Vulnerabilities |
765 via 765 paths |
---|---|
Dependencies |
180 |
Source |
Docker |
Target OS |
centos:8 |
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-4.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-4.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-25235
- https://access.redhat.com/errata/RHSA-2022:0951
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/
- http://www.openwall.com/lists/oss-security/2022/02/19/1
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/562
- https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/
- https://security.gentoo.org/glsa/202209-24
- https://security.netapp.com/advisory/ntap-20220303-0008/
- https://www.debian.org/security/2022/dsa-5085
- https://www.oracle.com/security-alerts/cpuapr2022.html
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-4.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-4.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-25236
- https://access.redhat.com/errata/RHSA-2022:0951
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/
- http://packetstormsecurity.com/files/167238/Zoom-XMPP-Stanza-Smuggling-Remote-Code-Execution.html
- http://www.openwall.com/lists/oss-security/2022/02/19/1
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/561
- https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/
- https://security.gentoo.org/glsa/202209-24
- https://security.netapp.com/advisory/ntap-20220303-0008/
- https://www.debian.org/security/2022/dsa-5085
- https://www.oracle.com/security-alerts/cpuapr2022.html
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-4.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-4.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-22823
- https://access.redhat.com/errata/RHSA-2022:0951
- http://www.openwall.com/lists/oss-security/2022/01/17/3
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/539
- https://security.gentoo.org/glsa/202209-24
- https://www.debian.org/security/2022/dsa-5073
- https://www.tenable.com/security/tns-2022-05
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-4.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-4.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-22822
- https://access.redhat.com/errata/RHSA-2022:0951
- http://www.openwall.com/lists/oss-security/2022/01/17/3
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/539
- https://security.gentoo.org/glsa/202209-24
- https://www.debian.org/security/2022/dsa-5073
- https://www.tenable.com/security/tns-2022-05
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-4.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-4.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-23852
- https://access.redhat.com/errata/RHSA-2022:0951
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/550
- https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html
- https://security.gentoo.org/glsa/202209-24
- https://security.netapp.com/advisory/ntap-20220217-0001/
- https://www.debian.org/security/2022/dsa-5073
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.tenable.com/security/tns-2022-05
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-4.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-4.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-22824
- https://access.redhat.com/errata/RHSA-2022:0951
- http://www.openwall.com/lists/oss-security/2022/01/17/3
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/539
- https://security.gentoo.org/glsa/202209-24
- https://www.debian.org/security/2022/dsa-5073
- https://www.tenable.com/security/tns-2022-05
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-4.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-4.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-25315
- https://access.redhat.com/errata/RHSA-2022:0951
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/
- http://www.openwall.com/lists/oss-security/2022/02/19/1
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/559
- https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/
- https://security.gentoo.org/glsa/202209-24
- https://security.netapp.com/advisory/ntap-20220303-0008/
- https://www.debian.org/security/2022/dsa-5085
- https://www.oracle.com/security-alerts/cpuapr2022.html
high severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-10.el8_4
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-10.el8_4 or higher.
References
- https://security.netapp.com/advisory/ntap-20210319-0004/
- https://access.redhat.com/security/cve/CVE-2021-27219
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2REA7RVKN7ZHRLJOEGBRQKJIPZQPAELZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JJMPNDO4GDVURYQFYKFOWY5HAF4FTEPN/
- https://gitlab.gnome.org/GNOME/glib/-/issues/2319
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E
- https://access.redhat.com/errata/RHSA-2021:2170
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2022/06/msg00006.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2REA7RVKN7ZHRLJOEGBRQKJIPZQPAELZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JJMPNDO4GDVURYQFYKFOWY5HAF4FTEPN/
- https://security.gentoo.org/glsa/202107-13
high severity
- Vulnerable module: systemd
- Introduced through: systemd@239-45.el8
- Fixed in: 0:239-58.el8_6.4
Detailed paths
-
Introduced through: centos@centos8 › systemd@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd
package and not the systemd
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.
Remediation
Upgrade Centos:8
systemd
to version 0:239-58.el8_6.4 or higher.
References
high severity
- Vulnerable module: systemd-libs
- Introduced through: systemd-libs@239-45.el8
- Fixed in: 0:239-58.el8_6.4
Detailed paths
-
Introduced through: centos@centos8 › systemd-libs@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-libs
package and not the systemd-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.
Remediation
Upgrade Centos:8
systemd-libs
to version 0:239-58.el8_6.4 or higher.
References
high severity
- Vulnerable module: systemd-pam
- Introduced through: systemd-pam@239-45.el8
- Fixed in: 0:239-58.el8_6.4
Detailed paths
-
Introduced through: centos@centos8 › systemd-pam@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-pam
package and not the systemd-pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.
Remediation
Upgrade Centos:8
systemd-pam
to version 0:239-58.el8_6.4 or higher.
References
high severity
- Vulnerable module: systemd-udev
- Introduced through: systemd-udev@239-45.el8
- Fixed in: 0:239-58.el8_6.4
Detailed paths
-
Introduced through: centos@centos8 › systemd-udev@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-udev
package and not the systemd-udev
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.
Remediation
Upgrade Centos:8
systemd-udev
to version 0:239-58.el8_6.4 or higher.
References
high severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-21.el8_10.1
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-21.el8_10.1 or higher.
References
high severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-21.el8_10.1
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-21.el8_10.1 or higher.
References
high severity
- Vulnerable module: krb5-libs
- Introduced through: krb5-libs@1.18.2-8.el8
- Fixed in: 0:1.18.2-30.el8_10
Detailed paths
-
Introduced through: centos@centos8 › krb5-libs@1.18.2-8.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream krb5-libs
package and not the krb5-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
Remediation
Upgrade Centos:8
krb5-libs
to version 0:1.18.2-30.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-3596
- https://www.kb.cert.org/vuls/id/456537
- https://security.netapp.com/advisory/ntap-20240822-0001/
- https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocol
- https://cert-portal.siemens.com/productcert/html/ssa-723487.html
- https://cert-portal.siemens.com/productcert/html/ssa-794185.html
- http://www.openwall.com/lists/oss-security/2024/07/09/4
- https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/
- https://datatracker.ietf.org/doc/html/rfc2865
- https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014
- https://www.blastradius.fail/
high severity
- Vulnerable module: cyrus-sasl-lib
- Introduced through: cyrus-sasl-lib@2.1.27-5.el8
- Fixed in: 0:2.1.27-6.el8_5
Detailed paths
-
Introduced through: centos@centos8 › cyrus-sasl-lib@2.1.27-5.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream cyrus-sasl-lib
package and not the cyrus-sasl-lib
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
Remediation
Upgrade Centos:8
cyrus-sasl-lib
to version 0:2.1.27-6.el8_5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-24407
- https://access.redhat.com/errata/RHSA-2022:0658
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4FIXU75Q6RBNK6UYM7MQ3TCFGXR7AX4U/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H26R4SMGM3WHXX4XYNNJB4YGFIL5UNF4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZZC6BMPI3V3MC2IGNLN377ETUWO7QBIH/
- http://www.openwall.com/lists/oss-security/2022/02/23/4
- https://github.com/cyrusimap/cyrus-sasl/blob/fdcd13ceaef8de684dc69008011fa865c5b4a3ac/docsrc/sasl/release-notes/2.1/index.rst
- https://lists.debian.org/debian-lts-announce/2022/03/msg00002.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4FIXU75Q6RBNK6UYM7MQ3TCFGXR7AX4U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H26R4SMGM3WHXX4XYNNJB4YGFIL5UNF4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZC6BMPI3V3MC2IGNLN377ETUWO7QBIH/
- https://security.netapp.com/advisory/ntap-20221007-0003/
- https://www.cyrusimap.org/sasl/sasl/release-notes/2.1/index.html#new-in-2-1-28
- https://www.debian.org/security/2022/dsa-5087
- https://www.oracle.com/security-alerts/cpujul2022.html
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-4.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-4.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-45960
- https://access.redhat.com/errata/RHSA-2022:0951
- http://www.openwall.com/lists/oss-security/2022/01/17/3
- https://bugzilla.mozilla.org/show_bug.cgi?id=1217609
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/issues/531
- https://github.com/libexpat/libexpat/pull/534
- https://security.gentoo.org/glsa/202209-24
- https://security.netapp.com/advisory/ntap-20220121-0004/
- https://www.debian.org/security/2022/dsa-5073
- https://www.tenable.com/security/tns-2022-05
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-4.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-4.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-22826
- https://access.redhat.com/errata/RHSA-2022:0951
- http://www.openwall.com/lists/oss-security/2022/01/17/3
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/539
- https://security.gentoo.org/glsa/202209-24
- https://www.debian.org/security/2022/dsa-5073
- https://www.tenable.com/security/tns-2022-05
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-4.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-4.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-22825
- https://access.redhat.com/errata/RHSA-2022:0951
- http://www.openwall.com/lists/oss-security/2022/01/17/3
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/539
- https://security.gentoo.org/glsa/202209-24
- https://www.debian.org/security/2022/dsa-5073
- https://www.tenable.com/security/tns-2022-05
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-4.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-4.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-22827
- https://access.redhat.com/errata/RHSA-2022:0951
- http://www.openwall.com/lists/oss-security/2022/01/17/3
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/539
- https://security.gentoo.org/glsa/202209-24
- https://www.debian.org/security/2022/dsa-5073
- https://www.tenable.com/security/tns-2022-05
high severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.1
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-251.el8_10.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-2961
- https://www.ambionics.io/blog/iconv-cve-2024-2961-p1
- https://www.ambionics.io/blog/iconv-cve-2024-2961-p2
- https://www.ambionics.io/blog/iconv-cve-2024-2961-p3
- http://www.openwall.com/lists/oss-security/2024/04/17/9
- http://www.openwall.com/lists/oss-security/2024/04/18/4
- http://www.openwall.com/lists/oss-security/2024/04/24/2
- http://www.openwall.com/lists/oss-security/2024/05/27/1
- http://www.openwall.com/lists/oss-security/2024/05/27/2
- http://www.openwall.com/lists/oss-security/2024/05/27/3
- http://www.openwall.com/lists/oss-security/2024/05/27/4
- http://www.openwall.com/lists/oss-security/2024/05/27/5
- http://www.openwall.com/lists/oss-security/2024/05/27/6
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/
- https://security.netapp.com/advisory/ntap-20240531-0002/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004
- https://github.com/ambionics/cnext-exploits
- https://github.com/projectdiscovery/nuclei-templates/blob/main/dast/cves/2024/CVE-2024-2961.yaml
high severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.1
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-251.el8_10.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-2961
- https://www.ambionics.io/blog/iconv-cve-2024-2961-p1
- https://www.ambionics.io/blog/iconv-cve-2024-2961-p2
- https://www.ambionics.io/blog/iconv-cve-2024-2961-p3
- http://www.openwall.com/lists/oss-security/2024/04/17/9
- http://www.openwall.com/lists/oss-security/2024/04/18/4
- http://www.openwall.com/lists/oss-security/2024/04/24/2
- http://www.openwall.com/lists/oss-security/2024/05/27/1
- http://www.openwall.com/lists/oss-security/2024/05/27/2
- http://www.openwall.com/lists/oss-security/2024/05/27/3
- http://www.openwall.com/lists/oss-security/2024/05/27/4
- http://www.openwall.com/lists/oss-security/2024/05/27/5
- http://www.openwall.com/lists/oss-security/2024/05/27/6
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/
- https://security.netapp.com/advisory/ntap-20240531-0002/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004
- https://github.com/ambionics/cnext-exploits
- https://github.com/projectdiscovery/nuclei-templates/blob/main/dast/cves/2024/CVE-2024-2961.yaml
high severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.1
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-251.el8_10.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-2961
- https://www.ambionics.io/blog/iconv-cve-2024-2961-p1
- https://www.ambionics.io/blog/iconv-cve-2024-2961-p2
- https://www.ambionics.io/blog/iconv-cve-2024-2961-p3
- http://www.openwall.com/lists/oss-security/2024/04/17/9
- http://www.openwall.com/lists/oss-security/2024/04/18/4
- http://www.openwall.com/lists/oss-security/2024/04/24/2
- http://www.openwall.com/lists/oss-security/2024/05/27/1
- http://www.openwall.com/lists/oss-security/2024/05/27/2
- http://www.openwall.com/lists/oss-security/2024/05/27/3
- http://www.openwall.com/lists/oss-security/2024/05/27/4
- http://www.openwall.com/lists/oss-security/2024/05/27/5
- http://www.openwall.com/lists/oss-security/2024/05/27/6
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/
- https://security.netapp.com/advisory/ntap-20240531-0002/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004
- https://github.com/ambionics/cnext-exploits
- https://github.com/projectdiscovery/nuclei-templates/blob/main/dast/cves/2024/CVE-2024-2961.yaml
high severity
- Vulnerable module: gzip
- Introduced through: gzip@1.9-12.el8
- Fixed in: 0:1.9-13.el8_5
Detailed paths
-
Introduced through: centos@centos8 › gzip@1.9-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream gzip
package and not the gzip
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
Remediation
Upgrade Centos:8
gzip
to version 0:1.9-13.el8_5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-1271
- https://access.redhat.com/errata/RHSA-2022:1537
- https://git.tukaani.org/?p=xz.git;a=commit;h=69d1b3fc29677af8ade8dc15dba83f0589cb63d6
- https://bugzilla.redhat.com/show_bug.cgi?id=2073310
- https://git.tukaani.org/?p=xz.git%3Ba=commit%3Bh=69d1b3fc29677af8ade8dc15dba83f0589cb63d6
- https://lists.gnu.org/r/bug-gzip/2022-04/msg00011.html
- https://security-tracker.debian.org/tracker/CVE-2022-1271
- https://security.gentoo.org/glsa/202209-01
- https://security.netapp.com/advisory/ntap-20220930-0006/
- https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch
- https://www.openwall.com/lists/oss-security/2022/04/07/8
high severity
- Vulnerable module: krb5-libs
- Introduced through: krb5-libs@1.18.2-8.el8
- Fixed in: 0:1.18.2-22.el8_7
Detailed paths
-
Introduced through: centos@centos8 › krb5-libs@1.18.2-8.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream krb5-libs
package and not the krb5-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."
Remediation
Upgrade Centos:8
krb5-libs
to version 0:1.18.2-22.el8_7 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42898
- https://access.redhat.com/errata/RHSA-2022:8638
- https://bugzilla.samba.org/show_bug.cgi?id=15203
- https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c
- https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583
- https://security.gentoo.org/glsa/202309-06
- https://security.gentoo.org/glsa/202310-06
- https://security.netapp.com/advisory/ntap-20230216-0008/
- https://security.netapp.com/advisory/ntap-20230223-0001/
- https://web.mit.edu/kerberos/advisories/
- https://web.mit.edu/kerberos/krb5-1.19/
- https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt
- https://www.samba.org/samba/security/CVE-2022-42898.html
high severity
- Vulnerable module: platform-python-setuptools
- Introduced through: platform-python-setuptools@39.2.0-6.el8
- Fixed in: 0:39.2.0-8.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python-setuptools@39.2.0-6.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python-setuptools
package and not the platform-python-setuptools
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.
Remediation
Upgrade Centos:8
platform-python-setuptools
to version 0:39.2.0-8.el8_10 or higher.
References
high severity
- Vulnerable module: python3-setuptools-wheel
- Introduced through: python3-setuptools-wheel@39.2.0-6.el8
- Fixed in: 0:39.2.0-8.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-setuptools-wheel@39.2.0-6.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-setuptools-wheel
package and not the python3-setuptools-wheel
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.
Remediation
Upgrade Centos:8
python3-setuptools-wheel
to version 0:39.2.0-8.el8_10 or higher.
References
high severity
- Vulnerable module: xz
- Introduced through: xz@5.2.4-3.el8
- Fixed in: 0:5.2.4-4.el8_6
Detailed paths
-
Introduced through: centos@centos8 › xz@5.2.4-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream xz
package and not the xz
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
Remediation
Upgrade Centos:8
xz
to version 0:5.2.4-4.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-1271
- https://access.redhat.com/errata/RHSA-2022:4991
- https://git.tukaani.org/?p=xz.git;a=commit;h=69d1b3fc29677af8ade8dc15dba83f0589cb63d6
- https://bugzilla.redhat.com/show_bug.cgi?id=2073310
- https://git.tukaani.org/?p=xz.git%3Ba=commit%3Bh=69d1b3fc29677af8ade8dc15dba83f0589cb63d6
- https://lists.gnu.org/r/bug-gzip/2022-04/msg00011.html
- https://security-tracker.debian.org/tracker/CVE-2022-1271
- https://security.gentoo.org/glsa/202209-01
- https://security.netapp.com/advisory/ntap-20220930-0006/
- https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch
- https://www.openwall.com/lists/oss-security/2022/04/07/8
high severity
- Vulnerable module: xz-libs
- Introduced through: xz-libs@5.2.4-3.el8
- Fixed in: 0:5.2.4-4.el8_6
Detailed paths
-
Introduced through: centos@centos8 › xz-libs@5.2.4-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream xz-libs
package and not the xz-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
Remediation
Upgrade Centos:8
xz-libs
to version 0:5.2.4-4.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-1271
- https://access.redhat.com/errata/RHSA-2022:4991
- https://git.tukaani.org/?p=xz.git;a=commit;h=69d1b3fc29677af8ade8dc15dba83f0589cb63d6
- https://bugzilla.redhat.com/show_bug.cgi?id=2073310
- https://git.tukaani.org/?p=xz.git%3Ba=commit%3Bh=69d1b3fc29677af8ade8dc15dba83f0589cb63d6
- https://lists.gnu.org/r/bug-gzip/2022-04/msg00011.html
- https://security-tracker.debian.org/tracker/CVE-2022-1271
- https://security.gentoo.org/glsa/202209-01
- https://security.netapp.com/advisory/ntap-20220930-0006/
- https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch
- https://www.openwall.com/lists/oss-security/2022/04/07/8
high severity
- Vulnerable module: less
- Introduced through: less@530-1.el8
- Fixed in: 0:530-3.el8_10
Detailed paths
-
Introduced through: centos@centos8 › less@530-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream less
package and not the less
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
Remediation
Upgrade Centos:8
less
to version 0:530-3.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-32487
- http://www.openwall.com/lists/oss-security/2024/04/15/1
- https://github.com/gwsw/less/commit/007521ac3c95bc76e3d59c6dbfe75d06c8075c33
- https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html
- https://security.netapp.com/advisory/ntap-20240605-0009/
- https://www.openwall.com/lists/oss-security/2024/04/12/5
- https://www.openwall.com/lists/oss-security/2024/04/13/2
high severity
- Vulnerable module: libksba
- Introduced through: libksba@1.3.5-7.el8
- Fixed in: 0:1.3.5-8.el8_6
Detailed paths
-
Introduced through: centos@centos8 › libksba@1.3.5-7.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libksba
package and not the libksba
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
Remediation
Upgrade Centos:8
libksba
to version 0:1.3.5-8.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-3515
- https://access.redhat.com/errata/RHSA-2022:7089
- https://bugzilla.redhat.com/show_bug.cgi?id=2135610
- https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582b
- https://security.netapp.com/advisory/ntap-20230706-0008/
- https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html
high severity
- Vulnerable module: libksba
- Introduced through: libksba@1.3.5-7.el8
- Fixed in: 0:1.3.5-9.el8_7
Detailed paths
-
Introduced through: centos@centos8 › libksba@1.3.5-7.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libksba
package and not the libksba
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Remediation
Upgrade Centos:8
libksba
to version 0:1.3.5-9.el8_7 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-47629
- https://access.redhat.com/errata/RHSA-2023:0625
- https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libksba.git;a=commit;h=f61a5ea4e0f6a80fd4b28ef0174bee77793cf070
- https://dev.gnupg.org/T6284
- https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libksba.git%3Ba=commit%3Bh=f61a5ea4e0f6a80fd4b28ef0174bee77793cf070
- https://lists.debian.org/debian-lts-announce/2022/12/msg00035.html
- https://security.gentoo.org/glsa/202212-07
- https://security.netapp.com/advisory/ntap-20230316-0011/
- https://www.debian.org/security/2022/dsa-5305
high severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-51.el8_8.2
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-51.el8_8.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-40217
- https://mail.python.org/archives/list/security-announce@python.org/thread/PEPLII27KYHLF4AK3ZQGKYNCRERG4YXY/
- https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html
- https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html
- https://mail.python.org/archives/list/security-announce%40python.org/thread/PEPLII27KYHLF4AK3ZQGKYNCRERG4YXY/
- https://security.netapp.com/advisory/ntap-20231006-0014/
- https://www.python.org/dev/security/
high severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-51.el8_8.2
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-51.el8_8.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-40217
- https://mail.python.org/archives/list/security-announce@python.org/thread/PEPLII27KYHLF4AK3ZQGKYNCRERG4YXY/
- https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html
- https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html
- https://mail.python.org/archives/list/security-announce%40python.org/thread/PEPLII27KYHLF4AK3ZQGKYNCRERG4YXY/
- https://security.netapp.com/advisory/ntap-20231006-0014/
- https://www.python.org/dev/security/
high severity
- Vulnerable module: zlib
- Introduced through: zlib@1.2.11-17.el8
- Fixed in: 0:1.2.11-18.el8_5
Detailed paths
-
Introduced through: centos@centos8 › zlib@1.2.11-17.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream zlib
package and not the zlib
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Remediation
Upgrade Centos:8
zlib
to version 0:1.2.11-18.el8_5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2018-25032
- https://access.redhat.com/errata/RHSA-2022:1642
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/
- http://seclists.org/fulldisclosure/2022/May/33
- http://seclists.org/fulldisclosure/2022/May/35
- http://seclists.org/fulldisclosure/2022/May/38
- http://www.openwall.com/lists/oss-security/2022/03/25/2
- http://www.openwall.com/lists/oss-security/2022/03/26/1
- https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf
- https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
- https://github.com/madler/zlib/compare/v1.2.11...v1.2.12
- https://github.com/madler/zlib/issues/605
- https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html
- https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html
- https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/
- https://security.gentoo.org/glsa/202210-42
- https://security.netapp.com/advisory/ntap-20220526-0009/
- https://security.netapp.com/advisory/ntap-20220729-0004/
- https://support.apple.com/kb/HT213255
- https://support.apple.com/kb/HT213256
- https://support.apple.com/kb/HT213257
- https://www.debian.org/security/2022/dsa-5111
- https://www.openwall.com/lists/oss-security/2022/03/24/1
- https://www.openwall.com/lists/oss-security/2022/03/28/1
- https://www.openwall.com/lists/oss-security/2022/03/28/3
- https://www.oracle.com/security-alerts/cpujul2022.html
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-8.el8_6.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-8.el8_6.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-40674
- https://access.redhat.com/errata/RHSA-2022:6878
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSVZN3IJ6OCPSJL7AEX3ZHSHAHFOGESK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J2IGJNHFV53PYST7VQV3T4NHVYAMXA36/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LQB6FJAM5YQ35SF5B2MN25Y2FX56EOEZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2ZKEPGFCZ7R6DRVH3K6RBJPT42ZBEG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XCGBVQQ47URGJAZWHCISHDWF6QBTV2LE/
- https://github.com/libexpat/libexpat/pull/629
- https://github.com/libexpat/libexpat/pull/640
- https://lists.debian.org/debian-lts-announce/2022/09/msg00029.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GSVZN3IJ6OCPSJL7AEX3ZHSHAHFOGESK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J2IGJNHFV53PYST7VQV3T4NHVYAMXA36/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LQB6FJAM5YQ35SF5B2MN25Y2FX56EOEZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2ZKEPGFCZ7R6DRVH3K6RBJPT42ZBEG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCGBVQQ47URGJAZWHCISHDWF6QBTV2LE/
- https://security.gentoo.org/glsa/202209-24
- https://security.gentoo.org/glsa/202211-06
- https://security.netapp.com/advisory/ntap-20221028-0008/
- https://www.debian.org/security/2022/dsa-5236
high severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
- Fixed in: 0:3.6.14-8.el8_3
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.
Remediation
Upgrade Centos:8
gnutls
to version 0:3.6.14-8.el8_3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-20305
- https://www.debian.org/security/2021/dsa-4933
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MQKWVVMAIDAJ7YAA3VVO32BHLDOH2E63/
- https://security.gentoo.org/glsa/202105-31
- https://bugzilla.redhat.com/show_bug.cgi?id=1942533
- https://lists.debian.org/debian-lts-announce/2021/09/msg00008.html
- https://access.redhat.com/errata/RHSA-2021:1206
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MQKWVVMAIDAJ7YAA3VVO32BHLDOH2E63/
- https://security.netapp.com/advisory/ntap-20211022-0002/
high severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-19.el8_10
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-19.el8_10 or higher.
References
high severity
- Vulnerable module: nettle
- Introduced through: nettle@3.4.1-2.el8
- Fixed in: 0:3.4.1-4.el8_3
Detailed paths
-
Introduced through: centos@centos8 › nettle@3.4.1-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream nettle
package and not the nettle
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.
Remediation
Upgrade Centos:8
nettle
to version 0:3.4.1-4.el8_3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-20305
- https://www.debian.org/security/2021/dsa-4933
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MQKWVVMAIDAJ7YAA3VVO32BHLDOH2E63/
- https://security.gentoo.org/glsa/202105-31
- https://bugzilla.redhat.com/show_bug.cgi?id=1942533
- https://lists.debian.org/debian-lts-announce/2021/09/msg00008.html
- https://access.redhat.com/errata/RHSA-2021:1206
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MQKWVVMAIDAJ7YAA3VVO32BHLDOH2E63/
- https://security.netapp.com/advisory/ntap-20211022-0002/
high severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-4.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-4.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-46143
- https://access.redhat.com/errata/RHSA-2022:0951
- http://www.openwall.com/lists/oss-security/2022/01/17/3
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/issues/532
- https://github.com/libexpat/libexpat/pull/538
- https://security.gentoo.org/glsa/202209-24
- https://security.netapp.com/advisory/ntap-20220121-0006/
- https://www.debian.org/security/2022/dsa-5073
- https://www.tenable.com/security/tns-2022-05
high severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-225.el8_8.6
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-225.el8_8.6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4911
- http://packetstormsecurity.com/files/174986/glibc-ld.so-Local-Privilege-Escalation.html
- http://packetstormsecurity.com/files/176288/Glibc-Tunables-Privilege-Escalation.html
- http://seclists.org/fulldisclosure/2023/Oct/11
- http://www.openwall.com/lists/oss-security/2023/10/03/2
- http://www.openwall.com/lists/oss-security/2023/10/03/3
- http://www.openwall.com/lists/oss-security/2023/10/05/1
- http://www.openwall.com/lists/oss-security/2023/10/13/11
- http://www.openwall.com/lists/oss-security/2023/10/14/3
- http://www.openwall.com/lists/oss-security/2023/10/14/5
- http://www.openwall.com/lists/oss-security/2023/10/14/6
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/
- https://security.gentoo.org/glsa/202310-03
- https://security.netapp.com/advisory/ntap-20231013-0006/
- https://www.debian.org/security/2023/dsa-5514
- https://access.redhat.com/errata/RHBA-2024:2413
- https://access.redhat.com/errata/RHSA-2023:5455
- https://bugzilla.redhat.com/show_bug.cgi?id=2238352
- https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
- https://www.qualys.com/cve-2023-4911/
- https://github.com/projectdiscovery/nuclei-templates/blob/main/code/cves/2023/CVE-2023-4911.yaml
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://github.com/KernelKrise/CVE-2023-4911
high severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-225.el8_8.6
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-225.el8_8.6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4911
- http://packetstormsecurity.com/files/174986/glibc-ld.so-Local-Privilege-Escalation.html
- http://packetstormsecurity.com/files/176288/Glibc-Tunables-Privilege-Escalation.html
- http://seclists.org/fulldisclosure/2023/Oct/11
- http://www.openwall.com/lists/oss-security/2023/10/03/2
- http://www.openwall.com/lists/oss-security/2023/10/03/3
- http://www.openwall.com/lists/oss-security/2023/10/05/1
- http://www.openwall.com/lists/oss-security/2023/10/13/11
- http://www.openwall.com/lists/oss-security/2023/10/14/3
- http://www.openwall.com/lists/oss-security/2023/10/14/5
- http://www.openwall.com/lists/oss-security/2023/10/14/6
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/
- https://security.gentoo.org/glsa/202310-03
- https://security.netapp.com/advisory/ntap-20231013-0006/
- https://www.debian.org/security/2023/dsa-5514
- https://access.redhat.com/errata/RHBA-2024:2413
- https://access.redhat.com/errata/RHSA-2023:5455
- https://bugzilla.redhat.com/show_bug.cgi?id=2238352
- https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
- https://www.qualys.com/cve-2023-4911/
- https://github.com/projectdiscovery/nuclei-templates/blob/main/code/cves/2023/CVE-2023-4911.yaml
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://github.com/KernelKrise/CVE-2023-4911
high severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-225.el8_8.6
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-225.el8_8.6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4911
- http://packetstormsecurity.com/files/174986/glibc-ld.so-Local-Privilege-Escalation.html
- http://packetstormsecurity.com/files/176288/Glibc-Tunables-Privilege-Escalation.html
- http://seclists.org/fulldisclosure/2023/Oct/11
- http://www.openwall.com/lists/oss-security/2023/10/03/2
- http://www.openwall.com/lists/oss-security/2023/10/03/3
- http://www.openwall.com/lists/oss-security/2023/10/05/1
- http://www.openwall.com/lists/oss-security/2023/10/13/11
- http://www.openwall.com/lists/oss-security/2023/10/14/3
- http://www.openwall.com/lists/oss-security/2023/10/14/5
- http://www.openwall.com/lists/oss-security/2023/10/14/6
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/
- https://security.gentoo.org/glsa/202310-03
- https://security.netapp.com/advisory/ntap-20231013-0006/
- https://www.debian.org/security/2023/dsa-5514
- https://access.redhat.com/errata/RHBA-2024:2413
- https://access.redhat.com/errata/RHSA-2023:5455
- https://bugzilla.redhat.com/show_bug.cgi?id=2238352
- https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
- https://www.qualys.com/cve-2023-4911/
- https://github.com/projectdiscovery/nuclei-templates/blob/main/code/cves/2023/CVE-2023-4911.yaml
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://github.com/KernelKrise/CVE-2023-4911
high severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-19.el8_10
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-19.el8_10 or higher.
References
high severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-21.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-21.el8_10.2 or higher.
References
high severity
- Vulnerable module: pam
- Introduced through: pam@1.3.1-14.el8
- Fixed in: 0:1.3.1-37.el8_10
Detailed paths
-
Introduced through: centos@centos8 › pam@1.3.1-14.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream pam
package and not the pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
Remediation
Upgrade Centos:8
pam
to version 0:1.3.1-37.el8_10 or higher.
References
high severity
new
- Vulnerable module: pam
- Introduced through: pam@1.3.1-14.el8
- Fixed in: 0:1.3.1-38.el8_10
Detailed paths
-
Introduced through: centos@centos8 › pam@1.3.1-14.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream pam
package and not the pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
Remediation
Upgrade Centos:8
pam
to version 0:1.3.1-38.el8_10 or higher.
References
high severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-62.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was found in the CPython tempfile.TemporaryDirectory
class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.
The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-62.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-6597
- http://www.openwall.com/lists/oss-security/2024/03/20/5
- https://github.com/python/cpython/commit/02a9259c717738dfe6b463c44d7e17f2b6d2cb3a
- https://github.com/python/cpython/commit/5585334d772b253a01a6730e8202ffb1607c3d25
- https://github.com/python/cpython/commit/6ceb8aeda504b079fef7a57b8d81472f15cdd9a5
- https://github.com/python/cpython/commit/81c16cd94ec38d61aa478b9a452436dc3b1b524d
- https://github.com/python/cpython/commit/8eaeefe49d179ca4908d052745e3bb8b6f238f82
- https://github.com/python/cpython/commit/d54e22a669ae6e987199bb5d2c69bb5a46b0083b
- https://github.com/python/cpython/issues/91133
- https://lists.debian.org/debian-lts-announce/2024/03/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3IGRX54M7RNCQOXVQO5KQKTGWCOABIM/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5VHWS52HGD743C47UMCSAK2A773M2YE/
- https://mail.python.org/archives/list/security-announce@python.org/thread/Q5C6ATFC67K53XFV4KE45325S7NS62LD/
high severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-62.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was found in the CPython tempfile.TemporaryDirectory
class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.
The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-62.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-6597
- http://www.openwall.com/lists/oss-security/2024/03/20/5
- https://github.com/python/cpython/commit/02a9259c717738dfe6b463c44d7e17f2b6d2cb3a
- https://github.com/python/cpython/commit/5585334d772b253a01a6730e8202ffb1607c3d25
- https://github.com/python/cpython/commit/6ceb8aeda504b079fef7a57b8d81472f15cdd9a5
- https://github.com/python/cpython/commit/81c16cd94ec38d61aa478b9a452436dc3b1b524d
- https://github.com/python/cpython/commit/8eaeefe49d179ca4908d052745e3bb8b6f238f82
- https://github.com/python/cpython/commit/d54e22a669ae6e987199bb5d2c69bb5a46b0083b
- https://github.com/python/cpython/issues/91133
- https://lists.debian.org/debian-lts-announce/2024/03/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3IGRX54M7RNCQOXVQO5KQKTGWCOABIM/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5VHWS52HGD743C47UMCSAK2A773M2YE/
- https://mail.python.org/archives/list/security-announce@python.org/thread/Q5C6ATFC67K53XFV4KE45325S7NS62LD/
high severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
- Fixed in: 0:3.26.0-20.el8_10
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
Remediation
Upgrade Centos:8
sqlite-libs
to version 0:3.26.0-20.el8_10 or higher.
References
high severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nscd: Stack-based buffer overflow in netgroup cache
If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-251.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-33599
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
- https://security.netapp.com/advisory/ntap-20240524-0011/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0005
high severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nscd: Stack-based buffer overflow in netgroup cache
If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-251.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-33599
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
- https://security.netapp.com/advisory/ntap-20240524-0011/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0005
high severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nscd: Stack-based buffer overflow in netgroup cache
If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-251.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-33599
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
- https://security.netapp.com/advisory/ntap-20240524-0011/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0005
high severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-70.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extraction directory. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature.
Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected.
Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-70.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-12718
- https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f
- https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a
- https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a
- https://github.com/python/cpython/issues/135034
- https://github.com/python/cpython/pull/135037
- https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/
- https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da
- https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9
- https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e
- https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a
- https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01
- https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1
- https://github.com/python/cpython/issues/127987
high severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-70.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data".
You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information.
Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected.
Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-70.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-4517
- https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f
- https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a
- https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a
- https://github.com/python/cpython/issues/135034
- https://github.com/python/cpython/pull/135037
- https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/
- https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da
- https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01
- https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9
- https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e
- https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a
- https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1
high severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-70.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extraction directory. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature.
Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected.
Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-70.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-12718
- https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f
- https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a
- https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a
- https://github.com/python/cpython/issues/135034
- https://github.com/python/cpython/pull/135037
- https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/
- https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da
- https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9
- https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e
- https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a
- https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01
- https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1
- https://github.com/python/cpython/issues/127987
high severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-70.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data".
You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information.
Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected.
Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-70.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-4517
- https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f
- https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a
- https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a
- https://github.com/python/cpython/issues/135034
- https://github.com/python/cpython/pull/135037
- https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/
- https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da
- https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01
- https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9
- https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e
- https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a
- https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1
high severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-8.el8_8.1
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Every named
instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the max-cache-size
statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. When the size of the cache reaches 7/8 of the configured limit, a cache-cleaning algorithm starts to remove expired and/or least-recently used RRsets from the cache, to keep memory use below the configured limit.
It has been discovered that the effectiveness of the cache-cleaning algorithm used in named
can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configured max-cache-size
limit to be significantly exceeded.
This issue affects BIND 9 versions 9.11.0 through 9.16.41, 9.18.0 through 9.18.15, 9.19.0 through 9.19.13, 9.11.3-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-8.el8_8.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-2828
- http://www.openwall.com/lists/oss-security/2023/06/21/6
- https://kb.isc.org/docs/cve-2023-2828
- https://lists.debian.org/debian-lts-announce/2023/07/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SEFCEVCTYEMKTWA7V7EYPI5YQQ4JWDLI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U3K6AJK7RRSR53HRF5GGKPA6PDUDWOD2/
- https://security.netapp.com/advisory/ntap-20230703-0010/
- https://www.debian.org/security/2023/dsa-5439
high severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-8.el8_8.2
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The code that processes control channel messages sent to named
calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing named
to terminate unexpectedly. Since each incoming control channel message is fully parsed before its contents are authenticated, exploiting this flaw does not require the attacker to hold a valid RNDC key; only network access to the control channel's configured TCP port is necessary.
This issue affects BIND 9 versions 9.2.0 through 9.16.43, 9.18.0 through 9.18.18, 9.19.0 through 9.19.16, 9.9.3-S1 through 9.16.43-S1, and 9.18.0-S1 through 9.18.18-S1.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-8.el8_8.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-3341
- http://www.openwall.com/lists/oss-security/2023/09/20/2
- https://kb.isc.org/docs/cve-2023-3341
- https://lists.debian.org/debian-lts-announce/2024/01/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPJLLTJCSDJJII7IIZPLTBQNWP7MZH7F/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U35OARLQCPMVCBBPHWBXY5M6XJLD2TZ5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSK5V4W4OHPM3JTJGWAQD6CZW7SFD75B/
- https://security.netapp.com/advisory/ntap-20231013-0003/
- https://www.debian.org/security/2023/dsa-5504
high severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-3.el8_6.1
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-3.el8_6.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-38177
- https://access.redhat.com/errata/RHSA-2022:6778
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/
- http://www.openwall.com/lists/oss-security/2022/09/21/3
- https://kb.isc.org/docs/cve-2022-38177
- https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/
- https://security.gentoo.org/glsa/202210-25
- https://security.netapp.com/advisory/ntap-20221228-0010/
- https://www.debian.org/security/2022/dsa-5235
high severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-3.el8_6.1
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-3.el8_6.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-38178
- https://access.redhat.com/errata/RHSA-2022:6778
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/
- http://www.openwall.com/lists/oss-security/2022/09/21/3
- https://kb.isc.org/docs/cve-2022-38178
- https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/
- https://security.gentoo.org/glsa/202210-25
- https://security.netapp.com/advisory/ntap-20221228-0009/
- https://www.debian.org/security/2022/dsa-5235
high severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.26-4.el8_4
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due to a failed assertion check. The vulnerability affects all currently maintained BIND 9 branches (9.11, 9.11-S, 9.16, 9.16-S, 9.17) as well as all other versions of BIND 9.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.26-4.el8_4 or higher.
References
- https://kb.isc.org/v1/docs/cve-2021-25215
- https://security.netapp.com/advisory/ntap-20210521-0006/
- https://access.redhat.com/security/cve/CVE-2021-25215
- https://www.debian.org/security/2021/dsa-4909
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VEC2XG4Q2ODTN2C4CGXEIXU3EUTBMK7L/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZDSRPCJQ7MZC6CENH5PO3VQOFI7VSWBE/
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.debian.org/debian-lts-announce/2021/05/msg00001.html
- http://www.openwall.com/lists/oss-security/2021/04/29/1
- http://www.openwall.com/lists/oss-security/2021/04/29/2
- http://www.openwall.com/lists/oss-security/2021/04/29/3
- http://www.openwall.com/lists/oss-security/2021/04/29/4
- https://access.redhat.com/errata/RHSA-2021:1989
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VEC2XG4Q2ODTN2C4CGXEIXU3EUTBMK7L/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZDSRPCJQ7MZC6CENH5PO3VQOFI7VSWBE/
high severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-14.el8_10
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The DNS message parsing code in named
includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected named
instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers.
This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-14.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4408
- http://www.openwall.com/lists/oss-security/2024/02/13/1
- https://kb.isc.org/docs/cve-2023-4408
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/
- https://security.netapp.com/advisory/ntap-20240426-0001/
high severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-14.el8_10
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-14.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-50387
- https://datatracker.ietf.org/doc/html/rfc4035
- http://www.openwall.com/lists/oss-security/2024/02/16/2
- http://www.openwall.com/lists/oss-security/2024/02/16/3
- https://bugzilla.suse.com/show_bug.cgi?id=1219823
- https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.html
- https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1
- https://kb.isc.org/docs/cve-2023-50387
- https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html
- https://lists.debian.org/debian-lts-announce/2024/05/msg00011.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6FV5O347JTX7P5OZA6NGO4MKTXRXMKOZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IGSLGKUAQTW5JPPZCMF5YPEYALLRUZZ6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEXGOYGW7DBS3N2QSSQONZ4ENIRQEAPG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQESRWMJCF4JEYJEAKLRM6CT55GLJAB7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/
- https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-50387
- https://news.ycombinator.com/item?id=39367411
- https://news.ycombinator.com/item?id=39372384
- https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/
- https://security.netapp.com/advisory/ntap-20240307-0007/
- https://www.athene-center.de/aktuelles/key-trap
- https://www.athene-center.de/fileadmin/content/PDF/Technical_Report_KeyTrap.pdf
- https://www.isc.org/blogs/2024-bind-security-release/
- https://www.securityweek.com/keytrap-dns-attack-could-disable-large-parts-of-internet-researchers/
- https://www.theregister.com/2024/02/13/dnssec_vulnerability_internet/
- https://github.com/knqyf263/CVE-2023-50387
high severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-14.el8_10
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-14.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-50868
- http://www.openwall.com/lists/oss-security/2024/02/16/2
- http://www.openwall.com/lists/oss-security/2024/02/16/3
- https://bugzilla.suse.com/show_bug.cgi?id=1219826
- https://datatracker.ietf.org/doc/html/rfc5155
- https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.html
- https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1
- https://kb.isc.org/docs/cve-2023-50868
- https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html
- https://lists.debian.org/debian-lts-announce/2024/05/msg00011.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6FV5O347JTX7P5OZA6NGO4MKTXRXMKOZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IGSLGKUAQTW5JPPZCMF5YPEYALLRUZZ6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEXGOYGW7DBS3N2QSSQONZ4ENIRQEAPG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQESRWMJCF4JEYJEAKLRM6CT55GLJAB7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/
- https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html
- https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/
- https://security.netapp.com/advisory/ntap-20240307-0008/
- https://www.isc.org/blogs/2024-bind-security-release/
high severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-16.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as content is being added or updated, and also when handling client queries for this name. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.4-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-16.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-1737
- http://www.openwall.com/lists/oss-security/2024/07/31/2
- http://www.openwall.com/lists/oss-security/2024/07/23/1
- https://kb.isc.org/docs/cve-2024-1737
- https://kb.isc.org/docs/rrset-limits-in-zones
- https://security.netapp.com/advisory/ntap-20240731-0003/
high severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-16.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests. This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.49-S1, and 9.18.11-S1 through 9.18.27-S1.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-16.el8_10.2 or higher.
References
high severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-16.el8_10.4
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-16.el8_10.4 or higher.
References
high severity
- Vulnerable module: libnghttp2
- Introduced through: libnghttp2@1.33.0-3.el8_2.1
- Fixed in: 0:1.33.0-5.el8_8
Detailed paths
-
Introduced through: centos@centos8 › libnghttp2@1.33.0-3.el8_2.1
NVD Description
Note: Versions mentioned in the description apply only to the upstream libnghttp2
package and not the libnghttp2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Remediation
Upgrade Centos:8
libnghttp2
to version 0:1.33.0-5.el8_8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-44487
- https://chaos.social/@icing/111210915918780532
- https://github.com/hyperium/hyper/issues/3337
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/
- https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/
- http://www.openwall.com/lists/oss-security/2023/10/10/6
- http://www.openwall.com/lists/oss-security/2023/10/10/7
- https://github.com/grpc/grpc/releases/tag/v1.59.2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ
- http://www.openwall.com/lists/oss-security/2023/10/13/4
- http://www.openwall.com/lists/oss-security/2023/10/13/9
- http://www.openwall.com/lists/oss-security/2023/10/18/4
- http://www.openwall.com/lists/oss-security/2023/10/18/8
- http://www.openwall.com/lists/oss-security/2023/10/19/6
- http://www.openwall.com/lists/oss-security/2023/10/20/8
- https://access.redhat.com/security/cve/cve-2023-44487
- https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/
- https://aws.amazon.com/security/security-bulletins/AWS-2023-011/
- https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
- https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/
- https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/
- https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack
- https://blog.vespa.ai/cve-2023-44487/
- https://bugzilla.proxmox.com/show_bug.cgi?id=4988
- https://bugzilla.redhat.com/show_bug.cgi?id=2242803
- https://bugzilla.suse.com/show_bug.cgi?id=1216123
- https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9
- https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/
- https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack
- https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125
- https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715
- https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve
- https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764
- https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088
- https://github.com/Azure/AKS/issues/3947
- https://github.com/Kong/kong/discussions/11741
- https://github.com/advisories/GHSA-qppj-fm5r-hxr3
- https://github.com/advisories/GHSA-vx74-f528-fxqg
- https://github.com/advisories/GHSA-xpw8-rcwv-8f8p
- https://github.com/akka/akka-http/issues/4323
- https://github.com/alibaba/tengine/issues/1872
- https://github.com/apache/apisix/issues/10320
- https://github.com/apache/httpd-site/pull/10
- https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113
- https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2
- https://github.com/apache/trafficserver/pull/10564
- https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487
- https://github.com/bcdannyboy/CVE-2023-44487
- https://github.com/caddyserver/caddy/issues/5877
- https://github.com/caddyserver/caddy/releases/tag/v2.7.5
- https://github.com/dotnet/announcements/issues/277
- https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73
- https://github.com/eclipse/jetty.project/issues/10679
- https://github.com/envoyproxy/envoy/pull/30055
- https://github.com/etcd-io/etcd/issues/16740
- https://github.com/facebook/proxygen/pull/466
- https://github.com/golang/go/issues/63417
- https://github.com/grpc/grpc-go/pull/6703
- https://github.com/h2o/h2o/pull/3291
- https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf
- https://github.com/haproxy/haproxy/issues/2312
- https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244
- https://github.com/junkurihara/rust-rpxy/issues/97
- https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1
- https://github.com/kazu-yamamoto/http2/issues/93
- https://github.com/kubernetes/kubernetes/pull/121120
- https://github.com/line/armeria/pull/5232
- https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632
- https://github.com/micrictor/http2-rst-stream
- https://github.com/microsoft/CBL-Mariner/pull/6381
- https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61
- https://github.com/nghttp2/nghttp2/pull/1961
- https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0
- https://github.com/ninenines/cowboy/issues/1615
- https://github.com/nodejs/node/pull/50121
- https://github.com/openresty/openresty/issues/930
- https://github.com/opensearch-project/data-prepper/issues/3474
- https://github.com/oqtane/oqtane.framework/discussions/3367
- https://github.com/projectcontour/contour/pull/5826
- https://github.com/tempesta-tech/tempesta/issues/1986
- https://github.com/varnishcache/varnish-cache/issues/3996
- https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo
- https://istio.io/latest/news/security/istio-security-2023-004/
- https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/
- https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q
- https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html
- https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html
- https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html
- https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html
- https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html
- https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html
- https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html
- https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html
- https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html
- https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487
- https://my.f5.com/manage/s/article/K000137106
- https://netty.io/news/2023/10/10/4-1-100-Final.html
- https://news.ycombinator.com/item?id=37830987
- https://news.ycombinator.com/item?id=37830998
- https://news.ycombinator.com/item?id=37831062
- https://news.ycombinator.com/item?id=37837043
- https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/
- https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected
- https://security.gentoo.org/glsa/202311-09
- https://security.netapp.com/advisory/ntap-20231016-0001/
- https://security.netapp.com/advisory/ntap-20240426-0007/
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://security.netapp.com/advisory/ntap-20240621-0007/
- https://security.paloaltonetworks.com/CVE-2023-44487
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14
- https://ubuntu.com/security/CVE-2023-44487
- https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/
- https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487
- https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event
- https://www.debian.org/security/2023/dsa-5521
- https://www.debian.org/security/2023/dsa-5522
- https://www.debian.org/security/2023/dsa-5540
- https://www.debian.org/security/2023/dsa-5549
- https://www.debian.org/security/2023/dsa-5558
- https://www.debian.org/security/2023/dsa-5570
- https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487
- https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/
- https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/
- https://www.openwall.com/lists/oss-security/2023/10/10/6
- https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack
- https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://github.com/studiogangster/CVE-2023-44487
high severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-21.el8_10.1
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-21.el8_10.1 or higher.
References
high severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-9.el8_7
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing the relevant decoded data. The caller is responsible for freeing those buffers. It is possible to construct a PEM file that results in 0 bytes of payload data. In this case PEM_read_bio_ex() will return a failure code but will populate the header argument with a pointer to a buffer that has already been freed. If the caller also frees this buffer then a double free will occur. This will most likely lead to a crash. This could be exploited by an attacker who has the ability to supply malicious PEM files for parsing to achieve a denial of service attack.
The functions PEM_read_bio() and PEM_read() are simple wrappers around PEM_read_bio_ex() and therefore these functions are also directly affected.
These functions are also called indirectly by a number of other OpenSSL functions including PEM_X509_INFO_read_bio_ex() and SSL_CTX_use_serverinfo_file() which are also vulnerable. Some OpenSSL internal uses of these functions are not vulnerable because the caller does not free the header argument if PEM_read_bio_ex() returns a failure code. These locations include the PEM_read_bio_TYPE() functions as well as the decoders introduced in OpenSSL 3.0.
The OpenSSL asn1parse command line application is also impacted by this issue.
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-9.el8_7 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-4450
- https://access.redhat.com/errata/RHSA-2023:1405
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=63bcf189be73a9cc1264059bed6f57974be74a83
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=bbcf509bd046b34cca19c766bbddc31683d0858b
- https://security.gentoo.org/glsa/202402-08
- https://www.openssl.org/news/secadv/20230207.txt
high severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-6.el8_5
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-6.el8_5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-0778
- https://access.redhat.com/errata/RHSA-2022:1065
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=380085481c64de749a6dd25cdf0bcf4360b30f83
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=3118eb64934499d93db3230748a452351d1d9a65
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a466912611aa6cbdf550cd10601390e587451246
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG/
- http://packetstormsecurity.com/files/167344/OpenSSL-1.0.2-1.1.1-3.0-BN_mod_sqrt-Infinite-Loop.html
- http://seclists.org/fulldisclosure/2022/May/33
- http://seclists.org/fulldisclosure/2022/May/35
- http://seclists.org/fulldisclosure/2022/May/38
- https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246
- https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html
- https://lists.debian.org/debian-lts-announce/2022/03/msg00024.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG/
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0002
- https://security.gentoo.org/glsa/202210-02
- https://security.netapp.com/advisory/ntap-20220321-0002/
- https://security.netapp.com/advisory/ntap-20220429-0005/
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://support.apple.com/kb/HT213255
- https://support.apple.com/kb/HT213256
- https://support.apple.com/kb/HT213257
- https://www.debian.org/security/2022/dsa-5103
- https://www.openssl.org/news/secadv/20220315.txt
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.tenable.com/security/tns-2022-06
- https://www.tenable.com/security/tns-2022-07
- https://www.tenable.com/security/tns-2022-08
- https://www.tenable.com/security/tns-2022-09
- https://github.com/jkakavas/CVE-2022-0778-POC
high severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-9.el8_7
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications.
The function receives a BIO from the caller, prepends a new BIO_f_asn1 filter BIO onto the front of it to form a BIO chain, and then returns the new head of the BIO chain to the caller. Under certain conditions, for example if a CMS recipient public key is invalid, the new filter BIO is freed and the function returns a NULL result indicating a failure. However, in this case, the BIO chain is not properly cleaned up and the BIO passed by the caller still retains internal pointers to the previously freed filter BIO. If the caller then goes on to call BIO_pop() on the BIO then a use-after-free will occur. This will most likely result in a crash.
This scenario occurs directly in the internal function B64_write_ASN1() which may cause BIO_new_NDEF() to be called and will subsequently call BIO_pop() on the BIO. This internal function is in turn called by the public API functions PEM_write_bio_ASN1_stream, PEM_write_bio_CMS_stream, PEM_write_bio_PKCS7_stream, SMIME_write_ASN1, SMIME_write_CMS and SMIME_write_PKCS7.
Other public API functions that may be impacted by this include i2d_ASN1_bio_stream, BIO_new_CMS, BIO_new_PKCS7, i2d_CMS_bio_stream and i2d_PKCS7_bio_stream.
The OpenSSL cms and smime command line applications are similarly affected.
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-9.el8_7 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-0215
- https://access.redhat.com/errata/RHSA-2023:1405
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8818064ce3c3c0f1b740a5aaba2a987e75bfbafd
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9816136fe31d92ace4037d5da5257f763aeeb4eb
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=c3829dd8825c654652201e16f8a0a0c46ee3f344
- https://security.gentoo.org/glsa/202402-08
- https://security.netapp.com/advisory/ntap-20230427-0007/
- https://security.netapp.com/advisory/ntap-20230427-0009/
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://www.openssl.org/news/secadv/20230207.txt
high severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-70.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.
You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information.
Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected.
Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-70.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-4138
- https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f
- https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a
- https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a
- https://github.com/python/cpython/issues/135034
- https://github.com/python/cpython/pull/135037
- https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/
- https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da
- https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01
- https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9
- https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e
- https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a
- https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1
high severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-51.el8_8.1
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-51.el8_8.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-24329
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6PEVICI7YNGGMSL3UCMWGE66QFLATH72/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DSL6NSOAXWBJJ67XPLSSC74MNKZF3BBO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EM2XLZSTXG44TMFXF4E6VTGKR2MQCW3G/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F2NY75GFDZ5T6YPN44D3VMFT5SUVTOTG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GR5US3BYILYJ4SKBV6YBNPRUBAL5P2CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H23OSKC6UG6IWOQAUPW74YUHWRWVXJP7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JZTLGV2HYFF4AMYJL25VDIGAIHCU7UPA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LWC4WGXER5P6Q75RFGL7QUTPP3N5JR7T/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MZEHSXSCMA4WWQKXT6QV7AAR6SWNZ2VP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O5SP4RT3RRS434ZS2HQKQJ3VZW7YPKYR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OHHJHJRLEF3TDT2K3676CAUVRDD4CCMR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PEUN6T22UJFXR7J5F6UUHCXXPKJ2DVHI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PURM5CFDABEWAIWZFD2MQ7ZJGCPYSQ44/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q3J5N24ECS4B6MJDRO6UAYU6GPLYBDCL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRQHN7RWJQJHYP6E5EKESOYP5VDSHZG4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RA2MBEEES6L46OD64OBSVUUMGKNGMOWW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4IDB5OAR5Y4UK3HLMZBW4WEL2B7YFMJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TZH26JGNZ5XYPZ5SAU3NKSBSPRE5OHTG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U2MZOJYGFCB5PPT6AKMAU72N7QOYWLBP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UONZWLB4QVLQIY5CPDLEUEKH6WX4VQMC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTOAUJNDWZDRWVSXJ354AYZYKRMT56HU/
- https://github.com/python/cpython/issues/102153
- https://github.com/python/cpython/pull/99421
- https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PEVICI7YNGGMSL3UCMWGE66QFLATH72/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSL6NSOAXWBJJ67XPLSSC74MNKZF3BBO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EM2XLZSTXG44TMFXF4E6VTGKR2MQCW3G/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2NY75GFDZ5T6YPN44D3VMFT5SUVTOTG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GR5US3BYILYJ4SKBV6YBNPRUBAL5P2CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H23OSKC6UG6IWOQAUPW74YUHWRWVXJP7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTLGV2HYFF4AMYJL25VDIGAIHCU7UPA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWC4WGXER5P6Q75RFGL7QUTPP3N5JR7T/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZEHSXSCMA4WWQKXT6QV7AAR6SWNZ2VP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5SP4RT3RRS434ZS2HQKQJ3VZW7YPKYR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHHJHJRLEF3TDT2K3676CAUVRDD4CCMR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PEUN6T22UJFXR7J5F6UUHCXXPKJ2DVHI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PURM5CFDABEWAIWZFD2MQ7ZJGCPYSQ44/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3J5N24ECS4B6MJDRO6UAYU6GPLYBDCL/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRQHN7RWJQJHYP6E5EKESOYP5VDSHZG4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RA2MBEEES6L46OD64OBSVUUMGKNGMOWW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4IDB5OAR5Y4UK3HLMZBW4WEL2B7YFMJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZH26JGNZ5XYPZ5SAU3NKSBSPRE5OHTG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2MZOJYGFCB5PPT6AKMAU72N7QOYWLBP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UONZWLB4QVLQIY5CPDLEUEKH6WX4VQMC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTOAUJNDWZDRWVSXJ354AYZYKRMT56HU/
- https://pointernull.com/security/python-url-parse-problem.html
- https://security.netapp.com/advisory/ntap-20230324-0004/
- https://www.kb.cert.org/vuls/id/127587
high severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-70.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-70.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-4435
- https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a
- https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a
- https://github.com/python/cpython/issues/135034
- https://github.com/python/cpython/pull/135037
- https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/
- https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da
- https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01
- https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9
- https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e
- https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a
- https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1
high severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-70.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.
You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information.
Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected.
Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-70.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-4138
- https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f
- https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a
- https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a
- https://github.com/python/cpython/issues/135034
- https://github.com/python/cpython/pull/135037
- https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/
- https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da
- https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01
- https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9
- https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e
- https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a
- https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1
high severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-51.el8_8.1
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-51.el8_8.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-24329
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6PEVICI7YNGGMSL3UCMWGE66QFLATH72/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DSL6NSOAXWBJJ67XPLSSC74MNKZF3BBO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EM2XLZSTXG44TMFXF4E6VTGKR2MQCW3G/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F2NY75GFDZ5T6YPN44D3VMFT5SUVTOTG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GR5US3BYILYJ4SKBV6YBNPRUBAL5P2CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H23OSKC6UG6IWOQAUPW74YUHWRWVXJP7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JZTLGV2HYFF4AMYJL25VDIGAIHCU7UPA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LWC4WGXER5P6Q75RFGL7QUTPP3N5JR7T/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MZEHSXSCMA4WWQKXT6QV7AAR6SWNZ2VP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O5SP4RT3RRS434ZS2HQKQJ3VZW7YPKYR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OHHJHJRLEF3TDT2K3676CAUVRDD4CCMR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PEUN6T22UJFXR7J5F6UUHCXXPKJ2DVHI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PURM5CFDABEWAIWZFD2MQ7ZJGCPYSQ44/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q3J5N24ECS4B6MJDRO6UAYU6GPLYBDCL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRQHN7RWJQJHYP6E5EKESOYP5VDSHZG4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RA2MBEEES6L46OD64OBSVUUMGKNGMOWW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4IDB5OAR5Y4UK3HLMZBW4WEL2B7YFMJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TZH26JGNZ5XYPZ5SAU3NKSBSPRE5OHTG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U2MZOJYGFCB5PPT6AKMAU72N7QOYWLBP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UONZWLB4QVLQIY5CPDLEUEKH6WX4VQMC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTOAUJNDWZDRWVSXJ354AYZYKRMT56HU/
- https://github.com/python/cpython/issues/102153
- https://github.com/python/cpython/pull/99421
- https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PEVICI7YNGGMSL3UCMWGE66QFLATH72/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSL6NSOAXWBJJ67XPLSSC74MNKZF3BBO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EM2XLZSTXG44TMFXF4E6VTGKR2MQCW3G/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2NY75GFDZ5T6YPN44D3VMFT5SUVTOTG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GR5US3BYILYJ4SKBV6YBNPRUBAL5P2CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H23OSKC6UG6IWOQAUPW74YUHWRWVXJP7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTLGV2HYFF4AMYJL25VDIGAIHCU7UPA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWC4WGXER5P6Q75RFGL7QUTPP3N5JR7T/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZEHSXSCMA4WWQKXT6QV7AAR6SWNZ2VP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5SP4RT3RRS434ZS2HQKQJ3VZW7YPKYR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHHJHJRLEF3TDT2K3676CAUVRDD4CCMR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PEUN6T22UJFXR7J5F6UUHCXXPKJ2DVHI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PURM5CFDABEWAIWZFD2MQ7ZJGCPYSQ44/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3J5N24ECS4B6MJDRO6UAYU6GPLYBDCL/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRQHN7RWJQJHYP6E5EKESOYP5VDSHZG4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RA2MBEEES6L46OD64OBSVUUMGKNGMOWW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4IDB5OAR5Y4UK3HLMZBW4WEL2B7YFMJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZH26JGNZ5XYPZ5SAU3NKSBSPRE5OHTG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2MZOJYGFCB5PPT6AKMAU72N7QOYWLBP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UONZWLB4QVLQIY5CPDLEUEKH6WX4VQMC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTOAUJNDWZDRWVSXJ354AYZYKRMT56HU/
- https://pointernull.com/security/python-url-parse-problem.html
- https://security.netapp.com/advisory/ntap-20230324-0004/
- https://www.kb.cert.org/vuls/id/127587
high severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-70.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-70.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-4435
- https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a
- https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a
- https://github.com/python/cpython/issues/135034
- https://github.com/python/cpython/pull/135037
- https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/
- https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da
- https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01
- https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9
- https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e
- https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a
- https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1
high severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-9.el8_7
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING.
When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect applications which have implemented their own functionality for retrieving CRLs over a network.
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-9.el8_7 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-0286
- https://access.redhat.com/errata/RHSA-2023:1405
- https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.6.2-relnotes.txt
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/018_x509.patch.sig
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2c6c9d439b484e1ba9830d8454a34fa4f80fdfe9
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2f7530077e0ef79d98718138716bc51ca0cad658
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fd2af07dc083a350c959147097003a14a5e8ac4d
- https://security.gentoo.org/glsa/202402-08
- https://www.openssl.org/news/secadv/20230207.txt
high severity
- Vulnerable module: pam
- Introduced through: pam@1.3.1-14.el8
- Fixed in: 0:1.3.1-36.el8_10
Detailed paths
-
Introduced through: centos@centos8 › pam@1.3.1-14.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream pam
package and not the pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who can access certain services or terminals.
Remediation
Upgrade Centos:8
pam
to version 0:1.3.1-36.el8_10 or higher.
References
high severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
- Fixed in: 0:3.3.3-6.el8_10
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.
Remediation
Upgrade Centos:8
libarchive
to version 0:3.3.3-6.el8_10 or higher.
References
high severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-70.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.
You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information.
Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected.
Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-70.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-4330
- https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f
- https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a
- https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a
- https://github.com/python/cpython/issues/135034
- https://github.com/python/cpython/pull/135037
- https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/
- https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da
- https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01
- https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9
- https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e
- https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a
- https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1
high severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-70.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.
You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information.
Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected.
Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-70.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-4330
- https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f
- https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a
- https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a
- https://github.com/python/cpython/issues/135034
- https://github.com/python/cpython/pull/135037
- https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/
- https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da
- https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01
- https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9
- https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e
- https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a
- https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1
high severity
- Vulnerable module: less
- Introduced through: less@530-1.el8
- Fixed in: 0:530-3.el8_10
Detailed paths
-
Introduced through: centos@centos8 › less@530-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream less
package and not the less
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
Remediation
Upgrade Centos:8
less
to version 0:530-3.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-48624
- https://github.com/gwsw/less/commit/c6ac6de49698be84d264a0c4c0c40bb870b10144
- https://github.com/gwsw/less/compare/v605...v606
- https://greenwoodsoftware.com/less/
- https://lists.debian.org/debian-lts-announce/2024/05/msg00018.html
- https://security.netapp.com/advisory/ntap-20240605-0010/
high severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-225.el8_8.6
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-225.el8_8.6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4527
- http://www.openwall.com/lists/oss-security/2023/09/25/1
- https://access.redhat.com/errata/RHSA-2023:5455
- https://bugzilla.redhat.com/show_bug.cgi?id=2234712
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/
- https://security.gentoo.org/glsa/202310-03
- https://security.netapp.com/advisory/ntap-20231116-0012/
high severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-225.el8_8.6
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-225.el8_8.6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4527
- http://www.openwall.com/lists/oss-security/2023/09/25/1
- https://access.redhat.com/errata/RHSA-2023:5455
- https://bugzilla.redhat.com/show_bug.cgi?id=2234712
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/
- https://security.gentoo.org/glsa/202310-03
- https://security.netapp.com/advisory/ntap-20231116-0012/
high severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-225.el8_8.6
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-225.el8_8.6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4527
- http://www.openwall.com/lists/oss-security/2023/09/25/1
- https://access.redhat.com/errata/RHSA-2023:5455
- https://bugzilla.redhat.com/show_bug.cgi?id=2234712
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/
- https://security.gentoo.org/glsa/202310-03
- https://security.netapp.com/advisory/ntap-20231116-0012/
high severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-62.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was found in the CPython zipfile
module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.
The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-62.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-0450
- http://www.openwall.com/lists/oss-security/2024/03/20/5
- https://github.com/python/cpython/commit/30fe5d853b56138dbec62432d370a1f99409fc85
- https://github.com/python/cpython/commit/66363b9a7b9fe7c99eba3a185b74c5fdbf842eba
- https://github.com/python/cpython/commit/70497218351ba44bffc8b571201ecb5652d84675
- https://github.com/python/cpython/commit/a2c59992e9e8d35baba9695eb186ad6c6ff85c51
- https://github.com/python/cpython/commit/a956e510f6336d5ae111ba429a61c3ade30a7549
- https://github.com/python/cpython/commit/d05bac0b74153beb541b88b4fca33bf053990183
- https://github.com/python/cpython/commit/fa181fcf2156f703347b03a3b1966ce47be8ab3b
- https://github.com/python/cpython/issues/109858
- https://lists.debian.org/debian-lts-announce/2024/03/msg00024.html
- https://lists.debian.org/debian-lts-announce/2024/03/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3IGRX54M7RNCQOXVQO5KQKTGWCOABIM/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5VHWS52HGD743C47UMCSAK2A773M2YE/
- https://mail.python.org/archives/list/security-announce@python.org/thread/XELNUX2L3IOHBTFU7RQHCY6OUVEWZ2FG/
- https://security.netapp.com/advisory/ntap-20250411-0005/
- https://www.bamsoftware.com/hacks/zipbomb/
high severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-62.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was found in the CPython zipfile
module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.
The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-62.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-0450
- http://www.openwall.com/lists/oss-security/2024/03/20/5
- https://github.com/python/cpython/commit/30fe5d853b56138dbec62432d370a1f99409fc85
- https://github.com/python/cpython/commit/66363b9a7b9fe7c99eba3a185b74c5fdbf842eba
- https://github.com/python/cpython/commit/70497218351ba44bffc8b571201ecb5652d84675
- https://github.com/python/cpython/commit/a2c59992e9e8d35baba9695eb186ad6c6ff85c51
- https://github.com/python/cpython/commit/a956e510f6336d5ae111ba429a61c3ade30a7549
- https://github.com/python/cpython/commit/d05bac0b74153beb541b88b4fca33bf053990183
- https://github.com/python/cpython/commit/fa181fcf2156f703347b03a3b1966ce47be8ab3b
- https://github.com/python/cpython/issues/109858
- https://lists.debian.org/debian-lts-announce/2024/03/msg00024.html
- https://lists.debian.org/debian-lts-announce/2024/03/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3IGRX54M7RNCQOXVQO5KQKTGWCOABIM/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5VHWS52HGD743C47UMCSAK2A773M2YE/
- https://mail.python.org/archives/list/security-announce@python.org/thread/XELNUX2L3IOHBTFU7RQHCY6OUVEWZ2FG/
- https://security.netapp.com/advisory/ntap-20250411-0005/
- https://www.bamsoftware.com/hacks/zipbomb/
high severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-225.el8_8.6
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-225.el8_8.6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4813
- http://www.openwall.com/lists/oss-security/2023/10/03/8
- https://security.netapp.com/advisory/ntap-20231110-0003/
- https://access.redhat.com/errata/RHBA-2024:2413
- https://access.redhat.com/errata/RHSA-2023:5455
- https://bugzilla.redhat.com/show_bug.cgi?id=2237798
high severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-225.el8_8.6
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the nss_gethostbyname2_r and nss_getcanonname_r hooks without implementing the nss*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-225.el8_8.6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4806
- http://www.openwall.com/lists/oss-security/2023/10/03/4
- http://www.openwall.com/lists/oss-security/2023/10/03/5
- http://www.openwall.com/lists/oss-security/2023/10/03/6
- http://www.openwall.com/lists/oss-security/2023/10/03/8
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/
- https://security.gentoo.org/glsa/202310-03
- https://security.netapp.com/advisory/ntap-20240125-0008/
- https://access.redhat.com/errata/RHBA-2024:2413
- https://access.redhat.com/errata/RHSA-2023:5455
- https://bugzilla.redhat.com/show_bug.cgi?id=2237782
high severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-225.el8_8.6
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-225.el8_8.6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4813
- http://www.openwall.com/lists/oss-security/2023/10/03/8
- https://security.netapp.com/advisory/ntap-20231110-0003/
- https://access.redhat.com/errata/RHBA-2024:2413
- https://access.redhat.com/errata/RHSA-2023:5455
- https://bugzilla.redhat.com/show_bug.cgi?id=2237798
high severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-225.el8_8.6
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the nss_gethostbyname2_r and nss_getcanonname_r hooks without implementing the nss*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-225.el8_8.6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4806
- http://www.openwall.com/lists/oss-security/2023/10/03/4
- http://www.openwall.com/lists/oss-security/2023/10/03/5
- http://www.openwall.com/lists/oss-security/2023/10/03/6
- http://www.openwall.com/lists/oss-security/2023/10/03/8
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/
- https://security.gentoo.org/glsa/202310-03
- https://security.netapp.com/advisory/ntap-20240125-0008/
- https://access.redhat.com/errata/RHBA-2024:2413
- https://access.redhat.com/errata/RHSA-2023:5455
- https://bugzilla.redhat.com/show_bug.cgi?id=2237782
high severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-225.el8_8.6
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-225.el8_8.6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4813
- http://www.openwall.com/lists/oss-security/2023/10/03/8
- https://security.netapp.com/advisory/ntap-20231110-0003/
- https://access.redhat.com/errata/RHBA-2024:2413
- https://access.redhat.com/errata/RHSA-2023:5455
- https://bugzilla.redhat.com/show_bug.cgi?id=2237798
high severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-225.el8_8.6
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the nss_gethostbyname2_r and nss_getcanonname_r hooks without implementing the nss*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-225.el8_8.6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-4806
- http://www.openwall.com/lists/oss-security/2023/10/03/4
- http://www.openwall.com/lists/oss-security/2023/10/03/5
- http://www.openwall.com/lists/oss-security/2023/10/03/6
- http://www.openwall.com/lists/oss-security/2023/10/03/8
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/
- https://security.gentoo.org/glsa/202310-03
- https://security.netapp.com/advisory/ntap-20240125-0008/
- https://access.redhat.com/errata/RHBA-2024:2413
- https://access.redhat.com/errata/RHSA-2023:5455
- https://bugzilla.redhat.com/show_bug.cgi?id=2237782
high severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-9.el8_7
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE.
For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-9.el8_7 or higher.
References
high severity
- Vulnerable module: systemd
- Introduced through: systemd@239-45.el8
- Fixed in: 0:239-45.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › systemd@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd
package and not the systemd
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
Remediation
Upgrade Centos:8
systemd
to version 0:239-45.el8_4.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-33910
- https://www.debian.org/security/2021/dsa-4942
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/
- https://security.gentoo.org/glsa/202107-48
- http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.html
- https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896b
- https://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9
- https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b
- https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce
- https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538
- https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61
- https://www.openwall.com/lists/oss-security/2021/07/20/2
- http://www.openwall.com/lists/oss-security/2021/08/04/2
- http://www.openwall.com/lists/oss-security/2021/08/17/3
- http://www.openwall.com/lists/oss-security/2021/09/07/3
- https://access.redhat.com/errata/RHSA-2021:2717
- https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/
- https://security.netapp.com/advisory/ntap-20211104-0008/
high severity
- Vulnerable module: systemd-libs
- Introduced through: systemd-libs@239-45.el8
- Fixed in: 0:239-45.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › systemd-libs@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-libs
package and not the systemd-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
Remediation
Upgrade Centos:8
systemd-libs
to version 0:239-45.el8_4.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-33910
- https://www.debian.org/security/2021/dsa-4942
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/
- https://security.gentoo.org/glsa/202107-48
- http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.html
- https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896b
- https://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9
- https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b
- https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce
- https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538
- https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61
- https://www.openwall.com/lists/oss-security/2021/07/20/2
- http://www.openwall.com/lists/oss-security/2021/08/04/2
- http://www.openwall.com/lists/oss-security/2021/08/17/3
- http://www.openwall.com/lists/oss-security/2021/09/07/3
- https://access.redhat.com/errata/RHSA-2021:2717
- https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/
- https://security.netapp.com/advisory/ntap-20211104-0008/
high severity
- Vulnerable module: systemd-pam
- Introduced through: systemd-pam@239-45.el8
- Fixed in: 0:239-45.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › systemd-pam@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-pam
package and not the systemd-pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
Remediation
Upgrade Centos:8
systemd-pam
to version 0:239-45.el8_4.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-33910
- https://www.debian.org/security/2021/dsa-4942
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/
- https://security.gentoo.org/glsa/202107-48
- http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.html
- https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896b
- https://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9
- https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b
- https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce
- https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538
- https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61
- https://www.openwall.com/lists/oss-security/2021/07/20/2
- http://www.openwall.com/lists/oss-security/2021/08/04/2
- http://www.openwall.com/lists/oss-security/2021/08/17/3
- http://www.openwall.com/lists/oss-security/2021/09/07/3
- https://access.redhat.com/errata/RHSA-2021:2717
- https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/
- https://security.netapp.com/advisory/ntap-20211104-0008/
high severity
- Vulnerable module: systemd-udev
- Introduced through: systemd-udev@239-45.el8
- Fixed in: 0:239-45.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › systemd-udev@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-udev
package and not the systemd-udev
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
Remediation
Upgrade Centos:8
systemd-udev
to version 0:239-45.el8_4.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-33910
- https://www.debian.org/security/2021/dsa-4942
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/
- https://security.gentoo.org/glsa/202107-48
- http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.html
- https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896b
- https://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9
- https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b
- https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce
- https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538
- https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61
- https://www.openwall.com/lists/oss-security/2021/07/20/2
- http://www.openwall.com/lists/oss-security/2021/08/04/2
- http://www.openwall.com/lists/oss-security/2021/08/17/3
- http://www.openwall.com/lists/oss-security/2021/09/07/3
- https://access.redhat.com/errata/RHSA-2021:2717
- https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/
- https://security.netapp.com/advisory/ntap-20211104-0008/
high severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nscd: Null pointer crashes after notfound response
If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-251.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-33600
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
- https://security.netapp.com/advisory/ntap-20240524-0013/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0006
high severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nscd: Null pointer crashes after notfound response
If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-251.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-33600
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
- https://security.netapp.com/advisory/ntap-20240524-0013/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0006
high severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nscd: Null pointer crashes after notfound response
If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-251.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-33600
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
- https://security.netapp.com/advisory/ntap-20240524-0013/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0006
high severity
- Vulnerable module: pam
- Introduced through: pam@1.3.1-14.el8
- Fixed in: 0:1.3.1-36.el8_10
Detailed paths
-
Introduced through: centos@centos8 › pam@1.3.1-14.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream pam
package and not the pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.
Remediation
Upgrade Centos:8
pam
to version 0:1.3.1-36.el8_10 or higher.
References
high severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nscd: netgroup cache assumes NSS callback uses in-buffer strings
The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-251.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-33602
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
- https://security.netapp.com/advisory/ntap-20240524-0012/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008
high severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nscd: netgroup cache may terminate daemon on memory allocation failure
The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-251.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-33601
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
- https://security.netapp.com/advisory/ntap-20240524-0014/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0007
high severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nscd: netgroup cache assumes NSS callback uses in-buffer strings
The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-251.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-33602
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
- https://security.netapp.com/advisory/ntap-20240524-0012/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008
high severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nscd: netgroup cache may terminate daemon on memory allocation failure
The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-251.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-33601
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
- https://security.netapp.com/advisory/ntap-20240524-0014/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0007
high severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nscd: netgroup cache assumes NSS callback uses in-buffer strings
The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-251.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-33602
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
- https://security.netapp.com/advisory/ntap-20240524-0012/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008
high severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nscd: netgroup cache may terminate daemon on memory allocation failure
The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-251.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-33601
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
- https://security.netapp.com/advisory/ntap-20240524-0014/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0007
medium severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-164.el8
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-164.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210827-0005/
- https://sourceware.org/bugzilla/show_bug.cgi?id=28011
- https://sourceware.org/git/?p=glibc.git;a=commit;h=5adda61f62b77384718b4c0d8336ade8f2b4b35c
- https://access.redhat.com/security/cve/CVE-2021-35942
- https://sourceware.org/glibc/wiki/Security%20Exceptions
- https://access.redhat.com/errata/RHSA-2021:4358
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://security.gentoo.org/glsa/202208-24
- https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=5adda61f62b77384718b4c0d8336ade8f2b4b35c
medium severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-164.el8
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-164.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210827-0005/
- https://sourceware.org/bugzilla/show_bug.cgi?id=28011
- https://sourceware.org/git/?p=glibc.git;a=commit;h=5adda61f62b77384718b4c0d8336ade8f2b4b35c
- https://access.redhat.com/security/cve/CVE-2021-35942
- https://sourceware.org/glibc/wiki/Security%20Exceptions
- https://access.redhat.com/errata/RHSA-2021:4358
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://security.gentoo.org/glsa/202208-24
- https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=5adda61f62b77384718b4c0d8336ade8f2b4b35c
medium severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-164.el8
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-164.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210827-0005/
- https://sourceware.org/bugzilla/show_bug.cgi?id=28011
- https://sourceware.org/git/?p=glibc.git;a=commit;h=5adda61f62b77384718b4c0d8336ade8f2b4b35c
- https://access.redhat.com/security/cve/CVE-2021-35942
- https://sourceware.org/glibc/wiki/Security%20Exceptions
- https://access.redhat.com/errata/RHSA-2021:4358
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://security.gentoo.org/glsa/202208-24
- https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=5adda61f62b77384718b4c0d8336ade8f2b4b35c
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-22629
- https://access.redhat.com/errata/RHSA-2022:7704
- https://support.apple.com/en-us/HT213182
- https://support.apple.com/en-us/HT213183
- https://support.apple.com/en-us/HT213186
- https://support.apple.com/en-us/HT213187
- https://support.apple.com/en-us/HT213188
- https://support.apple.com/en-us/HT213193
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to code execution.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-26700
- https://access.redhat.com/errata/RHSA-2022:7704
- https://support.apple.com/en-us/HT213253
- https://support.apple.com/en-us/HT213254
- https://support.apple.com/en-us/HT213257
- https://support.apple.com/en-us/HT213258
- https://support.apple.com/en-us/HT213260
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-26716
- https://access.redhat.com/errata/RHSA-2022:7704
- https://support.apple.com/en-us/HT213253
- https://support.apple.com/en-us/HT213254
- https://support.apple.com/en-us/HT213257
- https://support.apple.com/en-us/HT213258
- https://support.apple.com/en-us/HT213260
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-26719
- https://access.redhat.com/errata/RHSA-2022:7704
- https://support.apple.com/en-us/HT213253
- https://support.apple.com/en-us/HT213254
- https://support.apple.com/en-us/HT213257
- https://support.apple.com/en-us/HT213258
- https://support.apple.com/en-us/HT213260
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4, tvOS 15.4, Safari 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-22628
- https://access.redhat.com/errata/RHSA-2022:7704
- https://support.apple.com/en-us/HT213182
- https://support.apple.com/en-us/HT213183
- https://support.apple.com/en-us/HT213186
- https://support.apple.com/en-us/HT213187
- https://support.apple.com/en-us/HT213193
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-26709
- https://access.redhat.com/errata/RHSA-2022:7704
- https://support.apple.com/en-us/HT213253
- https://support.apple.com/en-us/HT213254
- https://support.apple.com/en-us/HT213257
- https://support.apple.com/en-us/HT213258
- https://support.apple.com/en-us/HT213260
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, tvOS 15.5, watchOS 8.6. Processing maliciously crafted web content may lead to arbitrary code execution.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-26717
- https://access.redhat.com/errata/RHSA-2022:7704
- https://support.apple.com/en-us/HT213253
- https://support.apple.com/en-us/HT213254
- https://support.apple.com/en-us/HT213257
- https://support.apple.com/en-us/HT213258
- https://support.apple.com/en-us/HT213259
- https://support.apple.com/en-us/HT213260
- https://github.com/theori-io/CVE-2022-26717-Safari-WebGL-Exploit
medium severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
- Fixed in: 0:3.26.0-15.el8
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Remediation
Upgrade Centos:8
sqlite-libs
to version 0:3.26.0-15.el8 or higher.
References
- https://seclists.org/bugtraq/2019/Aug/19
- https://access.redhat.com/security/cve/CVE-2019-5827
- https://www.debian.org/security/2019/dsa-4500
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CPM7VPE27DUNJLXM4F5PAAEFFWOEND6X/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FKN4GPMBQ3SDXWB4HL45II5CZ7P2E4AI/
- https://security.gentoo.org/glsa/202003-16
- https://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_30.html
- https://crbug.com/952406
- https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
- https://access.redhat.com/errata/RHSA-2021:4396
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00085.html
- https://usn.ubuntu.com/4205-1/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CPM7VPE27DUNJLXM4F5PAAEFFWOEND6X/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FKN4GPMBQ3SDXWB4HL45II5CZ7P2E4AI/
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-9.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-9.el8_4.2 or higher.
References
- https://security.netapp.com/advisory/ntap-20210625-0002/
- https://access.redhat.com/security/cve/CVE-2021-3517
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZOMV5J4PMZAORVT64BKLV6YIZAFDGX6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QVM4UJ3376I6ZVOYMHBNX4GY3NIV52WV/
- https://security.gentoo.org/glsa/202107-05
- https://bugzilla.redhat.com/show_bug.cgi?id=1954232
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/05/msg00008.html
- https://access.redhat.com/errata/RHSA-2021:2569
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZOMV5J4PMZAORVT64BKLV6YIZAFDGX6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QVM4UJ3376I6ZVOYMHBNX4GY3NIV52WV/
- https://security.netapp.com/advisory/ntap-20211022-0004/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-9.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-9.el8_4.2 or higher.
References
- https://security.netapp.com/advisory/ntap-20210625-0002/
- https://support.apple.com/kb/HT212601
- https://support.apple.com/kb/HT212602
- https://support.apple.com/kb/HT212604
- https://support.apple.com/kb/HT212605
- https://access.redhat.com/security/cve/CVE-2021-3518
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZOMV5J4PMZAORVT64BKLV6YIZAFDGX6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QVM4UJ3376I6ZVOYMHBNX4GY3NIV52WV/
- http://seclists.org/fulldisclosure/2021/Jul/54
- http://seclists.org/fulldisclosure/2021/Jul/55
- http://seclists.org/fulldisclosure/2021/Jul/58
- http://seclists.org/fulldisclosure/2021/Jul/59
- https://security.gentoo.org/glsa/202107-05
- https://bugzilla.redhat.com/show_bug.cgi?id=1954242
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/05/msg00008.html
- https://access.redhat.com/errata/RHSA-2021:2569
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZOMV5J4PMZAORVT64BKLV6YIZAFDGX6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QVM4UJ3376I6ZVOYMHBNX4GY3NIV52WV/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: lz4-libs
- Introduced through: lz4-libs@1.8.3-2.el8
- Fixed in: 0:1.8.3-3.el8_4
Detailed paths
-
Introduced through: centos@centos8 › lz4-libs@1.8.3-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream lz4-libs
package and not the lz4-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
Remediation
Upgrade Centos:8
lz4-libs
to version 0:1.8.3-3.el8_4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3520
- https://bugzilla.redhat.com/show_bug.cgi?id=1954559
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://access.redhat.com/errata/RHSA-2021:2575
- https://access.redhat.com/errata/RHBA-2021:2854
- https://security.netapp.com/advisory/ntap-20211104-0005/
- https://www.oracle.com/security-alerts/cpuapr2022.html
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
- Fixed in: 0:2.30-108.el8_5.1
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard and the Unicode Bidirectional Algorithm (all versions). Due to text display behavior when text includes left-to-right and right-to-left characters, the visual order of tokens may be different from their logical order. Additionally, control characters needed to fully support the requirements of bidirectional text can further obfuscate the logical order of tokens. Unless mitigated, an adversary could craft source code such that the ordering of tokens perceived by human reviewers does not match what will be processed by a compiler/interpreter/etc. The Unicode Consortium has documented this class of vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. Also, the BIDI specification allows applications to tailor the implementation in ways that can mitigate misleading visual reordering in program text; see HL4 in Unicode Standard Annex #9, Unicode Bidirectional Algorithm.
Remediation
Upgrade Centos:8
binutils
to version 0:2.30-108.el8_5.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-42574
- https://trojansource.codes
- http://www.unicode.org/versions/Unicode14.0.0/
- http://www.openwall.com/lists/oss-security/2021/11/01/1
- https://access.redhat.com/errata/RHSA-2021:4595
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/
- http://www.openwall.com/lists/oss-security/2021/11/01/4
- http://www.openwall.com/lists/oss-security/2021/11/01/5
- http://www.openwall.com/lists/oss-security/2021/11/01/6
- http://www.openwall.com/lists/oss-security/2021/11/02/10
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/
- https://security.gentoo.org/glsa/202210-09
- https://www.kb.cert.org/vuls/id/999008
- https://www.scyon.nl/post/trojans-in-your-source-code
- https://www.starwindsoftware.com/security/sw-20220804-0002/
- https://www.unicode.org/reports/tr31/
- https://www.unicode.org/reports/tr36/
- https://www.unicode.org/reports/tr39/
- https://www.unicode.org/reports/tr9/tr9-44.html#HL4
medium severity
- Vulnerable module: libgcc
- Introduced through: libgcc@8.4.1-1.el8
- Fixed in: 0:8.5.0-4.el8_5
Detailed paths
-
Introduced through: centos@centos8 › libgcc@8.4.1-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libgcc
package and not the libgcc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard and the Unicode Bidirectional Algorithm (all versions). Due to text display behavior when text includes left-to-right and right-to-left characters, the visual order of tokens may be different from their logical order. Additionally, control characters needed to fully support the requirements of bidirectional text can further obfuscate the logical order of tokens. Unless mitigated, an adversary could craft source code such that the ordering of tokens perceived by human reviewers does not match what will be processed by a compiler/interpreter/etc. The Unicode Consortium has documented this class of vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. Also, the BIDI specification allows applications to tailor the implementation in ways that can mitigate misleading visual reordering in program text; see HL4 in Unicode Standard Annex #9, Unicode Bidirectional Algorithm.
Remediation
Upgrade Centos:8
libgcc
to version 0:8.5.0-4.el8_5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-42574
- https://trojansource.codes
- http://www.unicode.org/versions/Unicode14.0.0/
- http://www.openwall.com/lists/oss-security/2021/11/01/1
- https://access.redhat.com/errata/RHSA-2021:4587
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/
- http://www.openwall.com/lists/oss-security/2021/11/01/4
- http://www.openwall.com/lists/oss-security/2021/11/01/5
- http://www.openwall.com/lists/oss-security/2021/11/01/6
- http://www.openwall.com/lists/oss-security/2021/11/02/10
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/
- https://security.gentoo.org/glsa/202210-09
- https://www.kb.cert.org/vuls/id/999008
- https://www.scyon.nl/post/trojans-in-your-source-code
- https://www.starwindsoftware.com/security/sw-20220804-0002/
- https://www.unicode.org/reports/tr31/
- https://www.unicode.org/reports/tr36/
- https://www.unicode.org/reports/tr39/
- https://www.unicode.org/reports/tr9/tr9-44.html#HL4
medium severity
- Vulnerable module: libstdc++
- Introduced through: libstdc++@8.4.1-1.el8
- Fixed in: 0:8.5.0-4.el8_5
Detailed paths
-
Introduced through: centos@centos8 › libstdc++@8.4.1-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libstdc++
package and not the libstdc++
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard and the Unicode Bidirectional Algorithm (all versions). Due to text display behavior when text includes left-to-right and right-to-left characters, the visual order of tokens may be different from their logical order. Additionally, control characters needed to fully support the requirements of bidirectional text can further obfuscate the logical order of tokens. Unless mitigated, an adversary could craft source code such that the ordering of tokens perceived by human reviewers does not match what will be processed by a compiler/interpreter/etc. The Unicode Consortium has documented this class of vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. Also, the BIDI specification allows applications to tailor the implementation in ways that can mitigate misleading visual reordering in program text; see HL4 in Unicode Standard Annex #9, Unicode Bidirectional Algorithm.
Remediation
Upgrade Centos:8
libstdc++
to version 0:8.5.0-4.el8_5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-42574
- https://trojansource.codes
- http://www.unicode.org/versions/Unicode14.0.0/
- http://www.openwall.com/lists/oss-security/2021/11/01/1
- https://access.redhat.com/errata/RHSA-2021:4587
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/
- http://www.openwall.com/lists/oss-security/2021/11/01/4
- http://www.openwall.com/lists/oss-security/2021/11/01/5
- http://www.openwall.com/lists/oss-security/2021/11/01/6
- http://www.openwall.com/lists/oss-security/2021/11/02/10
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/
- https://security.gentoo.org/glsa/202210-09
- https://www.kb.cert.org/vuls/id/999008
- https://www.scyon.nl/post/trojans-in-your-source-code
- https://www.starwindsoftware.com/security/sw-20220804-0002/
- https://www.unicode.org/reports/tr31/
- https://www.unicode.org/reports/tr36/
- https://www.unicode.org/reports/tr39/
- https://www.unicode.org/reports/tr9/tr9-44.html#HL4
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8_6.3
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-22.el8_6.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-22576
- https://access.redhat.com/errata/RHSA-2022:5313
- https://hackerone.com/reports/1526328
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220609-0008/
- https://www.debian.org/security/2022/dsa-5197
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8_6.3
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-22.el8_6.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-22576
- https://access.redhat.com/errata/RHSA-2022:5313
- https://hackerone.com/reports/1526328
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220609-0008/
- https://www.debian.org/security/2022/dsa-5197
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-12.el8_5
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-12.el8_5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-23308
- https://access.redhat.com/errata/RHSA-2022:0899
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LA3MWWAYZADWJ5F6JOUBX65UZAMQB7RF/
- http://seclists.org/fulldisclosure/2022/May/33
- http://seclists.org/fulldisclosure/2022/May/34
- http://seclists.org/fulldisclosure/2022/May/35
- http://seclists.org/fulldisclosure/2022/May/36
- http://seclists.org/fulldisclosure/2022/May/37
- http://seclists.org/fulldisclosure/2022/May/38
- https://github.com/GNOME/libxml2/commit/652dd12a858989b14eed4e84e453059cd3ba340e
- https://gitlab.gnome.org/GNOME/libxml2/-/blob/v2.9.13/NEWS
- https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LA3MWWAYZADWJ5F6JOUBX65UZAMQB7RF/
- https://security.gentoo.org/glsa/202210-03
- https://security.netapp.com/advisory/ntap-20220331-0008/
- https://support.apple.com/kb/HT213253
- https://support.apple.com/kb/HT213254
- https://support.apple.com/kb/HT213255
- https://support.apple.com/kb/HT213256
- https://support.apple.com/kb/HT213257
- https://support.apple.com/kb/HT213258
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: lz4-libs
- Introduced through: lz4-libs@1.8.3-2.el8
- Fixed in: 0:1.8.3-5.el8_10
Detailed paths
-
Introduced through: centos@centos8 › lz4-libs@1.8.3-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream lz4-libs
package and not the lz4-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."
Remediation
Upgrade Centos:8
lz4-libs
to version 0:1.8.3-5.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2019-17543
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15941
- https://github.com/lz4/lz4/compare/v1.9.1...v1.9.2
- https://github.com/lz4/lz4/issues/801
- https://github.com/lz4/lz4/pull/756
- https://github.com/lz4/lz4/pull/760
- https://lists.apache.org/thread.html/r0fb226357e7988a241b06b93bab065bcea2eb38658b382e485960e26@%3Cissues.kudu.apache.org%3E
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://lists.apache.org/thread.html/25015588b770d67470b7ba7ea49a305d6735dd7f00eabe7d50ec1e17@%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/543302d55e2d2da4311994e9b0debdc676bf3fd05e1a2be3407aa2d6@%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/793012683dc0fa6819b7c2560e6cf990811014c40c7d75412099c357@%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/9ff0606d16be2ab6a81619e1c9e23c3e251756638e36272c8c8b7fa3@%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/f0038c4fab2ee25aee849ebeff6b33b3aa89e07ccfb06b5c87b36316@%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/f506bc371d4a068d5d84d7361293568f61167d3a1c3e91f0def2d7d3@%3Cdev.arrow.apache.org%3E
- https://lists.apache.org/thread.html/r4068ba81066792f2b4d208b39c4c4713c5d4c79bd8cb6c1904af5720@%3Cissues.kudu.apache.org%3E
- https://lists.apache.org/thread.html/r7bc72200f94298bc9a0e35637f388deb53467ca4b2e2ad1ff66d8960@%3Cissues.kudu.apache.org%3E
- https://www.oracle.com//security-alerts/cpujul2021.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00069.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00070.html
- https://lists.apache.org/thread.html/25015588b770d67470b7ba7ea49a305d6735dd7f00eabe7d50ec1e17%40%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/543302d55e2d2da4311994e9b0debdc676bf3fd05e1a2be3407aa2d6%40%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/793012683dc0fa6819b7c2560e6cf990811014c40c7d75412099c357%40%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/9ff0606d16be2ab6a81619e1c9e23c3e251756638e36272c8c8b7fa3%40%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/f0038c4fab2ee25aee849ebeff6b33b3aa89e07ccfb06b5c87b36316%40%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/f506bc371d4a068d5d84d7361293568f61167d3a1c3e91f0def2d7d3%40%3Cdev.arrow.apache.org%3E
- https://lists.apache.org/thread.html/r0fb226357e7988a241b06b93bab065bcea2eb38658b382e485960e26%40%3Cissues.kudu.apache.org%3E
- https://lists.apache.org/thread.html/r4068ba81066792f2b4d208b39c4c4713c5d4c79bd8cb6c1904af5720%40%3Cissues.kudu.apache.org%3E
- https://lists.apache.org/thread.html/r7bc72200f94298bc9a0e35637f388deb53467ca4b2e2ad1ff66d8960%40%3Cissues.kudu.apache.org%3E
- https://security.netapp.com/advisory/ntap-20210723-0001/
medium severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
- Fixed in: 0:3.26.0-16.el8_6
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
Remediation
Upgrade Centos:8
sqlite-libs
to version 0:3.26.0-16.el8_6 or higher.
References
medium severity
- Vulnerable module: squashfs-tools
- Introduced through: squashfs-tools@4.3-20.el8
- Fixed in: 0:4.3-21.el8
Detailed paths
-
Introduced through: centos@centos8 › squashfs-tools@4.3-20.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream squashfs-tools
package and not the squashfs-tools
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.
Remediation
Upgrade Centos:8
squashfs-tools
to version 0:4.3-21.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-40153
- https://www.debian.org/security/2021/dsa-4967
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSMRKVJMJFX3MB7D3PXJSYY3TLZROE5S/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RAOZ4BKWAC4Y3U2K5MMW3S77HWWXHQDL/
- https://bugs.launchpad.net/ubuntu/+source/squashfs-tools/+bug/1941790
- https://github.com/plougher/squashfs-tools/commit/79b5a555058eef4e1e7ff220c344d39f8cd09646
- https://github.com/plougher/squashfs-tools/issues/72
- https://lists.debian.org/debian-lts-announce/2021/08/msg00030.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GSMRKVJMJFX3MB7D3PXJSYY3TLZROE5S/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RAOZ4BKWAC4Y3U2K5MMW3S77HWWXHQDL/
- https://security.gentoo.org/glsa/202305-29
medium severity
- Vulnerable module: squashfs-tools
- Introduced through: squashfs-tools@4.3-20.el8
- Fixed in: 0:4.3-21.el8
Detailed paths
-
Introduced through: centos@centos8 › squashfs-tools@4.3-20.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream squashfs-tools
package and not the squashfs-tools
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.
Remediation
Upgrade Centos:8
squashfs-tools
to version 0:4.3-21.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-41072
- https://www.debian.org/security/2021/dsa-4987
- https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd
- https://github.com/plougher/squashfs-tools/issues/72#issuecomment-913833405
- https://lists.debian.org/debian-lts-announce/2021/10/msg00017.html
- https://security.gentoo.org/glsa/202305-29
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://access.redhat.com/security/cve/CVE-2021-45078
- https://sourceware.org/bugzilla/show_bug.cgi?id=28694
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=161e87d12167b1e36193385485c1f6ce92f74f02
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UQBH244M5PV6S6UMHUTCVCWFZDX7Y4M6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UUHLDDT3HH7YEY6TX7IJRGPJUTNNVEL3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQBH244M5PV6S6UMHUTCVCWFZDX7Y4M6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UUHLDDT3HH7YEY6TX7IJRGPJUTNNVEL3/
- https://security.gentoo.org/glsa/202208-30
- https://security.netapp.com/advisory/ntap-20220107-0002/
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=161e87d12167b1e36193385485c1f6ce92f74f02
medium severity
- Vulnerable module: file-libs
- Introduced through: file-libs@5.33-16.el8_3.1
- Fixed in: 0:5.33-20.el8
Detailed paths
-
Introduced through: centos@centos8 › file-libs@5.33-16.el8_3.1
NVD Description
Note: Versions mentioned in the description apply only to the upstream file-libs
package and not the file-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
Remediation
Upgrade Centos:8
file-libs
to version 0:5.33-20.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20200115-0001/
- https://access.redhat.com/security/cve/CVE-2019-18218
- https://www.debian.org/security/2019/dsa-4550
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CV6PFCEYHYALMTT45QE2U5C5TEJZQPXJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6BJVGXSCC6NMIAWX36FPWHEIFON3OSE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VBK6XOJR6OVWT2FUEBO7V7KCOSSLAP52/
- https://security.gentoo.org/glsa/202003-24
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16780
- https://github.com/file/file/commit/46a8443f76cec4b41ec736eca396984c74664f84
- https://lists.debian.org/debian-lts-announce/2019/10/msg00032.html
- https://lists.debian.org/debian-lts-announce/2021/07/msg00008.html
- https://access.redhat.com/errata/RHSA-2021:4374
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00044.html
- https://usn.ubuntu.com/4172-1/
- https://usn.ubuntu.com/4172-2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV6PFCEYHYALMTT45QE2U5C5TEJZQPXJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D6BJVGXSCC6NMIAWX36FPWHEIFON3OSE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VBK6XOJR6OVWT2FUEBO7V7KCOSSLAP52/
medium severity
- Vulnerable module: json-c
- Introduced through: json-c@0.13.1-0.4.el8
- Fixed in: 0:0.13.1-2.el8
Detailed paths
-
Introduced through: centos@centos8 › json-c@0.13.1-0.4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream json-c
package and not the json-c
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
Remediation
Upgrade Centos:8
json-c
to version 0:0.13.1-2.el8 or higher.
References
- https://github.com/json-c/json-c/pull/592
- https://security.netapp.com/advisory/ntap-20210521-0001/
- https://access.redhat.com/security/cve/CVE-2020-12762
- https://www.debian.org/security/2020/dsa-4741
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBR36IXYBHITAZFB5PFBJTED22WO5ONB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CQQRRGBQCAWNCCJ2HN3W5SSCZ4QGMXQI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W226TSCJBEOXDUFVKNWNH7ETG7AR6MCS/
- https://security.gentoo.org/glsa/202006-13
- https://github.com/rsyslog/libfastjson/issues/161
- https://lists.debian.org/debian-lts-announce/2020/05/msg00032.html
- https://lists.debian.org/debian-lts-announce/2020/05/msg00034.html
- https://lists.debian.org/debian-lts-announce/2020/07/msg00031.html
- https://access.redhat.com/errata/RHSA-2021:4382
- https://usn.ubuntu.com/4360-1/
- https://usn.ubuntu.com/4360-4/
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
- https://lists.debian.org/debian-lts-announce/2023/06/msg00023.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBR36IXYBHITAZFB5PFBJTED22WO5ONB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CQQRRGBQCAWNCCJ2HN3W5SSCZ4QGMXQI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W226TSCJBEOXDUFVKNWNH7ETG7AR6MCS/
medium severity
- Vulnerable module: libcap
- Introduced through: libcap@2.26-4.el8
- Fixed in: 0:2.48-5.el8_8
Detailed paths
-
Introduced through: centos@centos8 › libcap@2.26-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcap
package and not the libcap
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
Remediation
Upgrade Centos:8
libcap
to version 0:2.48-5.el8_8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-2603
- https://bugzilla.redhat.com/show_bug.cgi?id=2209113
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZ57ICDLMVYEREXQGZWL4GWI7FRJCRQT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPEGCFMCN5KGCFX5Y2VTKR732TTD4ADW/
- https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdf
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-15.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-15.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-40304
- https://access.redhat.com/errata/RHSA-2023:0173
- http://seclists.org/fulldisclosure/2022/Dec/21
- http://seclists.org/fulldisclosure/2022/Dec/24
- http://seclists.org/fulldisclosure/2022/Dec/25
- http://seclists.org/fulldisclosure/2022/Dec/26
- http://seclists.org/fulldisclosure/2022/Dec/27
- https://gitlab.gnome.org/GNOME/libxml2/-/commit/1b41ec4e9433b05bb0376be4725804c54ef1d80b
- https://gitlab.gnome.org/GNOME/libxml2/-/tags
- https://gitlab.gnome.org/GNOME/libxml2/-/tags/v2.10.3
- https://security.netapp.com/advisory/ntap-20221209-0003/
- https://support.apple.com/kb/HT213531
- https://support.apple.com/kb/HT213533
- https://support.apple.com/kb/HT213534
- https://support.apple.com/kb/HT213535
- https://support.apple.com/kb/HT213536
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-9.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-9.el8_4.2 or higher.
References
- https://security.netapp.com/advisory/ntap-20210716-0005/
- https://access.redhat.com/security/cve/CVE-2021-3516
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZOMV5J4PMZAORVT64BKLV6YIZAFDGX6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QVM4UJ3376I6ZVOYMHBNX4GY3NIV52WV/
- https://security.gentoo.org/glsa/202107-05
- https://bugzilla.redhat.com/show_bug.cgi?id=1954225
- https://gitlab.gnome.org/GNOME/libxml2/-/commit/1358d157d0bd83be1dfe356a69213df9fac0b539
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/230
- https://lists.debian.org/debian-lts-announce/2021/05/msg00008.html
- https://access.redhat.com/errata/RHSA-2021:2569
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZOMV5J4PMZAORVT64BKLV6YIZAFDGX6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QVM4UJ3376I6ZVOYMHBNX4GY3NIV52WV/
- https://www.oracle.com/security-alerts/cpujan2022.html
medium severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
- Fixed in: 0:6.1-9.20180224.el8_8.1
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
Remediation
Upgrade Centos:8
ncurses-base
to version 0:6.1-9.20180224.el8_8.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-29491
- http://ncurses.scripts.mit.edu/?p=ncurses.git;a=commit;h=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56
- http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56
- http://www.openwall.com/lists/oss-security/2023/04/19/10
- http://www.openwall.com/lists/oss-security/2023/04/19/11
- https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/
- https://security.netapp.com/advisory/ntap-20230517-0009/
- https://support.apple.com/kb/HT213843
- https://support.apple.com/kb/HT213844
- https://support.apple.com/kb/HT213845
- https://www.openwall.com/lists/oss-security/2023/04/12/5
- https://www.openwall.com/lists/oss-security/2023/04/13/4
medium severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
- Fixed in: 0:6.1-9.20180224.el8_8.1
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
Remediation
Upgrade Centos:8
ncurses-libs
to version 0:6.1-9.20180224.el8_8.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-29491
- http://ncurses.scripts.mit.edu/?p=ncurses.git;a=commit;h=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56
- http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56
- http://www.openwall.com/lists/oss-security/2023/04/19/10
- http://www.openwall.com/lists/oss-security/2023/04/19/11
- https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/
- https://security.netapp.com/advisory/ntap-20230517-0009/
- https://support.apple.com/kb/HT213843
- https://support.apple.com/kb/HT213844
- https://support.apple.com/kb/HT213845
- https://www.openwall.com/lists/oss-security/2023/04/12/5
- https://www.openwall.com/lists/oss-security/2023/04/13/4
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
vim is vulnerable to Heap-based Buffer Overflow
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8 or higher.
References
- https://huntr.dev/bounties/d9c17308-2c99-4f9f-a706-f7f72c24c273
- https://access.redhat.com/security/cve/CVE-2021-3778
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TE62UMYBZE4AE53K6OBBWK32XQ7544QM/
- https://github.com/vim/vim/commit/65b605665997fad54ef39a93199e305af2fe4d7f
- http://www.openwall.com/lists/oss-security/2021/10/01/1
- https://access.redhat.com/errata/RHSA-2021:4517
- https://lists.debian.org/debian-lts-announce/2022/01/msg00003.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7K4JJBIH3OQSZRVTWKCJCDLGMFGQ5DOH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S42L4Z4DTW4LHLQ4FJ33VEOXRCBE7WN4/
- https://security.gentoo.org/glsa/202208-32
- https://security.netapp.com/advisory/ntap-20221118-0003/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7K4JJBIH3OQSZRVTWKCJCDLGMFGQ5DOH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S42L4Z4DTW4LHLQ4FJ33VEOXRCBE7WN4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TE62UMYBZE4AE53K6OBBWK32XQ7544QM/
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-19.el8_6.2
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-19.el8_6.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-1629
- https://access.redhat.com/errata/RHSA-2022:5319
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HIP7KG7TVS5YF3QREAY2GOGUT3YUBZAI/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- https://github.com/vim/vim/commit/53a70289c2712808e6d4e88927e03cac01b470dd
- https://huntr.dev/bounties/e26d08d4-1886-41f0-9af4-f3e1bf3d52ee
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HIP7KG7TVS5YF3QREAY2GOGUT3YUBZAI/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213488
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-19.el8_6.4
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-19.el8_6.4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-1927
- https://access.redhat.com/errata/RHSA-2022:5813
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OZSLFIKFYU5Y2KM5EJKQNYHWRUBDQ4GJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QMFHBC5OQXDPV2SDYA2JUQGVCPYASTJB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TYNK6SDCMOLQJOI3B4AOE66P2G2IH4ZM/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- https://github.com/vim/vim/commit/4d97a565ae8be0d4debba04ebd2ac3e75a0c8010
- https://huntr.dev/bounties/945107ef-0b27-41c7-a03c-db99def0e777
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OZSLFIKFYU5Y2KM5EJKQNYHWRUBDQ4GJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMFHBC5OQXDPV2SDYA2JUQGVCPYASTJB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TYNK6SDCMOLQJOI3B4AOE66P2G2IH4ZM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213488
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8_5.12
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8_5.12 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-0261
- https://access.redhat.com/errata/RHSA-2022:0894
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- https://github.com/vim/vim/commit/9f8c304c8a390ade133bac29963dc8e56ab14cbc
- https://huntr.dev/bounties/fa795954-8775-4f23-98c6-d4d4d3fe8a82
- https://lists.debian.org/debian-lts-announce/2022/05/msg00022.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://security.gentoo.org/glsa/202208-32
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8_5.12
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8_5.12 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-0359
- https://access.redhat.com/errata/RHSA-2022:0894
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- https://github.com/vim/vim/commit/85b6747abc15a7a81086db31289cf1b8b17e6cb1
- https://huntr.dev/bounties/a3192d90-4f82-4a67-b7a6-37046cc88def
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://security.gentoo.org/glsa/202208-32
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8_5.12
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8_5.12 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-0392
- https://access.redhat.com/errata/RHSA-2022:0894
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- https://github.com/vim/vim/commit/806d037671e133bd28a7864248763f643967973a
- https://huntr.dev/bounties/d00a2acd-1935-4195-9d5b-4115ef6b3126
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html
- https://security.gentoo.org/glsa/202208-32
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8_5.12
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8_5.12 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-0361
- https://access.redhat.com/errata/RHSA-2022:0894
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- https://github.com/vim/vim/commit/dc5490e2cbc8c16022a23b449b48c1bd0083f366
- https://huntr.dev/bounties/a055618c-0311-409c-a78a-99477121965b
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://security.gentoo.org/glsa/202208-32
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-19.el8_6.4
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-19.el8_6.4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-1897
- https://access.redhat.com/errata/RHSA-2022:5813
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OZSLFIKFYU5Y2KM5EJKQNYHWRUBDQ4GJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QMFHBC5OQXDPV2SDYA2JUQGVCPYASTJB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TYNK6SDCMOLQJOI3B4AOE66P2G2IH4ZM/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- https://github.com/vim/vim/commit/338f1fc0ee3ca929387448fe464579d6113fa76a
- https://huntr.dev/bounties/82c12151-c283-40cf-aa05-2e39efa89118
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OZSLFIKFYU5Y2KM5EJKQNYHWRUBDQ4GJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMFHBC5OQXDPV2SDYA2JUQGVCPYASTJB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TYNK6SDCMOLQJOI3B4AOE66P2G2IH4ZM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213488
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8_5.4
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
vim is vulnerable to Use After Free
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8_5.4 or higher.
References
- https://huntr.dev/bounties/6dd9cb2e-a940-4093-856e-59b502429f22
- https://access.redhat.com/security/cve/CVE-2021-4192
- https://github.com/vim/vim/commit/4c13e5e6763c6eb36a343a2b8235ea227202e952
- https://access.redhat.com/errata/RHSA-2022:0366
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3FH2J57GDA2WMBS6J56F6QQRA6BXQQFZ/
- http://seclists.org/fulldisclosure/2022/Jul/14
- http://seclists.org/fulldisclosure/2022/Mar/29
- http://seclists.org/fulldisclosure/2022/May/35
- http://www.openwall.com/lists/oss-security/2022/01/15/1
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3FH2J57GDA2WMBS6J56F6QQRA6BXQQFZ/
- https://security.gentoo.org/glsa/202208-32
- https://support.apple.com/kb/HT213183
- https://support.apple.com/kb/HT213256
- https://support.apple.com/kb/HT213343
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8_5.13
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8_5.13 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-1154
- https://access.redhat.com/errata/RHSA-2022:1552
- https://github.com/vim/vim/commit/b55986c52d4cd88a22d0b0b0e8a79547ba13e1d5
- https://huntr.dev/bounties/7f0ec6bc-ea0e-45b0-8128-caac72d23425
- https://lists.debian.org/debian-lts-announce/2022/05/msg00022.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C2CQXRLBIC4S7JQVEIN5QXKQPYWB5E3J/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RAIQTUO35U5WO2NYMY47637EMCVDJRSL/
- https://security.gentoo.org/glsa/202208-32
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://security.gentoo.org/glsa/202305-16
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C2CQXRLBIC4S7JQVEIN5QXKQPYWB5E3J/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RAIQTUO35U5WO2NYMY47637EMCVDJRSL/
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-47.el8_6
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-47.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2015-20107
- https://access.redhat.com/errata/RHSA-2022:6457
- https://bugs.python.org/issue24778
- https://github.com/python/cpython/issues/68966
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/46KWPTI72SSEOF53DOYQBQOCN4QQB2GE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/53TQZFLS6O3FLIMVSXFEEPZSWLDZLBOX/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/57NECACX333A3BBZM2TR2VZ4ZE3UG3SN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5DBVY4YC2P6EPZZ2DROOXHDOWZ4BJFLW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QIKVSW3H6W2GQGDE5DTIWLGFNH6KKEW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AKGMYDVKI3XNM27B6I6RQ6QV3TVJAUCG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ERYMM2QVDPOJLX4LYXWYIQN5FOIJLDRY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F3LNY2NHM6J22O6Q5ANOE3SZRK3OACKR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FCIO2W4DUVVMI6L52QCC4TT2B3K5VWHS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FIRUTX47BJD2HYJDLMI7JJBVCYFAPKAQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GPCLGZZJPVXFWUWVV5WCD5FNUAFLKBDN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HAI2GBC7WKH7J5NH6J2IW5RT3VF2SF5M/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KAY6VBNVEFUXKJF37WFHYXUSRDEK34N3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MYG3EMFR7ZHC46TDNM7SNWO64A3W7EUF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ONXSGLASNLGFL57YU6WT6Y5YURSFV43U/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PTTZGLD2YBMMG6U6F5HOTPOGGPBIURMA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UIOJUZ5JMEMGSKNISTOVI4PDP36FDL5Y/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W5664BGZVTA46LQDNTYX5THG6CN4FYJX/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XO2H6CKWLRGTTZCGUQVELW6LUH437Q3O/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y4E2WBEJ42CGLGDHD6ZXOLZ2W6G3YOVD/
- https://python-security.readthedocs.io/vuln/mailcap-shell-injection.html
- https://security.netapp.com/advisory/ntap-20220616-0001/
- https://security.gentoo.org/glsa/202305-02
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46KWPTI72SSEOF53DOYQBQOCN4QQB2GE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/53TQZFLS6O3FLIMVSXFEEPZSWLDZLBOX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/57NECACX333A3BBZM2TR2VZ4ZE3UG3SN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5DBVY4YC2P6EPZZ2DROOXHDOWZ4BJFLW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QIKVSW3H6W2GQGDE5DTIWLGFNH6KKEW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AKGMYDVKI3XNM27B6I6RQ6QV3TVJAUCG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ERYMM2QVDPOJLX4LYXWYIQN5FOIJLDRY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F3LNY2NHM6J22O6Q5ANOE3SZRK3OACKR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCIO2W4DUVVMI6L52QCC4TT2B3K5VWHS/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FIRUTX47BJD2HYJDLMI7JJBVCYFAPKAQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GPCLGZZJPVXFWUWVV5WCD5FNUAFLKBDN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HAI2GBC7WKH7J5NH6J2IW5RT3VF2SF5M/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KAY6VBNVEFUXKJF37WFHYXUSRDEK34N3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYG3EMFR7ZHC46TDNM7SNWO64A3W7EUF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ONXSGLASNLGFL57YU6WT6Y5YURSFV43U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTTZGLD2YBMMG6U6F5HOTPOGGPBIURMA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UIOJUZ5JMEMGSKNISTOVI4PDP36FDL5Y/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W5664BGZVTA46LQDNTYX5THG6CN4FYJX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XO2H6CKWLRGTTZCGUQVELW6LUH437Q3O/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4E2WBEJ42CGLGDHD6ZXOLZ2W6G3YOVD/
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-47.el8_6
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-47.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2015-20107
- https://access.redhat.com/errata/RHSA-2022:6457
- https://bugs.python.org/issue24778
- https://github.com/python/cpython/issues/68966
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/46KWPTI72SSEOF53DOYQBQOCN4QQB2GE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/53TQZFLS6O3FLIMVSXFEEPZSWLDZLBOX/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/57NECACX333A3BBZM2TR2VZ4ZE3UG3SN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5DBVY4YC2P6EPZZ2DROOXHDOWZ4BJFLW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QIKVSW3H6W2GQGDE5DTIWLGFNH6KKEW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AKGMYDVKI3XNM27B6I6RQ6QV3TVJAUCG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ERYMM2QVDPOJLX4LYXWYIQN5FOIJLDRY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F3LNY2NHM6J22O6Q5ANOE3SZRK3OACKR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FCIO2W4DUVVMI6L52QCC4TT2B3K5VWHS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FIRUTX47BJD2HYJDLMI7JJBVCYFAPKAQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GPCLGZZJPVXFWUWVV5WCD5FNUAFLKBDN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HAI2GBC7WKH7J5NH6J2IW5RT3VF2SF5M/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KAY6VBNVEFUXKJF37WFHYXUSRDEK34N3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MYG3EMFR7ZHC46TDNM7SNWO64A3W7EUF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ONXSGLASNLGFL57YU6WT6Y5YURSFV43U/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PTTZGLD2YBMMG6U6F5HOTPOGGPBIURMA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UIOJUZ5JMEMGSKNISTOVI4PDP36FDL5Y/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W5664BGZVTA46LQDNTYX5THG6CN4FYJX/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XO2H6CKWLRGTTZCGUQVELW6LUH437Q3O/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y4E2WBEJ42CGLGDHD6ZXOLZ2W6G3YOVD/
- https://python-security.readthedocs.io/vuln/mailcap-shell-injection.html
- https://security.netapp.com/advisory/ntap-20220616-0001/
- https://security.gentoo.org/glsa/202305-02
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46KWPTI72SSEOF53DOYQBQOCN4QQB2GE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/53TQZFLS6O3FLIMVSXFEEPZSWLDZLBOX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/57NECACX333A3BBZM2TR2VZ4ZE3UG3SN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5DBVY4YC2P6EPZZ2DROOXHDOWZ4BJFLW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QIKVSW3H6W2GQGDE5DTIWLGFNH6KKEW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AKGMYDVKI3XNM27B6I6RQ6QV3TVJAUCG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ERYMM2QVDPOJLX4LYXWYIQN5FOIJLDRY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F3LNY2NHM6J22O6Q5ANOE3SZRK3OACKR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCIO2W4DUVVMI6L52QCC4TT2B3K5VWHS/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FIRUTX47BJD2HYJDLMI7JJBVCYFAPKAQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GPCLGZZJPVXFWUWVV5WCD5FNUAFLKBDN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HAI2GBC7WKH7J5NH6J2IW5RT3VF2SF5M/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KAY6VBNVEFUXKJF37WFHYXUSRDEK34N3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYG3EMFR7ZHC46TDNM7SNWO64A3W7EUF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ONXSGLASNLGFL57YU6WT6Y5YURSFV43U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTTZGLD2YBMMG6U6F5HOTPOGGPBIURMA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UIOJUZ5JMEMGSKNISTOVI4PDP36FDL5Y/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W5664BGZVTA46LQDNTYX5THG6CN4FYJX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XO2H6CKWLRGTTZCGUQVELW6LUH437Q3O/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4E2WBEJ42CGLGDHD6ZXOLZ2W6G3YOVD/
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-18.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (--ssl-reqd
on the command line orCURLOPT_USE_SSL
set to CURLUSESSL_CONTROL
or CURLUSESSL_ALL
withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations withoutTLS contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-18.el8_4.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-22946
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/
- https://hackerone.com/reports/1334111
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html
- https://access.redhat.com/errata/RHSA-2021:4059
- http://seclists.org/fulldisclosure/2022/Mar/29
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20211029-0003/
- https://security.netapp.com/advisory/ntap-20220121-0008/
- https://support.apple.com/kb/HT213183
- https://www.debian.org/security/2022/dsa-5197
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8_6.3
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-22.el8_6.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-27782
- https://access.redhat.com/errata/RHSA-2022:5313
- http://www.openwall.com/lists/oss-security/2023/03/20/6
- https://hackerone.com/reports/1555796
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220609-0009/
- https://www.debian.org/security/2022/dsa-5197
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-34.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-34.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-2398
- http://seclists.org/fulldisclosure/2024/Jul/18
- http://seclists.org/fulldisclosure/2024/Jul/19
- http://seclists.org/fulldisclosure/2024/Jul/20
- http://www.openwall.com/lists/oss-security/2024/03/27/3
- https://curl.se/docs/CVE-2024-2398.html
- https://curl.se/docs/CVE-2024-2398.json
- https://hackerone.com/reports/2402845
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2D44YLAUFJU6BZ4XFG2FYV7SBKXB5IZ6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GMD6UYKCCRCYETWQZUJ65ZRFULT6SHLI/
- https://security.netapp.com/advisory/ntap-20240503-0009/
- https://support.apple.com/kb/HT214118
- https://support.apple.com/kb/HT214119
- https://support.apple.com/kb/HT214120
medium severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-8.el8_6.2
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-8.el8_6.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-25314
- https://access.redhat.com/errata/RHSA-2022:5314
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/
- http://www.openwall.com/lists/oss-security/2022/02/19/1
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/560
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/
- https://security.gentoo.org/glsa/202209-24
- https://security.netapp.com/advisory/ntap-20220303-0008/
- https://www.debian.org/security/2022/dsa-5085
- https://www.oracle.com/security-alerts/cpuapr2022.html
medium severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-15.el8_10
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-15.el8_10 or higher.
References
medium severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-15.el8_10
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-15.el8_10 or higher.
References
medium severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-11.el8_9.1
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-11.el8_9.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-52425
- http://www.openwall.com/lists/oss-security/2024/03/20/5
- https://github.com/libexpat/libexpat/pull/789
- https://lists.debian.org/debian-lts-announce/2024/04/msg00006.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNUBSGZFEZOBHJFTAD42SAN4ATW2VEMV/
- https://security.netapp.com/advisory/ntap-20240614-0003/
medium severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-17.el8_10
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-17.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-8176
- https://bugzilla.redhat.com/show_bug.cgi?id=2310137
- https://github.com/libexpat/libexpat/issues/893
- http://www.openwall.com/lists/oss-security/2025/03/15/1
- https://blog.hartwork.org/posts/expat-2-7-0-released/
- https://bugzilla.suse.com/show_bug.cgi?id=1239618
- https://github.com/libexpat/libexpat/blob/R_2_7_0/expat/Changes#L40-L52
- https://gitlab.alpinelinux.org/alpine/aports/-/commit/d068c3ff36fc6f4789988a09c69b434db757db53
- https://security-tracker.debian.org/tracker/CVE-2024-8176
- https://ubuntu.com/security/CVE-2024-8176
- https://security.netapp.com/advisory/ntap-20250328-0009/
- https://access.redhat.com/errata/RHSA-2025:3913
- https://www.kb.cert.org/vuls/id/760160
medium severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-10.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-10.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-43680
- https://access.redhat.com/errata/RHSA-2023:0103
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AJ5VY2VYXE4WTRGQ6LMGLF6FV3SY37YE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BY4OPSIB33ETNUXZY2UPZ4NGQ3OKDY4D/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DPQVIF6TOJNY2T3ZZETFKR4G34FFREBQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FFCOMBSOJKLIKCGCJWHLJXO4EVYBG7AR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IUJ2BULJTZ2BMSKQHB6US674P55UCWWS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XG5XOOB7CD55CEE6OJYKSACSIMQ4RWQ6/
- http://www.openwall.com/lists/oss-security/2023/12/28/5
- http://www.openwall.com/lists/oss-security/2024/01/03/5
- https://github.com/libexpat/libexpat/issues/649
- https://github.com/libexpat/libexpat/pull/616
- https://github.com/libexpat/libexpat/pull/650
- https://lists.debian.org/debian-lts-announce/2022/10/msg00033.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJ5VY2VYXE4WTRGQ6LMGLF6FV3SY37YE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BY4OPSIB33ETNUXZY2UPZ4NGQ3OKDY4D/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPQVIF6TOJNY2T3ZZETFKR4G34FFREBQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFCOMBSOJKLIKCGCJWHLJXO4EVYBG7AR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUJ2BULJTZ2BMSKQHB6US674P55UCWWS/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XG5XOOB7CD55CEE6OJYKSACSIMQ4RWQ6/
- https://security.gentoo.org/glsa/202210-38
- https://security.netapp.com/advisory/ntap-20221118-0007/
- https://www.debian.org/security/2022/dsa-5266
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-10.el8_4.1
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-10.el8_4.1 or higher.
References
- https://security.netapp.com/advisory/ntap-20210319-0004/
- https://access.redhat.com/security/cve/CVE-2021-27218
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2REA7RVKN7ZHRLJOEGBRQKJIPZQPAELZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JJMPNDO4GDVURYQFYKFOWY5HAF4FTEPN/
- https://security.gentoo.org/glsa/202107-13
- https://gitlab.gnome.org/GNOME/glib/-/merge_requests/1942
- https://gitlab.gnome.org/GNOME/glib/-/merge_requests/1944
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E
- https://access.redhat.com/errata/RHSA-2021:3058
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2022/06/msg00006.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2REA7RVKN7ZHRLJOEGBRQKJIPZQPAELZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JJMPNDO4GDVURYQFYKFOWY5HAF4FTEPN/
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-30293
- https://access.redhat.com/errata/RHSA-2022:7704
- http://www.openwall.com/lists/oss-security/2022/05/30/1
- https://bugs.webkit.org/show_bug.cgi?id=237187
- https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.36.0
- https://security.gentoo.org/glsa/202208-39
- https://www.debian.org/security/2022/dsa-5154
- https://www.debian.org/security/2022/dsa-5155
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
- Fixed in: 0:3.6.16-5.el8_6
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.
Remediation
Upgrade Centos:8
gnutls
to version 0:3.6.16-5.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-2509
- https://access.redhat.com/errata/RHSA-2022:7105
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6FL27JS3VM74YEQU7PGB62USO3KSBYZX/
- https://lists.debian.org/debian-lts-announce/2022/08/msg00002.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6FL27JS3VM74YEQU7PGB62USO3KSBYZX/
- https://lists.gnupg.org/pipermail/gnutls-help/2022-July/004746.html
- https://www.debian.org/security/2022/dsa-5203
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
- Fixed in: 0:3.6.16-4.el8
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
Remediation
Upgrade Centos:8
gnutls
to version 0:3.6.16-4.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3580
- https://bugzilla.redhat.com/show_bug.cgi?id=1967983
- https://lists.debian.org/debian-lts-announce/2021/09/msg00008.html
- https://access.redhat.com/errata/RHSA-2021:4451
- https://security.gentoo.org/glsa/202401-24
- https://security.netapp.com/advisory/ntap-20211104-0006/
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
- Fixed in: 0:3.6.16-8.el8_9.1
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.
Remediation
Upgrade Centos:8
gnutls
to version 0:3.6.16-8.el8_9.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-0553
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- https://access.redhat.com/errata/RHSA-2024:0627
- https://bugzilla.redhat.com/show_bug.cgi?id=2258412
- https://gitlab.com/gnutls/gnutls/-/issues/1522
- https://lists.debian.org/debian-lts-announce/2024/02/msg00010.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZEIOLORQ7N6WRPFXZSYDL2MC4LP7VFV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GNXKVR5YNUEBNHAHM5GSYKBZX4W2HMN2/
- https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.html
- https://security.netapp.com/advisory/ntap-20240202-0011/
medium severity
- Vulnerable module: krb5-libs
- Introduced through: krb5-libs@1.18.2-8.el8
- Fixed in: 0:1.18.2-29.el8_10
Detailed paths
-
Introduced through: centos@centos8 › krb5-libs@1.18.2-8.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream krb5-libs
package and not the krb5-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.
Remediation
Upgrade Centos:8
krb5-libs
to version 0:1.18.2-29.el8_10 or higher.
References
medium severity
- Vulnerable module: krb5-libs
- Introduced through: krb5-libs@1.18.2-8.el8
- Fixed in: 0:1.18.2-8.3.el8_4
Detailed paths
-
Introduced through: centos@centos8 › krb5-libs@1.18.2-8.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream krb5-libs
package and not the krb5-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation.
Remediation
Upgrade Centos:8
krb5-libs
to version 0:1.18.2-8.3.el8_4 or higher.
References
- https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562
- https://access.redhat.com/security/cve/CVE-2021-36222
- https://www.debian.org/security/2021/dsa-4944
- https://github.com/krb5/krb5/releases
- https://web.mit.edu/kerberos/advisories/
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://access.redhat.com/errata/RHSA-2021:3576
- https://security.netapp.com/advisory/ntap-20211022-0003/
- https://security.netapp.com/advisory/ntap-20211104-0007/
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-18.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (--ssl-reqd
on the command line orCURLOPT_USE_SSL
set to CURLUSESSL_CONTROL
or CURLUSESSL_ALL
withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations withoutTLS contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-18.el8_4.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-22946
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/
- https://hackerone.com/reports/1334111
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html
- https://access.redhat.com/errata/RHSA-2021:4059
- http://seclists.org/fulldisclosure/2022/Mar/29
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20211029-0003/
- https://security.netapp.com/advisory/ntap-20220121-0008/
- https://support.apple.com/kb/HT213183
- https://www.debian.org/security/2022/dsa-5197
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8_6.3
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-22.el8_6.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-27782
- https://access.redhat.com/errata/RHSA-2022:5313
- http://www.openwall.com/lists/oss-security/2023/03/20/6
- https://hackerone.com/reports/1555796
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220609-0009/
- https://www.debian.org/security/2022/dsa-5197
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-34.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-34.el8_10.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-2398
- http://seclists.org/fulldisclosure/2024/Jul/18
- http://seclists.org/fulldisclosure/2024/Jul/19
- http://seclists.org/fulldisclosure/2024/Jul/20
- http://www.openwall.com/lists/oss-security/2024/03/27/3
- https://curl.se/docs/CVE-2024-2398.html
- https://curl.se/docs/CVE-2024-2398.json
- https://hackerone.com/reports/2402845
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2D44YLAUFJU6BZ4XFG2FYV7SBKXB5IZ6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GMD6UYKCCRCYETWQZUJ65ZRFULT6SHLI/
- https://security.netapp.com/advisory/ntap-20240503-0009/
- https://support.apple.com/kb/HT214118
- https://support.apple.com/kb/HT214119
- https://support.apple.com/kb/HT214120
medium severity
- Vulnerable module: libgcrypt
- Introduced through: libgcrypt@1.8.5-4.el8
- Fixed in: 0:1.8.5-6.el8
Detailed paths
-
Introduced through: centos@centos8 › libgcrypt@1.8.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libgcrypt
package and not the libgcrypt
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
Remediation
Upgrade Centos:8
libgcrypt
to version 0:1.8.5-6.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-33560
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/
- https://dev.gnupg.org/rCe8b7f10be275bcedb5fc05ed4837a89bfd605c61
- https://dev.gnupg.org/T5305
- https://dev.gnupg.org/T5328
- https://dev.gnupg.org/T5466
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.debian.org/debian-lts-announce/2021/06/msg00021.html
- https://access.redhat.com/errata/RHSA-2021:4409
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/
- https://security.gentoo.org/glsa/202210-13
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: libsolv
- Introduced through: libsolv@0.7.16-2.el8
- Fixed in: 0:0.7.16-3.el8_4
Detailed paths
-
Introduced through: centos@centos8 › libsolv@0.7.16-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libsolv
package and not the libsolv
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
Remediation
Upgrade Centos:8
libsolv
to version 0:0.7.16-3.el8_4 or higher.
References
medium severity
- Vulnerable module: libsolv
- Introduced through: libsolv@0.7.16-2.el8
- Fixed in: 0:0.7.16-3.el8_4
Detailed paths
-
Introduced through: centos@centos8 › libsolv@0.7.16-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libsolv
package and not the libsolv
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
Remediation
Upgrade Centos:8
libsolv
to version 0:0.7.16-3.el8_4 or higher.
References
medium severity
- Vulnerable module: libsolv
- Introduced through: libsolv@0.7.16-2.el8
- Fixed in: 0:0.7.16-3.el8_4
Detailed paths
-
Introduced through: centos@centos8 › libsolv@0.7.16-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libsolv
package and not the libsolv
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
Remediation
Upgrade Centos:8
libsolv
to version 0:0.7.16-3.el8_4 or higher.
References
medium severity
- Vulnerable module: libsolv
- Introduced through: libsolv@0.7.16-2.el8
- Fixed in: 0:0.7.16-3.el8_4
Detailed paths
-
Introduced through: centos@centos8 › libsolv@0.7.16-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libsolv
package and not the libsolv
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
Remediation
Upgrade Centos:8
libsolv
to version 0:0.7.16-3.el8_4 or higher.
References
medium severity
- Vulnerable module: libtirpc
- Introduced through: libtirpc@1.1.4-4.el8
- Fixed in: 0:1.1.4-6.el8
Detailed paths
-
Introduced through: centos@centos8 › libtirpc@1.1.4-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libtirpc
package and not the libtirpc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.
Remediation
Upgrade Centos:8
libtirpc
to version 0:1.1.4-6.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-46828
- https://access.redhat.com/errata/RHBA-2022:2065
- http://git.linux-nfs.org/?p=steved/libtirpc.git;a=commit;h=86529758570cef4c73fb9b9c4104fdc510f701ed
- http://git.linux-nfs.org/?p=steved/libtirpc.git%3Ba=commit%3Bh=86529758570cef4c73fb9b9c4104fdc510f701ed
- https://lists.debian.org/debian-lts-announce/2022/08/msg00004.html
- https://security.gentoo.org/glsa/202210-33
- https://security.netapp.com/advisory/ntap-20221007-0004/
- https://www.debian.org/security/2022/dsa-5200
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-15.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-15.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-40303
- https://access.redhat.com/errata/RHSA-2023:0173
- http://seclists.org/fulldisclosure/2022/Dec/21
- http://seclists.org/fulldisclosure/2022/Dec/24
- http://seclists.org/fulldisclosure/2022/Dec/25
- http://seclists.org/fulldisclosure/2022/Dec/26
- http://seclists.org/fulldisclosure/2022/Dec/27
- https://gitlab.gnome.org/GNOME/libxml2/-/commit/c846986356fc149915a74972bf198abc266bc2c0
- https://gitlab.gnome.org/GNOME/libxml2/-/tags/v2.10.3
- https://security.netapp.com/advisory/ntap-20221209-0003/
- https://support.apple.com/kb/HT213531
- https://support.apple.com/kb/HT213533
- https://support.apple.com/kb/HT213534
- https://support.apple.com/kb/HT213535
- https://support.apple.com/kb/HT213536
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-9.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-9.el8_4.2 or higher.
