ALT-BU-2024-10918-1
Branch sisyphus_e2k update bulletin.
Package xdg-utils updated to version 1.2.1-alt2 for branch sisyphus_e2k.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-4055
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.
Closed bugs
Устарел, есть 1.2.1
Package alt-csp-cryptopro updated to version 0.3.0-alt4 for branch sisyphus_e2k.
Closed bugs
Задана неверная маска или ключ при подписании группы файлов с помощью alt-csp-cryptopro
Недоступны функции "Создать имя" и "Подписать и сжать" при подписи одного файла
Package curl updated to version 8.9.1-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2024-05923
Уязвимость функции GTime2str парсера ASN1 Parser библиотеки libcurl, позволяющая нарушителю вызвать октаз в обслуживании
Modified: 2024-11-21
CVE-2024-7264
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.