ALT-BU-2024-3661-1
Branch sisyphus_riscv64 update bulletin.
Package salt updated to version 3006.6-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2024-22231
Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.
Modified: 2024-11-21
CVE-2024-22232
A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.
Package python3-module-openssl updated to version 24.0.0-alt1 for branch sisyphus_riscv64.
Closed bugs
support for cryptography 39
Package docs-alt-server updated to version 10.2-alt8 for branch sisyphus_riscv64.
Closed bugs
Опечатка в команде proxmox-backup-manager datastore remove store2
Package xl2tpd updated to version 1.3.18-alt2 for branch sisyphus_riscv64.
Closed bugs
xl2tpd-control не отображает вывод от xl2tpd
pfc не работает по примеру из man
Package alterator-fbi updated to version 5.49.4-alt1 for branch sisyphus_riscv64.
Closed bugs
Cоединение только по протоколу TLS 1.3
Package python3-module-cryptography updated to version 42.0.4-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2025-02-06
CVE-2024-26130
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.
- https://github.com/pyca/cryptography/commit/97d231672763cdb5959a3b191e692a362f1b9e55
- https://github.com/pyca/cryptography/commit/97d231672763cdb5959a3b191e692a362f1b9e55
- https://github.com/pyca/cryptography/pull/10423
- https://github.com/pyca/cryptography/pull/10423
- https://github.com/pyca/cryptography/security/advisories/GHSA-6vqw-3v5j-54x4
- https://github.com/pyca/cryptography/security/advisories/GHSA-6vqw-3v5j-54x4
Package hplip updated to version 3.23.12-alt2 for branch sisyphus_riscv64.
Closed bugs
crashes on start: ConfigParser object has no attribute 'readfp'