References
- https://security.netapp.com/advisory/ntap-20210625-0002/
- https://access.redhat.com/security/cve/CVE-2021-3537
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZOMV5J4PMZAORVT64BKLV6YIZAFDGX6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QVM4UJ3376I6ZVOYMHBNX4GY3NIV52WV/
- https://security.gentoo.org/glsa/202107-05
- https://bugzilla.redhat.com/show_bug.cgi?id=1956522
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.debian.org/debian-lts-announce/2021/05/msg00008.html
- https://access.redhat.com/errata/RHSA-2021:2569
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZOMV5J4PMZAORVT64BKLV6YIZAFDGX6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QVM4UJ3376I6ZVOYMHBNX4GY3NIV52WV/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-21.el8_10.3
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-21.el8_10.3 or higher.
References
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-18.el8_10.1
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-18.el8_10.1 or higher.
References
medium severity
- Vulnerable module: libzstd
- Introduced through: libzstd@1.4.4-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libzstd@1.4.4-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libzstd
package and not the libzstd
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
Remediation
There is no fixed version for Centos:8
libzstd
.
References
- https://access.redhat.com/security/cve/CVE-2022-4899
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C63HAGVLQA6FJNDCHR7CNZZL6VSLILB2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JEHRBBYYTPA4DETOM5XAKGCP37NUTLOA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QYLDK6ODVC4LJSDULLX6Q2YHTFOWABCN/
- https://github.com/facebook/zstd/issues/3200
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C63HAGVLQA6FJNDCHR7CNZZL6VSLILB2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JEHRBBYYTPA4DETOM5XAKGCP37NUTLOA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QYLDK6ODVC4LJSDULLX6Q2YHTFOWABCN/
- https://security.netapp.com/advisory/ntap-20230725-0005/
medium severity
- Vulnerable module: nettle
- Introduced through: nettle@3.4.1-2.el8
- Fixed in: 0:3.4.1-7.el8
Detailed paths
-
Introduced through: centos@centos8 › nettle@3.4.1-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream nettle
package and not the nettle
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
Remediation
Upgrade Centos:8
nettle
to version 0:3.4.1-7.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3580
- https://bugzilla.redhat.com/show_bug.cgi?id=1967983
- https://lists.debian.org/debian-lts-announce/2021/09/msg00008.html
- https://access.redhat.com/errata/RHSA-2021:4451
- https://security.gentoo.org/glsa/202401-24
- https://security.netapp.com/advisory/ntap-20211104-0006/
medium severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-4.el8
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-4.el8 or higher.
References
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=6a51b9e1d0cf0bf8515f7201b68fb0a3482b3dc1
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9b1129239f3ebb1d1c98ce9ed41d5c9476c47cb2
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846
- https://security.netapp.com/advisory/ntap-20210219-0009/
- https://www.openssl.org/news/secadv/20210216.txt
- https://www.tenable.com/security/tns-2021-03
- https://www.tenable.com/security/tns-2021-09
- https://www.tenable.com/security/tns-2021-10
- https://access.redhat.com/security/cve/CVE-2021-23840
- https://www.debian.org/security/2021/dsa-4855
- https://security.gentoo.org/glsa/202103-03
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://access.redhat.com/errata/RHSA-2021:4424
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=6a51b9e1d0cf0bf8515f7201b68fb0a3482b3dc1
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9b1129239f3ebb1d1c98ce9ed41d5c9476c47cb2
- https://kc.mcafee.com/corporate/index?page=content&id=SB10366
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
medium severity
- Vulnerable module: pcre2
- Introduced through: pcre2@10.32-2.el8
- Fixed in: 0:10.32-3.el8_6
Detailed paths
-
Introduced through: centos@centos8 › pcre2@10.32-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream pcre2
package and not the pcre2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.
Remediation
Upgrade Centos:8
pcre2
to version 0:10.32-3.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-1586
- https://access.redhat.com/errata/RHSA-2022:5809
- https://bugzilla.redhat.com/show_bug.cgi?id=2077976,
- https://github.com/PCRE2Project/pcre2/commit/50a51cb7e67268e6ad417eb07c9de9bfea5cc55a,
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DWNG2NS3GINO6LQYUVC4BZLUQPJ3DYHA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JXINO3KKI5DICQ45E2FKD6MKVMGJLEKJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KAX7767BCUFC7JMDGP7GOQ5GIZCAUGBB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M2GLQQUEY5VFM57CFYXVIFOXN2HUZPDM/
- https://bugzilla.redhat.com/show_bug.cgi?id=2077976
- https://bugzilla.redhat.com/show_bug.cgi?id=2077976%2C
- https://github.com/PCRE2Project/pcre2/commit/50a51cb7e67268e6ad417eb07c9de9bfea5cc55a
- https://github.com/PCRE2Project/pcre2/commit/50a51cb7e67268e6ad417eb07c9de9bfea5cc55a%2C
- https://github.com/PCRE2Project/pcre2/commit/d4fa336fbcc388f89095b184ba6d99422cfc676c
- https://lists.debian.org/debian-lts-announce/2023/03/msg00014.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DWNG2NS3GINO6LQYUVC4BZLUQPJ3DYHA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXINO3KKI5DICQ45E2FKD6MKVMGJLEKJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KAX7767BCUFC7JMDGP7GOQ5GIZCAUGBB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M2GLQQUEY5VFM57CFYXVIFOXN2HUZPDM/
- https://security.netapp.com/advisory/ntap-20221028-0009/
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-48.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-48.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2020-10735
- https://access.redhat.com/errata/RHSA-2023:0833
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2VCU6EVQDIXNCEDJUCTFIER2WVNNDTYZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/32AAQKABEKFCB5DDV5OONRZK6BS23HPW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EWKR2SPX3JORLWCXFY3KN2U5B5CIUQQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6XL6E5A3I36TRR73VNBOXNIQP4AMZDFZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/76YE7AM37MRU76XJV4M27CWDAMUGNRYK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HSRPVJZL6DJFWKYRHMNJB7VCEUCBKRF5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NHC6IUU7CLRQ3QLPWUXLONSG3SXFTR47/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OKYE2DOI2X7WZXAWTQJZAXYIWM37HDCY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OT5U223OE5ZOUHZAZYSYSWVJQIKDE73E/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OT5WQB7Z3CXOWVBD2AFAHYPA5ONYFFZ4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PD7FTLJOIGMUSCDR3JAN6WRFHJEE4PH5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SZYJSGLSCQOKXXFVJVJQAXLEOJBIWGEL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TD7JDDKJXK6D26XAN3YRFNM2LAJHT5UO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMWPRAAJS7I6U3U45V7GZVXWNSECI22M/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U4ZZV4CDFRMTPDBI7C5L43RFL3XLIGUY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UBPDVCDIUCEBE7C4NAGNA2KQJYOTPBAZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V7ZUJDHK7KNG6SLIFXW7MNZ6O2PUJYK6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZEOAJWGGY55QU35UM2OVZATBW5MX2OZD/
- http://www.openwall.com/lists/oss-security/2022/09/21/1
- http://www.openwall.com/lists/oss-security/2022/09/21/4
- https://bugzilla.redhat.com/show_bug.cgi?id=1834423
- https://docs.google.com/document/d/1KjuF_aXlzPUxTK4BMgezGJ2Pn7uevfX7g0_mvgHlL7Y
- https://github.com/python/cpython/issues/95778
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2VCU6EVQDIXNCEDJUCTFIER2WVNNDTYZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/32AAQKABEKFCB5DDV5OONRZK6BS23HPW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4EWKR2SPX3JORLWCXFY3KN2U5B5CIUQQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XL6E5A3I36TRR73VNBOXNIQP4AMZDFZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/76YE7AM37MRU76XJV4M27CWDAMUGNRYK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSRPVJZL6DJFWKYRHMNJB7VCEUCBKRF5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NHC6IUU7CLRQ3QLPWUXLONSG3SXFTR47/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OKYE2DOI2X7WZXAWTQJZAXYIWM37HDCY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OT5U223OE5ZOUHZAZYSYSWVJQIKDE73E/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OT5WQB7Z3CXOWVBD2AFAHYPA5ONYFFZ4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PD7FTLJOIGMUSCDR3JAN6WRFHJEE4PH5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SZYJSGLSCQOKXXFVJVJQAXLEOJBIWGEL/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TD7JDDKJXK6D26XAN3YRFNM2LAJHT5UO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMWPRAAJS7I6U3U45V7GZVXWNSECI22M/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U4ZZV4CDFRMTPDBI7C5L43RFL3XLIGUY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UBPDVCDIUCEBE7C4NAGNA2KQJYOTPBAZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V7ZUJDHK7KNG6SLIFXW7MNZ6O2PUJYK6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZEOAJWGGY55QU35UM2OVZATBW5MX2OZD/
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-67.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a MEDIUM severity vulnerability affecting CPython.
Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-67.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-6232
- https://github.com/python/cpython/commit/4eaf4891c12589e3c7bdad5f5b076e4c8392dd06
- https://github.com/python/cpython/commit/743acbe872485dc18df4d8ab2dc7895187f062c4
- https://github.com/python/cpython/commit/d449caf8a179e3b954268b3a88eb9170be3c8fbf
- https://github.com/python/cpython/commit/ed3a49ea734ada357ff4442996fd4ae71d253373
- https://github.com/python/cpython/issues/121285
- https://github.com/python/cpython/pull/121286
- https://mail.python.org/archives/list/security-announce@python.org/thread/JRYFTPRHZRTLMZLWQEUHZSJXNHM4ACTY/
- https://github.com/python/cpython/commit/34ddb64d088dd7ccc321f6103d23153256caa5d4
- https://github.com/python/cpython/commit/7d1f50cd92ff7e10a1c15a8f591dde8a6843a64d
- https://github.com/python/cpython/commit/b4225ca91547aa97ed3aca391614afbb255bc877
- http://www.openwall.com/lists/oss-security/2024/09/03/5
- https://security.netapp.com/advisory/ntap-20241018-0007/
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives.
This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1
Remediation
There is no fixed version for Centos:8
platform-python
.
References
- https://access.redhat.com/security/cve/CVE-2025-8194
- https://github.com/python/cpython/issues/130577
- https://github.com/python/cpython/pull/137027
- https://mail.python.org/archives/list/security-announce@python.org/thread/ZULLF3IZ726XP5EY7XJ7YIN3K5MDYR2D/
- https://github.com/python/cpython/commit/7040aa54f14676938970e10c5f74ea93cd56aa38
- https://github.com/python/cpython/commit/cdae923ffe187d6ef916c0f665a31249619193fe
- https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1
- https://github.com/python/cpython/commit/c9d9f78feb1467e73fd29356c040bde1c104f29f
- https://github.com/python/cpython/commit/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-48.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-48.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-45061
- https://access.redhat.com/errata/RHSA-2023:0833
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4WBZJNSALFGMPYTINIF57HAAK46U72WQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O67LRHDTJWH544KXB6KY4HMHQLYDXFPK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2AOUKI72ACV6CHY2QUFO6VK2DNMVJ2MB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/35YDIWCUMWTMDBWFRAVENFH6BLB65D6S/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/63FS6VHY4DCS74HBTEINUDOECQ2X6ZCH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7WQPHKGNXUJC3TC3BDW5RKGROWRJVSFR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B3YI6JYARWU6GULWOHNUROSACT54XFFS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GTPVDZDATRQFE6KAT6B4BQIQ4GRHIIIJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IN26PWZTYG6IF3APLRXQJBVACQHZUPT2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JCDJXNBHWXNYUTOEV4H2HCFSRKV3SYL3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JTYVESWVBPD57ZJC35G5722Q6TS37WSB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KNE4GMD45RGC2HWUAAIGTDHT5VJ2E4O4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKWAMPURWUV3DCCT4J7VHRF4NT2CFVBR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORVCQGJCCAVLN4DJDTWGREFCUWXKQRML/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PLQ2BNZVBBAQPV3SPRU24ZD37UYJJS7W/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QLUGZSEAO3MBWGKCUSMKQIRYJZKJCIOB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDK3ZZBRYFO47ET3N4BNTKVXN47U6ICY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RH57BNT4VQERGEJ5SXNXSVMDYP66YD4H/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RTN2OOLKYTG34DODUEJGT5MLC2PFGPBA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3D5TX4TDJPXHXD2QICKTY3OCQC3JARP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UHVW73QZJMHA4MK7JBT7CXX7XSNYQEGF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCMDX6IFKLOA3NXUQEV524L5LHTPI2JI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X3EJ6J7PXVQOULBQZQGBXCXY6LFF6LZD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XXZJL3CNAFS5PAIR7K4RL62S3Y7THR7O/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YPNWZKXPKTNHS5FVMN7UQZ2UPCSEFJUK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB5YCMIRVX35RUB6XPOWKENCVCJEVDRK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QCKD4AFBHXIMHS64ZER2U7QRT33HNE7L/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BWJREJHWVRBYDP43YB5WRL3QC7UBA7BR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4MYQ3IV6NWA4CKSXEHW45CH2YNDHEPH/
- https://github.com/python/cpython/issues/98433
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AOUKI72ACV6CHY2QUFO6VK2DNMVJ2MB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/35YDIWCUMWTMDBWFRAVENFH6BLB65D6S/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4WBZJNSALFGMPYTINIF57HAAK46U72WQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63FS6VHY4DCS74HBTEINUDOECQ2X6ZCH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WQPHKGNXUJC3TC3BDW5RKGROWRJVSFR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B3YI6JYARWU6GULWOHNUROSACT54XFFS/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4MYQ3IV6NWA4CKSXEHW45CH2YNDHEPH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BWJREJHWVRBYDP43YB5WRL3QC7UBA7BR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTPVDZDATRQFE6KAT6B4BQIQ4GRHIIIJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN26PWZTYG6IF3APLRXQJBVACQHZUPT2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCDJXNBHWXNYUTOEV4H2HCFSRKV3SYL3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JTYVESWVBPD57ZJC35G5722Q6TS37WSB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KNE4GMD45RGC2HWUAAIGTDHT5VJ2E4O4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKWAMPURWUV3DCCT4J7VHRF4NT2CFVBR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O67LRHDTJWH544KXB6KY4HMHQLYDXFPK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORVCQGJCCAVLN4DJDTWGREFCUWXKQRML/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PLQ2BNZVBBAQPV3SPRU24ZD37UYJJS7W/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCKD4AFBHXIMHS64ZER2U7QRT33HNE7L/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLUGZSEAO3MBWGKCUSMKQIRYJZKJCIOB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDK3ZZBRYFO47ET3N4BNTKVXN47U6ICY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RH57BNT4VQERGEJ5SXNXSVMDYP66YD4H/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTN2OOLKYTG34DODUEJGT5MLC2PFGPBA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3D5TX4TDJPXHXD2QICKTY3OCQC3JARP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHVW73QZJMHA4MK7JBT7CXX7XSNYQEGF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMDX6IFKLOA3NXUQEV524L5LHTPI2JI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3EJ6J7PXVQOULBQZQGBXCXY6LFF6LZD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XXZJL3CNAFS5PAIR7K4RL62S3Y7THR7O/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPNWZKXPKTNHS5FVMN7UQZ2UPCSEFJUK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB5YCMIRVX35RUB6XPOWKENCVCJEVDRK/
- https://security.gentoo.org/glsa/202305-02
- https://security.netapp.com/advisory/ntap-20221209-0007/
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-56.el8_9.2
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-56.el8_9.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-48560
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JZ5OOBWNYWXFTZDMCGHJVGDLDTHLWITJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VO7Y2YZSDK3UYJD2KBGLXRTGNG6T326J/
- https://bugs.python.org/issue39421
- https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html
- https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZ5OOBWNYWXFTZDMCGHJVGDLDTHLWITJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VO7Y2YZSDK3UYJD2KBGLXRTGNG6T326J/
- https://security.netapp.com/advisory/ntap-20230929-0008/
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-48.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-48.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2020-10735
- https://access.redhat.com/errata/RHSA-2023:0833
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2VCU6EVQDIXNCEDJUCTFIER2WVNNDTYZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/32AAQKABEKFCB5DDV5OONRZK6BS23HPW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EWKR2SPX3JORLWCXFY3KN2U5B5CIUQQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6XL6E5A3I36TRR73VNBOXNIQP4AMZDFZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/76YE7AM37MRU76XJV4M27CWDAMUGNRYK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HSRPVJZL6DJFWKYRHMNJB7VCEUCBKRF5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NHC6IUU7CLRQ3QLPWUXLONSG3SXFTR47/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OKYE2DOI2X7WZXAWTQJZAXYIWM37HDCY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OT5U223OE5ZOUHZAZYSYSWVJQIKDE73E/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OT5WQB7Z3CXOWVBD2AFAHYPA5ONYFFZ4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PD7FTLJOIGMUSCDR3JAN6WRFHJEE4PH5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SZYJSGLSCQOKXXFVJVJQAXLEOJBIWGEL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TD7JDDKJXK6D26XAN3YRFNM2LAJHT5UO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMWPRAAJS7I6U3U45V7GZVXWNSECI22M/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U4ZZV4CDFRMTPDBI7C5L43RFL3XLIGUY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UBPDVCDIUCEBE7C4NAGNA2KQJYOTPBAZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V7ZUJDHK7KNG6SLIFXW7MNZ6O2PUJYK6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZEOAJWGGY55QU35UM2OVZATBW5MX2OZD/
- http://www.openwall.com/lists/oss-security/2022/09/21/1
- http://www.openwall.com/lists/oss-security/2022/09/21/4
- https://bugzilla.redhat.com/show_bug.cgi?id=1834423
- https://docs.google.com/document/d/1KjuF_aXlzPUxTK4BMgezGJ2Pn7uevfX7g0_mvgHlL7Y
- https://github.com/python/cpython/issues/95778
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2VCU6EVQDIXNCEDJUCTFIER2WVNNDTYZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/32AAQKABEKFCB5DDV5OONRZK6BS23HPW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4EWKR2SPX3JORLWCXFY3KN2U5B5CIUQQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XL6E5A3I36TRR73VNBOXNIQP4AMZDFZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/76YE7AM37MRU76XJV4M27CWDAMUGNRYK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSRPVJZL6DJFWKYRHMNJB7VCEUCBKRF5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NHC6IUU7CLRQ3QLPWUXLONSG3SXFTR47/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OKYE2DOI2X7WZXAWTQJZAXYIWM37HDCY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OT5U223OE5ZOUHZAZYSYSWVJQIKDE73E/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OT5WQB7Z3CXOWVBD2AFAHYPA5ONYFFZ4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PD7FTLJOIGMUSCDR3JAN6WRFHJEE4PH5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SZYJSGLSCQOKXXFVJVJQAXLEOJBIWGEL/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TD7JDDKJXK6D26XAN3YRFNM2LAJHT5UO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMWPRAAJS7I6U3U45V7GZVXWNSECI22M/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U4ZZV4CDFRMTPDBI7C5L43RFL3XLIGUY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UBPDVCDIUCEBE7C4NAGNA2KQJYOTPBAZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V7ZUJDHK7KNG6SLIFXW7MNZ6O2PUJYK6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZEOAJWGGY55QU35UM2OVZATBW5MX2OZD/
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-67.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a MEDIUM severity vulnerability affecting CPython.
Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-67.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-6232
- https://github.com/python/cpython/commit/4eaf4891c12589e3c7bdad5f5b076e4c8392dd06
- https://github.com/python/cpython/commit/743acbe872485dc18df4d8ab2dc7895187f062c4
- https://github.com/python/cpython/commit/d449caf8a179e3b954268b3a88eb9170be3c8fbf
- https://github.com/python/cpython/commit/ed3a49ea734ada357ff4442996fd4ae71d253373
- https://github.com/python/cpython/issues/121285
- https://github.com/python/cpython/pull/121286
- https://mail.python.org/archives/list/security-announce@python.org/thread/JRYFTPRHZRTLMZLWQEUHZSJXNHM4ACTY/
- https://github.com/python/cpython/commit/34ddb64d088dd7ccc321f6103d23153256caa5d4
- https://github.com/python/cpython/commit/7d1f50cd92ff7e10a1c15a8f591dde8a6843a64d
- https://github.com/python/cpython/commit/b4225ca91547aa97ed3aca391614afbb255bc877
- http://www.openwall.com/lists/oss-security/2024/09/03/5
- https://security.netapp.com/advisory/ntap-20241018-0007/
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives.
This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1
Remediation
There is no fixed version for Centos:8
python3-libs
.
References
- https://access.redhat.com/security/cve/CVE-2025-8194
- https://github.com/python/cpython/issues/130577
- https://github.com/python/cpython/pull/137027
- https://mail.python.org/archives/list/security-announce@python.org/thread/ZULLF3IZ726XP5EY7XJ7YIN3K5MDYR2D/
- https://github.com/python/cpython/commit/7040aa54f14676938970e10c5f74ea93cd56aa38
- https://github.com/python/cpython/commit/cdae923ffe187d6ef916c0f665a31249619193fe
- https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1
- https://github.com/python/cpython/commit/c9d9f78feb1467e73fd29356c040bde1c104f29f
- https://github.com/python/cpython/commit/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-48.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-48.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-45061
- https://access.redhat.com/errata/RHSA-2023:0833
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4WBZJNSALFGMPYTINIF57HAAK46U72WQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O67LRHDTJWH544KXB6KY4HMHQLYDXFPK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2AOUKI72ACV6CHY2QUFO6VK2DNMVJ2MB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/35YDIWCUMWTMDBWFRAVENFH6BLB65D6S/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/63FS6VHY4DCS74HBTEINUDOECQ2X6ZCH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7WQPHKGNXUJC3TC3BDW5RKGROWRJVSFR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B3YI6JYARWU6GULWOHNUROSACT54XFFS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GTPVDZDATRQFE6KAT6B4BQIQ4GRHIIIJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IN26PWZTYG6IF3APLRXQJBVACQHZUPT2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JCDJXNBHWXNYUTOEV4H2HCFSRKV3SYL3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JTYVESWVBPD57ZJC35G5722Q6TS37WSB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KNE4GMD45RGC2HWUAAIGTDHT5VJ2E4O4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKWAMPURWUV3DCCT4J7VHRF4NT2CFVBR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORVCQGJCCAVLN4DJDTWGREFCUWXKQRML/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PLQ2BNZVBBAQPV3SPRU24ZD37UYJJS7W/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QLUGZSEAO3MBWGKCUSMKQIRYJZKJCIOB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDK3ZZBRYFO47ET3N4BNTKVXN47U6ICY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RH57BNT4VQERGEJ5SXNXSVMDYP66YD4H/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RTN2OOLKYTG34DODUEJGT5MLC2PFGPBA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3D5TX4TDJPXHXD2QICKTY3OCQC3JARP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UHVW73QZJMHA4MK7JBT7CXX7XSNYQEGF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCMDX6IFKLOA3NXUQEV524L5LHTPI2JI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X3EJ6J7PXVQOULBQZQGBXCXY6LFF6LZD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XXZJL3CNAFS5PAIR7K4RL62S3Y7THR7O/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YPNWZKXPKTNHS5FVMN7UQZ2UPCSEFJUK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB5YCMIRVX35RUB6XPOWKENCVCJEVDRK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QCKD4AFBHXIMHS64ZER2U7QRT33HNE7L/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BWJREJHWVRBYDP43YB5WRL3QC7UBA7BR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4MYQ3IV6NWA4CKSXEHW45CH2YNDHEPH/
- https://github.com/python/cpython/issues/98433
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AOUKI72ACV6CHY2QUFO6VK2DNMVJ2MB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/35YDIWCUMWTMDBWFRAVENFH6BLB65D6S/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4WBZJNSALFGMPYTINIF57HAAK46U72WQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63FS6VHY4DCS74HBTEINUDOECQ2X6ZCH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WQPHKGNXUJC3TC3BDW5RKGROWRJVSFR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B3YI6JYARWU6GULWOHNUROSACT54XFFS/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4MYQ3IV6NWA4CKSXEHW45CH2YNDHEPH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BWJREJHWVRBYDP43YB5WRL3QC7UBA7BR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTPVDZDATRQFE6KAT6B4BQIQ4GRHIIIJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN26PWZTYG6IF3APLRXQJBVACQHZUPT2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCDJXNBHWXNYUTOEV4H2HCFSRKV3SYL3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JTYVESWVBPD57ZJC35G5722Q6TS37WSB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KNE4GMD45RGC2HWUAAIGTDHT5VJ2E4O4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKWAMPURWUV3DCCT4J7VHRF4NT2CFVBR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O67LRHDTJWH544KXB6KY4HMHQLYDXFPK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORVCQGJCCAVLN4DJDTWGREFCUWXKQRML/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PLQ2BNZVBBAQPV3SPRU24ZD37UYJJS7W/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCKD4AFBHXIMHS64ZER2U7QRT33HNE7L/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLUGZSEAO3MBWGKCUSMKQIRYJZKJCIOB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDK3ZZBRYFO47ET3N4BNTKVXN47U6ICY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RH57BNT4VQERGEJ5SXNXSVMDYP66YD4H/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTN2OOLKYTG34DODUEJGT5MLC2PFGPBA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3D5TX4TDJPXHXD2QICKTY3OCQC3JARP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHVW73QZJMHA4MK7JBT7CXX7XSNYQEGF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMDX6IFKLOA3NXUQEV524L5LHTPI2JI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3EJ6J7PXVQOULBQZQGBXCXY6LFF6LZD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XXZJL3CNAFS5PAIR7K4RL62S3Y7THR7O/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPNWZKXPKTNHS5FVMN7UQZ2UPCSEFJUK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB5YCMIRVX35RUB6XPOWKENCVCJEVDRK/
- https://security.gentoo.org/glsa/202305-02
- https://security.netapp.com/advisory/ntap-20221209-0007/
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-56.el8_9.2
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-56.el8_9.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-48560
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JZ5OOBWNYWXFTZDMCGHJVGDLDTHLWITJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VO7Y2YZSDK3UYJD2KBGLXRTGNG6T326J/
- https://bugs.python.org/issue39421
- https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html
- https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZ5OOBWNYWXFTZDMCGHJVGDLDTHLWITJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VO7Y2YZSDK3UYJD2KBGLXRTGNG6T326J/
- https://security.netapp.com/advisory/ntap-20230929-0008/
medium severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
- Fixed in: 0:3.26.0-15.el8
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
Remediation
Upgrade Centos:8
sqlite-libs
to version 0:3.26.0-15.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20191223-0001/
- https://access.redhat.com/security/cve/CVE-2019-19603
- https://github.com/sqlite/sqlite/commit/527cbd4a104cb93bf3994b3dd3619a6299a78b13
- https://www.sqlite.org/
- https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c@%3Cissues.guacamole.apache.org%3E
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://access.redhat.com/errata/RHSA-2021:4396
- https://usn.ubuntu.com/4394-1/
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E
medium severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
- Fixed in: 0:3.26.0-16.el8_6
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.
Remediation
Upgrade Centos:8
sqlite-libs
to version 0:3.26.0-16.el8_6 or higher.
References
medium severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-164.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-164.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3999
- https://access.redhat.com/errata/RHSA-2022:0896
- https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=23e0e8f5f1fb5ed150253d986ecccdc90c2dcd5e
- https://bugzilla.redhat.com/show_bug.cgi?id=2024637
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://security-tracker.debian.org/tracker/CVE-2021-3999
- https://security.netapp.com/advisory/ntap-20221104-0001/
- https://sourceware.org/bugzilla/show_bug.cgi?id=28769
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=23e0e8f5f1fb5ed150253d986ecccdc90c2dcd5e
- https://www.openwall.com/lists/oss-security/2022/01/24/4
medium severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-164.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-164.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3999
- https://access.redhat.com/errata/RHSA-2022:0896
- https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=23e0e8f5f1fb5ed150253d986ecccdc90c2dcd5e
- https://bugzilla.redhat.com/show_bug.cgi?id=2024637
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://security-tracker.debian.org/tracker/CVE-2021-3999
- https://security.netapp.com/advisory/ntap-20221104-0001/
- https://sourceware.org/bugzilla/show_bug.cgi?id=28769
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=23e0e8f5f1fb5ed150253d986ecccdc90c2dcd5e
- https://www.openwall.com/lists/oss-security/2022/01/24/4
medium severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-164.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-164.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3999
- https://access.redhat.com/errata/RHSA-2022:0896
- https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=23e0e8f5f1fb5ed150253d986ecccdc90c2dcd5e
- https://bugzilla.redhat.com/show_bug.cgi?id=2024637
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://security-tracker.debian.org/tracker/CVE-2021-3999
- https://security.netapp.com/advisory/ntap-20221104-0001/
- https://sourceware.org/bugzilla/show_bug.cgi?id=28769
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=23e0e8f5f1fb5ed150253d986ecccdc90c2dcd5e
- https://www.openwall.com/lists/oss-security/2022/01/24/4
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
- Fixed in: 0:3.6.16-6.el8_7
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.
Remediation
Upgrade Centos:8
gnutls
to version 0:3.6.16-6.el8_7 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-0361
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFIA3X4IZ3CW7SRQ2UHNHNPMRIAWF2FI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WS4KVDOG6QTALWHC2QE4Y7VPDRMLTRWQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z634YBXAJ5VLDI62IOPBVP5K6YFHAWCY/
- https://github.com/tlsfuzzer/tlsfuzzer/pull/679
- https://gitlab.com/gnutls/gnutls/-/issues/1050
- https://lists.debian.org/debian-lts-announce/2023/02/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UFIA3X4IZ3CW7SRQ2UHNHNPMRIAWF2FI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WS4KVDOG6QTALWHC2QE4Y7VPDRMLTRWQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z634YBXAJ5VLDI62IOPBVP5K6YFHAWCY/
- https://security.netapp.com/advisory/ntap-20230324-0005/
- https://security.netapp.com/advisory/ntap-20230725-0005/
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-13.el8_6.1
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-13.el8_6.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-29824
- https://access.redhat.com/errata/RHSA-2022:5317
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FZOBT5Y6Y2QLDDX2HZGMV7MJMWGXORKK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3NVZVWFRBXBI3AKZZWUWY6INQQPQVSF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P5363EDV5VHZ5C77ODA43RYDCPMA7ARM/
- http://packetstormsecurity.com/files/167345/libxml2-xmlBufAdd-Heap-Buffer-Overflow.html
- http://packetstormsecurity.com/files/169825/libxml2-xmlParseNameComplex-Integer-Overflow.html
- https://gitlab.gnome.org/GNOME/libxml2/-/commit/2554a2408e09f13652049e5ffb0d26196b02ebab
- https://gitlab.gnome.org/GNOME/libxml2/-/commit/6c283d83eccd940bcde15634ac8c7f100e3caefd
- https://gitlab.gnome.org/GNOME/libxml2/-/tags/v2.9.14
- https://gitlab.gnome.org/GNOME/libxslt/-/tags
- https://lists.debian.org/debian-lts-announce/2022/05/msg00023.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FZOBT5Y6Y2QLDDX2HZGMV7MJMWGXORKK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3NVZVWFRBXBI3AKZZWUWY6INQQPQVSF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P5363EDV5VHZ5C77ODA43RYDCPMA7ARM/
- https://security.gentoo.org/glsa/202210-03
- https://security.netapp.com/advisory/ntap-20220715-0006/
- https://www.debian.org/security/2022/dsa-5142
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-5.el8_5
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own "d2i" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the "data" and "length" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the "data" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y).
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-5.el8_5 or higher.
References
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=94d23fcff9b2a7a8368dfe52214d5c2569882c11
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ccb0a11145ee72b042d10593a64eaf9e8a55ec12
- https://security.netapp.com/advisory/ntap-20210827-0010/
- https://www.openssl.org/news/secadv/20210824.txt
- https://www.tenable.com/security/tns-2021-16
- https://access.redhat.com/security/cve/CVE-2021-3712
- https://www.debian.org/security/2021/dsa-4963
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.apache.org/thread.html/r18995de860f0e63635f3008fd2a6aca82394249476d21691e7c59c9e@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rad5d9f83f0d11fb3f8bb148d179b8a9ad7c6a17f18d70e5805a713d1@%3Cdev.tomcat.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/09/msg00014.html
- https://lists.debian.org/debian-lts-announce/2021/09/msg00021.html
- http://www.openwall.com/lists/oss-security/2021/08/26/2
- https://access.redhat.com/errata/RHSA-2021:5226
- https://cert-portal.siemens.com/productcert/pdf/ssa-244969.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=94d23fcff9b2a7a8368dfe52214d5c2569882c11
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ccb0a11145ee72b042d10593a64eaf9e8a55ec12
- https://kc.mcafee.com/corporate/index?page=content&id=SB10366
- https://lists.apache.org/thread.html/r18995de860f0e63635f3008fd2a6aca82394249476d21691e7c59c9e%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rad5d9f83f0d11fb3f8bb148d179b8a9ad7c6a17f18d70e5805a713d1%40%3Cdev.tomcat.apache.org%3E
- https://security.gentoo.org/glsa/202209-02
- https://security.gentoo.org/glsa/202210-02
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.tenable.com/security/tns-2022-02
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-48.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-48.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-28861
- https://access.redhat.com/errata/RHSA-2023:0833
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2TRINJE3INWDVIHIABW4L2NP3RUSK7BJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5LTSPFIULY2GZJN3QYNFVM4JSU6H4D6J/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5OABQ5CMPQETJLFHROAXDIDXCMDTNVYG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DISZAFSIQ7IAPAEQTC7G2Z5QUA2V2PSW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HPX4XHT2FGVQYLY2STT2MRVENILNZTTU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I3MQT5ZE3QH5PVDJMERTBOCILHK35CBE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KRGKPYA5YHIXQAMRIXO5DSCX7D4UUW4Q/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OKYE2DOI2X7WZXAWTQJZAXYIWM37HDCY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QLE5INSVJUZJGY5OJXV6JREXWD7UDHYN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S7G66SRWUM36ENQ3X6LAIG7HAB27D4XJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TZEPOPUFC42KXXSLFPZ47ZZRGPOR7SQE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X46T4EFTIBXZRYTGASBDEZGYJINH2OWV/
- https://bugs.python.org/issue43223
- https://github.com/python/cpython/pull/24848
- https://github.com/python/cpython/pull/93879
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2TRINJE3INWDVIHIABW4L2NP3RUSK7BJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LTSPFIULY2GZJN3QYNFVM4JSU6H4D6J/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5OABQ5CMPQETJLFHROAXDIDXCMDTNVYG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DISZAFSIQ7IAPAEQTC7G2Z5QUA2V2PSW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPX4XHT2FGVQYLY2STT2MRVENILNZTTU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I3MQT5ZE3QH5PVDJMERTBOCILHK35CBE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRGKPYA5YHIXQAMRIXO5DSCX7D4UUW4Q/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OKYE2DOI2X7WZXAWTQJZAXYIWM37HDCY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLE5INSVJUZJGY5OJXV6JREXWD7UDHYN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S7G66SRWUM36ENQ3X6LAIG7HAB27D4XJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZEPOPUFC42KXXSLFPZ47ZZRGPOR7SQE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X46T4EFTIBXZRYTGASBDEZGYJINH2OWV/
- https://security.gentoo.org/glsa/202305-02
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-48.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-48.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-28861
- https://access.redhat.com/errata/RHSA-2023:0833
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2TRINJE3INWDVIHIABW4L2NP3RUSK7BJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5LTSPFIULY2GZJN3QYNFVM4JSU6H4D6J/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5OABQ5CMPQETJLFHROAXDIDXCMDTNVYG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DISZAFSIQ7IAPAEQTC7G2Z5QUA2V2PSW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HPX4XHT2FGVQYLY2STT2MRVENILNZTTU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I3MQT5ZE3QH5PVDJMERTBOCILHK35CBE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KRGKPYA5YHIXQAMRIXO5DSCX7D4UUW4Q/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OKYE2DOI2X7WZXAWTQJZAXYIWM37HDCY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QLE5INSVJUZJGY5OJXV6JREXWD7UDHYN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S7G66SRWUM36ENQ3X6LAIG7HAB27D4XJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TZEPOPUFC42KXXSLFPZ47ZZRGPOR7SQE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X46T4EFTIBXZRYTGASBDEZGYJINH2OWV/
- https://bugs.python.org/issue43223
- https://github.com/python/cpython/pull/24848
- https://github.com/python/cpython/pull/93879
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2TRINJE3INWDVIHIABW4L2NP3RUSK7BJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LTSPFIULY2GZJN3QYNFVM4JSU6H4D6J/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5OABQ5CMPQETJLFHROAXDIDXCMDTNVYG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DISZAFSIQ7IAPAEQTC7G2Z5QUA2V2PSW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPX4XHT2FGVQYLY2STT2MRVENILNZTTU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I3MQT5ZE3QH5PVDJMERTBOCILHK35CBE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRGKPYA5YHIXQAMRIXO5DSCX7D4UUW4Q/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OKYE2DOI2X7WZXAWTQJZAXYIWM37HDCY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLE5INSVJUZJGY5OJXV6JREXWD7UDHYN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S7G66SRWUM36ENQ3X6LAIG7HAB27D4XJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZEPOPUFC42KXXSLFPZ47ZZRGPOR7SQE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X46T4EFTIBXZRYTGASBDEZGYJINH2OWV/
- https://security.gentoo.org/glsa/202305-02
medium severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
- Fixed in: 0:3.3.3-3.el8_5
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.
Remediation
Upgrade Centos:8
libarchive
to version 0:3.3.3-3.el8_5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-23177
- https://access.redhat.com/errata/RHSA-2022:0892
- https://bugzilla.redhat.com/show_bug.cgi?id=2024245
- https://github.com/libarchive/libarchive/commit/fba4f123cc456d2b2538f811bb831483bf336bad
- https://github.com/libarchive/libarchive/issues/1565
- https://lists.debian.org/debian-lts-announce/2022/11/msg00030.html
medium severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
- Fixed in: 0:3.26.0-19.el8_9
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.
Remediation
Upgrade Centos:8
sqlite-libs
to version 0:3.26.0-19.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-7104
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AYONA2XSNFMXLAW4IHLFI5UVV3QRNG5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/
- https://security.netapp.com/advisory/ntap-20240112-0008/
- https://sqlite.org/forum/forumpost/5bcbf4571c
- https://sqlite.org/src/info/0e4e7a05c4204b47
- https://vuldb.com/?ctiid.248999
- https://vuldb.com/?id.248999
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8_5.4
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
vim is vulnerable to Heap-based Buffer Overflow
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8_5.4 or higher.
References
- https://huntr.dev/bounties/b114b5a2-18e2-49f0-b350-15994d71426a
- https://access.redhat.com/security/cve/CVE-2021-3984
- https://github.com/vim/vim/commit/2de9b7c7c8791da8853a9a7ca9c467867465b655
- https://access.redhat.com/errata/RHSA-2022:0366
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNXY7T5OORA7UJIMGSJBGHFMU6UZWS6P/
- http://www.openwall.com/lists/oss-security/2022/01/15/1
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNXY7T5OORA7UJIMGSJBGHFMU6UZWS6P/
- https://security.gentoo.org/glsa/202208-32
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-19.el8_6.2
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-19.el8_6.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-1621
- https://access.redhat.com/errata/RHSA-2022:5319
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HIP7KG7TVS5YF3QREAY2GOGUT3YUBZAI/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- https://github.com/vim/vim/commit/7c824682d2028432ee082703ef0ab399867a089b
- https://huntr.dev/bounties/520ce714-bfd2-4646-9458-f52cd22bb2fb
- https://lists.debian.org/debian-lts-announce/2022/05/msg00022.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HIP7KG7TVS5YF3QREAY2GOGUT3YUBZAI/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213488
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-19.el8_6.4
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-19.el8_6.4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-1785
- https://access.redhat.com/errata/RHSA-2022:5813
- https://github.com/vim/vim/commit/e2bd8600b873d2cd1f9d667c28cba8b1dba18839
- https://huntr.dev/bounties/8c969cba-eef2-4943-b44a-4e3089599109
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
vim is vulnerable to Use After Free
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8 or higher.
References
- https://huntr.dev/bounties/ab60b7f3-6fb1-4ac2-a4fa-4d592e08008d
- https://access.redhat.com/security/cve/CVE-2021-3796
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TE62UMYBZE4AE53K6OBBWK32XQ7544QM/
- https://github.com/vim/vim/commit/35a9a00afcb20897d462a766793ff45534810dc3
- http://www.openwall.com/lists/oss-security/2021/10/01/1
- https://access.redhat.com/errata/RHSA-2021:4517
- https://lists.debian.org/debian-lts-announce/2022/01/msg00003.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7K4JJBIH3OQSZRVTWKCJCDLGMFGQ5DOH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S42L4Z4DTW4LHLQ4FJ33VEOXRCBE7WN4/
- https://security.gentoo.org/glsa/202208-32
- https://security.netapp.com/advisory/ntap-20221118-0004/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7K4JJBIH3OQSZRVTWKCJCDLGMFGQ5DOH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S42L4Z4DTW4LHLQ4FJ33VEOXRCBE7WN4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TE62UMYBZE4AE53K6OBBWK32XQ7544QM/
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8_5.12
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use After Free in GitHub repository vim/vim prior to 8.2.
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8_5.12 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-0413
- https://access.redhat.com/errata/RHSA-2022:0894
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZLEHVP4LNAGER4ZDGUDS5V5YVQD6INF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFXFAILMLUIK4MBUEZO4HNBNKYZRJ5AP/
- https://github.com/vim/vim/commit/37f47958b8a2a44abc60614271d9537e7f14e51a
- https://huntr.dev/bounties/563d1e8f-5c3d-4669-941c-3216f4a87c38
- https://lists.debian.org/debian-lts-announce/2022/05/msg00022.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7ZLEHVP4LNAGER4ZDGUDS5V5YVQD6INF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UFXFAILMLUIK4MBUEZO4HNBNKYZRJ5AP/
- https://security.gentoo.org/glsa/202208-32
medium severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
- Fixed in: 0:3.3.3-3.el8_5
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.
Remediation
Upgrade Centos:8
libarchive
to version 0:3.3.3-3.el8_5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-31566
- https://access.redhat.com/errata/RHSA-2022:0892
- https://bugzilla.redhat.com/show_bug.cgi?id=2024237
- https://github.com/libarchive/libarchive/commit/b41daecb5ccb4c8e3b2c53fd6147109fc12c3043
- https://github.com/libarchive/libarchive/issues/1566
- https://lists.debian.org/debian-lts-announce/2022/11/msg00030.html
medium severity
- Vulnerable module: platform-python-setuptools
- Introduced through: platform-python-setuptools@39.2.0-6.el8
- Fixed in: 0:39.2.0-9.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python-setuptools@39.2.0-6.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python-setuptools
package and not the platform-python-setuptools
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in PackageIndex
is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.
Remediation
Upgrade Centos:8
platform-python-setuptools
to version 0:39.2.0-9.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-47273
- https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88
- https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b
- https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf
- https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html
- https://github.com/pypa/setuptools/issues/4946
medium severity
- Vulnerable module: python3-setuptools-wheel
- Introduced through: python3-setuptools-wheel@39.2.0-6.el8
- Fixed in: 0:39.2.0-9.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-setuptools-wheel@39.2.0-6.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-setuptools-wheel
package and not the python3-setuptools-wheel
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in PackageIndex
is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.
Remediation
Upgrade Centos:8
python3-setuptools-wheel
to version 0:39.2.0-9.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-47273
- https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88
- https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b
- https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf
- https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html
- https://github.com/pypa/setuptools/issues/4946
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8_5.4
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
vim is vulnerable to Heap-based Buffer Overflow
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8_5.4 or higher.
