ALT-BU-2024-2290-1
Branch c10f2 update bulletin.
Package poppler-current updated to version 23.08.0-alt1 for branch c10f2 in task 339564.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2023-34872
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
- https://gitlab.freedesktop.org/poppler/poppler/-/commit/591235c8b6c65a2eee88991b9ae73490fd9afdfe
- https://gitlab.freedesktop.org/poppler/poppler/-/issues/1399
- FEDORA-2023-f0be0daaa5
- FEDORA-2023-6b20b7807a
- FEDORA-2023-4285cca9bf
- FEDORA-2023-4eff9e2cd6
- https://gitlab.freedesktop.org/poppler/poppler/-/commit/591235c8b6c65a2eee88991b9ae73490fd9afdfe
- FEDORA-2023-4eff9e2cd6
- FEDORA-2023-4285cca9bf
- FEDORA-2023-6b20b7807a
- FEDORA-2023-f0be0daaa5
- https://gitlab.freedesktop.org/poppler/poppler/-/issues/1399
Package apache2-mod_wsgi updated to version 4.9.4-alt0.c10f2.1 for branch c10f2 in task 340167.
Closed vulnerabilities
BDU:2022-05209
Уязвимость модуля mod_wsgi веб-сервера Apache, связанная с ошибками при обработке заголовока X-Client-IP, позволяющая нарушителю получить несанкционированный доступ к сетевым службам
Modified: 2024-11-21
CVE-2022-2255
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.
- https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L13940-L13941
- https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L13940-L13941
- https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L14046-L14082
- https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L14046-L14082
- [debian-lts-announce] 20220915 [SECURITY] [DLA 3111-1] mod-wsgi security update
- [debian-lts-announce] 20220915 [SECURITY] [DLA 3111-1] mod-wsgi security update
- https://modwsgi.readthedocs.io/en/latest/release-notes/version-4.9.3.html
- https://modwsgi.readthedocs.io/en/latest/release-notes/version-4.9.3.html