: 2024-11-21
CVE-2021-32278
An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in lt_predict.c. It allows an attacker to cause code Execution.
Package libsixel updated to version 1.10.3-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-11721
load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service.
Modified: 2024-11-21
CVE-2020-19668
Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6.
Modified: 2024-11-21
CVE-2021-40656
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
Package glmark2 updated to version 2021.12-alt3 for branch sisyphus_mipsel.
Closed bugs
Добавить пакету glmark2-es2 зависимость на libGLES