ALT-BU-2024-12446-1
Branch sisyphus_riscv64 update bulletin.
Package plasma-desktop updated to version 6.1.4-alt4 for branch sisyphus_riscv64.
Closed bugs
При разблокировке экрана выводится запрос пароля вместо пин-кода
Package xorg-drv-ati updated to version 22.0.0-alt1 for branch sisyphus_riscv64.
Closed bugs
xrandr --scale crashes Xorg
Package deepin-turbo updated to version 0.0.9.0.28.8f4b-alt1 for branch sisyphus_riscv64.
Closed bugs
deepin-default-settings содержит системные настройки
Package wget updated to version 1.24.5-alt2 for branch sisyphus_riscv64.
Closed vulnerabilities
BDU:2024-04683
Уязвимость компонента userinfo URI менеджера загрузок GNU Wget, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации
Modified: 2024-11-21
CVE-2024-38428
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
- https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace
- https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html
- https://security.netapp.com/advisory/ntap-20241115-0005/
- https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html
- https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace