ALT-PU-2024-1165-3
Closed vulnerabilities
Published: 2020-11-06
BDU:2021-03499
Уязвимость компонента raptor_xml_writer_start_element_common библиотеки на Си Raptor, связанная с записью за границами буфера, позволяющая нарушителю нарушить целостность данных или вызвать отказ в обслуживании
Severity: HIGH (7.1)
Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Severity: HIGH (8.5)
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:C
References:
Published: 2021-05-13
BDU:2022-05307
Уязвимость функции raptor_xml_writer_start_element_common библиотеки Raptor, позволяющая нарушителю выполнить произвольный код
Severity: MEDIUM (6.5)
Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity: MEDIUM (6.8)
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C
References:
Published: 2020-11-06
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-18926
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).
Severity: MEDIUM (5.8)
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P
Severity: HIGH (7.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
References:
- http://www.openwall.com/lists/oss-security/2020/11/13/1
- http://www.openwall.com/lists/oss-security/2020/11/13/2
- http://www.openwall.com/lists/oss-security/2020/11/14/2
- http://www.openwall.com/lists/oss-security/2020/11/16/2
- http://www.openwall.com/lists/oss-security/2020/11/16/3
- https://github.com/LibreOffice/core/blob/master/external/redland/raptor/0001-Calcualte-max-nspace-declarations-correctly-for-XML-.patch.1
- https://lists.debian.org/debian-lts-announce/2020/11/msg00012.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RD67AVORGQXORPWNYYUHCH6YPPT6CI4O/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVHFYQDMVEBICIL4DBAGRRLPUR4QYWMV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDZRNM45VPTQF2BKRWG4YRCHJGQ2L7NS/
- https://www.debian.org/security/2020/dsa-4785
- https://www.openwall.com/lists/oss-security/2017/06/07/1
- http://www.openwall.com/lists/oss-security/2020/11/13/1
- http://www.openwall.com/lists/oss-security/2020/11/13/2
- http://www.openwall.com/lists/oss-security/2020/11/14/2
- http://www.openwall.com/lists/oss-security/2020/11/16/2
- http://www.openwall.com/lists/oss-security/2020/11/16/3
- https://github.com/LibreOffice/core/blob/master/external/redland/raptor/0001-Calcualte-max-nspace-declarations-correctly-for-XML-.patch.1
- https://lists.debian.org/debian-lts-announce/2020/11/msg00012.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RD67AVORGQXORPWNYYUHCH6YPPT6CI4O/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVHFYQDMVEBICIL4DBAGRRLPUR4QYWMV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDZRNM45VPTQF2BKRWG4YRCHJGQ2L7NS/
- https://www.debian.org/security/2020/dsa-4785
- https://www.openwall.com/lists/oss-security/2017/06/07/1
Published: 2021-05-13
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-25713
A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.
Severity: MEDIUM (4.0)
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P
Severity: MEDIUM (6.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References:
- http://www.openwall.com/lists/oss-security/2020/11/16/1
- https://bugs.librdf.org/mantis/view.php?id=650
- https://bugzilla.redhat.com/show_bug.cgi?id=1900685
- https://lists.debian.org/debian-lts-announce/2021/12/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27EQ2JCVMKG3EYTBYO4642P773I2NYUV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SUIND56AOKEHHBE4OYV57M73LLOLJRLV/
- http://www.openwall.com/lists/oss-security/2020/11/16/1
- https://bugs.librdf.org/mantis/view.php?id=650
- https://bugzilla.redhat.com/show_bug.cgi?id=1900685
- https://lists.debian.org/debian-lts-announce/2021/12/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27EQ2JCVMKG3EYTBYO4642P773I2NYUV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SUIND56AOKEHHBE4OYV57M73LLOLJRLV/
Closed bugs
FTBFS с 16 декабря