References
- https://huntr.dev/bounties/d8798584-a6c9-4619-b18f-001b9a6fca92
- https://access.redhat.com/security/cve/CVE-2021-4019
- https://github.com/vim/vim/commit/bd228fd097b41a798f90944b5d1245eddd484142
- https://access.redhat.com/errata/RHSA-2022:0366
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DRPAI5JVZLI7WHWSBR6NWAPBQAYUQREW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNXY7T5OORA7UJIMGSJBGHFMU6UZWS6P/
- http://www.openwall.com/lists/oss-security/2022/01/15/1
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DRPAI5JVZLI7WHWSBR6NWAPBQAYUQREW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNXY7T5OORA7UJIMGSJBGHFMU6UZWS6P/
- https://security.gentoo.org/glsa/202208-32
medium severity
- Vulnerable module: cpio
- Introduced through: cpio@2.12-10.el8
- Fixed in: 0:2.12-11.el8
Detailed paths
-
Introduced through: centos@centos8 › cpio@2.12-10.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream cpio
package and not the cpio
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
Remediation
Upgrade Centos:8
cpio
to version 0:2.12-11.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-38185
- https://github.com/fangqyi/cpiopwn
- https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=dd96882877721703e19272fe25034560b794061b
- https://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00000.html
- https://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00002.html
- https://access.redhat.com/errata/RHSA-2022:1991
- https://lists.debian.org/debian-lts-announce/2023/06/msg00007.html
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-166.el8_10
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-166.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-52533
- https://gitlab.gnome.org/GNOME/glib/-/issues/3461
- https://gitlab.gnome.org/GNOME/glib/-/releases/2.82.1
- https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home
- http://www.openwall.com/lists/oss-security/2024/11/12/11
- https://lists.debian.org/debian-lts-announce/2024/11/msg00020.html
- https://security.netapp.com/advisory/ntap-20241206-0009/
medium severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-164.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-164.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-23218
- https://access.redhat.com/errata/RHSA-2022:0896
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://security.gentoo.org/glsa/202208-24
- https://sourceware.org/bugzilla/show_bug.cgi?id=28768
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-164.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-164.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-23219
- https://access.redhat.com/errata/RHSA-2022:0896
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://security.gentoo.org/glsa/202208-24
- https://sourceware.org/bugzilla/show_bug.cgi?id=22542
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.22
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-251.el8_10.22 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-4802
- https://sourceware.org/bugzilla/show_bug.cgi?id=32976
- https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e
- http://www.openwall.com/lists/oss-security/2025/05/16/7
- http://www.openwall.com/lists/oss-security/2025/05/17/2
medium severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-164.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-164.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-23218
- https://access.redhat.com/errata/RHSA-2022:0896
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://security.gentoo.org/glsa/202208-24
- https://sourceware.org/bugzilla/show_bug.cgi?id=28768
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-164.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-164.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-23219
- https://access.redhat.com/errata/RHSA-2022:0896
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://security.gentoo.org/glsa/202208-24
- https://sourceware.org/bugzilla/show_bug.cgi?id=22542
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.22
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-251.el8_10.22 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-4802
- https://sourceware.org/bugzilla/show_bug.cgi?id=32976
- https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e
- http://www.openwall.com/lists/oss-security/2025/05/16/7
- http://www.openwall.com/lists/oss-security/2025/05/17/2
medium severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-164.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-164.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-23218
- https://access.redhat.com/errata/RHSA-2022:0896
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://security.gentoo.org/glsa/202208-24
- https://sourceware.org/bugzilla/show_bug.cgi?id=28768
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-164.el8_5.3
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-164.el8_5.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-23219
- https://access.redhat.com/errata/RHSA-2022:0896
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://security.gentoo.org/glsa/202208-24
- https://sourceware.org/bugzilla/show_bug.cgi?id=22542
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.22
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-251.el8_10.22 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-4802
- https://sourceware.org/bugzilla/show_bug.cgi?id=32976
- https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e
- http://www.openwall.com/lists/oss-security/2025/05/16/7
- http://www.openwall.com/lists/oss-security/2025/05/17/2
medium severity
- Vulnerable module: tar
- Introduced through: tar@2:1.30-5.el8
Detailed paths
-
Introduced through: centos@centos8 › tar@2:1.30-5.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream tar
package and not the tar
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
Remediation
There is no fixed version for Centos:8
tar
.
References
- http://marc.info/?l=bugtraq&m=112327628230258&w=2
- https://access.redhat.com/security/cve/CVE-2005-2541
- https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c@%3Cissues.guacamole.apache.org%3E
- https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E
medium severity
- Vulnerable module: zlib
- Introduced through: zlib@1.2.11-17.el8
- Fixed in: 0:1.2.11-19.el8_6
Detailed paths
-
Introduced through: centos@centos8 › zlib@1.2.11-17.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream zlib
package and not the zlib
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
Remediation
Upgrade Centos:8
zlib
to version 0:1.2.11-19.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-37434
- https://access.redhat.com/errata/RHSA-2022:7106
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/
- https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d
- http://seclists.org/fulldisclosure/2022/Oct/37
- http://seclists.org/fulldisclosure/2022/Oct/38
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/42
- http://www.openwall.com/lists/oss-security/2022/08/05/2
- http://www.openwall.com/lists/oss-security/2022/08/09/1
- https://github.com/ivd38/zlib_overflow
- https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063
- https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1
- https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764
- https://lists.debian.org/debian-lts-announce/2022/09/msg00012.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/
- https://security.netapp.com/advisory/ntap-20220901-0005/
- https://security.netapp.com/advisory/ntap-20230427-0007/
- https://support.apple.com/kb/HT213488
- https://support.apple.com/kb/HT213489
- https://support.apple.com/kb/HT213490
- https://support.apple.com/kb/HT213491
- https://support.apple.com/kb/HT213493
- https://support.apple.com/kb/HT213494
- https://www.debian.org/security/2022/dsa-5218
- https://github.com/curl/curl/issues/9271
medium severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-5.el8
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-5.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-25220
- https://access.redhat.com/errata/RHSA-2022:7790
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
- https://kb.isc.org/v1/docs/cve-2021-25220
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2SXT7247QTKNBQ67MNRGZD23ADXU6E5U/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5VX3I2U3ICOIEI5Y7OYA6CHOLFMNH3YQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/API7U5E7SX7BAAVFNW366FFJGD6NZZKV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DE3UAVCPUMAKG27ZL5YXSP2C3RIOW3JZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYD7US4HZRFUGAJ66ZTHFBYVP5N3OQBY/
- https://security.gentoo.org/glsa/202210-25
- https://security.netapp.com/advisory/ntap-20220408-0001/
- https://supportportal.juniper.net/s/article/2022-10-Security-Bulletin-Junos-OS-SRX-Series-Cache-poisoning-vulnerability-in-BIND-used-by-DNS-Proxy-CVE-2021-25220?language=en_US
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SXT7247QTKNBQ67MNRGZD23ADXU6E5U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VX3I2U3ICOIEI5Y7OYA6CHOLFMNH3YQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/API7U5E7SX7BAAVFNW366FFJGD6NZZKV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DE3UAVCPUMAKG27ZL5YXSP2C3RIOW3JZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYD7US4HZRFUGAJ66ZTHFBYVP5N3OQBY/
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-67.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a MEDIUM severity vulnerability affecting CPython.
The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-67.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-6923
- https://github.com/python/cpython/issues/121650
- https://github.com/python/cpython/pull/122233
- https://mail.python.org/archives/list/security-announce@python.org/thread/QH3BUOE2DYQBWP7NAQ7UNHPPOELKISRW/
- https://github.com/python/cpython/commit/4766d1200fdf8b6728137aa2927a297e224d5fa7
- https://github.com/python/cpython/commit/4aaa4259b5a6e664b7316a4d60bdec7ee0f124d0
- https://github.com/python/cpython/commit/06f28dc236708f72871c64d4bc4b4ea144c50147
- https://github.com/python/cpython/commit/b158a76ce094897c870fb6b3de62887b7ccc33f1
- https://github.com/python/cpython/commit/f7be505d137a22528cb0fc004422c0081d5d90e6
- https://github.com/python/cpython/commit/f7c0f09e69e950cf3c5ada9dbde93898eb975533
- http://www.openwall.com/lists/oss-security/2024/08/01/3
- http://www.openwall.com/lists/oss-security/2024/08/02/2
- https://security.netapp.com/advisory/ntap-20240926-0003/
- https://lists.debian.org/debian-lts-announce/2025/01/msg00005.html
- https://github.com/python/cpython/commit/097633981879b3c9de9a1dd120d3aa585ecc2384
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The Python standard library functions urllib.parse.urlsplit
and urlparse
accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.
Remediation
There is no fixed version for Centos:8
platform-python
.
References
- https://access.redhat.com/security/cve/CVE-2025-0938
- https://github.com/python/cpython/issues/105704
- https://github.com/python/cpython/pull/129418
- https://github.com/python/cpython/commit/d89a5f6a6e65511a5f6e0618c4c30a7aa5aba56a
- https://mail.python.org/archives/list/security-announce@python.org/thread/K4EUG6EKV6JYFIC24BASYOZS4M5XOQIB/
- https://github.com/python/cpython/commit/90e526ae67b172ed7c6c56e7edad36263b0f9403
- https://github.com/python/cpython/commit/a7084f6075c9595ba60119ce8c62f1496f50c568
- https://github.com/python/cpython/commit/526617ed68cde460236c973e5d0a8bad4de896ba
- https://github.com/python/cpython/commit/b8b4b713c5f8ec0958c7ef8d29d6711889bc94ab
- https://github.com/python/cpython/commit/ff4e5c25666f63544071a6b075ae8b25c98b7a32
- https://security.netapp.com/advisory/ntap-20250314-0002/
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-67.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a MEDIUM severity vulnerability affecting CPython.
The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-67.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-6923
- https://github.com/python/cpython/issues/121650
- https://github.com/python/cpython/pull/122233
- https://mail.python.org/archives/list/security-announce@python.org/thread/QH3BUOE2DYQBWP7NAQ7UNHPPOELKISRW/
- https://github.com/python/cpython/commit/4766d1200fdf8b6728137aa2927a297e224d5fa7
- https://github.com/python/cpython/commit/4aaa4259b5a6e664b7316a4d60bdec7ee0f124d0
- https://github.com/python/cpython/commit/06f28dc236708f72871c64d4bc4b4ea144c50147
- https://github.com/python/cpython/commit/b158a76ce094897c870fb6b3de62887b7ccc33f1
- https://github.com/python/cpython/commit/f7be505d137a22528cb0fc004422c0081d5d90e6
- https://github.com/python/cpython/commit/f7c0f09e69e950cf3c5ada9dbde93898eb975533
- http://www.openwall.com/lists/oss-security/2024/08/01/3
- http://www.openwall.com/lists/oss-security/2024/08/02/2
- https://security.netapp.com/advisory/ntap-20240926-0003/
- https://lists.debian.org/debian-lts-announce/2025/01/msg00005.html
- https://github.com/python/cpython/commit/097633981879b3c9de9a1dd120d3aa585ecc2384
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The Python standard library functions urllib.parse.urlsplit
and urlparse
accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.
Remediation
There is no fixed version for Centos:8
python3-libs
.
References
- https://access.redhat.com/security/cve/CVE-2025-0938
- https://github.com/python/cpython/issues/105704
- https://github.com/python/cpython/pull/129418
- https://github.com/python/cpython/commit/d89a5f6a6e65511a5f6e0618c4c30a7aa5aba56a
- https://mail.python.org/archives/list/security-announce@python.org/thread/K4EUG6EKV6JYFIC24BASYOZS4M5XOQIB/
- https://github.com/python/cpython/commit/90e526ae67b172ed7c6c56e7edad36263b0f9403
- https://github.com/python/cpython/commit/a7084f6075c9595ba60119ce8c62f1496f50c568
- https://github.com/python/cpython/commit/526617ed68cde460236c973e5d0a8bad4de896ba
- https://github.com/python/cpython/commit/b8b4b713c5f8ec0958c7ef8d29d6711889bc94ab
- https://github.com/python/cpython/commit/ff4e5c25666f63544071a6b075ae8b25c98b7a32
- https://security.netapp.com/advisory/ntap-20250314-0002/
medium severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-7.el8_6
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-7.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-1292
- https://access.redhat.com/errata/RHSA-2022:5818
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=548d3f280a6e737673f5b61fce24bb100108dfeb
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VX4KWHPMKYJL6ZLW4M5IU7E5UV5ZWJQU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZNU5M7BXMML26G3GPYKFGQYPQDRSNKDD/
- https://cert-portal.siemens.com/productcert/pdf/ssa-953464.pdf
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=548d3f280a6e737673f5b61fce24bb100108dfeb
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23
- https://gitlab.com/fraf0/cve-2022-1292-re_score-analysis
- https://lists.debian.org/debian-lts-announce/2022/05/msg00019.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VX4KWHPMKYJL6ZLW4M5IU7E5UV5ZWJQU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNU5M7BXMML26G3GPYKFGQYPQDRSNKDD/
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0011
- https://security.gentoo.org/glsa/202210-02
- https://security.netapp.com/advisory/ntap-20220602-0009/
- https://security.netapp.com/advisory/ntap-20220729-0004/
- https://www.debian.org/security/2022/dsa-5139
- https://www.openssl.org/news/secadv/20220503.txt
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://github.com/alcaparra/CVE-2022-1292
medium severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-7.el8_6
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze).
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-7.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-2068
- https://access.redhat.com/errata/RHSA-2022:5818
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2c9c35870601b4a44d86ddbf512b38df38285cfa
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=7a9c027159fe9e1bbc2cd38a8a2914bff0d5abd9
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9639817dac8bbbaa64d09efad7464ccc405527c7
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6WZZBKUHQFGSKGNXXKICSRPL7AMVW5M5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/
- https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2c9c35870601b4a44d86ddbf512b38df38285cfa
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7a9c027159fe9e1bbc2cd38a8a2914bff0d5abd9
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9639817dac8bbbaa64d09efad7464ccc405527c7
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WZZBKUHQFGSKGNXXKICSRPL7AMVW5M5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/
- https://security.netapp.com/advisory/ntap-20220707-0008/
- https://www.debian.org/security/2022/dsa-5169
- https://www.openssl.org/news/secadv/20220621.txt
medium severity
- Vulnerable module: python3-rpm
- Introduced through: python3-rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-14.el8_4
Detailed paths
-
Introduced through: centos@centos8 › python3-rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-rpm
package and not the python3-rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
Remediation
Upgrade Centos:8
python3-rpm
to version 0:4.14.3-14.el8_4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-20271
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://bugzilla.redhat.com/show_bug.cgi?id=1934125
- https://github.com/rpm-software-management/rpm/commit/d6a86b5e69e46cc283b1e06c92343319beb42e21
- https://access.redhat.com/errata/RHSA-2021:2574
- https://access.redhat.com/errata/RHBA-2021:2854
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://security.gentoo.org/glsa/202107-43
- https://www.starwindsoftware.com/security/sw-20220805-0002/
medium severity
- Vulnerable module: rpm
- Introduced through: rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-14.el8_4
Detailed paths
-
Introduced through: centos@centos8 › rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm
package and not the rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
Remediation
Upgrade Centos:8
rpm
to version 0:4.14.3-14.el8_4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-20271
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://bugzilla.redhat.com/show_bug.cgi?id=1934125
- https://github.com/rpm-software-management/rpm/commit/d6a86b5e69e46cc283b1e06c92343319beb42e21
- https://access.redhat.com/errata/RHSA-2021:2574
- https://access.redhat.com/errata/RHBA-2021:2854
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://security.gentoo.org/glsa/202107-43
- https://www.starwindsoftware.com/security/sw-20220805-0002/
medium severity
- Vulnerable module: rpm-build-libs
- Introduced through: rpm-build-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-14.el8_4
Detailed paths
-
Introduced through: centos@centos8 › rpm-build-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-build-libs
package and not the rpm-build-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
Remediation
Upgrade Centos:8
rpm-build-libs
to version 0:4.14.3-14.el8_4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-20271
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://bugzilla.redhat.com/show_bug.cgi?id=1934125
- https://github.com/rpm-software-management/rpm/commit/d6a86b5e69e46cc283b1e06c92343319beb42e21
- https://access.redhat.com/errata/RHSA-2021:2574
- https://access.redhat.com/errata/RHBA-2021:2854
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://security.gentoo.org/glsa/202107-43
- https://www.starwindsoftware.com/security/sw-20220805-0002/
medium severity
- Vulnerable module: rpm-libs
- Introduced through: rpm-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-14.el8_4
Detailed paths
-
Introduced through: centos@centos8 › rpm-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-libs
package and not the rpm-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
Remediation
Upgrade Centos:8
rpm-libs
to version 0:4.14.3-14.el8_4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-20271
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://bugzilla.redhat.com/show_bug.cgi?id=1934125
- https://github.com/rpm-software-management/rpm/commit/d6a86b5e69e46cc283b1e06c92343319beb42e21
- https://access.redhat.com/errata/RHSA-2021:2574
- https://access.redhat.com/errata/RHBA-2021:2854
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://security.gentoo.org/glsa/202107-43
- https://www.starwindsoftware.com/security/sw-20220805-0002/
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8_5.12
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in vim/vim prior to 8.2.
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8_5.12 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-0318
- https://access.redhat.com/errata/RHSA-2022:0894
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- https://github.com/vim/vim/commit/57df9e8a9f9ae1aafdde9b86b10ad907627a87dc
- https://huntr.dev/bounties/0d10ba02-b138-4e68-a284-67f781a62d08
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html
- https://security.gentoo.org/glsa/202208-32
- https://security.netapp.com/advisory/ntap-20241115-0004/
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8_5.4
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
vim is vulnerable to Heap-based Buffer Overflow
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8_5.4 or higher.
References
- https://huntr.dev/bounties/c958013b-1c09-4939-92ca-92f50aa169e8
- https://access.redhat.com/security/cve/CVE-2021-3872
- https://github.com/vim/vim/commit/826bfe4bbd7594188e3d74d2539d9707b1c6a14b
- https://access.redhat.com/errata/RHSA-2022:0366
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7K4JJBIH3OQSZRVTWKCJCDLGMFGQ5DOH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S42L4Z4DTW4LHLQ4FJ33VEOXRCBE7WN4/
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7K4JJBIH3OQSZRVTWKCJCDLGMFGQ5DOH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S42L4Z4DTW4LHLQ4FJ33VEOXRCBE7WN4/
- https://security.gentoo.org/glsa/202208-32
medium severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-11.el8_9
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Sending a flood of dynamic DNS updates may cause named
to allocate large amounts of memory. This, in turn, may cause named
to exit due to a lack of free memory. We are not aware of any cases where this has been exploited.
Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes.
If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop named
by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome.
BIND 9.11 and earlier branches are also affected, but through exhaustion of internal resources rather than memory constraints. This may reduce performance but should not be a significant problem for most servers. Therefore we don't intend to address this for BIND versions prior to BIND 9.16. This issue affects BIND 9 versions 9.16.0 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.8-S1 through 9.16.36-S1.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-11.el8_9 or higher.
References
medium severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.26-6.el8
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the named process will terminate due to a failed assertion the next time the transferred secondary zone is refreshed.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.26-6.el8 or higher.
References
- https://kb.isc.org/v1/docs/cve-2021-25214
- https://security.netapp.com/advisory/ntap-20210521-0006/
- https://access.redhat.com/security/cve/CVE-2021-25214
- https://www.debian.org/security/2021/dsa-4909
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VEC2XG4Q2ODTN2C4CGXEIXU3EUTBMK7L/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZDSRPCJQ7MZC6CENH5PO3VQOFI7VSWBE/
- https://lists.debian.org/debian-lts-announce/2021/05/msg00001.html
- http://www.openwall.com/lists/oss-security/2021/04/29/1
- http://www.openwall.com/lists/oss-security/2021/04/29/2
- http://www.openwall.com/lists/oss-security/2021/04/29/3
- http://www.openwall.com/lists/oss-security/2021/04/29/4
- https://access.redhat.com/errata/RHSA-2021:4384
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VEC2XG4Q2ODTN2C4CGXEIXU3EUTBMK7L/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZDSRPCJQ7MZC6CENH5PO3VQOFI7VSWBE/
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8_6.4
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-22.el8_6.4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-32206
- https://access.redhat.com/errata/RHSA-2022:6159
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://www.openwall.com/lists/oss-security/2023/02/15/3
- https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf
- https://hackerone.com/reports/1570651
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220915-0003/
- https://support.apple.com/kb/HT213488
- https://www.debian.org/security/2022/dsa-5197
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-25.el8_7.3
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain" wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a "malloc bomb", making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-25.el8_7.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-23916
- https://access.redhat.com/errata/RHSA-2023:1140
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BQKE6TXYDHOTFHLTBZ5X73GTKI7II5KO/
- https://hackerone.com/reports/1826048
- https://lists.debian.org/debian-lts-announce/2023/02/msg00035.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQKE6TXYDHOTFHLTBZ5X73GTKI7II5KO/
- https://security.gentoo.org/glsa/202310-12
- https://security.netapp.com/advisory/ntap-20230309-0006/
- https://www.debian.org/security/2023/dsa-5365
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-18.el8_4.1
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several of them. In a serial orparallel manner.If one of the servers hosting the contents has been breached and the contentsof the specific file on that server is replaced with a modified payload, curlshould detect this when the hash of the file mismatches after a completeddownload. It should remove the contents and instead try getting the contentsfrom another URL. This is not done, and instead such a hash mismatch is onlymentioned in text and the potentially malicious content is kept in the file ondisk.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-18.el8_4.1 or higher.
References
- https://security.netapp.com/advisory/ntap-20210902-0003/
- https://access.redhat.com/security/cve/CVE-2021-22922
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://hackerone.com/reports/1213175
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cusers.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cusers.kafka.apache.org%3E
- https://access.redhat.com/errata/RHSA-2021:3582
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://security.gentoo.org/glsa/202212-01
medium severity
- Vulnerable module: dbus
- Introduced through: dbus@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus
package and not the dbus
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.
Remediation
Upgrade Centos:8
dbus
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42010
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/418
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus
- Introduced through: dbus@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus
package and not the dbus
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.
Remediation
Upgrade Centos:8
dbus
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42011
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/413
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus
- Introduced through: dbus@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus
package and not the dbus
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.
Remediation
Upgrade Centos:8
dbus
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42012
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/417
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus-common
- Introduced through: dbus-common@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-common@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-common
package and not the dbus-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.
Remediation
Upgrade Centos:8
dbus-common
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42010
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/418
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus-common
- Introduced through: dbus-common@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-common@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-common
package and not the dbus-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.
Remediation
Upgrade Centos:8
dbus-common
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42012
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/417
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus-common
- Introduced through: dbus-common@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-common@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-common
package and not the dbus-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.
Remediation
Upgrade Centos:8
dbus-common
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42011
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/413
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus-daemon
- Introduced through: dbus-daemon@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-daemon@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-daemon
package and not the dbus-daemon
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.
Remediation
Upgrade Centos:8
dbus-daemon
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42010
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/418
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus-daemon
- Introduced through: dbus-daemon@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-daemon@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-daemon
package and not the dbus-daemon
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.
Remediation
Upgrade Centos:8
dbus-daemon
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42011
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/413
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus-daemon
- Introduced through: dbus-daemon@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-daemon@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-daemon
package and not the dbus-daemon
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.
Remediation
Upgrade Centos:8
dbus-daemon
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42012
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/417
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus-libs
- Introduced through: dbus-libs@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-libs@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-libs
package and not the dbus-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.
Remediation
Upgrade Centos:8
dbus-libs
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42010
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/418
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus-libs
- Introduced through: dbus-libs@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-libs@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-libs
package and not the dbus-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.
Remediation
Upgrade Centos:8
dbus-libs
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42011
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/413
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus-libs
- Introduced through: dbus-libs@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-libs@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-libs
package and not the dbus-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.
Remediation
Upgrade Centos:8
dbus-libs
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42012
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/417
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus-tools
- Introduced through: dbus-tools@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-tools@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-tools
package and not the dbus-tools
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.
Remediation
Upgrade Centos:8
dbus-tools
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42010
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/418
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus-tools
- Introduced through: dbus-tools@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-tools@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-tools
package and not the dbus-tools
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.
Remediation
Upgrade Centos:8
dbus-tools
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42011
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/413
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dbus-tools
- Introduced through: dbus-tools@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-23.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-tools@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-tools
package and not the dbus-tools
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.
Remediation
Upgrade Centos:8
dbus-tools
to version 1:1.12.8-23.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-42012
- https://access.redhat.com/errata/RHSA-2023:0096
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/417
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/
- https://security.gentoo.org/glsa/202305-08
- https://www.openwall.com/lists/oss-security/2022/10/06/1
medium severity
- Vulnerable module: dhcp-client
- Introduced through: dhcp-client@12:4.3.6-44.0.1.el8
- Fixed in: 12:4.3.6-49.el8
Detailed paths
-
Introduced through: centos@centos8 › dhcp-client@12:4.3.6-44.0.1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dhcp-client
package and not the dhcp-client
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.
Remediation
Upgrade Centos:8
dhcp-client
to version 12:4.3.6-49.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-2929
- https://www.cve.org/CVERecord?id=CVE-2022-2929
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://kb.isc.org/docs/cve-2022-2929
- https://lists.debian.org/debian-lts-announce/2022/10/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://security.gentoo.org/glsa/202305-22
medium severity
- Vulnerable module: dhcp-client
- Introduced through: dhcp-client@12:4.3.6-44.0.1.el8
- Fixed in: 12:4.3.6-49.el8
Detailed paths
-
Introduced through: centos@centos8 › dhcp-client@12:4.3.6-44.0.1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dhcp-client
package and not the dhcp-client
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding call to option_dereference() to decrement the refcount field. The function add_option() is only used in server responses to lease query packets. Each lease query response calls this function for several options, so eventually, the reference counters could overflow and cause the server to abort.
Remediation
Upgrade Centos:8
dhcp-client
to version 12:4.3.6-49.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-2928
- https://www.cve.org/CVERecord?id=CVE-2022-2928
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://kb.isc.org/docs/cve-2022-2928
- https://lists.debian.org/debian-lts-announce/2022/10/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://security.gentoo.org/glsa/202305-22
medium severity
- Vulnerable module: dhcp-common
- Introduced through: dhcp-common@12:4.3.6-44.0.1.el8
- Fixed in: 12:4.3.6-49.el8
Detailed paths
-
Introduced through: centos@centos8 › dhcp-common@12:4.3.6-44.0.1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dhcp-common
package and not the dhcp-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.
Remediation
Upgrade Centos:8
dhcp-common
to version 12:4.3.6-49.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-2929
- https://www.cve.org/CVERecord?id=CVE-2022-2929
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://kb.isc.org/docs/cve-2022-2929
- https://lists.debian.org/debian-lts-announce/2022/10/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://security.gentoo.org/glsa/202305-22
medium severity
- Vulnerable module: dhcp-common
- Introduced through: dhcp-common@12:4.3.6-44.0.1.el8
- Fixed in: 12:4.3.6-49.el8
Detailed paths
-
Introduced through: centos@centos8 › dhcp-common@12:4.3.6-44.0.1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dhcp-common
package and not the dhcp-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding call to option_dereference() to decrement the refcount field. The function add_option() is only used in server responses to lease query packets. Each lease query response calls this function for several options, so eventually, the reference counters could overflow and cause the server to abort.
Remediation
Upgrade Centos:8
dhcp-common
to version 12:4.3.6-49.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-2928
- https://www.cve.org/CVERecord?id=CVE-2022-2928
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://kb.isc.org/docs/cve-2022-2928
- https://lists.debian.org/debian-lts-announce/2022/10/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://security.gentoo.org/glsa/202305-22
medium severity
- Vulnerable module: dhcp-libs
- Introduced through: dhcp-libs@12:4.3.6-44.0.1.el8
- Fixed in: 12:4.3.6-49.el8
Detailed paths
-
Introduced through: centos@centos8 › dhcp-libs@12:4.3.6-44.0.1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dhcp-libs
package and not the dhcp-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.
Remediation
Upgrade Centos:8
dhcp-libs
to version 12:4.3.6-49.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-2929
- https://www.cve.org/CVERecord?id=CVE-2022-2929
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://kb.isc.org/docs/cve-2022-2929
- https://lists.debian.org/debian-lts-announce/2022/10/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://security.gentoo.org/glsa/202305-22
medium severity
- Vulnerable module: dhcp-libs
- Introduced through: dhcp-libs@12:4.3.6-44.0.1.el8
- Fixed in: 12:4.3.6-49.el8
Detailed paths
-
Introduced through: centos@centos8 › dhcp-libs@12:4.3.6-44.0.1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dhcp-libs
package and not the dhcp-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding call to option_dereference() to decrement the refcount field. The function add_option() is only used in server responses to lease query packets. Each lease query response calls this function for several options, so eventually, the reference counters could overflow and cause the server to abort.
Remediation
Upgrade Centos:8
dhcp-libs
to version 12:4.3.6-49.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-2928
- https://www.cve.org/CVERecord?id=CVE-2022-2928
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://kb.isc.org/docs/cve-2022-2928
- https://lists.debian.org/debian-lts-announce/2022/10/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://security.gentoo.org/glsa/202305-22
medium severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
Remediation
There is no fixed version for Centos:8
expat
.
References
- https://access.redhat.com/security/cve/CVE-2022-23990
- https://access.redhat.com/errata/RHSA-2022:7811
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/34NXVL2RZC2YZRV74ZQ3RNFB7WCEUP7D/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R7FF2UH7MPXKTADYSJUAHI2Y5UHBSHUH/
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/551
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/34NXVL2RZC2YZRV74ZQ3RNFB7WCEUP7D/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7FF2UH7MPXKTADYSJUAHI2Y5UHBSHUH/
- https://security.gentoo.org/glsa/202209-24
- https://www.debian.org/security/2022/dsa-5073
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.tenable.com/security/tns-2022-05
medium severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-8.el8_6.2
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-8.el8_6.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-25313
- https://access.redhat.com/errata/RHSA-2022:5314
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/
- http://www.openwall.com/lists/oss-security/2022/02/19/1
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://github.com/libexpat/libexpat/pull/558
- https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/
- https://security.gentoo.org/glsa/202209-24
- https://security.netapp.com/advisory/ntap-20220303-0008/
- https://www.debian.org/security/2022/dsa-5085
- https://www.oracle.com/security-alerts/cpuapr2022.html
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may lead to UI spoofing.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5. Processing maliciously crafted web content may disclose sensitive user information.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-22662
- https://access.redhat.com/errata/RHSA-2022:7704
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/33BWWAQLLBHKGSI332ZZCORTFZ2XLOIH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ANNHXXARVBRGI74TVQNZOAG6P7AGSMUJ/
- http://www.openwall.com/lists/oss-security/2022/07/05/3
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33BWWAQLLBHKGSI332ZZCORTFZ2XLOIH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ANNHXXARVBRGI74TVQNZOAG6P7AGSMUJ/
- https://security.gentoo.org/glsa/202208-39
- https://support.apple.com/en-us/HT213184
- https://support.apple.com/en-us/HT213185
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure.
This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.
Remediation
There is no fixed version for Centos:8
gnutls
.
References
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.
Remediation
There is no fixed version for Centos:8
gnutls
.
References
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().
Remediation
There is no fixed version for Centos:8
gnutls
.
References
medium severity
- Vulnerable module: iputils
- Introduced through: iputils@20180629-7.el8
Detailed paths
-
Introduced through: centos@centos8 › iputils@20180629-7.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream iputils
package and not the iputils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication.
Remediation
There is no fixed version for Centos:8
iputils
.
References
medium severity
- Vulnerable module: krb5-libs
- Introduced through: krb5-libs@1.18.2-8.el8
- Fixed in: 0:1.18.2-29.el8_10
Detailed paths
-
Introduced through: centos@centos8 › krb5-libs@1.18.2-8.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream krb5-libs
package and not the krb5-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
Remediation
Upgrade Centos:8
krb5-libs
to version 0:1.18.2-29.el8_10 or higher.
References
medium severity
- Vulnerable module: krb5-libs
- Introduced through: krb5-libs@1.18.2-8.el8
- Fixed in: 0:1.18.2-8.3.el8_4
Detailed paths
-
Introduced through: centos@centos8 › krb5-libs@1.18.2-8.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream krb5-libs
package and not the krb5-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.
Remediation
Upgrade Centos:8
krb5-libs
to version 0:1.18.2-8.3.el8_4 or higher.
References
- https://github.com/krb5/krb5/commit/d775c95af7606a51bf79547a94fa52ddd1cb7f49
- https://security.netapp.com/advisory/ntap-20210923-0002/
- https://access.redhat.com/security/cve/CVE-2021-37750
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MFCLW7D46E4VCREKKH453T5DA4XOLHU2/
- https://github.com/krb5/krb5/releases
- https://web.mit.edu/kerberos/advisories/
- https://lists.debian.org/debian-lts-announce/2021/09/msg00019.html
- https://access.redhat.com/errata/RHSA-2021:3576
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MFCLW7D46E4VCREKKH453T5DA4XOLHU2/
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.starwindsoftware.com/security/sw-20220817-0004/
medium severity
- Vulnerable module: krb5-libs
- Introduced through: krb5-libs@1.18.2-8.el8
- Fixed in: 0:1.18.2-31.el8_10
Detailed paths
-
Introduced through: centos@centos8 › krb5-libs@1.18.2-8.el8
NVD Description
This vulnerability has not been analyzed by NVD yet.
Remediation
Upgrade Centos:8
krb5-libs
to version 0:1.18.2-31.el8_10 or higher.
References
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8_6.4
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-22.el8_6.4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-32206
- https://access.redhat.com/errata/RHSA-2022:6159
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://www.openwall.com/lists/oss-security/2023/02/15/3
- https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf
- https://hackerone.com/reports/1570651
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220915-0003/
- https://support.apple.com/kb/HT213488
- https://www.debian.org/security/2022/dsa-5197
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-25.el8_7.3
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain" wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a "malloc bomb", making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-25.el8_7.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-23916
- https://access.redhat.com/errata/RHSA-2023:1140
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BQKE6TXYDHOTFHLTBZ5X73GTKI7II5KO/
- https://hackerone.com/reports/1826048
- https://lists.debian.org/debian-lts-announce/2023/02/msg00035.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQKE6TXYDHOTFHLTBZ5X73GTKI7II5KO/
- https://security.gentoo.org/glsa/202310-12
- https://security.netapp.com/advisory/ntap-20230309-0006/
- https://www.debian.org/security/2023/dsa-5365
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-18.el8_4.1
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several of them. In a serial orparallel manner.If one of the servers hosting the contents has been breached and the contentsof the specific file on that server is replaced with a modified payload, curlshould detect this when the hash of the file mismatches after a completeddownload. It should remove the contents and instead try getting the contentsfrom another URL. This is not done, and instead such a hash mismatch is onlymentioned in text and the potentially malicious content is kept in the file ondisk.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-18.el8_4.1 or higher.
References
- https://security.netapp.com/advisory/ntap-20210902-0003/
- https://access.redhat.com/security/cve/CVE-2021-22922
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://hackerone.com/reports/1213175
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cusers.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cusers.kafka.apache.org%3E
- https://access.redhat.com/errata/RHSA-2021:3582
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://security.gentoo.org/glsa/202212-01
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-18.el8_9
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file. NOTE: the vendor's position is that the product does not support the legacy SAX1 interface with custom callbacks; there is a crash even without crafted input.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-18.el8_9 or higher.
References
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-9.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-9.el8_4.2 or higher.
References
medium severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party
Remediation
There is no fixed version for Centos:8
ncurses-base
.
References
medium severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party
Remediation
There is no fixed version for Centos:8
ncurses-libs
.
References
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-45.el8
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-45.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3737
- https://access.redhat.com/errata/RHSA-2022:1986
- https://bugs.python.org/issue44022
- https://bugzilla.redhat.com/show_bug.cgi?id=1995162
- https://github.com/python/cpython/pull/25916
- https://github.com/python/cpython/pull/26503
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://python-security.readthedocs.io/vuln/urllib-100-continue-loop.html
- https://security.netapp.com/advisory/ntap-20220407-0009/
- https://ubuntu.com/security/CVE-2021-3737
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-39.el8_4
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-39.el8_4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3733
- https://access.redhat.com/errata/RHSA-2021:4057
- https://bugs.python.org/issue43075
- https://bugzilla.redhat.com/show_bug.cgi?id=1995234
- https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb
- https://github.com/python/cpython/pull/24391
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://security.netapp.com/advisory/ntap-20220407-0001/
- https://ubuntu.com/security/CVE-2021-3733
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-56.el8_9.2
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-56.el8_9.2 or higher.
References
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-45.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-45.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3737
- https://access.redhat.com/errata/RHSA-2022:1986
- https://bugs.python.org/issue44022
- https://bugzilla.redhat.com/show_bug.cgi?id=1995162
- https://github.com/python/cpython/pull/25916
- https://github.com/python/cpython/pull/26503
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://python-security.readthedocs.io/vuln/urllib-100-continue-loop.html
- https://security.netapp.com/advisory/ntap-20220407-0009/
- https://ubuntu.com/security/CVE-2021-3737
- https://www.oracle.com/security-alerts/cpujul2022.html
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-39.el8_4
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-39.el8_4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3733
- https://access.redhat.com/errata/RHSA-2021:4057
- https://bugs.python.org/issue43075
- https://bugzilla.redhat.com/show_bug.cgi?id=1995234
- https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb
- https://github.com/python/cpython/pull/24391
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://security.netapp.com/advisory/ntap-20220407-0001/
- https://ubuntu.com/security/CVE-2021-3733
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-56.el8_9.2
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-56.el8_9.2 or higher.
References
medium severity
- Vulnerable module: python3-rpm
- Introduced through: python3-rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-28.el8_9
Detailed paths
-
Introduced through: centos@centos8 › python3-rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-rpm
package and not the python3-rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade Centos:8
python3-rpm
to version 0:4.14.3-28.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-35939
- https://bugzilla.redhat.com/show_bug.cgi?id=1964129
- https://github.com/rpm-software-management/rpm/commit/96ec957e281220f8e137a2d5eb23b83a6377d556
- https://github.com/rpm-software-management/rpm/pull/1919
- https://rpm.org/wiki/Releases/4.18.0
- https://security.gentoo.org/glsa/202210-22
medium severity
- Vulnerable module: python3-rpm
- Introduced through: python3-rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-28.el8_9
Detailed paths
-
Introduced through: centos@centos8 › python3-rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-rpm
package and not the python3-rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade Centos:8
python3-rpm
to version 0:4.14.3-28.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-35938
- https://bugzilla.redhat.com/show_bug.cgi?id=1964114
- https://bugzilla.suse.com/show_bug.cgi?id=1157880
- https://github.com/rpm-software-management/rpm/commit/25a435e90844ea98fe5eb7bef22c1aecf3a9c033
- https://github.com/rpm-software-management/rpm/pull/1919
- https://rpm.org/wiki/Releases/4.18.0
- https://security.gentoo.org/glsa/202210-22
medium severity
- Vulnerable module: rpm
- Introduced through: rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-28.el8_9
Detailed paths
-
Introduced through: centos@centos8 › rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm
package and not the rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade Centos:8
rpm
to version 0:4.14.3-28.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-35939
- https://bugzilla.redhat.com/show_bug.cgi?id=1964129
- https://github.com/rpm-software-management/rpm/commit/96ec957e281220f8e137a2d5eb23b83a6377d556
- https://github.com/rpm-software-management/rpm/pull/1919
- https://rpm.org/wiki/Releases/4.18.0
- https://security.gentoo.org/glsa/202210-22
medium severity
- Vulnerable module: rpm
- Introduced through: rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-28.el8_9
Detailed paths
-
Introduced through: centos@centos8 › rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm
package and not the rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade Centos:8
rpm
to version 0:4.14.3-28.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-35938
- https://bugzilla.redhat.com/show_bug.cgi?id=1964114
- https://bugzilla.suse.com/show_bug.cgi?id=1157880
- https://github.com/rpm-software-management/rpm/commit/25a435e90844ea98fe5eb7bef22c1aecf3a9c033
- https://github.com/rpm-software-management/rpm/pull/1919
- https://rpm.org/wiki/Releases/4.18.0
- https://security.gentoo.org/glsa/202210-22
medium severity
- Vulnerable module: rpm-build-libs
- Introduced through: rpm-build-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-28.el8_9
Detailed paths
-
Introduced through: centos@centos8 › rpm-build-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-build-libs
package and not the rpm-build-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade Centos:8
rpm-build-libs
to version 0:4.14.3-28.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-35938
- https://bugzilla.redhat.com/show_bug.cgi?id=1964114
- https://bugzilla.suse.com/show_bug.cgi?id=1157880
- https://github.com/rpm-software-management/rpm/commit/25a435e90844ea98fe5eb7bef22c1aecf3a9c033
- https://github.com/rpm-software-management/rpm/pull/1919
- https://rpm.org/wiki/Releases/4.18.0
- https://security.gentoo.org/glsa/202210-22
medium severity
- Vulnerable module: rpm-build-libs
- Introduced through: rpm-build-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-28.el8_9
Detailed paths
-
Introduced through: centos@centos8 › rpm-build-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-build-libs
package and not the rpm-build-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade Centos:8
rpm-build-libs
to version 0:4.14.3-28.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-35939
- https://bugzilla.redhat.com/show_bug.cgi?id=1964129
- https://github.com/rpm-software-management/rpm/commit/96ec957e281220f8e137a2d5eb23b83a6377d556
- https://github.com/rpm-software-management/rpm/pull/1919
- https://rpm.org/wiki/Releases/4.18.0
- https://security.gentoo.org/glsa/202210-22
medium severity
- Vulnerable module: rpm-libs
- Introduced through: rpm-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-28.el8_9
Detailed paths
-
Introduced through: centos@centos8 › rpm-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-libs
package and not the rpm-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade Centos:8
rpm-libs
to version 0:4.14.3-28.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-35938
- https://bugzilla.redhat.com/show_bug.cgi?id=1964114
- https://bugzilla.suse.com/show_bug.cgi?id=1157880
- https://github.com/rpm-software-management/rpm/commit/25a435e90844ea98fe5eb7bef22c1aecf3a9c033
- https://github.com/rpm-software-management/rpm/pull/1919
- https://rpm.org/wiki/Releases/4.18.0
- https://security.gentoo.org/glsa/202210-22
medium severity
- Vulnerable module: rpm-libs
- Introduced through: rpm-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-28.el8_9
Detailed paths
-
Introduced through: centos@centos8 › rpm-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-libs
package and not the rpm-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade Centos:8
rpm-libs
to version 0:4.14.3-28.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-35939
- https://bugzilla.redhat.com/show_bug.cgi?id=1964129
- https://github.com/rpm-software-management/rpm/commit/96ec957e281220f8e137a2d5eb23b83a6377d556
- https://github.com/rpm-software-management/rpm/pull/1919
- https://rpm.org/wiki/Releases/4.18.0
- https://security.gentoo.org/glsa/202210-22
medium severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
- Fixed in: 0:3.26.0-15.el8
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.
Remediation
Upgrade Centos:8
sqlite-libs
to version 0:3.26.0-15.el8 or higher.
References
- https://seclists.org/bugtraq/2020/Jan/27
- https://access.redhat.com/security/cve/CVE-2019-13750
- https://www.debian.org/security/2020/dsa-4606
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2Z5M4FPUMDNX2LDPHJKN5ZV5GIS2AKNU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N5CIQCVS6E3ULJCNU7YJXJPO2BLQZDTK/
- https://security.gentoo.org/glsa/202003-08
- https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
- https://crbug.com/1025464
- https://access.redhat.com/errata/RHSA-2021:4396
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00036.html
- https://usn.ubuntu.com/4298-1/
- https://usn.ubuntu.com/4298-2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2Z5M4FPUMDNX2LDPHJKN5ZV5GIS2AKNU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N5CIQCVS6E3ULJCNU7YJXJPO2BLQZDTK/
medium severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
- Fixed in: 0:3.26.0-15.el8
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Remediation
Upgrade Centos:8
sqlite-libs
to version 0:3.26.0-15.el8 or higher.
References
- https://seclists.org/bugtraq/2020/Jan/27
- https://access.redhat.com/security/cve/CVE-2019-13751
- https://www.debian.org/security/2020/dsa-4606
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2Z5M4FPUMDNX2LDPHJKN5ZV5GIS2AKNU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N5CIQCVS6E3ULJCNU7YJXJPO2BLQZDTK/
- https://security.gentoo.org/glsa/202003-08
- https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
- https://crbug.com/1025465
- https://access.redhat.com/errata/RHSA-2021:4396
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00036.html
- https://usn.ubuntu.com/4298-1/
- https://usn.ubuntu.com/4298-2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2Z5M4FPUMDNX2LDPHJKN5ZV5GIS2AKNU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N5CIQCVS6E3ULJCNU7YJXJPO2BLQZDTK/
medium severity
- Vulnerable module: dnf
- Introduced through: dnf@4.4.2-11.el8
- Fixed in: 0:4.7.0-4.el8
Detailed paths
-
Introduced through: centos@centos8 › dnf@4.4.2-11.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dnf
package and not the dnf
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.
