ALT-BU-2023-6962-1
Branch sisyphus_riscv64 update bulletin.
Package salt updated to version 3006.4-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2024-11-15
CVE-2023-34049
The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force Salt-SSH to run their script. If an attacker has access to the target VM and knows the path to the pre-flight script before it runs they can ensure Salt-SSH runs their script with the privileges of the user running Salt-SSH. Do not make the copy path on the target predictable and ensure we check return codes of the scp command if the copy fails.
Package alterator-l10n updated to version 2.9.137-alt3 for branch sisyphus_riscv64.
Closed bugs
В справке для alterator-vm указана ext3, а реально создаётся ext4.
Отсутствует help для шагов 1, 2, 4, 5, 6, 7, 8, 12 при установке (язык: English)
Package transmission updated to version 4.0.4-alt3 for branch sisyphus_riscv64.
Closed bugs
При скачивании файла через веб-интерфейс возникает ошибка : "Нет такого файла или каталога"
Package cinnamon-meta updated to version 5.6.0-alt2 for branch sisyphus_riscv64.
Closed bugs
Убрать зависимость на pulseaudio-daemon и alsa-plugins-pulse