ALT-BU-2024-2775-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2024-22231
Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.
Modified: 2024-11-21
CVE-2024-22232
A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.
Package php8.3-swoole updated to version 5.1.2-alt1.3 for branch sisyphus in task 341111.
Closed bugs
/usr/lib64/php/8.3.1/extensions/swoole.so.so: cannot open shared object file: No such file or directory
Package alterator-fbi updated to version 5.49.4-alt1 for branch sisyphus in task 341175.
Closed bugs
Cоединение только по протоколу TLS 1.3
Closed bugs
Обновление mono до версии 6.12.0.182.
Package python3-module-cryptography updated to version 42.0.4-alt1 for branch sisyphus in task 341213.
Closed vulnerabilities
Modified: 2025-02-06
CVE-2024-26130
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.
- https://github.com/pyca/cryptography/commit/97d231672763cdb5959a3b191e692a362f1b9e55
- https://github.com/pyca/cryptography/commit/97d231672763cdb5959a3b191e692a362f1b9e55
- https://github.com/pyca/cryptography/pull/10423
- https://github.com/pyca/cryptography/pull/10423
- https://github.com/pyca/cryptography/security/advisories/GHSA-6vqw-3v5j-54x4
- https://github.com/pyca/cryptography/security/advisories/GHSA-6vqw-3v5j-54x4
Closed bugs
crashes on start: ConfigParser object has no attribute 'readfp'