Remediation
Upgrade Centos:8
dnf
to version 0:4.7.0-4.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3445
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
- https://bugzilla.redhat.com/show_bug.cgi?id=1932079
- https://access.redhat.com/errata/RHSA-2021:4464
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
medium severity
- Vulnerable module: dnf-data
- Introduced through: dnf-data@4.4.2-11.el8
- Fixed in: 0:4.7.0-4.el8
Detailed paths
-
Introduced through: centos@centos8 › dnf-data@4.4.2-11.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dnf-data
package and not the dnf-data
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.
Remediation
Upgrade Centos:8
dnf-data
to version 0:4.7.0-4.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3445
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
- https://bugzilla.redhat.com/show_bug.cgi?id=1932079
- https://access.redhat.com/errata/RHSA-2021:4464
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
medium severity
- Vulnerable module: libdnf
- Introduced through: libdnf@0.55.0-7.el8
- Fixed in: 0:0.63.0-3.el8
Detailed paths
-
Introduced through: centos@centos8 › libdnf@0.55.0-7.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libdnf
package and not the libdnf
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.
Remediation
Upgrade Centos:8
libdnf
to version 0:0.63.0-3.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3445
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
- https://bugzilla.redhat.com/show_bug.cgi?id=1932079
- https://access.redhat.com/errata/RHSA-2021:4464
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
medium severity
- Vulnerable module: python3-dnf
- Introduced through: python3-dnf@4.4.2-11.el8
- Fixed in: 0:4.7.0-4.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-dnf@4.4.2-11.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-dnf
package and not the python3-dnf
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.
Remediation
Upgrade Centos:8
python3-dnf
to version 0:4.7.0-4.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3445
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
- https://bugzilla.redhat.com/show_bug.cgi?id=1932079
- https://access.redhat.com/errata/RHSA-2021:4464
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
medium severity
- Vulnerable module: python3-hawkey
- Introduced through: python3-hawkey@0.55.0-7.el8
- Fixed in: 0:0.63.0-3.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-hawkey@0.55.0-7.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-hawkey
package and not the python3-hawkey
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.
Remediation
Upgrade Centos:8
python3-hawkey
to version 0:0.63.0-3.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3445
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
- https://bugzilla.redhat.com/show_bug.cgi?id=1932079
- https://access.redhat.com/errata/RHSA-2021:4464
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
medium severity
- Vulnerable module: python3-libdnf
- Introduced through: python3-libdnf@0.55.0-7.el8
- Fixed in: 0:0.63.0-3.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libdnf@0.55.0-7.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libdnf
package and not the python3-libdnf
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.
Remediation
Upgrade Centos:8
python3-libdnf
to version 0:0.63.0-3.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3445
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
- https://bugzilla.redhat.com/show_bug.cgi?id=1932079
- https://access.redhat.com/errata/RHSA-2021:4464
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
medium severity
- Vulnerable module: yum
- Introduced through: yum@4.4.2-11.el8
- Fixed in: 0:4.7.0-4.el8
Detailed paths
-
Introduced through: centos@centos8 › yum@4.4.2-11.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream yum
package and not the yum
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.
Remediation
Upgrade Centos:8
yum
to version 0:4.7.0-4.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3445
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
- https://bugzilla.redhat.com/show_bug.cgi?id=1932079
- https://access.redhat.com/errata/RHSA-2021:4464
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-69.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability has been found in the CPython venv
module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-69.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-9287
- https://github.com/python/cpython/commit/633555735a023d3e4d92ba31da35b1205f9ecbd7
- https://github.com/python/cpython/commit/8450b2482586857d689b6658f08de9c8179af7db
- https://github.com/python/cpython/commit/9286ab3a107ea41bd3f3c3682ce2512692bdded8
- https://github.com/python/cpython/commit/ae961ae94bf19c8f8c7fbea3d1c25cc55ce8ae97
- https://github.com/python/cpython/commit/d48cc82ed25e26b02eb97c6263d95dcaa1e9111b
- https://github.com/python/cpython/commit/e52095a0c1005a87eed2276af7a1f2f66e2b6483
- https://github.com/python/cpython/issues/124651
- https://github.com/python/cpython/pull/124712
- https://mail.python.org/archives/list/security-announce@python.org/thread/RSPJ2B5JL22FG3TKUJ7D7DQ4N5JRRBZL/
- https://security.netapp.com/advisory/ntap-20250425-0006/
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-69.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability has been found in the CPython venv
module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-69.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-9287
- https://github.com/python/cpython/commit/633555735a023d3e4d92ba31da35b1205f9ecbd7
- https://github.com/python/cpython/commit/8450b2482586857d689b6658f08de9c8179af7db
- https://github.com/python/cpython/commit/9286ab3a107ea41bd3f3c3682ce2512692bdded8
- https://github.com/python/cpython/commit/ae961ae94bf19c8f8c7fbea3d1c25cc55ce8ae97
- https://github.com/python/cpython/commit/d48cc82ed25e26b02eb97c6263d95dcaa1e9111b
- https://github.com/python/cpython/commit/e52095a0c1005a87eed2276af7a1f2f66e2b6483
- https://github.com/python/cpython/issues/124651
- https://github.com/python/cpython/pull/124712
- https://mail.python.org/archives/list/security-announce@python.org/thread/RSPJ2B5JL22FG3TKUJ7D7DQ4N5JRRBZL/
- https://security.netapp.com/advisory/ntap-20250425-0006/
medium severity
- Vulnerable module: python3-rpm
- Introduced through: python3-rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-28.el8_9
Detailed paths
-
Introduced through: centos@centos8 › python3-rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-rpm
package and not the python3-rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade Centos:8
python3-rpm
to version 0:4.14.3-28.el8_9 or higher.
References
medium severity
- Vulnerable module: rpm
- Introduced through: rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-28.el8_9
Detailed paths
-
Introduced through: centos@centos8 › rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm
package and not the rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade Centos:8
rpm
to version 0:4.14.3-28.el8_9 or higher.
References
medium severity
- Vulnerable module: rpm-build-libs
- Introduced through: rpm-build-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-28.el8_9
Detailed paths
-
Introduced through: centos@centos8 › rpm-build-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-build-libs
package and not the rpm-build-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade Centos:8
rpm-build-libs
to version 0:4.14.3-28.el8_9 or higher.
References
medium severity
- Vulnerable module: rpm-libs
- Introduced through: rpm-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-28.el8_9
Detailed paths
-
Introduced through: centos@centos8 › rpm-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-libs
package and not the rpm-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade Centos:8
rpm-libs
to version 0:4.14.3-28.el8_9 or higher.
References
medium severity
- Vulnerable module: systemd
- Introduced through: systemd@239-45.el8
- Fixed in: 0:239-74.el8_8.2
Detailed paths
-
Introduced through: centos@centos8 › systemd@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd
package and not the systemd
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
Remediation
Upgrade Centos:8
systemd
to version 0:239-74.el8_8.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-26604
- https://medium.com/@zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7
- http://packetstormsecurity.com/files/174130/systemd-246-Local-Root-Privilege-Escalation.html
- https://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-2-insecure-functionality/
- https://github.com/systemd/systemd/blob/main/NEWS#L4335-L4340
- https://lists.debian.org/debian-lts-announce/2023/03/msg00032.html
- https://medium.com/%40zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7
- https://security.netapp.com/advisory/ntap-20230505-0009/
- https://www.exploit-db.com/exploits/51674
medium severity
- Vulnerable module: systemd-libs
- Introduced through: systemd-libs@239-45.el8
- Fixed in: 0:239-74.el8_8.2
Detailed paths
-
Introduced through: centos@centos8 › systemd-libs@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-libs
package and not the systemd-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
Remediation
Upgrade Centos:8
systemd-libs
to version 0:239-74.el8_8.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-26604
- https://medium.com/@zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7
- http://packetstormsecurity.com/files/174130/systemd-246-Local-Root-Privilege-Escalation.html
- https://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-2-insecure-functionality/
- https://github.com/systemd/systemd/blob/main/NEWS#L4335-L4340
- https://lists.debian.org/debian-lts-announce/2023/03/msg00032.html
- https://medium.com/%40zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7
- https://security.netapp.com/advisory/ntap-20230505-0009/
- https://www.exploit-db.com/exploits/51674
medium severity
- Vulnerable module: systemd-pam
- Introduced through: systemd-pam@239-45.el8
- Fixed in: 0:239-74.el8_8.2
Detailed paths
-
Introduced through: centos@centos8 › systemd-pam@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-pam
package and not the systemd-pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
Remediation
Upgrade Centos:8
systemd-pam
to version 0:239-74.el8_8.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-26604
- https://medium.com/@zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7
- http://packetstormsecurity.com/files/174130/systemd-246-Local-Root-Privilege-Escalation.html
- https://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-2-insecure-functionality/
- https://github.com/systemd/systemd/blob/main/NEWS#L4335-L4340
- https://lists.debian.org/debian-lts-announce/2023/03/msg00032.html
- https://medium.com/%40zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7
- https://security.netapp.com/advisory/ntap-20230505-0009/
- https://www.exploit-db.com/exploits/51674
medium severity
- Vulnerable module: systemd-udev
- Introduced through: systemd-udev@239-45.el8
- Fixed in: 0:239-74.el8_8.2
Detailed paths
-
Introduced through: centos@centos8 › systemd-udev@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-udev
package and not the systemd-udev
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
Remediation
Upgrade Centos:8
systemd-udev
to version 0:239-74.el8_8.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-26604
- https://medium.com/@zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7
- http://packetstormsecurity.com/files/174130/systemd-246-Local-Root-Privilege-Escalation.html
- https://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-2-insecure-functionality/
- https://github.com/systemd/systemd/blob/main/NEWS#L4335-L4340
- https://lists.debian.org/debian-lts-announce/2023/03/msg00032.html
- https://medium.com/%40zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7
- https://security.netapp.com/advisory/ntap-20230505-0009/
- https://www.exploit-db.com/exploits/51674
medium severity
- Vulnerable module: dbus
- Introduced through: dbus@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-24.el8_8.1
Detailed paths
-
Introduced through: centos@centos8 › dbus@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus
package and not the dbus
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.
Remediation
Upgrade Centos:8
dbus
to version 1:1.12.8-24.el8_8.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-34969
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/457
- https://lists.debian.org/debian-lts-announce/2023/10/msg00033.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/
- https://security.netapp.com/advisory/ntap-20231208-0007/
medium severity
- Vulnerable module: dbus-common
- Introduced through: dbus-common@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-24.el8_8.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-common@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-common
package and not the dbus-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.
Remediation
Upgrade Centos:8
dbus-common
to version 1:1.12.8-24.el8_8.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-34969
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/457
- https://lists.debian.org/debian-lts-announce/2023/10/msg00033.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/
- https://security.netapp.com/advisory/ntap-20231208-0007/
medium severity
- Vulnerable module: dbus-daemon
- Introduced through: dbus-daemon@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-24.el8_8.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-daemon@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-daemon
package and not the dbus-daemon
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.
Remediation
Upgrade Centos:8
dbus-daemon
to version 1:1.12.8-24.el8_8.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-34969
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/457
- https://lists.debian.org/debian-lts-announce/2023/10/msg00033.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/
- https://security.netapp.com/advisory/ntap-20231208-0007/
medium severity
- Vulnerable module: dbus-libs
- Introduced through: dbus-libs@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-24.el8_8.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-libs@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-libs
package and not the dbus-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.
Remediation
Upgrade Centos:8
dbus-libs
to version 1:1.12.8-24.el8_8.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-34969
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/457
- https://lists.debian.org/debian-lts-announce/2023/10/msg00033.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/
- https://security.netapp.com/advisory/ntap-20231208-0007/
medium severity
- Vulnerable module: dbus-tools
- Introduced through: dbus-tools@1:1.12.8-12.el8
- Fixed in: 1:1.12.8-24.el8_8.1
Detailed paths
-
Introduced through: centos@centos8 › dbus-tools@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-tools
package and not the dbus-tools
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.
Remediation
Upgrade Centos:8
dbus-tools
to version 1:1.12.8-24.el8_8.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-34969
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/
- https://gitlab.freedesktop.org/dbus/dbus/-/issues/457
- https://lists.debian.org/debian-lts-announce/2023/10/msg00033.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZYCDRMD7B4XO4HF6C6YTLH4YUD7TANP/
- https://security.netapp.com/advisory/ntap-20231208-0007/
medium severity
- Vulnerable module: elfutils-default-yama-scope
- Introduced through: elfutils-default-yama-scope@0.182-3.el8
Detailed paths
-
Introduced through: centos@centos8 › elfutils-default-yama-scope@0.182-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream elfutils-default-yama-scope
package and not the elfutils-default-yama-scope
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
Remediation
There is no fixed version for Centos:8
elfutils-default-yama-scope
.
References
medium severity
- Vulnerable module: elfutils-libelf
- Introduced through: elfutils-libelf@0.182-3.el8
Detailed paths
-
Introduced through: centos@centos8 › elfutils-libelf@0.182-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream elfutils-libelf
package and not the elfutils-libelf
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
Remediation
There is no fixed version for Centos:8
elfutils-libelf
.
References
medium severity
- Vulnerable module: elfutils-libs
- Introduced through: elfutils-libs@0.182-3.el8
Detailed paths
-
Introduced through: centos@centos8 › elfutils-libs@0.182-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream elfutils-libs
package and not the elfutils-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
Remediation
There is no fixed version for Centos:8
elfutils-libs
.
References
medium severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-15.el8_10
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-15.el8_10 or higher.
References
medium severity
- Vulnerable module: gmp
- Introduced through: gmp@1:6.1.2-10.el8
- Fixed in: 1:6.1.2-11.el8
Detailed paths
-
Introduced through: centos@centos8 › gmp@1:6.1.2-10.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream gmp
package and not the gmp
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.
Remediation
Upgrade Centos:8
gmp
to version 1:6.1.2-11.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-43618
- https://bugs.debian.org/994405
- https://gmplib.org/list-archives/gmp-bugs/2021-September/005077.html
- https://gmplib.org/repo/gmp-6.2/rev/561a9c25298e
- http://seclists.org/fulldisclosure/2022/Oct/8
- http://www.openwall.com/lists/oss-security/2022/10/13/3
- https://lists.debian.org/debian-lts-announce/2021/12/msg00001.html
- https://security.gentoo.org/glsa/202309-13
- https://security.netapp.com/advisory/ntap-20221111-0001/
medium severity
new
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions xmlXPathRunEval
, xmlXPathCtxtCompile
, and xmlXPathEvalExpr
were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.
Remediation
There is no fixed version for Centos:8
libxml2
.
References
medium severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
- Fixed in: 0:3.26.0-18.el8_8
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script.
Remediation
Upgrade Centos:8
sqlite-libs
to version 0:3.26.0-18.el8_8 or higher.
References
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-18.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got before the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-18.el8_4.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-22947
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/
- https://hackerone.com/reports/1334763
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html
- https://access.redhat.com/errata/RHSA-2021:4059
- http://seclists.org/fulldisclosure/2022/Mar/29
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20211029-0003/
- https://support.apple.com/kb/HT213183
- https://www.debian.org/security/2022/dsa-5197
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-159.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-159.el8 or higher.
References
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-18.el8_4.2
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got before the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-18.el8_4.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-22947
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/
- https://hackerone.com/reports/1334763
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html
- https://access.redhat.com/errata/RHSA-2021:4059
- http://seclists.org/fulldisclosure/2022/Mar/29
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20211029-0003/
- https://support.apple.com/kb/HT213183
- https://www.debian.org/security/2022/dsa-5197
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/
medium severity
- Vulnerable module: libgcc
- Introduced through: libgcc@8.4.1-1.el8
- Fixed in: 0:8.5.0-23.el8_10
Detailed paths
-
Introduced through: centos@centos8 › libgcc@8.4.1-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libgcc
package and not the libgcc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Remediation
Upgrade Centos:8
libgcc
to version 0:8.5.0-23.el8_10 or higher.
References
- https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6
- https://security.netapp.com/advisory/ntap-20200511-0006/
- https://www.drupal.org/sa-core-2020-002
- https://www.tenable.com/security/tns-2021-02
- https://www.tenable.com/security/tns-2021-10
- https://access.redhat.com/security/cve/CVE-2020-11023
- https://www.debian.org/security/2020/dsa-4693
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B/
- https://security.gentoo.org/glsa/202007-03
- http://packetstormsecurity.com/files/162160/jQuery-1.0.3-Cross-Site-Scripting.html
- https://blog.jquery.com/2020/04/10/jquery-3-5-0-released
- https://jquery.com/upgrade-guide/3.5/
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.apache.org/thread.html/r0593393ca1e97b1e7e098fe69d414d6bd0a467148e9138d07e86ebbb@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r07ab379471fb15644bf7a92e4a98cbc7df3cf4e736abae0cc7625fe6@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r094f435595582f6b5b24b66fedf80543aa8b1d57a3688fbcc21f06ec@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r1fed19c860a0d470f2a3eded12795772c8651ff583ef951ddac4918c@%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/r2c85121a47442036c7f8353a3724aa04f8ecdfda1819d311ba4f5330@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r3702ede0ff83a29ba3eb418f6f11c473d6e3736baba981a8dbd9c9ef@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r4aadb98086ca72ed75391f54167522d91489a0d0ae25b12baa8fc7c5@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r4dba67be3239b34861f1b9cfdf9dfb3a90272585dcce374112ed6e16@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r55f5e066cc7301e3630ce90bbbf8d28c82212ae1f2d4871012141494@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r6c4df3b33e625a44471009a172dabe6865faec8d8f21cac2303463b1@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r6e97b37963926f6059ecc1e417721608723a807a76af41d4e9dbed49@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r9006ad2abf81d02a0ef2126bab5177987e59095b7194a487c4ea247c@%3Ccommits.felix.apache.org%3E
- https://lists.apache.org/thread.html/r9c5fda81e4bca8daee305b4c03283dddb383ab8428a151d4cb0b3b15@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r9e0bd31b7da9e7403478d22652b8760c946861f8ebd7bd750844898e@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/ra32c7103ded9041c7c1cb8c12c8d125a6b2f3f3270e2937ef8417fac@%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/ra374bb0299b4aa3e04edde01ebc03ed6f90cf614dad40dd428ce8f72@%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/ra3c9219fcb0b289e18e9ec5a5ebeaa5c17d6b79a201667675af6721c@%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/ra406b3adfcffcb5ce8707013bdb7c35e3ffc2776a8a99022f15274c6@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rab82dd040f302018c85bd07d33f5604113573514895ada523c3401d9@%3Ccommits.hive.apache.org%3E
- https://lists.apache.org/thread.html/radcb2aa874a79647789f3563fcbbceaf1045a029ee8806b59812a8ea@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rb25c3bc7418ae75cba07988dafe1b6912f76a9dd7d94757878320d61@%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/rb69b7d8217c1a6a2100247a5d06ce610836b31e3f5d73fc113ded8e7@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67@%3Cdev.flink.apache.org%3E
- https://lists.apache.org/thread.html/rd38b4185a797b324c8dd940d9213cf99fcdc2dbf1fc5a63ba7dee8c9@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679@%3Ccommits.nifi.apache.org%3E
- https://lists.apache.org/thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/rf0f8939596081d84be1ae6a91d6248b96a02d8388898c372ac807817@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/rf1ba79e564fe7efc56aef7c986106f1cf67a3427d08e997e088e7a93@%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/rf661a90a15da8da5922ba6127b3f5f8194d4ebec8855d60a0dd13248@%3Cdev.hive.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/03/msg00033.html
- https://www.oracle.com//security-alerts/cpujul2021.html
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html
- https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36@%3Cissues.flink.apache.org%3E
- https://github.com/github/advisory-database/blob/99afa6fdeaf5d1d23e1021ff915a5e5dbc82c1f1/advisories/github-reviewed/2020/04/GHSA-jpcq-cgw6-v4j6/GHSA-jpcq-cgw6-v4j6.json#L20-L37
- https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r0593393ca1e97b1e7e098fe69d414d6bd0a467148e9138d07e86ebbb%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r07ab379471fb15644bf7a92e4a98cbc7df3cf4e736abae0cc7625fe6%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r094f435595582f6b5b24b66fedf80543aa8b1d57a3688fbcc21f06ec%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r1fed19c860a0d470f2a3eded12795772c8651ff583ef951ddac4918c%40%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/r2c85121a47442036c7f8353a3724aa04f8ecdfda1819d311ba4f5330%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r3702ede0ff83a29ba3eb418f6f11c473d6e3736baba981a8dbd9c9ef%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r4aadb98086ca72ed75391f54167522d91489a0d0ae25b12baa8fc7c5%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r4dba67be3239b34861f1b9cfdf9dfb3a90272585dcce374112ed6e16%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r55f5e066cc7301e3630ce90bbbf8d28c82212ae1f2d4871012141494%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r6c4df3b33e625a44471009a172dabe6865faec8d8f21cac2303463b1%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r6e97b37963926f6059ecc1e417721608723a807a76af41d4e9dbed49%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r9006ad2abf81d02a0ef2126bab5177987e59095b7194a487c4ea247c%40%3Ccommits.felix.apache.org%3E
- https://lists.apache.org/thread.html/r9c5fda81e4bca8daee305b4c03283dddb383ab8428a151d4cb0b3b15%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r9e0bd31b7da9e7403478d22652b8760c946861f8ebd7bd750844898e%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/ra32c7103ded9041c7c1cb8c12c8d125a6b2f3f3270e2937ef8417fac%40%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/ra374bb0299b4aa3e04edde01ebc03ed6f90cf614dad40dd428ce8f72%40%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/ra3c9219fcb0b289e18e9ec5a5ebeaa5c17d6b79a201667675af6721c%40%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/ra406b3adfcffcb5ce8707013bdb7c35e3ffc2776a8a99022f15274c6%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rab82dd040f302018c85bd07d33f5604113573514895ada523c3401d9%40%3Ccommits.hive.apache.org%3E
- https://lists.apache.org/thread.html/radcb2aa874a79647789f3563fcbbceaf1045a029ee8806b59812a8ea%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rb25c3bc7418ae75cba07988dafe1b6912f76a9dd7d94757878320d61%40%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/rb69b7d8217c1a6a2100247a5d06ce610836b31e3f5d73fc113ded8e7%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67%40%3Cdev.flink.apache.org%3E
- https://lists.apache.org/thread.html/rd38b4185a797b324c8dd940d9213cf99fcdc2dbf1fc5a63ba7dee8c9%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679%40%3Ccommits.nifi.apache.org%3E
- https://lists.apache.org/thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/rf0f8939596081d84be1ae6a91d6248b96a02d8388898c372ac807817%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/rf1ba79e564fe7efc56aef7c986106f1cf67a3427d08e997e088e7a93%40%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/rf661a90a15da8da5922ba6127b3f5f8194d4ebec8855d60a0dd13248%40%3Cdev.hive.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.exploit-db.com/exploits/49767
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
medium severity
- Vulnerable module: libstdc++
- Introduced through: libstdc++@8.4.1-1.el8
- Fixed in: 0:8.5.0-23.el8_10
Detailed paths
-
Introduced through: centos@centos8 › libstdc++@8.4.1-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libstdc++
package and not the libstdc++
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Remediation
Upgrade Centos:8
libstdc++
to version 0:8.5.0-23.el8_10 or higher.
References
- https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6
- https://security.netapp.com/advisory/ntap-20200511-0006/
- https://www.drupal.org/sa-core-2020-002
- https://www.tenable.com/security/tns-2021-02
- https://www.tenable.com/security/tns-2021-10
- https://access.redhat.com/security/cve/CVE-2020-11023
- https://www.debian.org/security/2020/dsa-4693
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B/
- https://security.gentoo.org/glsa/202007-03
- http://packetstormsecurity.com/files/162160/jQuery-1.0.3-Cross-Site-Scripting.html
- https://blog.jquery.com/2020/04/10/jquery-3-5-0-released
- https://jquery.com/upgrade-guide/3.5/
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.apache.org/thread.html/r0593393ca1e97b1e7e098fe69d414d6bd0a467148e9138d07e86ebbb@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r07ab379471fb15644bf7a92e4a98cbc7df3cf4e736abae0cc7625fe6@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r094f435595582f6b5b24b66fedf80543aa8b1d57a3688fbcc21f06ec@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r1fed19c860a0d470f2a3eded12795772c8651ff583ef951ddac4918c@%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/r2c85121a47442036c7f8353a3724aa04f8ecdfda1819d311ba4f5330@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r3702ede0ff83a29ba3eb418f6f11c473d6e3736baba981a8dbd9c9ef@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r4aadb98086ca72ed75391f54167522d91489a0d0ae25b12baa8fc7c5@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r4dba67be3239b34861f1b9cfdf9dfb3a90272585dcce374112ed6e16@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r55f5e066cc7301e3630ce90bbbf8d28c82212ae1f2d4871012141494@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r6c4df3b33e625a44471009a172dabe6865faec8d8f21cac2303463b1@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r6e97b37963926f6059ecc1e417721608723a807a76af41d4e9dbed49@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r9006ad2abf81d02a0ef2126bab5177987e59095b7194a487c4ea247c@%3Ccommits.felix.apache.org%3E
- https://lists.apache.org/thread.html/r9c5fda81e4bca8daee305b4c03283dddb383ab8428a151d4cb0b3b15@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r9e0bd31b7da9e7403478d22652b8760c946861f8ebd7bd750844898e@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/ra32c7103ded9041c7c1cb8c12c8d125a6b2f3f3270e2937ef8417fac@%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/ra374bb0299b4aa3e04edde01ebc03ed6f90cf614dad40dd428ce8f72@%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/ra3c9219fcb0b289e18e9ec5a5ebeaa5c17d6b79a201667675af6721c@%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/ra406b3adfcffcb5ce8707013bdb7c35e3ffc2776a8a99022f15274c6@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rab82dd040f302018c85bd07d33f5604113573514895ada523c3401d9@%3Ccommits.hive.apache.org%3E
- https://lists.apache.org/thread.html/radcb2aa874a79647789f3563fcbbceaf1045a029ee8806b59812a8ea@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rb25c3bc7418ae75cba07988dafe1b6912f76a9dd7d94757878320d61@%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/rb69b7d8217c1a6a2100247a5d06ce610836b31e3f5d73fc113ded8e7@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67@%3Cdev.flink.apache.org%3E
- https://lists.apache.org/thread.html/rd38b4185a797b324c8dd940d9213cf99fcdc2dbf1fc5a63ba7dee8c9@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679@%3Ccommits.nifi.apache.org%3E
- https://lists.apache.org/thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/rf0f8939596081d84be1ae6a91d6248b96a02d8388898c372ac807817@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/rf1ba79e564fe7efc56aef7c986106f1cf67a3427d08e997e088e7a93@%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/rf661a90a15da8da5922ba6127b3f5f8194d4ebec8855d60a0dd13248@%3Cdev.hive.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/03/msg00033.html
- https://www.oracle.com//security-alerts/cpujul2021.html
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html
- https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36@%3Cissues.flink.apache.org%3E
- https://github.com/github/advisory-database/blob/99afa6fdeaf5d1d23e1021ff915a5e5dbc82c1f1/advisories/github-reviewed/2020/04/GHSA-jpcq-cgw6-v4j6/GHSA-jpcq-cgw6-v4j6.json#L20-L37
- https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r0593393ca1e97b1e7e098fe69d414d6bd0a467148e9138d07e86ebbb%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r07ab379471fb15644bf7a92e4a98cbc7df3cf4e736abae0cc7625fe6%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r094f435595582f6b5b24b66fedf80543aa8b1d57a3688fbcc21f06ec%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r1fed19c860a0d470f2a3eded12795772c8651ff583ef951ddac4918c%40%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/r2c85121a47442036c7f8353a3724aa04f8ecdfda1819d311ba4f5330%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r3702ede0ff83a29ba3eb418f6f11c473d6e3736baba981a8dbd9c9ef%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r4aadb98086ca72ed75391f54167522d91489a0d0ae25b12baa8fc7c5%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r4dba67be3239b34861f1b9cfdf9dfb3a90272585dcce374112ed6e16%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r55f5e066cc7301e3630ce90bbbf8d28c82212ae1f2d4871012141494%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r6c4df3b33e625a44471009a172dabe6865faec8d8f21cac2303463b1%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r6e97b37963926f6059ecc1e417721608723a807a76af41d4e9dbed49%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r9006ad2abf81d02a0ef2126bab5177987e59095b7194a487c4ea247c%40%3Ccommits.felix.apache.org%3E
- https://lists.apache.org/thread.html/r9c5fda81e4bca8daee305b4c03283dddb383ab8428a151d4cb0b3b15%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r9e0bd31b7da9e7403478d22652b8760c946861f8ebd7bd750844898e%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/ra32c7103ded9041c7c1cb8c12c8d125a6b2f3f3270e2937ef8417fac%40%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/ra374bb0299b4aa3e04edde01ebc03ed6f90cf614dad40dd428ce8f72%40%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/ra3c9219fcb0b289e18e9ec5a5ebeaa5c17d6b79a201667675af6721c%40%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/ra406b3adfcffcb5ce8707013bdb7c35e3ffc2776a8a99022f15274c6%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rab82dd040f302018c85bd07d33f5604113573514895ada523c3401d9%40%3Ccommits.hive.apache.org%3E
- https://lists.apache.org/thread.html/radcb2aa874a79647789f3563fcbbceaf1045a029ee8806b59812a8ea%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rb25c3bc7418ae75cba07988dafe1b6912f76a9dd7d94757878320d61%40%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/rb69b7d8217c1a6a2100247a5d06ce610836b31e3f5d73fc113ded8e7%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67%40%3Cdev.flink.apache.org%3E
- https://lists.apache.org/thread.html/rd38b4185a797b324c8dd940d9213cf99fcdc2dbf1fc5a63ba7dee8c9%40%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679%40%3Ccommits.nifi.apache.org%3E
- https://lists.apache.org/thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/rf0f8939596081d84be1ae6a91d6248b96a02d8388898c372ac807817%40%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/rf1ba79e564fe7efc56aef7c986106f1cf67a3427d08e997e088e7a93%40%3Cgitbox.hive.apache.org%3E
- https://lists.apache.org/thread.html/rf661a90a15da8da5922ba6127b3f5f8194d4ebec8855d60a0dd13248%40%3Cdev.hive.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.exploit-db.com/exploits/49767
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-15.el8
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Possible cross-site scripting vulnerability in libxml after commit 960f0e2.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-15.el8 or higher.
References
medium severity
- Vulnerable module: cryptsetup-libs
- Introduced through: cryptsetup-libs@2.3.3-4.el8
- Fixed in: 0:2.3.3-4.el8_5.1
Detailed paths
-
Introduced through: centos@centos8 › cryptsetup-libs@2.3.3-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream cryptsetup-libs
package and not the cryptsetup-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.
Remediation
Upgrade Centos:8
cryptsetup-libs
to version 0:2.3.3-4.el8_5.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-4122
- https://access.redhat.com/errata/RHSA-2022:0370
- https://bugzilla.redhat.com/show_bug.cgi?id=2031859
- https://bugzilla.redhat.com/show_bug.cgi?id=2032401
- https://gitlab.com/cryptsetup/cryptsetup/-/commit/0113ac2d889c5322659ad0596d4cfc6da53e356c
- https://mirrors.edge.kernel.org/pub/linux/utils/cryptsetup/v2.4/v2.4.3-ReleaseNotes
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-30.el8_8.3
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-30.el8_8.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-27536
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
- https://hackerone.com/reports/1895135
- https://lists.debian.org/debian-lts-announce/2023/04/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
- https://security.gentoo.org/glsa/202310-12
- https://security.netapp.com/advisory/ntap-20230420-0010/
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-30.el8_8.2
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-30.el8_8.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-27535
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
- https://hackerone.com/reports/1892780
- https://lists.debian.org/debian-lts-announce/2023/04/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
- https://security.gentoo.org/glsa/202310-12
- https://security.netapp.com/advisory/ntap-20230420-0010/
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-30.el8_8.3
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with xn--
and should not be allowed to pattern match, but the wildcard check in curl could still check for x*
, which would match even though the IDN name most likely contained nothing even resembling an x
.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-30.el8_8.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-28321
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F4I75RDGX5ULSSCBE5BF3P5I5SFO7ULQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z2LIWHWKOVH24COGGBCVOWDXXIUPKOMK/
- http://seclists.org/fulldisclosure/2023/Jul/47
- http://seclists.org/fulldisclosure/2023/Jul/48
- http://seclists.org/fulldisclosure/2023/Jul/52
- https://hackerone.com/reports/1950627
- https://lists.debian.org/debian-lts-announce/2023/10/msg00016.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F4I75RDGX5ULSSCBE5BF3P5I5SFO7ULQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2LIWHWKOVH24COGGBCVOWDXXIUPKOMK/
- https://security.gentoo.org/glsa/202310-12
- https://security.netapp.com/advisory/ntap-20230609-0009/
- https://support.apple.com/kb/HT213843
- https://support.apple.com/kb/HT213844
- https://support.apple.com/kb/HT213845
medium severity
- Vulnerable module: expat
- Introduced through: expat@2.2.5-4.el8
- Fixed in: 0:2.2.5-16.el8_10
Detailed paths
-
Introduced through: centos@centos8 › expat@2.2.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat
package and not the expat
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
Remediation
Upgrade Centos:8
expat
to version 0:2.2.5-16.el8_10 or higher.
References
medium severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-164.el8
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-164.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210629-0005/
- https://access.redhat.com/security/cve/CVE-2021-33574
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RBUUWUGXVILQXVWEOU7N42ICHPJNAEUP/
- https://security.gentoo.org/glsa/202107-07
- https://sourceware.org/bugzilla/show_bug.cgi?id=27896
- https://sourceware.org/bugzilla/show_bug.cgi?id=27896#c1
- https://access.redhat.com/errata/RHSA-2021:4358
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJYYIMDDYOHTP2PORLABTOHYQYYREZDD/
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJYYIMDDYOHTP2PORLABTOHYQYYREZDD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBUUWUGXVILQXVWEOU7N42ICHPJNAEUP/
medium severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-164.el8
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-164.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210629-0005/
- https://access.redhat.com/security/cve/CVE-2021-33574
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RBUUWUGXVILQXVWEOU7N42ICHPJNAEUP/
- https://security.gentoo.org/glsa/202107-07
- https://sourceware.org/bugzilla/show_bug.cgi?id=27896
- https://sourceware.org/bugzilla/show_bug.cgi?id=27896#c1
- https://access.redhat.com/errata/RHSA-2021:4358
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJYYIMDDYOHTP2PORLABTOHYQYYREZDD/
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJYYIMDDYOHTP2PORLABTOHYQYYREZDD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBUUWUGXVILQXVWEOU7N42ICHPJNAEUP/
medium severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-164.el8
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-164.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210629-0005/
- https://access.redhat.com/security/cve/CVE-2021-33574
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RBUUWUGXVILQXVWEOU7N42ICHPJNAEUP/
- https://security.gentoo.org/glsa/202107-07
- https://sourceware.org/bugzilla/show_bug.cgi?id=27896
- https://sourceware.org/bugzilla/show_bug.cgi?id=27896#c1
- https://access.redhat.com/errata/RHSA-2021:4358
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJYYIMDDYOHTP2PORLABTOHYQYYREZDD/
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJYYIMDDYOHTP2PORLABTOHYQYYREZDD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBUUWUGXVILQXVWEOU7N42ICHPJNAEUP/
medium severity
- Vulnerable module: gnupg2
- Introduced through: gnupg2@2.2.20-2.el8
- Fixed in: 0:2.2.20-3.el8_6
Detailed paths
-
Introduced through: centos@centos8 › gnupg2@2.2.20-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnupg2
package and not the gnupg2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
Remediation
Upgrade Centos:8
gnupg2
to version 0:2.2.20-3.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-34903
- https://access.redhat.com/errata/RHSA-2022:6463
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRLWJQ76A4UKHI3Q36BKSJKS4LFLQO33/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NPTAR76EIZY7NQFENSOZO7U473257OVZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VN63GBTMRWO36Y7BKA2WQHROAKCXKCBL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VU64FUVG2PRZBSHFOQRSP7KDVEIZ23OS/
- http://www.openwall.com/lists/oss-security/2022/07/02/1
- https://bugs.debian.org/1014157
- https://dev.gnupg.org/T6027
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRLWJQ76A4UKHI3Q36BKSJKS4LFLQO33/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPTAR76EIZY7NQFENSOZO7U473257OVZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VN63GBTMRWO36Y7BKA2WQHROAKCXKCBL/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU64FUVG2PRZBSHFOQRSP7KDVEIZ23OS/
- https://security.netapp.com/advisory/ntap-20220826-0005/
- https://www.debian.org/security/2022/dsa-5174
- https://www.openwall.com/lists/oss-security/2022/06/30/1
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
- Fixed in: 0:3.6.16-8.el8_9
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
Remediation
Upgrade Centos:8
gnutls
to version 0:3.6.16-8.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-5981
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- https://access.redhat.com/errata/RHSA-2024:0155
- https://bugzilla.redhat.com/show_bug.cgi?id=2248445
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZEIOLORQ7N6WRPFXZSYDL2MC4LP7VFV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GNXKVR5YNUEBNHAHM5GSYKBZX4W2HMN2/
medium severity
- Vulnerable module: krb5-libs
- Introduced through: krb5-libs@1.18.2-8.el8
- Fixed in: 0:1.18.2-32.el8_10
Detailed paths
-
Introduced through: centos@centos8 › krb5-libs@1.18.2-8.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream krb5-libs
package and not the krb5-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.
Remediation
Upgrade Centos:8
krb5-libs
to version 0:1.18.2-32.el8_10 or higher.
References
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-30.el8_8.3
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-30.el8_8.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-27536
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
- https://hackerone.com/reports/1895135
- https://lists.debian.org/debian-lts-announce/2023/04/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
- https://security.gentoo.org/glsa/202310-12
- https://security.netapp.com/advisory/ntap-20230420-0010/
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-30.el8_8.2
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-30.el8_8.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-27535
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
- https://hackerone.com/reports/1892780
- https://lists.debian.org/debian-lts-announce/2023/04/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
- https://security.gentoo.org/glsa/202310-12
- https://security.netapp.com/advisory/ntap-20230420-0010/
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-30.el8_8.3
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with xn--
and should not be allowed to pattern match, but the wildcard check in curl could still check for x*
, which would match even though the IDN name most likely contained nothing even resembling an x
.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-30.el8_8.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-28321
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F4I75RDGX5ULSSCBE5BF3P5I5SFO7ULQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z2LIWHWKOVH24COGGBCVOWDXXIUPKOMK/
- http://seclists.org/fulldisclosure/2023/Jul/47
- http://seclists.org/fulldisclosure/2023/Jul/48
- http://seclists.org/fulldisclosure/2023/Jul/52
- https://hackerone.com/reports/1950627
- https://lists.debian.org/debian-lts-announce/2023/10/msg00016.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F4I75RDGX5ULSSCBE5BF3P5I5SFO7ULQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2LIWHWKOVH24COGGBCVOWDXXIUPKOMK/
- https://security.gentoo.org/glsa/202310-12
- https://security.netapp.com/advisory/ntap-20230609-0009/
- https://support.apple.com/kb/HT213843
- https://support.apple.com/kb/HT213844
- https://support.apple.com/kb/HT213845
medium severity
- Vulnerable module: libgcrypt
- Introduced through: libgcrypt@1.8.5-4.el8
Detailed paths
-
Introduced through: centos@centos8 › libgcrypt@1.8.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libgcrypt
package and not the libgcrypt
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack
Remediation
There is no fixed version for Centos:8
libgcrypt
.
References
- https://access.redhat.com/security/cve/CVE-2019-12904
- https://dev.gnupg.org/T4541
- https://github.com/gpg/libgcrypt/commit/a4c561aab1014c3630bc88faf6f5246fee16b020
- https://github.com/gpg/libgcrypt/commit/daedbbb5541cd8ecda1459d3b843ea4d92788762
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00049.html
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
medium severity
- Vulnerable module: libgcrypt
- Introduced through: libgcrypt@1.8.5-4.el8
Detailed paths
-
Introduced through: centos@centos8 › libgcrypt@1.8.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libgcrypt
package and not the libgcrypt
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.
Remediation
There is no fixed version for Centos:8
libgcrypt
.
References
- https://access.redhat.com/security/cve/CVE-2024-2236
- https://access.redhat.com/errata/RHSA-2024:9404
- https://bugzilla.redhat.com/show_bug.cgi?id=2268268
- https://access.redhat.com/errata/RHSA-2025:3534
- https://access.redhat.com/errata/RHSA-2025:3530
- https://bugzilla.redhat.com/show_bug.cgi?id=2245218
medium severity
- Vulnerable module: libgcrypt
- Introduced through: libgcrypt@1.8.5-4.el8
- Fixed in: 0:1.8.5-7.el8_6
Detailed paths
-
Introduced through: centos@centos8 › libgcrypt@1.8.5-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libgcrypt
package and not the libgcrypt
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
Remediation
Upgrade Centos:8
libgcrypt
to version 0:1.8.5-7.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-40528
- https://eprint.iacr.org/2021/923
- https://ibm.github.io/system-security-research-updates/2021/07/20/insecurity-elgamal-pt1
- https://ibm.github.io/system-security-research-updates/2021/09/06/insecurity-elgamal-pt2
- https://access.redhat.com/errata/RHSA-2022:5311
- https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=3462280f2e23e16adf3ed5176e0f2413d8861320
- https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=3462280f2e23e16adf3ed5176e0f2413d8861320
- https://security.gentoo.org/glsa/202210-13
medium severity
- Vulnerable module: libtasn1
- Introduced through: libtasn1@4.13-3.el8
- Fixed in: 0:4.13-4.el8_7
Detailed paths
-
Introduced through: centos@centos8 › libtasn1@4.13-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libtasn1
package and not the libtasn1
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
Remediation
Upgrade Centos:8
libtasn1
to version 0:4.13-4.el8_7 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-46848
- https://access.redhat.com/errata/RHSA-2023:0116
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AV4SHDJF2XLB4CUPTBPQQ6CLGZ5LKXPZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ECM2ELTVRYV4BZ5L5GMIRQE27RFHPAQ6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OGO7XST4EIJGX4B2ITZCYSWM24534BSU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V5LWOGF7QRMNFRUCZY6TDYQJVFI6MOQ2/
- https://bugs.gentoo.org/866237
- https://gitlab.com/gnutls/libtasn1/-/commit/44a700d2051a666235748970c2df047ff207aeb5
- https://gitlab.com/gnutls/libtasn1/-/issues/32
- https://lists.debian.org/debian-lts-announce/2023/01/msg00003.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AV4SHDJF2XLB4CUPTBPQQ6CLGZ5LKXPZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ECM2ELTVRYV4BZ5L5GMIRQE27RFHPAQ6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OGO7XST4EIJGX4B2ITZCYSWM24534BSU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V5LWOGF7QRMNFRUCZY6TDYQJVFI6MOQ2/
- https://security.netapp.com/advisory/ntap-20221118-0006/
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-16.el8_8.1
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the '\0' value).
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-16.el8_8.1 or higher.
References
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-16.el8_8.1
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-16.el8_8.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-28484
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/491
- https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.10.4
- https://lists.debian.org/debian-lts-announce/2023/04/msg00031.html
- https://security.netapp.com/advisory/ntap-20230601-0006/
- https://security.netapp.com/advisory/ntap-20240201-0005/
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-18.el8_10.2
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-18.el8_10.2 or higher.
References
medium severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-4.el8
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-4.el8 or higher.
