ALT-BU-2024-3387-1
Branch sisyphus_e2k update bulletin.
Package mate-panel updated to version 1.28.0-alt2 for branch sisyphus_e2k.
Closed bugs
mate-panel 1.28 бесконечно перезапускается, если не установлен dconf-editor
Package python3-module-dns updated to version 2.6.1-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2023-29483
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
- https://github.com/eventlet/eventlet/issues/913
- https://github.com/eventlet/eventlet/releases/tag/v0.35.2
- https://github.com/rthalley/dnspython/issues/1045
- https://github.com/rthalley/dnspython/releases/tag/v2.6.0
- FEDORA-2024-bbd76d7c63
- FEDORA-2024-930af3332f
- FEDORA-2024-3b4c7849ab
- https://security.netapp.com/advisory/ntap-20240510-0001/
- https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713
- https://www.dnspython.org/
- https://github.com/eventlet/eventlet/issues/913
- https://www.dnspython.org/
- https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713
- https://security.netapp.com/advisory/ntap-20240510-0001/
- FEDORA-2024-3b4c7849ab
- FEDORA-2024-930af3332f
- FEDORA-2024-bbd76d7c63
- https://github.com/rthalley/dnspython/releases/tag/v2.6.0
- https://github.com/rthalley/dnspython/issues/1045
- https://github.com/eventlet/eventlet/releases/tag/v0.35.2
Package frr updated to version 9.0.2-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2023-05649
Уязвимость программного средства реализации сетевой маршрутизации на Unix-подобных системах FRRouting, сетевой операционной системы Picos, операционной системы PAN-OS, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2023-08243
Уязвимость программного средства реализации сетевой маршрутизации на Unix-подобных системах FRRouting, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2023-08631
Уязвимость программного средства реализации сетевой маршрутизации на Unix-подобных системах FRRouting, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2023-38802
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
- https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
- https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- FEDORA-2023-ce436d56f8
- FEDORA-2023-ce436d56f8
- FEDORA-2023-514db5339e
- FEDORA-2023-514db5339e
- FEDORA-2023-61abba57d8
- FEDORA-2023-61abba57d8
- https://news.ycombinator.com/item?id=37305800
- https://news.ycombinator.com/item?id=37305800
- DSA-5495
- DSA-5495
Modified: 2024-11-21
CVE-2023-41358
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
- https://github.com/FRRouting/frr/pull/14260
- https://github.com/FRRouting/frr/pull/14260
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- FEDORA-2023-ce436d56f8
- FEDORA-2023-ce436d56f8
- FEDORA-2023-514db5339e
- FEDORA-2023-514db5339e
- FEDORA-2023-61abba57d8
- FEDORA-2023-61abba57d8
- DSA-5495
- DSA-5495
Modified: 2024-11-21
CVE-2023-41359
An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.
Modified: 2024-11-21
CVE-2023-41360
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
- https://github.com/FRRouting/frr/pull/14245
- https://github.com/FRRouting/frr/pull/14245
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- FEDORA-2023-ce436d56f8
- FEDORA-2023-ce436d56f8
- FEDORA-2023-514db5339e
- FEDORA-2023-514db5339e
- FEDORA-2023-61abba57d8
- FEDORA-2023-61abba57d8
Modified: 2024-11-21
CVE-2023-41361
An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.
Modified: 2024-11-21
CVE-2023-41909
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
- https://github.com/FRRouting/frr/pull/13222/commits/cfd04dcb3e689754a72507d086ba3b9709fc5ed8
- https://github.com/FRRouting/frr/pull/13222/commits/cfd04dcb3e689754a72507d086ba3b9709fc5ed8
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- FEDORA-2023-ce436d56f8
- FEDORA-2023-ce436d56f8
- FEDORA-2023-514db5339e
- FEDORA-2023-514db5339e
- FEDORA-2023-61abba57d8
- FEDORA-2023-61abba57d8
Modified: 2024-11-21
CVE-2023-46752
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
- https://github.com/FRRouting/frr/pull/14645/commits/b08afc81c60607a4f736f418f2e3eb06087f1a35
- https://github.com/FRRouting/frr/pull/14645/commits/b08afc81c60607a4f736f418f2e3eb06087f1a35
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
Modified: 2024-11-21
CVE-2023-46753
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
- https://github.com/FRRouting/frr/pull/14645/commits/d8482bf011cb2b173e85b65b4bf3d5061250cdb9
- https://github.com/FRRouting/frr/pull/14645/commits/d8482bf011cb2b173e85b65b4bf3d5061250cdb9
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
Modified: 2024-11-21
CVE-2023-47234
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
- https://github.com/FRRouting/frr/pull/14716/commits/c37119df45bbf4ef713bc10475af2ee06e12f3bf
- https://github.com/FRRouting/frr/pull/14716/commits/c37119df45bbf4ef713bc10475af2ee06e12f3bf
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
Modified: 2024-11-21
CVE-2023-47235
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
- https://github.com/FRRouting/frr/pull/14716/commits/6814f2e0138a6ea5e1f83bdd9085d9a77999900b
- https://github.com/FRRouting/frr/pull/14716/commits/6814f2e0138a6ea5e1f83bdd9085d9a77999900b
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
Package make-initrd-bootchain updated to version 0.1.5-alt21 for branch sisyphus_e2k.
Closed bugs
Не закрывает за собой tty2 и tty3
make-initrd-bootchain не завершается корректно
Package gpui updated to version 0.2.41-alt1 for branch sisyphus_e2k.
Closed bugs
Странно отображаются параметры настройки firefox (admx-firefox)
Групповая политика для Mozilla - Firefox - Домашняя страница: название поля URL отображается под полем для ввода
FR | Добавить пункт Изменить в контекстное меню предпочтений
Package python3 updated to version 3.12.2-alt1 for branch sisyphus_e2k.
Closed bugs
unknown encoding: rot13
Package hplip updated to version 3.23.12-alt3 for branch sisyphus_e2k.
Closed bugs
У hplip-gui устаревшая зависимость на python3-module-pygobject
Package neofetch updated to version 7.1.0-alt4 for branch sisyphus_e2k.
Closed bugs
neofetch: huge amount of dependencies