ALT-BU-2023-6943-1
Branch sisyphus_e2k update bulletin.
Package roundcube updated to version 1.6.4-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2023-06297
Уязвимость компонента program/lib/Roundcube/rcube_string_replacer.php почтового клиента RoundCube Webmail, позволяющая нарушителю провести атаку межсайтового скриптинга
BDU:2023-07143
Уязвимость библиотеки program/lib/Roundcube/rcube_washtml.php почтового клиента RoundCube Webmail, позволяющая нарушителю выполнить произвольный JavaScript-код
Modified: 2024-12-20
CVE-2023-43770
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
- https://github.com/roundcube/roundcubemail/commit/e92ec206a886461245e1672d8530cc93c618a49b
- https://github.com/roundcube/roundcubemail/commit/e92ec206a886461245e1672d8530cc93c618a49b
- [debian-lts-announce] 20230922 [SECURITY] [DLA 3577-1] roundcube security update
- [debian-lts-announce] 20230922 [SECURITY] [DLA 3577-1] roundcube security update
- https://roundcube.net/news/2023/09/15/security-update-1.6.3-released
- https://roundcube.net/news/2023/09/15/security-update-1.6.3-released
Modified: 2025-03-19
CVE-2023-5631
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
- http://www.openwall.com/lists/oss-security/2023/11/01/1
- http://www.openwall.com/lists/oss-security/2023/11/01/1
- http://www.openwall.com/lists/oss-security/2023/11/01/3
- http://www.openwall.com/lists/oss-security/2023/11/01/3
- http://www.openwall.com/lists/oss-security/2023/11/17/2
- http://www.openwall.com/lists/oss-security/2023/11/17/2
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054079
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054079
- https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b71886984474dc529dd31d
- https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b71886984474dc529dd31d
- https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf75552e5376613
- https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf75552e5376613
- https://github.com/roundcube/roundcubemail/issues/9168
- https://github.com/roundcube/roundcubemail/issues/9168
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.15
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.15
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.5
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.5
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.4
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.4
- https://lists.debian.org/debian-lts-announce/2023/10/msg00035.html
- https://lists.debian.org/debian-lts-announce/2023/10/msg00035.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LK67Q46OIEGJCRQUBHKLH3IIJTBNGGX4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LK67Q46OIEGJCRQUBHKLH3IIJTBNGGX4/
- https://roundcube.net/news/2023/10/16/security-update-1.6.4-released
- https://roundcube.net/news/2023/10/16/security-update-1.6.4-released
- https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15
- https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15
- https://www.debian.org/security/2023/dsa-5531
- https://www.debian.org/security/2023/dsa-5531
Package kf5-breeze-icons updated to version 5.111.0-alt2 for branch sisyphus_e2k.
Closed bugs
У Yandex Browser красно-белая иконка в icon-theme-breeze
Package python3-module-GitPython updated to version 3.1.40-alt1 for branch sisyphus_e2k.
Closed bugs
[CVE] Прошу собрать версию 3.1.37
Package netdata updated to version 1.43.0-alt2 for branch sisyphus_e2k.
Closed bugs
Собрать netdata без distutils
Package python3-module-passlib updated to version 1.7.4-alt2 for branch sisyphus_e2k.
Closed bugs
Собрать python3-module-passlib без distutils
Package vim updated to version 9.0.2081-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2023-5535
Use After Free in GitHub repository vim/vim prior to v9.0.2010.
- https://github.com/vim/vim/commit/41e6f7d6ba67b61d911f9b1d76325cd79224753d
- https://github.com/vim/vim/commit/41e6f7d6ba67b61d911f9b1d76325cd79224753d
- https://huntr.dev/bounties/2c2d85a7-1171-4014-bf7f-a2451745861f
- https://huntr.dev/bounties/2c2d85a7-1171-4014-bf7f-a2451745861f
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VDDWD25AZIHBAA44HQT75OWLQ5UMDKU3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VDDWD25AZIHBAA44HQT75OWLQ5UMDKU3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VGTVLUV7UCXXCZAIQIUCLG6JXAVYT3HE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VGTVLUV7UCXXCZAIQIUCLG6JXAVYT3HE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XPT7NMYJRLBPIALGSE24UWTY6F774GZW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XPT7NMYJRLBPIALGSE24UWTY6F774GZW/
Package appstream-data updated to version 20231031-alt1 for branch sisyphus_e2k.
Closed bugs
VLC устанавливает из Центра приложений Gnome vlc-mini а не vlc
Package python3-module-buildozer updated to version 1.5.0-alt2 for branch sisyphus_e2k.
