2024-08-20
ALT-BU-2024-11370-1
Branch p11 update bulletin.
Package adwaita-qt updated to version 1.4.2-alt1 for branch p11 in task 354333.
Closed bugs
Прошу обновить пакет adwaita-qt до версии 1.4.2
Closed bugs
Не хватает зависимостей php-*
Package kde5-plasma-addon-alt-weather updated to version 1.0.25-alt2 for branch p11 in task 354095.
Closed bugs
Показывает старую версию
Падения plasma после удаления виджета "Прогноз погоды"
Closed bugs
Не запускается Waydroid
Closed vulnerabilities
Published: 2024-07-19
BDU:2024-06186
Уязвимость компонента File Handler библиотеки импорта 3D-моделей Open Asset Import Library (Assimp), позволяющая нарушителю выполнить произвольный код
Severity: HIGH (8.4)
Vector: AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2024-07-19
Modified: 2025-03-25
Modified: 2025-03-25
CVE-2024-40724
Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary code by inputting a specially crafted file into the product.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
- https://github.com/assimp/assimp/pull/5651/commits/614911bb3b1bfc3a1799ae2b3cca306270f3fb97
- https://github.com/assimp/assimp/pull/5651/commits/614911bb3b1bfc3a1799ae2b3cca306270f3fb97
- https://github.com/assimp/assimp/releases/tag/v5.4.2
- https://github.com/assimp/assimp/releases/tag/v5.4.2
- https://jvn.jp/en/jp/JVN87710540/
- https://jvn.jp/en/jp/JVN87710540/