References
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=122a19ab48091c657f7cb1fb3af9fc07bd557bbf
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8252ee4d90f3f2004d3d0aeeed003ad49c9a7807
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846
- https://security.netapp.com/advisory/ntap-20210219-0009/
- https://security.netapp.com/advisory/ntap-20210513-0002/
- https://support.apple.com/kb/HT212528
- https://support.apple.com/kb/HT212529
- https://support.apple.com/kb/HT212534
- https://www.openssl.org/news/secadv/20210216.txt
- https://www.tenable.com/security/tns-2021-03
- https://www.tenable.com/security/tns-2021-09
- https://access.redhat.com/security/cve/CVE-2021-23841
- https://www.debian.org/security/2021/dsa-4855
- http://seclists.org/fulldisclosure/2021/May/67
- http://seclists.org/fulldisclosure/2021/May/68
- http://seclists.org/fulldisclosure/2021/May/70
- https://security.gentoo.org/glsa/202103-03
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://access.redhat.com/errata/RHSA-2021:4424
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=122a19ab48091c657f7cb1fb3af9fc07bd557bbf
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8252ee4d90f3f2004d3d0aeeed003ad49c9a7807
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://www.oracle.com/security-alerts/cpuapr2022.html
medium severity
- Vulnerable module: platform-python-setuptools
- Introduced through: platform-python-setuptools@39.2.0-6.el8
- Fixed in: 0:39.2.0-6.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › platform-python-setuptools@39.2.0-6.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python-setuptools
package and not the platform-python-setuptools
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
Remediation
Upgrade Centos:8
platform-python-setuptools
to version 0:39.2.0-6.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-40897
- https://access.redhat.com/errata/RHSA-2023:0835
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R/
- https://github.com/pypa/setuptools/blob/fe8a98e696241487ba6ac9f91faa38ade939ec5d/setuptools/package_index.py#L200
- https://github.com/pypa/setuptools/commit/43a9c9bfa6aa626ec2a22540bea28d2ca77964be
- https://github.com/pypa/setuptools/compare/v65.5.0...v65.5.1
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H/
- https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/
- https://pyup.io/vulnerabilities/CVE-2022-40897/52495/
- https://security.netapp.com/advisory/ntap-20230214-0001/
- https://security.netapp.com/advisory/ntap-20240621-0006/
medium severity
- Vulnerable module: python3-pip-wheel
- Introduced through: python3-pip-wheel@9.0.3-19.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-pip-wheel@9.0.3-19.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-pip-wheel
package and not the python3-pip-wheel
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the Cookie
HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a Cookie
header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.
Remediation
There is no fixed version for Centos:8
python3-pip-wheel
.
References
- https://access.redhat.com/security/cve/CVE-2023-43804
- https://www.vicarius.io/vsociety/posts/cve-2023-43804-urllib3-vulnerability-3
- https://github.com/urllib3/urllib3/commit/01220354d389cd05474713f8c982d05c9b17aafb
- https://github.com/urllib3/urllib3/commit/644124ecd0b6e417c527191f866daa05a5a2056d
- https://github.com/urllib3/urllib3/security/advisories/GHSA-v845-jxx5-vc9f
- https://lists.debian.org/debian-lts-announce/2023/10/msg00012.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I3PR7C6RJ6JUBQKIJ644DMIJSUP36VDY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAGZXYJ7H2G3SB47M453VQVNAWKAEJJ/
- https://security.netapp.com/advisory/ntap-20241213-0007/
medium severity
- Vulnerable module: python3-setuptools-wheel
- Introduced through: python3-setuptools-wheel@39.2.0-6.el8
- Fixed in: 0:39.2.0-6.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › python3-setuptools-wheel@39.2.0-6.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-setuptools-wheel
package and not the python3-setuptools-wheel
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
Remediation
Upgrade Centos:8
python3-setuptools-wheel
to version 0:39.2.0-6.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-40897
- https://access.redhat.com/errata/RHSA-2023:0835
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R/
- https://github.com/pypa/setuptools/blob/fe8a98e696241487ba6ac9f91faa38ade939ec5d/setuptools/package_index.py#L200
- https://github.com/pypa/setuptools/commit/43a9c9bfa6aa626ec2a22540bea28d2ca77964be
- https://github.com/pypa/setuptools/compare/v65.5.0...v65.5.1
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H/
- https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/
- https://pyup.io/vulnerabilities/CVE-2022-40897/52495/
- https://security.netapp.com/advisory/ntap-20230214-0001/
- https://security.netapp.com/advisory/ntap-20240621-0006/
medium severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
- Fixed in: 0:3.26.0-17.el8_7
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
Remediation
Upgrade Centos:8
sqlite-libs
to version 0:3.26.0-17.el8_7 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-35737
- https://access.redhat.com/errata/RHSA-2023:0110
- https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/
- https://kb.cert.org/vuls/id/720344
- https://security.gentoo.org/glsa/202210-40
- https://security.netapp.com/advisory/ntap-20220915-0009/
- https://sqlite.org/releaselog/3_39_2.html
- https://www.sqlite.org/cves.html
- https://github.com/gmh5225/CVE-2022-35737
medium severity
- Vulnerable module: systemd
- Introduced through: systemd@239-45.el8
- Fixed in: 0:239-82.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd
package and not the systemd
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
Remediation
Upgrade Centos:8
systemd
to version 0:239-82.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-7008
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4GMDEG5PKONWNHOEYSUDRT6JEOISRMN2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QHNBXGKJWISJETTTDTZKTBFIBJUOSLKL/
- https://access.redhat.com/errata/RHSA-2024:3203
- https://bugzilla.redhat.com/show_bug.cgi?id=2222261
- https://bugzilla.redhat.com/show_bug.cgi?id=2222672
- https://github.com/systemd/systemd/issues/25676
- https://security.netapp.com/advisory/ntap-20241122-0004/
medium severity
- Vulnerable module: systemd-libs
- Introduced through: systemd-libs@239-45.el8
- Fixed in: 0:239-82.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd-libs@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-libs
package and not the systemd-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
Remediation
Upgrade Centos:8
systemd-libs
to version 0:239-82.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-7008
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4GMDEG5PKONWNHOEYSUDRT6JEOISRMN2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QHNBXGKJWISJETTTDTZKTBFIBJUOSLKL/
- https://access.redhat.com/errata/RHSA-2024:3203
- https://bugzilla.redhat.com/show_bug.cgi?id=2222261
- https://bugzilla.redhat.com/show_bug.cgi?id=2222672
- https://github.com/systemd/systemd/issues/25676
- https://security.netapp.com/advisory/ntap-20241122-0004/
medium severity
- Vulnerable module: systemd-pam
- Introduced through: systemd-pam@239-45.el8
- Fixed in: 0:239-82.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd-pam@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-pam
package and not the systemd-pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
Remediation
Upgrade Centos:8
systemd-pam
to version 0:239-82.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-7008
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4GMDEG5PKONWNHOEYSUDRT6JEOISRMN2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QHNBXGKJWISJETTTDTZKTBFIBJUOSLKL/
- https://access.redhat.com/errata/RHSA-2024:3203
- https://bugzilla.redhat.com/show_bug.cgi?id=2222261
- https://bugzilla.redhat.com/show_bug.cgi?id=2222672
- https://github.com/systemd/systemd/issues/25676
- https://security.netapp.com/advisory/ntap-20241122-0004/
medium severity
- Vulnerable module: systemd-udev
- Introduced through: systemd-udev@239-45.el8
- Fixed in: 0:239-82.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd-udev@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-udev
package and not the systemd-udev
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
Remediation
Upgrade Centos:8
systemd-udev
to version 0:239-82.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-7008
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4GMDEG5PKONWNHOEYSUDRT6JEOISRMN2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QHNBXGKJWISJETTTDTZKTBFIBJUOSLKL/
- https://access.redhat.com/errata/RHSA-2024:3203
- https://bugzilla.redhat.com/show_bug.cgi?id=2222261
- https://bugzilla.redhat.com/show_bug.cgi?id=2222672
- https://github.com/systemd/systemd/issues/25676
- https://security.netapp.com/advisory/ntap-20241122-0004/
medium severity
- Vulnerable module: libcom_err
- Introduced through: libcom_err@1.45.6-1.el8
- Fixed in: 0:1.45.6-5.el8
Detailed paths
-
Introduced through: centos@centos8 › libcom_err@1.45.6-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcom_err
package and not the libcom_err
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
Remediation
Upgrade Centos:8
libcom_err
to version 0:1.45.6-5.el8 or higher.
References
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-18.el8_4.1
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-18.el8_4.1 or higher.
References
- https://security.netapp.com/advisory/ntap-20210902-0003/
- https://access.redhat.com/security/cve/CVE-2021-22923
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://hackerone.com/reports/1213181
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://access.redhat.com/errata/RHSA-2021:3582
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://security.gentoo.org/glsa/202212-01
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-18.el8_4.1
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-18.el8_4.1 or higher.
References
- https://security.netapp.com/advisory/ntap-20210902-0003/
- https://access.redhat.com/security/cve/CVE-2021-22923
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://hackerone.com/reports/1213181
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://access.redhat.com/errata/RHSA-2021:3582
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://security.gentoo.org/glsa/202212-01
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-41.el8
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-41.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210629-0003/
- https://access.redhat.com/security/cve/CVE-2021-3426
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/25HVHLBGO2KNPXJ3G426QEYSSCECJDU5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BF2K7HEWADHN6P52R3QLIOX27U3DJ4HI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DQYPUKLLBOZMKFPO7RD7CENTXHUUEUV7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LM5V4VPLBHBEASSAROYPSHXGXGGPHNOE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N6VXJZSZ6N64AILJX4CTMACYGQGHHD5C/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QNGAFMPIYIVJ47FCF2NK2PIX22HUG35B/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VPX7Y5GQDNB4FJTREWONGC4ZSVH7TGHF/
- https://security.gentoo.org/glsa/202104-04
- https://bugzilla.redhat.com/show_bug.cgi?id=1935913
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html
- https://access.redhat.com/errata/RHSA-2021:4399
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/25HVHLBGO2KNPXJ3G426QEYSSCECJDU5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BF2K7HEWADHN6P52R3QLIOX27U3DJ4HI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DQYPUKLLBOZMKFPO7RD7CENTXHUUEUV7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LM5V4VPLBHBEASSAROYPSHXGXGGPHNOE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6VXJZSZ6N64AILJX4CTMACYGQGHHD5C/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QNGAFMPIYIVJ47FCF2NK2PIX22HUG35B/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VPX7Y5GQDNB4FJTREWONGC4ZSVH7TGHF/
- https://www.oracle.com/security-alerts/cpujan2022.html
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-41.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-41.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210629-0003/
- https://access.redhat.com/security/cve/CVE-2021-3426
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/25HVHLBGO2KNPXJ3G426QEYSSCECJDU5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BF2K7HEWADHN6P52R3QLIOX27U3DJ4HI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DQYPUKLLBOZMKFPO7RD7CENTXHUUEUV7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LM5V4VPLBHBEASSAROYPSHXGXGGPHNOE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N6VXJZSZ6N64AILJX4CTMACYGQGHHD5C/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QNGAFMPIYIVJ47FCF2NK2PIX22HUG35B/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VPX7Y5GQDNB4FJTREWONGC4ZSVH7TGHF/
- https://security.gentoo.org/glsa/202104-04
- https://bugzilla.redhat.com/show_bug.cgi?id=1935913
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html
- https://access.redhat.com/errata/RHSA-2021:4399
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/25HVHLBGO2KNPXJ3G426QEYSSCECJDU5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BF2K7HEWADHN6P52R3QLIOX27U3DJ4HI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DQYPUKLLBOZMKFPO7RD7CENTXHUUEUV7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LM5V4VPLBHBEASSAROYPSHXGXGGPHNOE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6VXJZSZ6N64AILJX4CTMACYGQGHHD5C/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QNGAFMPIYIVJ47FCF2NK2PIX22HUG35B/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VPX7Y5GQDNB4FJTREWONGC4ZSVH7TGHF/
- https://www.oracle.com/security-alerts/cpujan2022.html
medium severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
- Fixed in: 0:2.9.7-20.el8_10
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between bytes and characters.
Remediation
Upgrade Centos:8
libxml2
to version 0:2.9.7-20.el8_10 or higher.
References
medium severity
- Vulnerable module: tar
- Introduced through: tar@2:1.30-5.el8
Detailed paths
-
Introduced through: centos@centos8 › tar@2:1.30-5.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream tar
package and not the tar
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which "tar xf" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages). NOTE: the official GNU Tar manual has an otherwise-empty directory for each "tar xf" in its Security Rules of Thumb; however, third-party advice leads users to run "tar xf" more than once into the same directory.
Remediation
There is no fixed version for Centos:8
tar
.
References
- https://access.redhat.com/security/cve/CVE-2025-45582
- https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md
- https://www.gnu.org/software/tar/
- https://lists.gnu.org/archive/html/bug-tar/2025-08/msg00012.html
- https://www.gnu.org/software/tar/manual/html_node/Integrity.html
- https://www.gnu.org/software/tar/manual/html_node/Security-rules-of-thumb.html
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The get_count function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31, allows remote attackers to cause a denial of service (malloc called with the result of an integer-overflowing calculation) or possibly have unspecified other impact via a crafted string, as demonstrated by c++filt.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/105689
- https://access.redhat.com/security/cve/CVE-2018-18483
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87602
- https://sourceware.org/bugzilla/show_bug.cgi?id=23767
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://usn.ubuntu.com/4326-1/
- https://usn.ubuntu.com/4336-1/
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
- Fixed in: 0:2.30-119.el8_8.2
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
Remediation
Upgrade Centos:8
binutils
to version 0:2.30-119.el8_8.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-4285
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=5c831a3c7f3ca98d6aba1200353311e1a1f84c70
- https://bugzilla.redhat.com/show_bug.cgi?id=2150768
- https://security.gentoo.org/glsa/202309-15
- https://sourceware.org/bugzilla/show_bug.cgi?id=29699
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=5c831a3c7f3ca98d6aba1200353311e1a1f84c70
medium severity
- Vulnerable module: cpio
- Introduced through: cpio@2.12-10.el8
Detailed paths
-
Introduced through: centos@centos8 › cpio@2.12-10.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream cpio
package and not the cpio
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
Remediation
There is no fixed version for Centos:8
cpio
.
References
- https://access.redhat.com/security/cve/CVE-2023-7207
- http://www.openwall.com/lists/oss-security/2024/01/05/1
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059163
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7207
- https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=376d663340a9dc91c91a5849e5713f07571c1628
- https://www.openwall.com/lists/oss-security/2023/12/21/8
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-156.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-156.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3800
- https://access.redhat.com/errata/RHSA-2021:4385
- https://bugzilla.redhat.com/show_bug.cgi?id=1938284
- https://gitlab.gnome.org/GNOME/glib/-/commit/3529bb4450a51995
- https://lists.debian.org/debian-lts-announce/2022/09/msg00020.html
- https://security.netapp.com/advisory/ntap-20221028-0004/
- https://www.openwall.com/lists/oss-security/2017/06/23/8
medium severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.16
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-251.el8_10.16 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-0395
- https://sourceware.org/bugzilla/show_bug.cgi?id=32582
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001
- https://sourceware.org/pipermail/libc-announce/2025/000044.html
- https://www.openwall.com/lists/oss-security/2025/01/22/4
- http://www.openwall.com/lists/oss-security/2025/01/22/4
- http://www.openwall.com/lists/oss-security/2025/01/23/2
- https://security.netapp.com/advisory/ntap-20250228-0006/
- http://www.openwall.com/lists/oss-security/2025/04/13/1
- http://www.openwall.com/lists/oss-security/2025/04/24/7
- https://lists.debian.org/debian-lts-announce/2025/04/msg00039.html
medium severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.16
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-251.el8_10.16 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-0395
- https://sourceware.org/bugzilla/show_bug.cgi?id=32582
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001
- https://sourceware.org/pipermail/libc-announce/2025/000044.html
- https://www.openwall.com/lists/oss-security/2025/01/22/4
- http://www.openwall.com/lists/oss-security/2025/01/22/4
- http://www.openwall.com/lists/oss-security/2025/01/23/2
- https://security.netapp.com/advisory/ntap-20250228-0006/
- http://www.openwall.com/lists/oss-security/2025/04/13/1
- http://www.openwall.com/lists/oss-security/2025/04/24/7
- https://lists.debian.org/debian-lts-announce/2025/04/msg00039.html
medium severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.16
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-251.el8_10.16 or higher.
References
- https://access.redhat.com/security/cve/CVE-2025-0395
- https://sourceware.org/bugzilla/show_bug.cgi?id=32582
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001
- https://sourceware.org/pipermail/libc-announce/2025/000044.html
- https://www.openwall.com/lists/oss-security/2025/01/22/4
- http://www.openwall.com/lists/oss-security/2025/01/22/4
- http://www.openwall.com/lists/oss-security/2025/01/23/2
- https://security.netapp.com/advisory/ntap-20250228-0006/
- http://www.openwall.com/lists/oss-security/2025/04/13/1
- http://www.openwall.com/lists/oss-security/2025/04/24/7
- https://lists.debian.org/debian-lts-announce/2025/04/msg00039.html
medium severity
- Vulnerable module: pam
- Introduced through: pam@1.3.1-14.el8
- Fixed in: 0:1.3.1-33.el8
Detailed paths
-
Introduced through: centos@centos8 › pam@1.3.1-14.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream pam
package and not the pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
Remediation
Upgrade Centos:8
pam
to version 0:1.3.1-33.el8 or higher.
References
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-56.el8_9
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-56.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2007-4559
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/
- http://mail.python.org/pipermail/python-dev/2007-August/074290.html
- http://mail.python.org/pipermail/python-dev/2007-August/074292.html
- http://secunia.com/advisories/26623
- http://www.vupen.com/english/advisories/2007/3022
- https://bugzilla.redhat.com/show_bug.cgi?id=263261
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/
- https://security.gentoo.org/glsa/202309-06
- https://github.com/advanced-threat-research/Creosote
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-56.el8_9
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-56.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2007-4559
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/
- http://mail.python.org/pipermail/python-dev/2007-August/074290.html
- http://mail.python.org/pipermail/python-dev/2007-August/074292.html
- http://secunia.com/advisories/26623
- http://www.vupen.com/english/advisories/2007/3022
- https://bugzilla.redhat.com/show_bug.cgi?id=263261
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/
- https://security.gentoo.org/glsa/202309-06
- https://github.com/advanced-threat-research/Creosote
medium severity
- Vulnerable module: python3-pip-wheel
- Introduced through: python3-pip-wheel@9.0.3-19.el8
- Fixed in: 0:9.0.3-23.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-pip-wheel@9.0.3-19.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-pip-wheel
package and not the python3-pip-wheel
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
Remediation
Upgrade Centos:8
python3-pip-wheel
to version 0:9.0.3-23.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2007-4559
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/
- http://mail.python.org/pipermail/python-dev/2007-August/074290.html
- http://mail.python.org/pipermail/python-dev/2007-August/074292.html
- http://secunia.com/advisories/26623
- http://www.vupen.com/english/advisories/2007/3022
- https://bugzilla.redhat.com/show_bug.cgi?id=263261
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/
- https://security.gentoo.org/glsa/202309-06
- https://github.com/advanced-threat-research/Creosote
medium severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
- Fixed in: 0:3.26.0-15.el8
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.
Remediation
Upgrade Centos:8
sqlite-libs
to version 0:3.26.0-15.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20200528-0004/
- https://support.apple.com/kb/HT211843
- https://support.apple.com/kb/HT211844
- https://support.apple.com/kb/HT211850
- https://support.apple.com/kb/HT211931
- https://support.apple.com/kb/HT211935
- https://support.apple.com/kb/HT211952
- https://access.redhat.com/security/cve/CVE-2020-13435
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L7KXQWHIY2MQP4LNM6ODWJENMXYYQYBN/
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:22.sqlite.asc
- http://seclists.org/fulldisclosure/2020/Dec/32
- http://seclists.org/fulldisclosure/2020/Nov/19
- http://seclists.org/fulldisclosure/2020/Nov/20
- http://seclists.org/fulldisclosure/2020/Nov/22
- https://security.gentoo.org/glsa/202007-26
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.sqlite.org/src/info/7a5279a25c57adf1
- https://access.redhat.com/errata/RHSA-2021:4396
- https://usn.ubuntu.com/4394-1/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7KXQWHIY2MQP4LNM6ODWJENMXYYQYBN/
medium severity
- Vulnerable module: systemd
- Introduced through: systemd@239-45.el8
- Fixed in: 0:239-68.el8_7.4
Detailed paths
-
Introduced through: centos@centos8 › systemd@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd
package and not the systemd
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
Remediation
Upgrade Centos:8
systemd
to version 0:239-68.el8_7.4 or higher.
References
medium severity
- Vulnerable module: systemd
- Introduced through: systemd@239-45.el8
- Fixed in: 0:239-68.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › systemd@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd
package and not the systemd
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
Remediation
Upgrade Centos:8
systemd
to version 0:239-68.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-3821
- https://access.redhat.com/errata/RHSA-2023:0100
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/
- https://bugzilla.redhat.com/show_bug.cgi?id=2139327
- https://github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4e
- https://github.com/systemd/systemd/issues/23928
- https://github.com/systemd/systemd/pull/23933
- https://lists.debian.org/debian-lts-announce/2023/06/msg00036.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/
- https://security.gentoo.org/glsa/202305-15
medium severity
- Vulnerable module: systemd-libs
- Introduced through: systemd-libs@239-45.el8
- Fixed in: 0:239-68.el8_7.4
Detailed paths
-
Introduced through: centos@centos8 › systemd-libs@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-libs
package and not the systemd-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
Remediation
Upgrade Centos:8
systemd-libs
to version 0:239-68.el8_7.4 or higher.
References
medium severity
- Vulnerable module: systemd-libs
- Introduced through: systemd-libs@239-45.el8
- Fixed in: 0:239-68.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › systemd-libs@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-libs
package and not the systemd-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
Remediation
Upgrade Centos:8
systemd-libs
to version 0:239-68.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-3821
- https://access.redhat.com/errata/RHSA-2023:0100
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/
- https://bugzilla.redhat.com/show_bug.cgi?id=2139327
- https://github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4e
- https://github.com/systemd/systemd/issues/23928
- https://github.com/systemd/systemd/pull/23933
- https://lists.debian.org/debian-lts-announce/2023/06/msg00036.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/
- https://security.gentoo.org/glsa/202305-15
medium severity
- Vulnerable module: systemd-pam
- Introduced through: systemd-pam@239-45.el8
- Fixed in: 0:239-68.el8_7.4
Detailed paths
-
Introduced through: centos@centos8 › systemd-pam@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-pam
package and not the systemd-pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
Remediation
Upgrade Centos:8
systemd-pam
to version 0:239-68.el8_7.4 or higher.
References
medium severity
- Vulnerable module: systemd-pam
- Introduced through: systemd-pam@239-45.el8
- Fixed in: 0:239-68.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › systemd-pam@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-pam
package and not the systemd-pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
Remediation
Upgrade Centos:8
systemd-pam
to version 0:239-68.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-3821
- https://access.redhat.com/errata/RHSA-2023:0100
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/
- https://bugzilla.redhat.com/show_bug.cgi?id=2139327
- https://github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4e
- https://github.com/systemd/systemd/issues/23928
- https://github.com/systemd/systemd/pull/23933
- https://lists.debian.org/debian-lts-announce/2023/06/msg00036.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/
- https://security.gentoo.org/glsa/202305-15
medium severity
- Vulnerable module: systemd-udev
- Introduced through: systemd-udev@239-45.el8
- Fixed in: 0:239-68.el8_7.4
Detailed paths
-
Introduced through: centos@centos8 › systemd-udev@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-udev
package and not the systemd-udev
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
Remediation
Upgrade Centos:8
systemd-udev
to version 0:239-68.el8_7.4 or higher.
References
medium severity
- Vulnerable module: systemd-udev
- Introduced through: systemd-udev@239-45.el8
- Fixed in: 0:239-68.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › systemd-udev@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-udev
package and not the systemd-udev
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
Remediation
Upgrade Centos:8
systemd-udev
to version 0:239-68.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-3821
- https://access.redhat.com/errata/RHSA-2023:0100
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/
- https://bugzilla.redhat.com/show_bug.cgi?id=2139327
- https://github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4e
- https://github.com/systemd/systemd/issues/23928
- https://github.com/systemd/systemd/pull/23933
- https://lists.debian.org/debian-lts-announce/2023/06/msg00036.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/
- https://security.gentoo.org/glsa/202305-15
medium severity
- Vulnerable module: tar
- Introduced through: tar@2:1.30-5.el8
- Fixed in: 2:1.30-6.el8_7.1
Detailed paths
-
Introduced through: centos@centos8 › tar@2:1.30-5.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream tar
package and not the tar
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
Remediation
Upgrade Centos:8
tar
to version 2:1.30-6.el8_7.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-48303
- https://access.redhat.com/errata/RHSA-2023:0842
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CRY7VEL4AIG3GLIEVCTOXRZNSVYDYYUD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X5VQYCO52Z7GAVCLRYUITN7KXHLRZQS4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CRY7VEL4AIG3GLIEVCTOXRZNSVYDYYUD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5VQYCO52Z7GAVCLRYUITN7KXHLRZQS4/
- https://savannah.gnu.org/bugs/?62387
- https://savannah.gnu.org/patch/?10307
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
- Fixed in: 2:8.0.1763-16.el8_5.4
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
vim is vulnerable to Out-of-bounds Read
Remediation
Upgrade Centos:8
vim-minimal
to version 2:8.0.1763-16.el8_5.4 or higher.
References
- https://huntr.dev/bounties/92c1940d-8154-473f-84ce-0de43b0c2eb0
- https://access.redhat.com/security/cve/CVE-2021-4193
- https://github.com/vim/vim/commit/94f3192b03ed27474db80b4d3a409e107140738b
- https://access.redhat.com/errata/RHSA-2022:0366
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3FH2J57GDA2WMBS6J56F6QQRA6BXQQFZ/
- http://seclists.org/fulldisclosure/2022/Jul/14
- http://seclists.org/fulldisclosure/2022/Mar/29
- http://seclists.org/fulldisclosure/2022/May/35
- http://www.openwall.com/lists/oss-security/2022/01/15/1
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3FH2J57GDA2WMBS6J56F6QQRA6BXQQFZ/
- https://security.gentoo.org/glsa/202208-32
- https://support.apple.com/kb/HT213183
- https://support.apple.com/kb/HT213256
- https://support.apple.com/kb/HT213343
medium severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
- Fixed in: 0:6.1-9.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
Remediation
Upgrade Centos:8
ncurses-base
to version 0:6.1-9.20180224.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2019-17595
- https://security.gentoo.org/glsa/202101-28
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00013.html
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00045.html
- https://access.redhat.com/errata/RHSA-2021:4426
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00061.html
medium severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
- Fixed in: 0:6.1-9.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
Remediation
Upgrade Centos:8
ncurses-libs
to version 0:6.1-9.20180224.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2019-17595
- https://security.gentoo.org/glsa/202101-28
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00013.html
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00045.html
- https://access.redhat.com/errata/RHSA-2021:4426
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00061.html
medium severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-3.el8
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way the lame cache is currently designed makes it possible for its internal data structures to grow almost infinitely, which may cause significant delays in client query processing.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-3.el8 or higher.
References
- https://kb.isc.org/v1/docs/cve-2021-25219
- https://access.redhat.com/security/cve/CVE-2021-25219
- https://www.debian.org/security/2021/dsa-4994
- https://access.redhat.com/errata/RHSA-2022:2092
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EF4NAVRV4H3W4GA3LGGZYUKD3HSJBAVW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YGV7SA27CTYLGFJSPUM3V36ZWK7WWDI4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YTKC4E3HUOLYN5IA4EBL4VAQSWG2ZVTX/
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.debian.org/debian-lts-announce/2021/11/msg00001.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EF4NAVRV4H3W4GA3LGGZYUKD3HSJBAVW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YGV7SA27CTYLGFJSPUM3V36ZWK7WWDI4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YTKC4E3HUOLYN5IA4EBL4VAQSWG2ZVTX/
- https://security.gentoo.org/glsa/202210-25
- https://security.netapp.com/advisory/ntap-20211118-0002/
- https://www.oracle.com/security-alerts/cpuapr2022.html
medium severity
- Vulnerable module: bind-export-libs
- Introduced through: bind-export-libs@32:9.11.26-3.el8
- Fixed in: 32:9.11.36-8.el8
Detailed paths
-
Introduced through: centos@centos8 › bind-export-libs@32:9.11.26-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bind-export-libs
package and not the bind-export-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
Remediation
Upgrade Centos:8
bind-export-libs
to version 32:9.11.36-8.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-2795
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/
- http://www.openwall.com/lists/oss-security/2022/09/21/3
- https://kb.isc.org/docs/cve-2022-2795
- https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/
- https://security.gentoo.org/glsa/202210-25
- https://security.netapp.com/advisory/ntap-20241129-0002/
- https://www.debian.org/security/2022/dsa-5235
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option section.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/107139
- https://security.netapp.com/advisory/ntap-20190314-0003/
- https://support.f5.com/csp/article/K00056379
- https://access.redhat.com/security/cve/CVE-2019-9077
- https://sourceware.org/bugzilla/show_bug.cgi?id=24243
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html
- https://usn.ubuntu.com/4336-1/
- https://security.gentoo.org/glsa/202107-24
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is a heap-based buffer overflow in _bfd_archive_64_bit_slurp_armap in archive64.c.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://security.netapp.com/advisory/ntap-20190314-0003/
- https://support.f5.com/csp/article/K42059040
- https://access.redhat.com/security/cve/CVE-2019-9075
- https://sourceware.org/bugzilla/show_bug.cgi?id=24236
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html
- https://usn.ubuntu.com/4336-1/
- https://security.gentoo.org/glsa/202107-24
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/106457
- https://access.redhat.com/security/cve/CVE-2018-20671
- https://sourceware.org/bugzilla/show_bug.cgi?id=24005
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=11fa9f134fd658075c6f74499c780df045d9e9ca
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://usn.ubuntu.com/4336-1/
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=11fa9f134fd658075c6f74499c780df045d9e9ca
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://access.redhat.com/security/cve/CVE-2025-7546
- https://sourceware.org/bugzilla/attachment.cgi?id=16118
- https://sourceware.org/bugzilla/show_bug.cgi?id=33050#c2
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=41461010eb7c79fee7a9d5f6209accdaac66cc6b
- https://vuldb.com/?ctiid.316244
- https://vuldb.com/?id.316244
- https://vuldb.com/?submit.614375
- https://www.gnu.org/
- https://sourceware.org/bugzilla/show_bug.cgi?id=33050
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://access.redhat.com/security/cve/CVE-2025-7545
- https://sourceware.org/bugzilla/attachment.cgi?id=16117
- https://sourceware.org/bugzilla/show_bug.cgi?id=33049
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944
- https://vuldb.com/?ctiid.316243
- https://vuldb.com/?id.316243
- https://vuldb.com/?submit.614355
- https://www.gnu.org/
- https://sourceware.org/bugzilla/show_bug.cgi?id=33049#c1
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archive function in readelf.c via a crafted ELF file.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/106370
- https://support.f5.com/csp/article/K38336243
- https://access.redhat.com/security/cve/CVE-2018-20623
- https://sourceware.org/bugzilla/show_bug.cgi?id=24049
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://usn.ubuntu.com/4336-1/
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8_6.4
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-22.el8_6.4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-32208
- https://access.redhat.com/errata/RHSA-2022:6159
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- https://hackerone.com/reports/1590071
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220915-0003/
- https://support.apple.com/kb/HT213488
- https://www.debian.org/security/2022/dsa-5197
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-33.el8_9.5
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains.
It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with domain=co.UK
when the URL used a lower
case hostname curl.co.uk
, even though co.uk
is listed as a PSL domain.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-33.el8_9.5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-46218
- https://curl.se/docs/CVE-2023-46218.html
- https://hackerone.com/reports/2212193
- https://lists.debian.org/debian-lts-announce/2023/12/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3ZX3VW67N4ACRAPMV2QS2LVYGD7H2MVE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UOGXU25FMMT2X6UUITQ7EZZYMJ42YWWD/
- https://security.netapp.com/advisory/ntap-20240125-0007/
- https://www.debian.org/security/2023/dsa-5587
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-156.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-156.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210416-0003/
- https://access.redhat.com/security/cve/CVE-2021-28153
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6RXTD5HCP2K4AAUSWWZTBKQNHRCTAEOF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ICUTQPHZNZWX2DZR46QFLQZRHVMHIILJ/
- https://gitlab.gnome.org/GNOME/glib/-/issues/2325
- https://access.redhat.com/errata/RHSA-2021:4385
- https://lists.debian.org/debian-lts-announce/2022/06/msg00006.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6RXTD5HCP2K4AAUSWWZTBKQNHRCTAEOF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICUTQPHZNZWX2DZR46QFLQZRHVMHIILJ/
- https://security.gentoo.org/glsa/202107-13
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
- Fixed in: 0:3.6.16-8.el8_10.3
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.
Remediation
Upgrade Centos:8
gnutls
to version 0:3.6.16-8.el8_10.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-12243
- https://bugzilla.redhat.com/show_bug.cgi?id=2344615
- https://gitlab.com/gnutls/libtasn1/-/issues/52
- https://lists.debian.org/debian-lts-announce/2025/02/msg00027.html
- https://access.redhat.com/errata/RHSA-2025:4051
- https://security.netapp.com/advisory/ntap-20250523-0002/
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly.
Remediation
There is no fixed version for Centos:8
gnutls
.
References
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
- Fixed in: 0:3.6.16-8.el8_9.3
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.
Remediation
Upgrade Centos:8
gnutls
to version 0:3.6.16-8.el8_9.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-28834
- http://www.openwall.com/lists/oss-security/2024/03/22/1
- http://www.openwall.com/lists/oss-security/2024/03/22/2
- https://people.redhat.com/~hkario/marvin/
- https://security.netapp.com/advisory/ntap-20240524-0004/
- https://access.redhat.com/errata/RHSA-2024:1784
- https://bugzilla.redhat.com/show_bug.cgi?id=2269228
- https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html
- https://minerva.crocs.fi.muni.cz/
medium severity
- Vulnerable module: iputils
- Introduced through: iputils@20180629-7.el8
Detailed paths
-
Introduced through: centos@centos8 › iputils@20180629-7.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream iputils
package and not the iputils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a zero timestamp can lead to large intermediate values that have an integer overflow when squared during statistics calculations. NOTE: this issue exists because of an incomplete fix for CVE-2025-47268 (that fix was only about timestamp calculations, and it did not account for a specific scenario where the original timestamp in the ICMP payload is zero).
Remediation
There is no fixed version for Centos:8
iputils
.
References
- https://access.redhat.com/security/cve/CVE-2025-48964
- https://bugzilla.suse.com/show_bug.cgi?id=1243772
- https://github.com/iputils/iputils/issues
- https://github.com/iputils/iputils/security/advisories/GHSA-25fr-jw29-74f9
- https://github.com/iputils/iputils/commit/afa36390394a6e0cceba03b52b59b6d41710608c
- https://github.com/iputils/iputils/releases/tag/20250602
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8_6.4
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-22.el8_6.4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-32208
- https://access.redhat.com/errata/RHSA-2022:6159
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- https://hackerone.com/reports/1590071
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220915-0003/
- https://support.apple.com/kb/HT213488
- https://www.debian.org/security/2022/dsa-5197
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-33.el8_9.5
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains.
It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with domain=co.UK
when the URL used a lower
case hostname curl.co.uk
, even though co.uk
is listed as a PSL domain.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-33.el8_9.5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-46218
- https://curl.se/docs/CVE-2023-46218.html
- https://hackerone.com/reports/2212193
- https://lists.debian.org/debian-lts-announce/2023/12/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3ZX3VW67N4ACRAPMV2QS2LVYGD7H2MVE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UOGXU25FMMT2X6UUITQ7EZZYMJ42YWWD/
- https://security.netapp.com/advisory/ntap-20240125-0007/
- https://www.debian.org/security/2023/dsa-5587
medium severity
- Vulnerable module: libnghttp2
- Introduced through: libnghttp2@1.33.0-3.el8_2.1
- Fixed in: 0:1.33.0-6.el8_10.1
Detailed paths
-
Introduced through: centos@centos8 › libnghttp2@1.33.0-3.el8_2.1
NVD Description
Note: Versions mentioned in the description apply only to the upstream libnghttp2
package and not the libnghttp2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.
Remediation
Upgrade Centos:8
libnghttp2
to version 0:1.33.0-6.el8_10.1 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-28182
- http://www.openwall.com/lists/oss-security/2024/04/03/16
- https://github.com/nghttp2/nghttp2/commit/00201ecd8f982da3b67d4f6868af72a1b03b14e0
- https://github.com/nghttp2/nghttp2/commit/d71a4668c6bead55805d18810d633fbb98315af9
- https://github.com/nghttp2/nghttp2/security/advisories/GHSA-x6x3-gv8h-m57q
- https://lists.debian.org/debian-lts-announce/2024/04/msg00026.html
- https://lists.debian.org/debian-lts-announce/2024/09/msg00041.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AGOME6ZXJG7664IPQNVE3DL67E3YP3HY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J6ZMXUGB66VAXDW5J6QSTHM5ET25FGSA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXJO2EASHM2OQQLGVDY5ZSO7UVDVHTDK/
medium severity
- Vulnerable module: libtasn1
- Introduced through: libtasn1@4.13-3.el8
- Fixed in: 0:4.13-5.el8_10
Detailed paths
-
Introduced through: centos@centos8 › libtasn1@4.13-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libtasn1
package and not the libtasn1
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.
Remediation
Upgrade Centos:8
libtasn1
to version 0:4.13-5.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-12133
- https://bugzilla.redhat.com/show_bug.cgi?id=2344611
- https://gitlab.com/gnutls/libtasn1/-/issues/52
- http://www.openwall.com/lists/oss-security/2025/02/06/6
- https://lists.debian.org/debian-lts-announce/2025/02/msg00025.html
- https://access.redhat.com/errata/RHSA-2025:4049
- https://security.netapp.com/advisory/ntap-20250523-0003/
medium severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
- Fixed in: 0:6.1-9.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
Remediation
Upgrade Centos:8
ncurses-base
to version 0:6.1-9.20180224.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2019-17594
- https://security.gentoo.org/glsa/202101-28
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00017.html
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00045.html
- https://access.redhat.com/errata/RHSA-2021:4426
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00061.html
medium severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
- Fixed in: 0:6.1-9.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
Remediation
Upgrade Centos:8
ncurses-libs
to version 0:6.1-9.20180224.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2019-17594
- https://security.gentoo.org/glsa/202101-28
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00017.html
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00045.html
- https://access.redhat.com/errata/RHSA-2021:4426
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00061.html
medium severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing certificate verification. However the implementation of the function does not enable the check which allows certificates with invalid or incorrect policies to pass the certificate verification.
As suddenly enabling the policy check could break existing deployments it was decided to keep the existing behavior of the X509_VERIFY_PARAM_add0_policy() function.
Instead the applications that require OpenSSL to perform certificate policy check need to use X509_VERIFY_PARAM_set1_policies() or explicitly enable the policy check by calling X509_VERIFY_PARAM_set_flags() with the X509_V_FLAG_POLICY_CHECK flag argument.
Certificate policy checks are disabled by default in OpenSSL and are not commonly used by applications.
Remediation
There is no fixed version for Centos:8
openssl-libs
.
References
- https://access.redhat.com/security/cve/CVE-2023-0466
- http://www.openwall.com/lists/oss-security/2023/09/28/4
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=0d16b7e99aafc0b4a6d729eec65a411a7e025f0a
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=51e8a84ce742db0f6c70510d0159dad8f7825908
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=73398dea26de9899fb4baa94098ad0a61f435c72
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fc814a30fc4f0bc54fcea7d9a7462f5457aab061
- https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html
- https://security.gentoo.org/glsa/202402-08
- https://security.netapp.com/advisory/ntap-20230414-0001/
- https://www.debian.org/security/2023/dsa-5417
- https://www.openssl.org/news/secadv/20230328.txt
medium severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-7.el8_6
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-7.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-2097
- https://access.redhat.com/errata/RHSA-2022:5818
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=919925673d6c9cfed3c1085497f5dfbbed5fc431
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a98f339ddd7e8f487d6e0088d4a9a42324885a93
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/
- https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=919925673d6c9cfed3c1085497f5dfbbed5fc431
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a98f339ddd7e8f487d6e0088d4a9a42324885a93
- https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/
- https://security.gentoo.org/glsa/202210-02
- https://security.netapp.com/advisory/ntap-20220715-0011/
- https://security.netapp.com/advisory/ntap-20230420-0008/
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://www.debian.org/security/2023/dsa-5343
- https://www.openssl.org/news/secadv/20220705.txt
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-47.el8_6
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-47.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-0391
- https://access.redhat.com/errata/RHSA-2022:6457
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/
- https://bugs.python.org/issue43882
- https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/
- https://security.gentoo.org/glsa/202305-02
- https://security.netapp.com/advisory/ntap-20220225-0009/
- https://www.oracle.com/security-alerts/cpuapr2022.html
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-56.el8_9.3
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-56.el8_9.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-27043
- http://python.com
- http://python.org
- https://github.com/python/cpython/issues/102988
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZAEFSFZDNBNJPNOUTLG5COISGQDLMGV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/75DTHSTNOFFNAWHXKMDXS7EJWC6W2FUC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ARI7VDSNTQVXRQFM6IK5GSSLEIYV4VZH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQAKLUJMHFGVBRDPEY57BJGNCE5UUPHW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXYVPEZUA3465AEFX5JVFVP7KIFZMF3N/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6M5I6OQHJABNEYY555HUMMKX3Y4P25Z/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NEUNZSZ3CVSM2QWVYH3N2XGOCDWNYUA3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORLXS5YTKN65E2Q2NWKXMFS5FWQHRNZW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2MAICLFDDO3QVNHTZ2OCERZQ34R2PIC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2W2BZQIHMCKRI5FNBJERFYMS5PK6TAH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PHVGRKQAGANCSGFI3QMYOCIMS4IFOZA5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PU6Y2S5CBN5BWCBDAJFTGIBZLK3S2G3J/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QDRDDPDN3VFIYXJIYEABY6USX5EU66AG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDDC2VOX7OQC6OHMYTVD4HLFZIV6PYBC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SINP4OVYNB2AGDYI2GS37EMW3H3F7XPZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SOX7BCN6YL7B3RFPEEXPIU5CMTEHJOKR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VZXC32CJ7TWDPJO6GY2XIQRO7JZX5FLP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWMBD4LNHWEXRI6YVFWJMTJQUL5WOFTS/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YQVY5C5REXWJIORJIL2FIL3ALOEJEF72/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZAEFSFZDNBNJPNOUTLG5COISGQDLMGV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/75DTHSTNOFFNAWHXKMDXS7EJWC6W2FUC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ARI7VDSNTQVXRQFM6IK5GSSLEIYV4VZH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BQAKLUJMHFGVBRDPEY57BJGNCE5UUPHW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HXYVPEZUA3465AEFX5JVFVP7KIFZMF3N/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N6M5I6OQHJABNEYY555HUMMKX3Y4P25Z/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NEUNZSZ3CVSM2QWVYH3N2XGOCDWNYUA3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORLXS5YTKN65E2Q2NWKXMFS5FWQHRNZW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2MAICLFDDO3QVNHTZ2OCERZQ34R2PIC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2W2BZQIHMCKRI5FNBJERFYMS5PK6TAH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PHVGRKQAGANCSGFI3QMYOCIMS4IFOZA5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PU6Y2S5CBN5BWCBDAJFTGIBZLK3S2G3J/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDRDDPDN3VFIYXJIYEABY6USX5EU66AG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDDC2VOX7OQC6OHMYTVD4HLFZIV6PYBC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SINP4OVYNB2AGDYI2GS37EMW3H3F7XPZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VZXC32CJ7TWDPJO6GY2XIQRO7JZX5FLP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWMBD4LNHWEXRI6YVFWJMTJQUL5WOFTS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YQVY5C5REXWJIORJIL2FIL3ALOEJEF72/
- https://python-security.readthedocs.io/vuln/email-parseaddr-realname.html
- https://security.netapp.com/advisory/ntap-20230601-0003/
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-45.el8
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-45.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-4189
- https://access.redhat.com/errata/RHSA-2022:1986
- https://bugs.python.org/issue43285
- https://bugzilla.redhat.com/show_bug.cgi?id=2036020
- https://github.com/python/cpython/commit/0ab152c6b5d95caa2dc1a30fa96e10258b5f188e
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://python-security.readthedocs.io/vuln/ftplib-pasv.html
- https://security-tracker.debian.org/tracker/CVE-2021-4189
- https://security.netapp.com/advisory/ntap-20221104-0004/
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-47.el8_6
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-47.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-0391
- https://access.redhat.com/errata/RHSA-2022:6457
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/
- https://bugs.python.org/issue43882
- https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/
- https://security.gentoo.org/glsa/202305-02
- https://security.netapp.com/advisory/ntap-20220225-0009/
- https://www.oracle.com/security-alerts/cpuapr2022.html
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-56.el8_9.3
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-56.el8_9.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-27043
- http://python.com
- http://python.org
- https://github.com/python/cpython/issues/102988
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZAEFSFZDNBNJPNOUTLG5COISGQDLMGV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/75DTHSTNOFFNAWHXKMDXS7EJWC6W2FUC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ARI7VDSNTQVXRQFM6IK5GSSLEIYV4VZH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQAKLUJMHFGVBRDPEY57BJGNCE5UUPHW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXYVPEZUA3465AEFX5JVFVP7KIFZMF3N/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6M5I6OQHJABNEYY555HUMMKX3Y4P25Z/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NEUNZSZ3CVSM2QWVYH3N2XGOCDWNYUA3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORLXS5YTKN65E2Q2NWKXMFS5FWQHRNZW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2MAICLFDDO3QVNHTZ2OCERZQ34R2PIC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2W2BZQIHMCKRI5FNBJERFYMS5PK6TAH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PHVGRKQAGANCSGFI3QMYOCIMS4IFOZA5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PU6Y2S5CBN5BWCBDAJFTGIBZLK3S2G3J/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QDRDDPDN3VFIYXJIYEABY6USX5EU66AG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDDC2VOX7OQC6OHMYTVD4HLFZIV6PYBC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SINP4OVYNB2AGDYI2GS37EMW3H3F7XPZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SOX7BCN6YL7B3RFPEEXPIU5CMTEHJOKR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VZXC32CJ7TWDPJO6GY2XIQRO7JZX5FLP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWMBD4LNHWEXRI6YVFWJMTJQUL5WOFTS/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YQVY5C5REXWJIORJIL2FIL3ALOEJEF72/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZAEFSFZDNBNJPNOUTLG5COISGQDLMGV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/75DTHSTNOFFNAWHXKMDXS7EJWC6W2FUC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ARI7VDSNTQVXRQFM6IK5GSSLEIYV4VZH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BQAKLUJMHFGVBRDPEY57BJGNCE5UUPHW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HXYVPEZUA3465AEFX5JVFVP7KIFZMF3N/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N6M5I6OQHJABNEYY555HUMMKX3Y4P25Z/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NEUNZSZ3CVSM2QWVYH3N2XGOCDWNYUA3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORLXS5YTKN65E2Q2NWKXMFS5FWQHRNZW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2MAICLFDDO3QVNHTZ2OCERZQ34R2PIC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2W2BZQIHMCKRI5FNBJERFYMS5PK6TAH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PHVGRKQAGANCSGFI3QMYOCIMS4IFOZA5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PU6Y2S5CBN5BWCBDAJFTGIBZLK3S2G3J/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDRDDPDN3VFIYXJIYEABY6USX5EU66AG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDDC2VOX7OQC6OHMYTVD4HLFZIV6PYBC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SINP4OVYNB2AGDYI2GS37EMW3H3F7XPZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VZXC32CJ7TWDPJO6GY2XIQRO7JZX5FLP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWMBD4LNHWEXRI6YVFWJMTJQUL5WOFTS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YQVY5C5REXWJIORJIL2FIL3ALOEJEF72/
- https://python-security.readthedocs.io/vuln/email-parseaddr-realname.html
- https://security.netapp.com/advisory/ntap-20230601-0003/
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-45.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-45.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-4189
- https://access.redhat.com/errata/RHSA-2022:1986
- https://bugs.python.org/issue43285
- https://bugzilla.redhat.com/show_bug.cgi?id=2036020
- https://github.com/python/cpython/commit/0ab152c6b5d95caa2dc1a30fa96e10258b5f188e
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://python-security.readthedocs.io/vuln/ftplib-pasv.html
- https://security-tracker.debian.org/tracker/CVE-2021-4189
- https://security.netapp.com/advisory/ntap-20221104-0004/
medium severity
- Vulnerable module: python3-pip-wheel
- Introduced through: python3-pip-wheel@9.0.3-19.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-pip-wheel@9.0.3-19.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-pip-wheel
package and not the python3-pip-wheel
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.
