ALT-BU-2024-12167-1
Branch c10f2 update bulletin.
Package python3-module-cvxopt updated to version 1.3.2-alt1 for branch c10f2 in task 356790.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2021-41500
Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.
Closed vulnerabilities
BDU:2023-07324
Уязвимость компонентов lib/comp/comp.c, lib/comp/zstd/zstd.c, lib/dl/multipart.c или lib/header.c программного средства для уменьшения размера файлов в формате RPM zchunk, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2023-46228
zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, lib/dl/multipart.c, or lib/header.c.
- https://bugzilla.suse.com/show_bug.cgi?id=1216268
- https://bugzilla.suse.com/show_bug.cgi?id=1216268
- https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe
- https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe
- https://github.com/zchunk/zchunk/compare/1.3.1...1.3.2
- https://github.com/zchunk/zchunk/compare/1.3.1...1.3.2