ALT-BU-2024-2366-3
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2024-24826
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.1. The vulnerable function, `QuickTimeVideo::NikonTagsDecoder`, was new in v0.28.0, so Exiv2 versions before v0.28 are _not_ affected. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. In most cases this out of bounds read will result in a crash. This bug is fixed in version v0.28.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Modified: 2024-11-21
CVE-2024-25112
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-service was found in Exiv2 version v0.28.1: an unbounded recursion can cause Exiv2 to crash by exhausting the stack. The vulnerable function, `QuickTimeVideo::multipleEntriesDecoder`, was new in v0.28.0, so Exiv2 versions before v0.28 are _not_ affected. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted video file. This bug is fixed in version v0.28.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Package pulseaudio-module-xrdp updated to version 0.7-alt3 for branch sisyphus in task 340677.
Closed bugs
Не транслируется звук при подключении по XRDP
Package plasma5-welcome updated to version 5.27.10-alt5 for branch sisyphus in task 340697.
Closed bugs
Не открывается пакет Endless Sky
Package python3-module-pycryptodomex updated to version 3.20.0-alt1 for branch sisyphus in task 340720.
Closed vulnerabilities
BDU:2024-00329
Уязвимость библиотек для генерации биткоин-адресов и приватных ключей PyCryptodome и PyCryptodomeX, связанная с раскрытием информации через несоответствие, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Modified: 2025-06-03
CVE-2023-52323
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
Closed bugs
>= 3.19.1
Closed bugs
Из пакета пропал скрипт run.go, необходимый для запуска тестов
Package libtommath updated to version 1.2.1-alt1 for branch sisyphus in task 340710.
Closed vulnerabilities
BDU:2023-06241
Уязвимость функции libtom библиотеки libtommath, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2023-36328
Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).