Errata ALT-PU-2018-1735-1: Information
Fixes
Published: May 26, 2016
BDU:2016-01470
Уязвимость библиотеки парсинга Expat, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Severity: HIGH (7.5)
Links:
Published: June 30, 2016
BDU:2016-01683
Уязвимость библиотеки Expat, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Severity: MEDIUM (6.8)
Links:
Published: June 25, 2017
BDU:2018-00112
Уязвимость функции entityValueInitProcessor библиотеки для анализа XML-файлов libexpat, позволяющая нарушителю вызвать отказ в обслуживании
Severity: HIGH (7.5) Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Links:
Published: Aug. 31, 2016
BDU:2021-03140
Уязвимость алгоритмов шифрования DES и Triple DES, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Severity: HIGH (7.5) Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Links:
Published: July 23, 2015
Modified: Nov. 7, 2023
Modified: Nov. 7, 2023
CVE-2015-1283
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
Severity: MEDIUM (6.8)
Links:
- https://www.tenable.com/security/tns-2016-20
- RHSA-2015:1499
- https://code.google.com/p/chromium/issues/detail?id=492052
- openSUSE-SU-2016:1523
- openSUSE-SU-2015:1287
- 1033031
- DSA-3318
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- SUSE-SU-2016:1508
- GLSA-201701-21
- https://source.android.com/security/bulletin/2016-11-01.html
- GLSA-201603-09
- SUSE-SU-2016:1512
- https://codereview.chromium.org/1224303003
- 75973
- http://googlechromereleases.blogspot.com/2015/07/stable-channel-update_21.html
- USN-2726-1
- openSUSE-SU-2016:1441
- DSA-3315
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365
Published: May 26, 2016
Modified: Feb. 13, 2023
Modified: Feb. 13, 2023
CVE-2016-0718
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Links:
- [oss-security] 20160517 CVE-2016-0718: Expat XML Parser Crashes on Malformed Input
- https://bugzilla.redhat.com/show_bug.cgi?id=1296102
- DSA-3582
- USN-2983-1
- SUSE-SU-2016:1508
- SUSE-SU-2016:1512
- openSUSE-SU-2016:1523
- APPLE-SA-2016-07-18-1
- https://support.apple.com/HT206903
- https://bugzilla.mozilla.org/show_bug.cgi?id=1236923
- http://www.mozilla.org/security/announce/2016/mfsa2016-68.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- USN-3044-1
- openSUSE-SU-2016:2026
- openSUSE-SU-2016:1964
- 90729
- https://source.android.com/security/bulletin/2016-11-01.html
- openSUSE-SU-2016:1441
- http://support.eset.com/ca6333/
- 20170227 CVE-2016-9892 - Remote Code Execution as Root via ESET Endpoint Antivirus 6
- http://packetstormsecurity.com/files/141350/ESET-Endpoint-Antivirus-6-Remote-Code-Execution.html
- GLSA-201701-21
- 1037705
- 1036415
- 1036348
- https://www.tenable.com/security/tns-2016-20
- RHSA-2016:2824
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- RHSA-2018:2486
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365
Published: Sept. 2, 2016
Modified: Feb. 9, 2019
Modified: Feb. 9, 2019
CVE-2016-0772
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."
Severity: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Links:
- [oss-security] 20160614 Python CVE-2016-0772: smtplib StartTLS stripping attack
- https://hg.python.org/cpython/rev/b3ce713fb9be
- https://bugzilla.redhat.com/show_bug.cgi?id=1303647
- https://docs.python.org/3.4/whatsnew/changelog.html#python-3-4-5
- https://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-2
- https://hg.python.org/cpython/raw-file/v2.7.12/Misc/NEWS
- https://hg.python.org/cpython/rev/d590114c2394
- 91225
- http://www.splunk.com/view/SP-CAAAPUE
- http://www.splunk.com/view/SP-CAAAPSV
- GLSA-201701-18
- RHSA-2016:1630
- RHSA-2016:1629
- RHSA-2016:1628
- RHSA-2016:1627
- RHSA-2016:1626
- [debian-lts-announce] 20190207 [SECURITY] [DLA 1663-1] python3.4 security update
- openSUSE-SU-2020:0086
Published: Nov. 27, 2019
Modified: Nov. 7, 2023
Modified: Nov. 7, 2023
CVE-2016-1000110
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
Severity: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Links:
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000110
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2016-1000110
- https://security-tracker.debian.org/tracker/CVE-2016-1000110
- openSUSE-SU-2020:0086
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7K3WFJO3SJQCODKRKU6EQV3ZGHH53YPU/
Published: Sept. 1, 2016
Modified: Feb. 13, 2023
Modified: Feb. 13, 2023
CVE-2016-2183
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Links:
- https://bugzilla.redhat.com/show_bug.cgi?id=1369383
- https://www.openssl.org/blog/blog/2016/08/24/sweet32/
- https://access.redhat.com/articles/2548661
- [tls] 20091120 RC4+3DES rekeying - long-lived TLS connections
- https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2016/august/new-practical-attacks-on-64-bit-block-ciphers-3des-blowfish/
- https://github.com/ssllabs/ssllabs-scan/issues/387#issuecomment-242514633
- https://blog.cryptographyengineering.com/2016/08/24/attack-of-week-64-bit-ciphers-in-tls/
- https://www.sigsac.org/ccs/CCS2016/accepted-papers/
- https://www.teskalabs.com/blog/teskalabs-bulletin-160826-seacat-sweet32-issue
- https://access.redhat.com/security/cve/cve-2016-2183
- https://nakedsecurity.sophos.com/2016/08/25/anatomy-of-a-cryptographic-collision-the-sweet32-attack/
- https://sweet32.info/
- SUSE-SU-2016:2470
- https://nodejs.org/en/blog/vulnerability/september-2016-security-releases/
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05302448
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05309984
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05323116
- 92630
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05349499
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388
- http://www.splunk.com/view/SP-CAAAPUE
- http://www.splunk.com/view/SP-CAAAPSV
- GLSA-201612-16
- https://kc.mcafee.com/corporate/index?page=content&id=SB10171
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40312
- https://bto.bluecoat.com/security-advisory/sa133
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369403
- 95568
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369415
- https://www.tenable.com/security/tns-2016-16
- http://www-01.ibm.com/support/docview.wss?uid=swg21995039
- http://www-01.ibm.com/support/docview.wss?uid=swg21991482
- http://www-01.ibm.com/support/docview.wss?uid=nas8N1021697
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680
- GLSA-201701-65
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390849
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03725en_us
- GLSA-201707-01
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03765en_us
- 1036696
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- https://www.tenable.com/security/tns-2017-09
- https://www.tenable.com/security/tns-2016-21
- https://www.tenable.com/security/tns-2016-20
- https://security.netapp.com/advisory/ntap-20170119-0001/
- https://security.netapp.com/advisory/ntap-20160915-0001/
- RHSA-2017:3240
- RHSA-2017:3239
- RHSA-2017:3114
- RHSA-2017:3113
- RHSA-2017:2710
- RHSA-2017:2709
- RHSA-2017:2708
- RHSA-2017:1216
- RHSA-2017:0462
- RHSA-2017:0338
- RHSA-2017:0337
- RHSA-2017:0336
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- RHSA-2018:2123
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-17-0008
- RHSA-2019:1245
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- RHSA-2019:2859
- https://www.oracle.com/security-alerts/cpujan2020.html
- RHSA-2020:0451
- https://kc.mcafee.com/corporate/index?page=content&id=SB10310
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- USN-3270-1
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05369415
- SUSE-SU-2017:0490
- 20170329 [security bulletin] HPESBUX03725 rev.1 - HPE HP-UX Web Server Suite running Apache, Multiple Vulnerabilities
- SUSE-SU-2017:0346
- 20181113 [security bulletin] MFSBGN03831 rev. - Service Management Automation, remote disclosure of information
- SUSE-SU-2017:2699
- openSUSE-SU-2016:2537
- https://www.arista.com/en/support/advisories-notices/security-advisories/1749-security-advisory-24
- USN-3372-1
- SUSE-SU-2016:2469
- 20170529 SSD Advisory - IBM Informix Dynamic Server and Informix Open Admin Tool Multiple Vulnerabilities
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05385680
- https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158613
- https://wiki.opendaylight.org/view/Security_Advisories
- USN-3087-2
- 20180510 [security bulletin] MFSBGN03805 - HP Service Manager, Remote Disclosure of Information
- openSUSE-SU-2017:0374
- SUSE-SU-2016:2468
- USN-3087-1
- openSUSE-SU-2016:2407
- USN-3194-1
- USN-3179-1
- USN-3198-1
- 20170717 Orion Elite Hidden IP Browser Pro - All Versions - Multiple Known Vulnerabilities
- openSUSE-SU-2016:2496
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05369403
- openSUSE-SU-2017:0513
- SUSE-SU-2016:2387
- 20170831 [security bulletin] HPESBGN03765 rev.2 - HPE LoadRunner and HPE Performance Center, Remote Disclosure of Information
- 20161207 [security bulletin] HPSBHF03674 rev.1 HPE Comware 5 and Comware 7 Network Products using SSL/TLS, Remote Disclosure of Information
- SUSE-SU-2017:0460
- https://kc.mcafee.com/corporate/index?page=content&id=SB10215
- 20161207 [security bulletin] HPSBHF03674 rev.1 HPE Comware 5 and Comware 7 Network Products using SSL/TLS, Remote Disclosure of Information
- SUSE-SU-2016:2458
- 20180510 [security bulletin] MFSBGN03805 - HP Service Manager, Remote Disclosure of Information
- https://support.f5.com/csp/article/K13167034
- 42091
- 20170214 [security bulletin] HPESBGN03697 rev.1 - HPE Business Service Management (BSM), Remote Disclosure of Information
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05390849
- DSA-3673
- SUSE-SU-2016:2394
- 20170831 [security bulletin] HPESBGN03765 rev.2 - HPE LoadRunner and HPE Performance Center, Remote Disclosure of Information
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05390722
- https://kc.mcafee.com/corporate/index?page=content&id=SB10186
- http://packetstormsecurity.com/files/142756/IBM-Informix-Dynamic-Server-DLL-Injection-Code-Execution.html
- openSUSE-SU-2018:0458
- https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03286178
- openSUSE-SU-2016:2391
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170322-01-openssl-en
- https://kc.mcafee.com/corporate/index?page=content&id=SB10197
- SUSE-SU-2017:1444
- SUSE-SU-2017:2700
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05302448
- 20170329 [security bulletin] HPESBUX03725 rev.1 - HPE HP-UX Web Server Suite running Apache, Multiple Vulnerabilities
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
Published: June 30, 2016
Modified: Nov. 7, 2023
Modified: Nov. 7, 2023
CVE-2016-4472
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
Severity: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Links:
Published: Sept. 2, 2016
Modified: Feb. 9, 2019
Modified: Feb. 9, 2019
CVE-2016-5636
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.
Severity: CRITICAL (9.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Links:
- [oss-security] 20160616 Re: CVE Request: heap overflow in Python zipimport module
- https://docs.python.org/3.4/whatsnew/changelog.html#python-3-4-5
- https://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-2
- [oss-security] 20160615 CVE Request: heap overflow in Python zipimport module
- https://hg.python.org/cpython/raw-file/v2.7.12/Misc/NEWS
- https://bugs.python.org/issue26171
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91247
- http://www.splunk.com/view/SP-CAAAPUE
- http://www.splunk.com/view/SP-CAAAPSV
- GLSA-201701-18
- 1038138
- RHSA-2016:2586
- [debian-lts-announce] 20190207 [SECURITY] [DLA 1663-1] python3.4 security update
- openSUSE-SU-2020:0086
Published: June 12, 2018
Modified: June 27, 2022
Modified: June 27, 2022
CVE-2016-9063
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Links:
Published: July 25, 2017
Modified: Nov. 7, 2023
Modified: Nov. 7, 2023
CVE-2017-9233
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Links:
- https://libexpat.github.io/doc/cve-2017-9233/
- https://github.com/libexpat/libexpat/blob/master/expat/Changes
- [oss-security] 20170618 Expat 2.2.1 security fixes
- 99276
- 1039427
- https://support.apple.com/HT208144
- https://support.apple.com/HT208115
- https://support.apple.com/HT208113
- https://support.apple.com/HT208112
- DSA-3898
- https://support.f5.com/csp/article/K03244804
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8