ALT-BU-2025-1369-1
Branch sisyphus_e2k update bulletin.
Package NetworkManager-openconnect updated to version 1.2.10-alt2 for branch sisyphus_e2k.
Closed bugs
Unknown username "nm-openconnect" in message bus configuration file в DBus
NetworkManager-openconnect-gtk4 зависит от NetworkManager-applet-gtk
Package libgtk4 updated to version 4.16.7-alt1 for branch sisyphus_e2k.
Closed bugs
allow to avoid include-image-data
Package veyon updated to version 4.9.1-alt1 for branch sisyphus_e2k.
Closed bugs
veyon не запускается с ошибкой CryptoCore: RSA not supported!
Package libgsf updated to version 1.14.53-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2024-08615
Уязвимость библиотеки структурированных файлов GNOME Project G libgsf, связанная с целочисленным переполнением, позволяющая нарушителю выполнить произвольный код
BDU:2024-08625
Уязвимость библиотеки структурированных файлов The GNOME Project libgsf, связанная с переполнением целых чисел на основе динамической памяти, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2024-36474
An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A specially crafted file can result in an integer overflow when processing the directory from the file that allows for an out-of-bounds index to be used when reading and writing to an array. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Modified: 2024-11-21
CVE-2024-42415
An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Package liferea updated to version 1.15.8-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2023-1350
A vulnerability was found in liferea. It has been rated as critical. Affected by this issue is the function update_job_run of the file src/update.c of the component Feed Enrichment. The manipulation of the argument source with the input |date >/tmp/bad-item-link.txt leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 8d8b5b963fa64c7a2122d1bbfbb0bed46e813e59. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-222848.
Package userpasswd updated to version 0.3.6-alt1 for branch sisyphus_e2k.
Closed bugs
Не показывает ошибку при passwd: Weak password
Package exaile updated to version 4.1.3-alt2 for branch sisyphus_e2k.
Closed bugs
Не хватает python3-module-bsddb3
Package parole updated to version 4.18.2-alt1 for branch sisyphus_e2k.
Closed bugs
Не работает функция "Сохранить список воспроизведения" в parole.
Не работает ползунок громкости
Не применяются настройки в Parole
Package phosh-mobile-settings updated to version 0.43.0-alt1 for branch sisyphus_e2k.
Closed bugs
Ломушка трассировки/останова
Package openfortivpn updated to version 1.22.1-alt1 for branch sisyphus_e2k.
Closed bugs
shell error on ip show route
Package dconf-editor updated to version 45.0.1-alt2 for branch sisyphus_e2k.
Closed bugs
Опечатка в русском переводе слова default
Package dnsmasq updated to version 2.90-alt3 for branch sisyphus_e2k.
Closed bugs
Необходимо собрать с dbus для работы SDN выдачи ip адресов для контейнеров и виртуальных машин
Package alterator-auth updated to version 0.44.11-alt1 for branch sisyphus_e2k.
Closed bugs
system-auth - На пробелах в OU падает, версию показать не может
Package gpupdate updated to version 0.12.2-alt1 for branch sisyphus_e2k.
Closed bugs
Error creating environment variables при применении политики Обои рабочего стола
Неправильно работают политики Thunderbird
Package neatvnc updated to version 0.8.1-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2024-06275
Уязвимость файла server.c серверной библиотеки для удалённого доступа к компьютерам Neat VNC, позволяющая нарушителю обойти существующие ограничения безопасности
Modified: 2024-09-05
CVE-2024-42458
server.c in Neat VNC (aka neatvnc) before 0.8.1 does not properly validate the security type, a related issue to CVE-2006-2369.
- https://github.com/any1/neatvnc/commit/cc71650a69abc2573a0d96d082409d2468802d47
- https://github.com/any1/neatvnc/compare/v0.8.0...v0.8.1
- https://github.com/any1/neatvnc/releases/tag/v0.8.1
- https://www.openwall.com/lists/oss-security/2024/08/02/1
- https://www.openwall.com/lists/oss-security/2024/08/02/10
- https://www.openwall.com/lists/oss-security/2024/08/02/7
Package perl-Glib-Object-Introspection updated to version 0.051-alt4 for branch sisyphus_e2k.
Closed bugs
perl-Glib-Object-Introspection: FTBFS
Package cheese updated to version 44.1-alt1.2 for branch sisyphus_e2k.
Closed bugs
cheese: Падает вместо того, чтобы работать
Package libgtk+2 updated to version 2.24.33-alt2 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2024-06447
Уязвимость библиотеки для создания графических пользовательских интерфейсов GTK (GIMP Toolkit), связанная с неверным управлением генерацией кода, позволяющая нарушителю повысить свои привилегии
Modified: 2025-03-14
CVE-2024-6655
A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory.
- http://www.openwall.com/lists/oss-security/2024/09/09/1
- RHSA-2024:6963
- RHSA-2024:9184
- https://access.redhat.com/security/cve/CVE-2024-6655
- https://access.redhat.com/security/cve/CVE-2024-6655
- RHBZ#2297098
- RHBZ#2297098
- https://gitlab.gnome.org/GNOME/gtk/-/merge_requests/7361/diffs?commit_id=3bbf0b6176d42836d23c36a6ac410e807ec0a7a7#diff-content-e3fbe6480add9420b69f82374fb26ccac2c015a0
- https://gitlab.gnome.org/GNOME/gtk/-/merge_requests/7361/diffs?commit_id=3bbf0b6176d42836d23c36a6ac410e807ec0a7a7#diff-content-e3fbe6480add9420b69f82374fb26ccac2c015a0
- https://www.openwall.com/lists/oss-security/2024/09/09/1
Package alt-csp-cryptopro updated to version 0.3.3-alt1 for branch sisyphus_e2k.
Closed bugs
При массовом подписании не создается присоединенная подпись
Package python3-module-pygobject3 updated to version 3.50.0-alt2 for branch sisyphus_e2k.
Closed bugs
Вытягивает libcairo
Package libaccounts-glib updated to version 1.27-alt1 for branch sisyphus_e2k.
Closed bugs
Устарел, есть 1.27