Closed bugs
Собрать python3-module-buildozer без distutils
Package apache2-mod_perl updated to version 2.0.13-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2022-02598
Уязвимость компонентов PerlRun.pm и RegistryCooker.pm модуль для веб-сервера Apache mod_perl, позволяющие нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2007-1349
PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
- 20070602-01-P
- 20070602-01-P
- RHSA-2007:0395
- RHSA-2007:0395
- RHSA-2008:0630
- RHSA-2008:0630
- 24678
- 24678
- 24839
- 24839
- 25072
- 25072
- 25110
- 25110
- 25432
- 25432
- 25655
- 25655
- 25730
- 25730
- 25894
- 25894
- 26084
- 26084
- 26231
- 26231
- 26290
- 26290
- 31490
- 31490
- 31493
- 31493
- 33720
- 33720
- 33723
- 33723
- GLSA-200705-04
- GLSA-200705-04
- 248386
- 248386
- 1021508
- 1021508
- http://support.avaya.com/elmodocs2/security/ASA-2007-293.htm
- http://support.avaya.com/elmodocs2/security/ASA-2007-293.htm
- http://svn.apache.org/repos/asf/perl/modperl/branches/1.x/Changes
- http://svn.apache.org/repos/asf/perl/modperl/branches/1.x/Changes
- http://www.gossamer-threads.com/lists/modperl/modperl/92739
- http://www.gossamer-threads.com/lists/modperl/modperl/92739
- MDKSA-2007:083
- MDKSA-2007:083
- SUSE-SR:2007:012
- SUSE-SR:2007:012
- SUSE-SR:2007:008
- SUSE-SR:2007:008
- RHSA-2007:0396
- RHSA-2007:0396
- RHSA-2007:0486
- RHSA-2007:0486
- RHSA-2008:0261
- RHSA-2008:0261
- RHSA-2008:0627
- RHSA-2008:0627
- 23192
- 23192
- 1018259
- 1018259
- 2007-0023
- 2007-0023
- USN-488-1
- USN-488-1
- ADV-2007-1150
- ADV-2007-1150
- modperl-pathinfo-dos(33312)
- modperl-pathinfo-dos(33312)
- oval:org.mitre.oval:def:10987
- oval:org.mitre.oval:def:10987
- oval:org.mitre.oval:def:8349
- oval:org.mitre.oval:def:8349
Closed bugs
apache2-mod_perl: update to 2.0.13 to support perl 5.38
Package alterator-ports-access updated to version 0.5.5-alt1 for branch sisyphus_e2k.
Closed bugs
Сломан редактор правил USB
Package tcpreplay updated to version 4.4.4-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2023-02104
Уязвимость функции rmacinstring утилиты редактирования и воспроизведения PCAP-файлов Tcpreplay, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-02-27
CVE-2023-27783
An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt_cleanup function at plugins/dlt_plugins.c.
- https://github.com/appneta/tcpreplay/issues/780
- https://github.com/appneta/tcpreplay/issues/780
- https://github.com/appneta/tcpreplay/pull/781
- https://github.com/appneta/tcpreplay/pull/781
- FEDORA-2023-7ffeed7339
- FEDORA-2023-7ffeed7339
- FEDORA-2023-37bdea9241
- FEDORA-2023-37bdea9241
- FEDORA-2023-96ffd40fd4
- FEDORA-2023-96ffd40fd4
Modified: 2025-02-27
CVE-2023-27784
An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint.
Modified: 2025-02-27
CVE-2023-27785
An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function.
Modified: 2025-02-26
CVE-2023-27786
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function.
- https://github.com/appneta/tcpreplay/issues/782
- https://github.com/appneta/tcpreplay/issues/782
- https://github.com/appneta/tcpreplay/pull/783
- https://github.com/appneta/tcpreplay/pull/783
- FEDORA-2023-7ffeed7339
- FEDORA-2023-7ffeed7339
- FEDORA-2023-37bdea9241
- FEDORA-2023-37bdea9241
- FEDORA-2023-96ffd40fd4
- FEDORA-2023-96ffd40fd4
Modified: 2025-02-26
CVE-2023-27787
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint.
Modified: 2025-02-26
CVE-2023-27788
An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint.
Modified: 2025-02-26
CVE-2023-27789
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the cidr2cidr function at the cidr.c:178 endpoint.
- https://github.com/appneta/tcpreplay/issues/784
- https://github.com/appneta/tcpreplay/issues/784
- https://github.com/appneta/tcpreplay/pull/783
- https://github.com/appneta/tcpreplay/pull/783
- FEDORA-2023-7ffeed7339
- FEDORA-2023-7ffeed7339
- FEDORA-2023-37bdea9241
- FEDORA-2023-37bdea9241
- FEDORA-2023-96ffd40fd4
- FEDORA-2023-96ffd40fd4
Package alterator-l10n updated to version 2.9.137-alt3 for branch sisyphus_e2k.
Closed bugs
В справке для alterator-vm указана ext3, а реально создаётся ext4.
Отсутствует help для шагов 1, 2, 4, 5, 6, 7, 8, 12 при установке (язык: English)