ALT-BU-2024-4298-1
Branch sisyphus_loongarch64 update bulletin.
Package avahi updated to version 0.8-alt3 for branch sisyphus_loongarch64.
Closed vulnerabilities
BDU:2023-08473
Уязвимость функции avahi_rdata_parse() системы обнаружения сервисов в локальной сети Avahi, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2023-38469
A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.
Modified: 2024-11-21
CVE-2023-38470
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.
Modified: 2024-11-21
CVE-2023-38471
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
Modified: 2024-11-21
CVE-2023-38472
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.
Modified: 2024-11-21
CVE-2023-38473
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.
Package lua5.4 updated to version 5.4.6-alt1.0.port for branch sisyphus_loongarch64.
Closed vulnerabilities
BDU:2022-04620
Уязвимость реализации функции singlevar() интерпретатора скриптов Lua, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2022-28805
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
- https://github.com/lua/lua/commit/1f3c6f4534c6411313361697d98d1145a1f030fa
- https://github.com/lua/lua/commit/1f3c6f4534c6411313361697d98d1145a1f030fa
- FEDORA-2022-b9ed35a7ad
- FEDORA-2022-b9ed35a7ad
- FEDORA-2022-5b5889f43a
- FEDORA-2022-5b5889f43a
- https://lua-users.org/lists/lua-l/2022-02/msg00001.html
- https://lua-users.org/lists/lua-l/2022-02/msg00001.html
- https://lua-users.org/lists/lua-l/2022-02/msg00070.html
- https://lua-users.org/lists/lua-l/2022-02/msg00070.html
- https://lua-users.org/lists/lua-l/2022-04/msg00009.html
- https://lua-users.org/lists/lua-l/2022-04/msg00009.html
- GLSA-202305-23
- GLSA-202305-23
Modified: 2024-11-21
CVE-2022-33099
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
- https://github.com/lua/lua/commit/42d40581dd919fb134c07027ca1ce0844c670daf
- https://github.com/lua/lua/commit/42d40581dd919fb134c07027ca1ce0844c670daf
- FEDORA-2022-b9ed35a7ad
- FEDORA-2022-b9ed35a7ad
- FEDORA-2022-5b5889f43a
- FEDORA-2022-5b5889f43a
- https://lua-users.org/lists/lua-l/2022-05/msg00035.html
- https://lua-users.org/lists/lua-l/2022-05/msg00035.html
- https://lua-users.org/lists/lua-l/2022-05/msg00042.html
- https://lua-users.org/lists/lua-l/2022-05/msg00042.html
- https://lua-users.org/lists/lua-l/2022-05/msg00073.html
- https://lua-users.org/lists/lua-l/2022-05/msg00073.html
- https://www.lua.org/bugs.html#Lua-stack%20overflow%20when%20C%20stack%20overflows%20while%20handling%20an%20error:~:text=Lua-stack%20overflow%20when%20C%20stack%20overflows%20while%20handling%20an%20error
- https://www.lua.org/bugs.html#Lua-stack%20overflow%20when%20C%20stack%20overflows%20while%20handling%20an%20error:~:text=Lua-stack%20overflow%20when%20C%20stack%20overflows%20while%20handling%20an%20error
Package phosh updated to version 0.37.0-alt1.2 for branch sisyphus_loongarch64.
Closed bugs
phosh: сломался запуск с переходом на gnome-session-46