ALT-BU-2025-5243-1
Branch c9f2 update bulletin.
Package xorg-server updated to version 1.20.8-alt13 for branch c9f2 in task 379279.
Closed vulnerabilities
BDU:2020-03915
Уязвимость сервера X Window System Xorg-server, связанная с некорректной инициализацией памяти, позволяющая нарушителю вызвать утечку части серверной памяти для клиента Xorg-server
Modified: 2024-11-21
CVE-2020-14347
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.
- openSUSE-SU-2020:1279
- openSUSE-SU-2020:1279
- openSUSE-SU-2020:1302
- openSUSE-SU-2020:1302
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14347
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14347
- [debian-lts-announce] 20200830 [SECURITY] [DLA 2359-1] xorg-server security update
- [debian-lts-announce] 20200830 [SECURITY] [DLA 2359-1] xorg-server security update
- https://lists.x.org/archives/xorg-announce/2020-July/003051.html
- https://lists.x.org/archives/xorg-announce/2020-July/003051.html
- GLSA-202012-01
- GLSA-202012-01
- USN-4488-1
- USN-4488-1
- USN-4488-2
- USN-4488-2
- DSA-4758
- DSA-4758
- https://www.openwall.com/lists/oss-security/2020/07/31/2
- https://www.openwall.com/lists/oss-security/2020/07/31/2
Closed vulnerabilities
Modified: 2024-11-21
CVE-2024-52522
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.
Closed bugs
rclone 1.61.1
Обновить rclone
Closed vulnerabilities
Modified: 2025-04-07
CVE-2025-31160
atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or possibly have unspecified other impact by running certain types of unprivileged processes while a different user runs atop.
- http://www.openwall.com/lists/oss-security/2025/03/26/3
- http://www.openwall.com/lists/oss-security/2025/03/27/1
- http://www.openwall.com/lists/oss-security/2025/03/27/2
- http://www.openwall.com/lists/oss-security/2025/03/27/3
- http://www.openwall.com/lists/oss-security/2025/03/29/1
- https://blog.bismuth.sh/blog/bismuth-found-the-atop-bug
- https://github.com/Atoptool/atop
- https://lists.debian.org/debian-lts-announce/2025/04/msg00013.html
- https://news.ycombinator.com/item?id=43477057
- https://news.ycombinator.com/item?id=43485980
- https://rachelbythebay.com/w/2025/03/26/atop/