ALT-BU-2024-14192-1
Branch sisyphus_riscv64 update bulletin.
Package pam-config updated to version 1.9.1-alt1 for branch sisyphus_riscv64.
Closed bugs
Модуль завершается с ошибкой при разном регистре в имени пользователя
Прописать в самом начале файла /etc/pam.d/system-auth-common строку
Package mbedtls updated to version 3.6.2-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
BDU:2024-07428
Уязвимость программного обеспечения Mbed TLS, связанная с использованием неисправного или рискованного криптографического алгоритма, позволяющая нарушителю раскрыть защищаемую информацию
Modified: 2025-03-14
CVE-2024-45157
An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.
Modified: 2025-03-13
CVE-2024-45159
An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of mbedtls_ssl_get_verify_result() would incorrectly have the MBEDTLS_X509_BADCERT_KEY_USAGE and MBEDTLS_X509_BADCERT_KEY_USAGE bits clear. As a result, an attacker that had a certificate valid for uses other than TLS client authentication would nonetheless be able to use it for TLS client authentication. Only TLS 1.3 servers were affected, and only with optional authentication (with required authentication, the handshake would be aborted with a fatal alert).
Package SDL2_gfx updated to version 1.0.4-alt3 for branch sisyphus_riscv64.
Closed bugs
Отсутствует SDL2_gfxPrimitives_font.h
Package MySQL updated to version 8.0.39-alt1.1 for branch sisyphus_riscv64.
Closed bugs
QMYSQL driver not loaded