ALT-BU-2023-4778-1
Branch sisyphus_riscv64 update bulletin.
Package podofo updated to version 0.9.8-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-30469
A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PDF file.
Modified: 2024-11-21
CVE-2021-30470
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.
Modified: 2024-11-21
CVE-2021-30471
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lead to a stack overflow.
Modified: 2024-11-21
CVE-2021-30472
A flaw was found in PoDoFo 0.9.7. A stack-based buffer overflow in PdfEncryptMD5Base::ComputeOwnerKey function in PdfEncrypt.cpp is possible because of a improper check of the keyLength value.
Package libjasper updated to version 4.0.0-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-2963
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
- https://access.redhat.com/security/cve/CVE-2022-2963
- https://access.redhat.com/security/cve/CVE-2022-2963
- https://bugzilla.redhat.com/show_bug.cgi?id=2118587
- https://bugzilla.redhat.com/show_bug.cgi?id=2118587
- https://github.com/jasper-software/jasper/issues/332
- https://github.com/jasper-software/jasper/issues/332
Modified: 2024-11-21
CVE-2022-40755
JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.
Package util-linux updated to version 2.39.1-alt2 for branch sisyphus_riscv64.
Closed bugs
util-linux: loongarch64 FTBFS
Package qpwgraph updated to version 0.5.1-alt1 for branch sisyphus_riscv64.
Closed bugs
Нет иконки в трее
Package NetworkManager updated to version 1.43.90-alt2 for branch sisyphus_riscv64.
Closed bugs
NetworkManager-daemon: depends on systemd