2024-11-15
ALT-BU-2024-15701-1
Branch sisyphus_e2k update bulletin.
Package jose updated to version 14-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Published: 2024-03-20
BDU:2024-02461
Уязвимость модуля языка С для подписи и шифрования объектов JSON latchset Jose, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
Severity: HIGH (7.5)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity: HIGH (7.8)
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C
References:
Published: 2024-03-20
Modified: 2025-06-17
Modified: 2025-06-17
CVE-2023-50967
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- https://github.com/P3ngu1nW/CVE_Request/blob/main/latch-jose.md
- https://github.com/latchset/jose
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CIFPQUCLNWEAHYYJWCQD3AZPWYIV6YT3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OOBFVMOAV732C7PY74AHJ62ZNKT3ISZ6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W7EGLOAFN2PWZ75ZRLTUDUZCIPH2VFZU/
- https://github.com/P3ngu1nW/CVE_Request/blob/main/latch-jose.md
- https://github.com/latchset/jose
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CIFPQUCLNWEAHYYJWCQD3AZPWYIV6YT3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OOBFVMOAV732C7PY74AHJ62ZNKT3ISZ6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W7EGLOAFN2PWZ75ZRLTUDUZCIPH2VFZU/
Package liblouisutdml updated to version 2.12.0-alt2 for branch sisyphus_e2k.
Closed bugs
Ошибка сегментирования при использования ключа -l в утилите file2brl.
Package timeshift updated to version 24.06.3-alt3 for branch sisyphus_e2k.
Closed bugs
Долго создается снимок текущей системы в timeshift Альт К 10.2