Remediation
There is no fixed version for Centos:8
python3-pip-wheel
.
References
medium severity
- Vulnerable module: python3-pip-wheel
- Introduced through: python3-pip-wheel@9.0.3-19.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-pip-wheel@9.0.3-19.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-pip-wheel
package and not the python3-pip-wheel
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodide; the runtime itself determines redirect behavior. This issue has been patched in version 2.5.0.
Remediation
There is no fixed version for Centos:8
python3-pip-wheel
.
References
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is an issue in CPython when using bytes.decode("unicode_escape", error="ignore|replace")
. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.
Remediation
There is no fixed version for Centos:8
platform-python
.
References
- https://access.redhat.com/security/cve/CVE-2025-4516
- https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142
- https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e
- https://github.com/python/cpython/issues/133767
- https://github.com/python/cpython/pull/129648
- https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/
- http://www.openwall.com/lists/oss-security/2025/05/16/4
- http://www.openwall.com/lists/oss-security/2025/05/19/1
- https://github.com/python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292
- https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d
- https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f
- https://github.com/python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77
- https://github.com/python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is an issue in CPython when using bytes.decode("unicode_escape", error="ignore|replace")
. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.
Remediation
There is no fixed version for Centos:8
python3-libs
.
References
- https://access.redhat.com/security/cve/CVE-2025-4516
- https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142
- https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e
- https://github.com/python/cpython/issues/133767
- https://github.com/python/cpython/pull/129648
- https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/
- http://www.openwall.com/lists/oss-security/2025/05/16/4
- http://www.openwall.com/lists/oss-security/2025/05/19/1
- https://github.com/python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292
- https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d
- https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f
- https://github.com/python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77
- https://github.com/python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8_6.3
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-22.el8_6.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-27774
- https://access.redhat.com/errata/RHSA-2022:5313
- https://hackerone.com/reports/1543773
- https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220609-0008/
- https://www.debian.org/security/2022/dsa-5197
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8_6.3
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-22.el8_6.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-27774
- https://access.redhat.com/errata/RHSA-2022:5313
- https://hackerone.com/reports/1543773
- https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220609-0008/
- https://www.debian.org/security/2022/dsa-5197
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-166.el8_10
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-166.el8_10 or higher.
References
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
- Fixed in: 0:2.30-108.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.
Remediation
Upgrade Centos:8
binutils
to version 0:2.30-108.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210521-0010/
- https://access.redhat.com/security/cve/CVE-2021-20284
- https://bugzilla.redhat.com/show_bug.cgi?id=1937784
- https://sourceware.org/bugzilla/show_bug.cgi?id=26931
- https://access.redhat.com/errata/RHSA-2021:4364
- https://security.gentoo.org/glsa/202208-30
medium severity
- Vulnerable module: python3-rpm
- Introduced through: python3-rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-14.el8_4
Detailed paths
-
Introduced through: centos@centos8 › python3-rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-rpm
package and not the python3-rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.
Remediation
Upgrade Centos:8
python3-rpm
to version 0:4.14.3-14.el8_4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3421
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://bugzilla.redhat.com/show_bug.cgi?id=1927747
- https://access.redhat.com/errata/RHSA-2021:2574
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://security.gentoo.org/glsa/202107-43
medium severity
- Vulnerable module: rpm
- Introduced through: rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-14.el8_4
Detailed paths
-
Introduced through: centos@centos8 › rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm
package and not the rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.
Remediation
Upgrade Centos:8
rpm
to version 0:4.14.3-14.el8_4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3421
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://bugzilla.redhat.com/show_bug.cgi?id=1927747
- https://access.redhat.com/errata/RHSA-2021:2574
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://security.gentoo.org/glsa/202107-43
medium severity
- Vulnerable module: rpm-build-libs
- Introduced through: rpm-build-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-14.el8_4
Detailed paths
-
Introduced through: centos@centos8 › rpm-build-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-build-libs
package and not the rpm-build-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.
Remediation
Upgrade Centos:8
rpm-build-libs
to version 0:4.14.3-14.el8_4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3421
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://bugzilla.redhat.com/show_bug.cgi?id=1927747
- https://access.redhat.com/errata/RHSA-2021:2574
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://security.gentoo.org/glsa/202107-43
medium severity
- Vulnerable module: rpm-libs
- Introduced through: rpm-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-14.el8_4
Detailed paths
-
Introduced through: centos@centos8 › rpm-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-libs
package and not the rpm-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.
Remediation
Upgrade Centos:8
rpm-libs
to version 0:4.14.3-14.el8_4 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3421
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://bugzilla.redhat.com/show_bug.cgi?id=1927747
- https://access.redhat.com/errata/RHSA-2021:2574
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
- https://security.gentoo.org/glsa/202107-43
medium severity
- Vulnerable module: systemd
- Introduced through: systemd@239-45.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd
package and not the systemd
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.
A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.
Remediation
There is no fixed version for Centos:8
systemd
.
References
- https://access.redhat.com/security/cve/CVE-2025-4598
- https://bugzilla.redhat.com/show_bug.cgi?id=2369242
- https://www.openwall.com/lists/oss-security/2025/05/29/3
- http://www.openwall.com/lists/oss-security/2025/06/05/1
- http://www.openwall.com/lists/oss-security/2025/06/05/3
- https://blogs.oracle.com/linux/post/analysis-of-cve-2025-4598
- https://ciq.com/blog/the-real-danger-of-systemd-coredump-cve-2025-4598/
- https://www.openwall.com/lists/oss-security/2025/08/18/3
medium severity
- Vulnerable module: systemd-libs
- Introduced through: systemd-libs@239-45.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd-libs@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-libs
package and not the systemd-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.
A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.
Remediation
There is no fixed version for Centos:8
systemd-libs
.
References
- https://access.redhat.com/security/cve/CVE-2025-4598
- https://bugzilla.redhat.com/show_bug.cgi?id=2369242
- https://www.openwall.com/lists/oss-security/2025/05/29/3
- http://www.openwall.com/lists/oss-security/2025/06/05/1
- http://www.openwall.com/lists/oss-security/2025/06/05/3
- https://blogs.oracle.com/linux/post/analysis-of-cve-2025-4598
- https://ciq.com/blog/the-real-danger-of-systemd-coredump-cve-2025-4598/
- https://www.openwall.com/lists/oss-security/2025/08/18/3
medium severity
- Vulnerable module: systemd-pam
- Introduced through: systemd-pam@239-45.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd-pam@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-pam
package and not the systemd-pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.
A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.
Remediation
There is no fixed version for Centos:8
systemd-pam
.
References
- https://access.redhat.com/security/cve/CVE-2025-4598
- https://bugzilla.redhat.com/show_bug.cgi?id=2369242
- https://www.openwall.com/lists/oss-security/2025/05/29/3
- http://www.openwall.com/lists/oss-security/2025/06/05/1
- http://www.openwall.com/lists/oss-security/2025/06/05/3
- https://blogs.oracle.com/linux/post/analysis-of-cve-2025-4598
- https://ciq.com/blog/the-real-danger-of-systemd-coredump-cve-2025-4598/
- https://www.openwall.com/lists/oss-security/2025/08/18/3
medium severity
- Vulnerable module: systemd-udev
- Introduced through: systemd-udev@239-45.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd-udev@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-udev
package and not the systemd-udev
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.
A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.
Remediation
There is no fixed version for Centos:8
systemd-udev
.
References
- https://access.redhat.com/security/cve/CVE-2025-4598
- https://bugzilla.redhat.com/show_bug.cgi?id=2369242
- https://www.openwall.com/lists/oss-security/2025/05/29/3
- http://www.openwall.com/lists/oss-security/2025/06/05/1
- http://www.openwall.com/lists/oss-security/2025/06/05/3
- https://blogs.oracle.com/linux/post/analysis-of-cve-2025-4598
- https://ciq.com/blog/the-real-danger-of-systemd-coredump-cve-2025-4598/
- https://www.openwall.com/lists/oss-security/2025/08/18/3
medium severity
- Vulnerable module: bzip2-libs
- Introduced through: bzip2-libs@1.0.6-26.el8
- Fixed in: 0:1.0.6-28.el8_10
Detailed paths
-
Introduced through: centos@centos8 › bzip2-libs@1.0.6-26.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream bzip2-libs
package and not the bzip2-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
Remediation
Upgrade Centos:8
bzip2-libs
to version 0:1.0.6-28.el8_10 or higher.
References
- https://seclists.org/bugtraq/2019/Aug/4
- https://seclists.org/bugtraq/2019/Jul/22
- https://support.f5.com/csp/article/K68713584?utm_source=f5support&utm_medium=RSS
- https://access.redhat.com/security/cve/CVE-2019-12900
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:18.bzip2.asc
- http://packetstormsecurity.com/files/153644/Slackware-Security-Advisory-bzip2-Updates.html
- http://packetstormsecurity.com/files/153957/FreeBSD-Security-Advisory-FreeBSD-SA-19-18.bzip2.html
- https://gitlab.com/federicomenaquintero/bzip2/commit/74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://lists.apache.org/thread.html/ra0adb9653c7de9539b93cc8434143b655f753b9f60580ff260becb2b@%3Cusers.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rce8cd8c30f60604b580ea01bebda8a671a25c9a1629f409fc24e7774@%3Cuser.flink.apache.org%3E
- https://lists.apache.org/thread.html/rda98305669476c4d90cc8527c4deda7e449019dd1fe9936b56671dd4@%3Cuser.flink.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2019/06/msg00021.html
- https://lists.debian.org/debian-lts-announce/2019/07/msg00014.html
- https://lists.debian.org/debian-lts-announce/2019/10/msg00012.html
- https://lists.debian.org/debian-lts-announce/2019/10/msg00018.html
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00040.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00050.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00078.html
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00000.html
- https://usn.ubuntu.com/4038-1/
- https://usn.ubuntu.com/4038-2/
- https://usn.ubuntu.com/4146-1/
- https://usn.ubuntu.com/4146-2/
- https://lists.apache.org/thread.html/ra0adb9653c7de9539b93cc8434143b655f753b9f60580ff260becb2b%40%3Cusers.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rce8cd8c30f60604b580ea01bebda8a671a25c9a1629f409fc24e7774%40%3Cuser.flink.apache.org%3E
- https://lists.apache.org/thread.html/rda98305669476c4d90cc8527c4deda7e449019dd1fe9936b56671dd4%40%3Cuser.flink.apache.org%3E
- https://support.f5.com/csp/article/K68713584?utm_source=f5support&%3Butm_medium=RSS
medium severity
- Vulnerable module: coreutils-single
- Introduced through: coreutils-single@8.30-8.el8
Detailed paths
-
Introduced through: centos@centos8 › coreutils-single@8.30-8.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream coreutils-single
package and not the coreutils-single
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.
Remediation
There is no fixed version for Centos:8
coreutils-single
.
References
- https://access.redhat.com/security/cve/CVE-2025-5278
- https://bugzilla.redhat.com/show_bug.cgi?id=2368764
- http://www.openwall.com/lists/oss-security/2025/05/27/2
- http://www.openwall.com/lists/oss-security/2025/05/29/1
- https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633
- https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14
- https://security-tracker.debian.org/tracker/CVE-2025-5278
- http://www.openwall.com/lists/oss-security/2025/05/29/2
medium severity
- Vulnerable module: file-libs
- Introduced through: file-libs@5.33-16.el8_3.1
Detailed paths
-
Introduced through: centos@centos8 › file-libs@5.33-16.el8_3.1
NVD Description
Note: Versions mentioned in the description apply only to the upstream file-libs
package and not the file-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.
Remediation
There is no fixed version for Centos:8
file-libs
.
References
- http://www.securityfocus.com/bid/107137
- https://access.redhat.com/security/cve/CVE-2019-8905
- https://bugs.astron.com/view.php?id=63
- https://lists.debian.org/debian-lts-announce/2019/02/msg00044.html
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html
- https://usn.ubuntu.com/3911-1/
medium severity
- Vulnerable module: python3-rpm
- Introduced through: python3-rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-19.el8_5.2
Detailed paths
-
Introduced through: centos@centos8 › python3-rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-rpm
package and not the python3-rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.
Remediation
Upgrade Centos:8
python3-rpm
to version 0:4.14.3-19.el8_5.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3521
- https://access.redhat.com/errata/RHSA-2022:0368
- https://bugzilla.redhat.com/show_bug.cgi?id=1941098
- https://github.com/rpm-software-management/rpm/commit/bd36c5dc9fb6d90c46fbfed8c2d67516fc571ec8
- https://github.com/rpm-software-management/rpm/pull/1795/
- https://security.gentoo.org/glsa/202210-22
medium severity
- Vulnerable module: rpm
- Introduced through: rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-19.el8_5.2
Detailed paths
-
Introduced through: centos@centos8 › rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm
package and not the rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.
Remediation
Upgrade Centos:8
rpm
to version 0:4.14.3-19.el8_5.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3521
- https://access.redhat.com/errata/RHSA-2022:0368
- https://bugzilla.redhat.com/show_bug.cgi?id=1941098
- https://github.com/rpm-software-management/rpm/commit/bd36c5dc9fb6d90c46fbfed8c2d67516fc571ec8
- https://github.com/rpm-software-management/rpm/pull/1795/
- https://security.gentoo.org/glsa/202210-22
medium severity
- Vulnerable module: rpm-build-libs
- Introduced through: rpm-build-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-19.el8_5.2
Detailed paths
-
Introduced through: centos@centos8 › rpm-build-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-build-libs
package and not the rpm-build-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.
Remediation
Upgrade Centos:8
rpm-build-libs
to version 0:4.14.3-19.el8_5.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3521
- https://access.redhat.com/errata/RHSA-2022:0368
- https://bugzilla.redhat.com/show_bug.cgi?id=1941098
- https://github.com/rpm-software-management/rpm/commit/bd36c5dc9fb6d90c46fbfed8c2d67516fc571ec8
- https://github.com/rpm-software-management/rpm/pull/1795/
- https://security.gentoo.org/glsa/202210-22
medium severity
- Vulnerable module: rpm-libs
- Introduced through: rpm-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-19.el8_5.2
Detailed paths
-
Introduced through: centos@centos8 › rpm-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-libs
package and not the rpm-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.
Remediation
Upgrade Centos:8
rpm-libs
to version 0:4.14.3-19.el8_5.2 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3521
- https://access.redhat.com/errata/RHSA-2022:0368
- https://bugzilla.redhat.com/show_bug.cgi?id=1941098
- https://github.com/rpm-software-management/rpm/commit/bd36c5dc9fb6d90c46fbfed8c2d67516fc571ec8
- https://github.com/rpm-software-management/rpm/pull/1795/
- https://security.gentoo.org/glsa/202210-22
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
medium severity
new
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A security flaw has been discovered in vim up to 9.1.1615. Affected by this vulnerability is the function main of the file src/xxd/xxd.c of the component xxd. The manipulation results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be exploited. Upgrading to version 9.1.1616 addresses this issue. The patch is identified as eeef7c77436a78cd27047b0f5fa6925d56de3cb0. It is recommended to upgrade the affected component.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2025-9390
- https://drive.google.com/file/d/1JLnqrdcGsjUhbYzIEweXIGZyETjHlKtX/view?usp=sharing
- https://github.com/vim/vim/commit/eeef7c77436a78cd27047b0f5fa6925d56de3cb0
- https://github.com/vim/vim/pull/17947
- https://github.com/vim/vim/releases/tag/v9.1.1616
- https://vuldb.com/?ctiid.321223
- https://vuldb.com/?id.321223
- https://github.com/vim/vim/issues/17944
- https://vuldb.com/?submit.630903
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8_6.3
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-22.el8_6.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-27776
- https://access.redhat.com/errata/RHSA-2022:5313
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7N5ZBWLNNPZKFK7Q4KEHGCJ2YELQEUJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DKKOQXPYLMBSEVDHFS32BPBR3ZQJKY5B/
- https://hackerone.com/reports/1547048
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7N5ZBWLNNPZKFK7Q4KEHGCJ2YELQEUJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKKOQXPYLMBSEVDHFS32BPBR3ZQJKY5B/
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220609-0008/
- https://www.debian.org/security/2022/dsa-5197
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8_6.3
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-22.el8_6.3 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-27776
- https://access.redhat.com/errata/RHSA-2022:5313
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7N5ZBWLNNPZKFK7Q4KEHGCJ2YELQEUJP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DKKOQXPYLMBSEVDHFS32BPBR3ZQJKY5B/
- https://hackerone.com/reports/1547048
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7N5ZBWLNNPZKFK7Q4KEHGCJ2YELQEUJP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKKOQXPYLMBSEVDHFS32BPBR3ZQJKY5B/
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220609-0008/
- https://www.debian.org/security/2022/dsa-5197
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.
Remediation
There is no fixed version for Centos:8
platform-python
.
References
- https://access.redhat.com/security/cve/CVE-2025-6069
- https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949
- https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41
- https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b
- https://github.com/python/cpython/issues/135462
- https://github.com/python/cpython/pull/135464
- https://mail.python.org/archives/list/security-announce@python.org/thread/K5PIYLR6EP3WR7ZOKKYQUWEDNQVUXOYM/
- https://github.com/python/cpython/commit/8d1b3dfa09135affbbf27fb8babcf3c11415df49
- https://github.com/python/cpython/commit/ab0893fd5c579d9cea30841680e6d35fc478afb5
- https://github.com/python/cpython/commit/f3c6f882cddc8dc30320d2e73edf019e201394fc
- https://github.com/python/cpython/commit/fdc9d214c01cb4588f540cfa03726bbf2a33fc15
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.
Remediation
There is no fixed version for Centos:8
python3-libs
.
References
- https://access.redhat.com/security/cve/CVE-2025-6069
- https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949
- https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41
- https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b
- https://github.com/python/cpython/issues/135462
- https://github.com/python/cpython/pull/135464
- https://mail.python.org/archives/list/security-announce@python.org/thread/K5PIYLR6EP3WR7ZOKKYQUWEDNQVUXOYM/
- https://github.com/python/cpython/commit/8d1b3dfa09135affbbf27fb8babcf3c11415df49
- https://github.com/python/cpython/commit/ab0893fd5c579d9cea30841680e6d35fc478afb5
- https://github.com/python/cpython/commit/f3c6f882cddc8dc30320d2e73edf019e201394fc
- https://github.com/python/cpython/commit/fdc9d214c01cb4588f540cfa03726bbf2a33fc15
medium severity
- Vulnerable module: systemd
- Introduced through: systemd@239-45.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd
package and not the systemd
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled.
Remediation
There is no fixed version for Centos:8
systemd
.
References
- http://www.securityfocus.com/bid/108389
- https://security.netapp.com/advisory/ntap-20190530-0002/
- https://access.redhat.com/security/cve/CVE-2018-20839
- https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1803993
- https://github.com/systemd/systemd/commit/9725f1a10f80f5e0ae7d9b60547458622aeb322f
- https://github.com/systemd/systemd/pull/12378
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
medium severity
- Vulnerable module: systemd-libs
- Introduced through: systemd-libs@239-45.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd-libs@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-libs
package and not the systemd-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled.
Remediation
There is no fixed version for Centos:8
systemd-libs
.
References
- http://www.securityfocus.com/bid/108389
- https://security.netapp.com/advisory/ntap-20190530-0002/
- https://access.redhat.com/security/cve/CVE-2018-20839
- https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1803993
- https://github.com/systemd/systemd/commit/9725f1a10f80f5e0ae7d9b60547458622aeb322f
- https://github.com/systemd/systemd/pull/12378
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
medium severity
- Vulnerable module: systemd-pam
- Introduced through: systemd-pam@239-45.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd-pam@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-pam
package and not the systemd-pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled.
Remediation
There is no fixed version for Centos:8
systemd-pam
.
References
- http://www.securityfocus.com/bid/108389
- https://security.netapp.com/advisory/ntap-20190530-0002/
- https://access.redhat.com/security/cve/CVE-2018-20839
- https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1803993
- https://github.com/systemd/systemd/commit/9725f1a10f80f5e0ae7d9b60547458622aeb322f
- https://github.com/systemd/systemd/pull/12378
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
medium severity
- Vulnerable module: systemd-udev
- Introduced through: systemd-udev@239-45.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd-udev@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-udev
package and not the systemd-udev
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled.
Remediation
There is no fixed version for Centos:8
systemd-udev
.
References
- http://www.securityfocus.com/bid/108389
- https://security.netapp.com/advisory/ntap-20190530-0002/
- https://access.redhat.com/security/cve/CVE-2018-20839
- https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1803993
- https://github.com/systemd/systemd/commit/9725f1a10f80f5e0ae7d9b60547458622aeb322f
- https://github.com/systemd/systemd/pull/12378
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
- Fixed in: 0:2.30-108.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.
Remediation
Upgrade Centos:8
binutils
to version 0:2.30-108.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210528-0009/
- https://access.redhat.com/security/cve/CVE-2021-20197
- https://bugzilla.redhat.com/show_bug.cgi?id=1913743
- https://sourceware.org/bugzilla/show_bug.cgi?id=26945
- https://access.redhat.com/errata/RHSA-2021:4364
- https://security.gentoo.org/glsa/202208-30
medium severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.25
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random malloc failures. The double free can allow buffer manipulation depending of how the regex is constructed. This issue affects all architectures and ABIs supported by the GNU C library.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-251.el8_10.25 or higher.
References
medium severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.25
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random malloc failures. The double free can allow buffer manipulation depending of how the regex is constructed. This issue affects all architectures and ABIs supported by the GNU C library.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-251.el8_10.25 or higher.
References
medium severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-251.el8_10.25
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random malloc failures. The double free can allow buffer manipulation depending of how the regex is constructed. This issue affects all architectures and ABIs supported by the GNU C library.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-251.el8_10.25 or higher.
References
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing executable code in privileged locations, depending on the permissions of the process editing the archive. The victim must edit such a file using Vim which will reveal the filename and the file content, a careful user may suspect some strange things going on. Successful exploitation could results in the ability to execute arbitrary commands on the underlying operating system. Version 9.1.1551 contains a patch for the vulnerability.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
medium severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plugin can allow overwriting of arbitrary files when opening specially crafted tar archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing executable code in privileged locations, depending on the permissions of the process editing the archive. The victim must edit such a file using Vim which will reveal the filename and the file content, a careful user may suspect some strange things going on. Successful exploitation could results in the ability to execute arbitrary commands on the underlying operating system. Version 9.1.1552 contains a patch for the vulnerability.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/106304
- https://access.redhat.com/security/cve/CVE-2018-1000876
- https://sourceware.org/bugzilla/show_bug.cgi?id=23994
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=3a551c7a1b80fca579461774860574eabfd7f18f
- https://access.redhat.com/errata/RHSA-2019:2075
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://usn.ubuntu.com/4336-1/
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=3a551c7a1b80fca579461774860574eabfd7f18f
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://access.redhat.com/security/cve/CVE-2025-5245
- https://sourceware.org/bugzilla/attachment.cgi?id=16004
- https://sourceware.org/bugzilla/show_bug.cgi?id=32829
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6c3458a8b7ee7d39f070c7b2350851cb2110c65a
- https://vuldb.com/?ctiid.310347
- https://vuldb.com/?id.310347
- https://vuldb.com/?submit.584635
- https://www.gnu.org/
medium severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.
Remediation
There is no fixed version for Centos:8
libarchive
.
References
medium severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
Remediation
There is no fixed version for Centos:8
libarchive
.
References
medium severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
- Fixed in: 0:2.56.4-166.el8_10
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
Remediation
Upgrade Centos:8
glib2
to version 0:2.56.4-166.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-34397
- https://gitlab.gnome.org/GNOME/glib/-/issues/3268
- https://lists.debian.org/debian-lts-announce/2024/05/msg00008.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A/
- https://security.netapp.com/advisory/ntap-20240531-0008/
- https://www.openwall.com/lists/oss-security/2024/05/07/5
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-33.el8_9.5
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (CURLOPT_READFUNCTION
) to ask for data to send, even when the CURLOPT_POSTFIELDS
option has been set, if the same handle previously wasused to issue a PUT
request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-33.el8_9.5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-28322
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F4I75RDGX5ULSSCBE5BF3P5I5SFO7ULQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z2LIWHWKOVH24COGGBCVOWDXXIUPKOMK/
- http://seclists.org/fulldisclosure/2023/Jul/47
- http://seclists.org/fulldisclosure/2023/Jul/48
- http://seclists.org/fulldisclosure/2023/Jul/52
- https://hackerone.com/reports/1954658
- https://lists.debian.org/debian-lts-announce/2023/12/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F4I75RDGX5ULSSCBE5BF3P5I5SFO7ULQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2LIWHWKOVH24COGGBCVOWDXXIUPKOMK/
- https://security.gentoo.org/glsa/202310-12
- https://security.netapp.com/advisory/ntap-20230609-0009/
- https://support.apple.com/kb/HT213843
- https://support.apple.com/kb/HT213844
- https://support.apple.com/kb/HT213845
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-33.el8_9.5
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met.
libcurl performs transfers. In its API, an application creates "easy handles" that are the individual handles for single transfers.
libcurl provides a function call that duplicates en easy handle called curl_easy_duphandle.
If a transfer has cookies enabled when the handle is duplicated, the
cookie-enable state is also cloned - but without cloning the actual
cookies. If the source handle did not read any cookies from a specific file on
disk, the cloned version of the handle would instead store the file name as
none
(using the four ASCII letters, no quotes).
Subsequent use of the cloned handle that does not explicitly set a source to
load cookies from would then inadvertently load cookies from a file named
none
- if such a file exists and is readable in the current directory of the
program using libcurl. And if using the correct file format of course.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-33.el8_9.5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-38546
- http://seclists.org/fulldisclosure/2024/Jan/34
- http://seclists.org/fulldisclosure/2024/Jan/37
- http://seclists.org/fulldisclosure/2024/Jan/38
- https://curl.se/docs/CVE-2023-38546.html
- https://forum.vmssoftware.com/viewtopic.php?f=8&t=8868
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OGMXNRNSJ4ETDK6FRNU3J7SABXPWCHSQ/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214057
- https://support.apple.com/kb/HT214058
- https://support.apple.com/kb/HT214063
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-18.el8_4.1
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths case insensitively,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-18.el8_4.1 or higher.
References
- https://security.netapp.com/advisory/ntap-20210902-0003/
- https://access.redhat.com/security/cve/CVE-2021-22924
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://hackerone.com/reports/1223565
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cusers.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cusers.kafka.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/08/msg00017.html
- https://access.redhat.com/errata/RHSA-2021:3582
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-732250.pdf
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://www.debian.org/security/2022/dsa-5197
- https://www.oracle.com/security-alerts/cpujan2022.html
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-22.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210521-0007/
- https://access.redhat.com/security/cve/CVE-2021-22876
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2ZC5BMIOKLBQJSFCHEDN2G2C2SH274BP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ITVWPVGLFISU5BJC2BXBRYSDXTXE2YGC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQUIOYX2KUU6FIUZVB5WWZ6JHSSYSQWJ/
- https://security.gentoo.org/glsa/202105-36
- https://curl.se/docs/CVE-2021-22876.html
- https://hackerone.com/reports/1101882
- https://lists.debian.org/debian-lts-announce/2021/05/msg00019.html
- https://access.redhat.com/errata/RHSA-2021:4511
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ZC5BMIOKLBQJSFCHEDN2G2C2SH274BP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITVWPVGLFISU5BJC2BXBRYSDXTXE2YGC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQUIOYX2KUU6FIUZVB5WWZ6JHSSYSQWJ/
- https://www.oracle.com//security-alerts/cpujul2021.html
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
- Fixed in: 0:3.6.16-4.el8
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
Remediation
Upgrade Centos:8
gnutls
to version 0:3.6.16-4.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210416-0005/
- https://access.redhat.com/security/cve/CVE-2021-20231
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OSLAE6PP33A7VYRYMYMUVB3U6B26GZER/
- https://bugzilla.redhat.com/show_bug.cgi?id=1922276
- https://www.gnutls.org/security-new.html#GNUTLS-SA-2021-03-10
- https://lists.apache.org/thread.html/r50661d6f0082709aad9a584431b59ec364f9974b63b07e0800230168@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5d4001031e7790d8c6396c499522b4ed2aab782da87b1a14184793bb@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5f88bed447742fcc5c47bf1c7be965ef450131914a6e1f85feba2779@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r6ac143ba6dd98bd4bf6bf010d46e56e254056459721ba18822d611f7@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r9cbc69e57276413788e90a6ee16c7c034ea4258d31935b70db2bd158@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rcd70a4c88a47a75fd2d5f3ffb7cee8c2a18c713320bd90fdcb57495f@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rf5e1256d870193def4a82ad89ab95e63943a313b5ff0d81aa87e4532@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rfd5273d72d244178441e6904a2f2b41a3268f569e8092ea0b3b2bb20@%3Cissues.spark.apache.org%3E
- https://access.redhat.com/errata/RHSA-2021:4451
- https://lists.apache.org/thread.html/r50661d6f0082709aad9a584431b59ec364f9974b63b07e0800230168%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5d4001031e7790d8c6396c499522b4ed2aab782da87b1a14184793bb%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5f88bed447742fcc5c47bf1c7be965ef450131914a6e1f85feba2779%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r6ac143ba6dd98bd4bf6bf010d46e56e254056459721ba18822d611f7%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r9cbc69e57276413788e90a6ee16c7c034ea4258d31935b70db2bd158%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rcd70a4c88a47a75fd2d5f3ffb7cee8c2a18c713320bd90fdcb57495f%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rf5e1256d870193def4a82ad89ab95e63943a313b5ff0d81aa87e4532%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rfd5273d72d244178441e6904a2f2b41a3268f569e8092ea0b3b2bb20%40%3Cissues.spark.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OSLAE6PP33A7VYRYMYMUVB3U6B26GZER/
medium severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
- Fixed in: 0:3.6.16-4.el8
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.
Remediation
Upgrade Centos:8
gnutls
to version 0:3.6.16-4.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210416-0005/
- https://access.redhat.com/security/cve/CVE-2021-20232
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OSLAE6PP33A7VYRYMYMUVB3U6B26GZER/
- https://bugzilla.redhat.com/show_bug.cgi?id=1922275
- https://www.gnutls.org/security-new.html#GNUTLS-SA-2021-03-10
- https://lists.apache.org/thread.html/r50661d6f0082709aad9a584431b59ec364f9974b63b07e0800230168@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5d4001031e7790d8c6396c499522b4ed2aab782da87b1a14184793bb@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5f88bed447742fcc5c47bf1c7be965ef450131914a6e1f85feba2779@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r6ac143ba6dd98bd4bf6bf010d46e56e254056459721ba18822d611f7@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r9cbc69e57276413788e90a6ee16c7c034ea4258d31935b70db2bd158@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rcd70a4c88a47a75fd2d5f3ffb7cee8c2a18c713320bd90fdcb57495f@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rf5e1256d870193def4a82ad89ab95e63943a313b5ff0d81aa87e4532@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rfd5273d72d244178441e6904a2f2b41a3268f569e8092ea0b3b2bb20@%3Cissues.spark.apache.org%3E
- https://access.redhat.com/errata/RHSA-2021:4451
- https://lists.apache.org/thread.html/r50661d6f0082709aad9a584431b59ec364f9974b63b07e0800230168%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5d4001031e7790d8c6396c499522b4ed2aab782da87b1a14184793bb%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5f88bed447742fcc5c47bf1c7be965ef450131914a6e1f85feba2779%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r6ac143ba6dd98bd4bf6bf010d46e56e254056459721ba18822d611f7%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r9cbc69e57276413788e90a6ee16c7c034ea4258d31935b70db2bd158%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rcd70a4c88a47a75fd2d5f3ffb7cee8c2a18c713320bd90fdcb57495f%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rf5e1256d870193def4a82ad89ab95e63943a313b5ff0d81aa87e4532%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rfd5273d72d244178441e6904a2f2b41a3268f569e8092ea0b3b2bb20%40%3Cissues.spark.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OSLAE6PP33A7VYRYMYMUVB3U6B26GZER/
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-33.el8_9.5
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (CURLOPT_READFUNCTION
) to ask for data to send, even when the CURLOPT_POSTFIELDS
option has been set, if the same handle previously wasused to issue a PUT
request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-33.el8_9.5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-28322
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F4I75RDGX5ULSSCBE5BF3P5I5SFO7ULQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z2LIWHWKOVH24COGGBCVOWDXXIUPKOMK/
- http://seclists.org/fulldisclosure/2023/Jul/47
- http://seclists.org/fulldisclosure/2023/Jul/48
- http://seclists.org/fulldisclosure/2023/Jul/52
- https://hackerone.com/reports/1954658
- https://lists.debian.org/debian-lts-announce/2023/12/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F4I75RDGX5ULSSCBE5BF3P5I5SFO7ULQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2LIWHWKOVH24COGGBCVOWDXXIUPKOMK/
- https://security.gentoo.org/glsa/202310-12
- https://security.netapp.com/advisory/ntap-20230609-0009/
- https://support.apple.com/kb/HT213843
- https://support.apple.com/kb/HT213844
- https://support.apple.com/kb/HT213845
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-33.el8_9.5
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met.
libcurl performs transfers. In its API, an application creates "easy handles" that are the individual handles for single transfers.
libcurl provides a function call that duplicates en easy handle called curl_easy_duphandle.
If a transfer has cookies enabled when the handle is duplicated, the
cookie-enable state is also cloned - but without cloning the actual
cookies. If the source handle did not read any cookies from a specific file on
disk, the cloned version of the handle would instead store the file name as
none
(using the four ASCII letters, no quotes).
Subsequent use of the cloned handle that does not explicitly set a source to
load cookies from would then inadvertently load cookies from a file named
none
- if such a file exists and is readable in the current directory of the
program using libcurl. And if using the correct file format of course.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-33.el8_9.5 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-38546
- http://seclists.org/fulldisclosure/2024/Jan/34
- http://seclists.org/fulldisclosure/2024/Jan/37
- http://seclists.org/fulldisclosure/2024/Jan/38
- https://curl.se/docs/CVE-2023-38546.html
- https://forum.vmssoftware.com/viewtopic.php?f=8&t=8868
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OGMXNRNSJ4ETDK6FRNU3J7SABXPWCHSQ/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214057
- https://support.apple.com/kb/HT214058
- https://support.apple.com/kb/HT214063
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-18.el8_4.1
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths case insensitively,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-18.el8_4.1 or higher.
References
- https://security.netapp.com/advisory/ntap-20210902-0003/
- https://access.redhat.com/security/cve/CVE-2021-22924
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://hackerone.com/reports/1223565
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cusers.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cusers.kafka.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/08/msg00017.html
- https://access.redhat.com/errata/RHSA-2021:3582
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-732250.pdf
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://www.debian.org/security/2022/dsa-5197
- https://www.oracle.com/security-alerts/cpujan2022.html
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-22.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210521-0007/
- https://access.redhat.com/security/cve/CVE-2021-22876
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2ZC5BMIOKLBQJSFCHEDN2G2C2SH274BP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ITVWPVGLFISU5BJC2BXBRYSDXTXE2YGC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQUIOYX2KUU6FIUZVB5WWZ6JHSSYSQWJ/
- https://security.gentoo.org/glsa/202105-36
- https://curl.se/docs/CVE-2021-22876.html
- https://hackerone.com/reports/1101882
- https://lists.debian.org/debian-lts-announce/2021/05/msg00019.html
- https://access.redhat.com/errata/RHSA-2021:4511
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ZC5BMIOKLBQJSFCHEDN2G2C2SH274BP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITVWPVGLFISU5BJC2BXBRYSDXTXE2YGC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQUIOYX2KUU6FIUZVB5WWZ6JHSSYSQWJ/
- https://www.oracle.com//security-alerts/cpujul2021.html
medium severity
- Vulnerable module: nettle
- Introduced through: nettle@3.4.1-2.el8
- Fixed in: 0:3.4.1-7.el8
Detailed paths
-
Introduced through: centos@centos8 › nettle@3.4.1-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream nettle
package and not the nettle
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
Remediation
Upgrade Centos:8
nettle
to version 0:3.4.1-7.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210416-0005/
- https://access.redhat.com/security/cve/CVE-2021-20231
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OSLAE6PP33A7VYRYMYMUVB3U6B26GZER/
- https://bugzilla.redhat.com/show_bug.cgi?id=1922276
- https://www.gnutls.org/security-new.html#GNUTLS-SA-2021-03-10
- https://lists.apache.org/thread.html/r50661d6f0082709aad9a584431b59ec364f9974b63b07e0800230168@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5d4001031e7790d8c6396c499522b4ed2aab782da87b1a14184793bb@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5f88bed447742fcc5c47bf1c7be965ef450131914a6e1f85feba2779@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r6ac143ba6dd98bd4bf6bf010d46e56e254056459721ba18822d611f7@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r9cbc69e57276413788e90a6ee16c7c034ea4258d31935b70db2bd158@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rcd70a4c88a47a75fd2d5f3ffb7cee8c2a18c713320bd90fdcb57495f@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rf5e1256d870193def4a82ad89ab95e63943a313b5ff0d81aa87e4532@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rfd5273d72d244178441e6904a2f2b41a3268f569e8092ea0b3b2bb20@%3Cissues.spark.apache.org%3E
- https://access.redhat.com/errata/RHSA-2021:4451
- https://lists.apache.org/thread.html/r50661d6f0082709aad9a584431b59ec364f9974b63b07e0800230168%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5d4001031e7790d8c6396c499522b4ed2aab782da87b1a14184793bb%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5f88bed447742fcc5c47bf1c7be965ef450131914a6e1f85feba2779%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r6ac143ba6dd98bd4bf6bf010d46e56e254056459721ba18822d611f7%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r9cbc69e57276413788e90a6ee16c7c034ea4258d31935b70db2bd158%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rcd70a4c88a47a75fd2d5f3ffb7cee8c2a18c713320bd90fdcb57495f%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rf5e1256d870193def4a82ad89ab95e63943a313b5ff0d81aa87e4532%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rfd5273d72d244178441e6904a2f2b41a3268f569e8092ea0b3b2bb20%40%3Cissues.spark.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OSLAE6PP33A7VYRYMYMUVB3U6B26GZER/
medium severity
- Vulnerable module: nettle
- Introduced through: nettle@3.4.1-2.el8
- Fixed in: 0:3.4.1-7.el8
Detailed paths
-
Introduced through: centos@centos8 › nettle@3.4.1-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream nettle
package and not the nettle
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.
Remediation
Upgrade Centos:8
nettle
to version 0:3.4.1-7.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210416-0005/
- https://access.redhat.com/security/cve/CVE-2021-20232
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OSLAE6PP33A7VYRYMYMUVB3U6B26GZER/
- https://bugzilla.redhat.com/show_bug.cgi?id=1922275
- https://www.gnutls.org/security-new.html#GNUTLS-SA-2021-03-10
- https://lists.apache.org/thread.html/r50661d6f0082709aad9a584431b59ec364f9974b63b07e0800230168@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5d4001031e7790d8c6396c499522b4ed2aab782da87b1a14184793bb@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5f88bed447742fcc5c47bf1c7be965ef450131914a6e1f85feba2779@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r6ac143ba6dd98bd4bf6bf010d46e56e254056459721ba18822d611f7@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r9cbc69e57276413788e90a6ee16c7c034ea4258d31935b70db2bd158@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rcd70a4c88a47a75fd2d5f3ffb7cee8c2a18c713320bd90fdcb57495f@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rf5e1256d870193def4a82ad89ab95e63943a313b5ff0d81aa87e4532@%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rfd5273d72d244178441e6904a2f2b41a3268f569e8092ea0b3b2bb20@%3Cissues.spark.apache.org%3E
- https://access.redhat.com/errata/RHSA-2021:4451
- https://lists.apache.org/thread.html/r50661d6f0082709aad9a584431b59ec364f9974b63b07e0800230168%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5d4001031e7790d8c6396c499522b4ed2aab782da87b1a14184793bb%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r5f88bed447742fcc5c47bf1c7be965ef450131914a6e1f85feba2779%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r6ac143ba6dd98bd4bf6bf010d46e56e254056459721ba18822d611f7%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r9cbc69e57276413788e90a6ee16c7c034ea4258d31935b70db2bd158%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rcd70a4c88a47a75fd2d5f3ffb7cee8c2a18c713320bd90fdcb57495f%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rf5e1256d870193def4a82ad89ab95e63943a313b5ff0d81aa87e4532%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/rfd5273d72d244178441e6904a2f2b41a3268f569e8092ea0b3b2bb20%40%3Cissues.spark.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OSLAE6PP33A7VYRYMYMUVB3U6B26GZER/
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-67.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.
CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-67.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-4032
- http://www.openwall.com/lists/oss-security/2024/06/17/3
- https://github.com/python/cpython/commit/22adf29da8d99933ffed8647d3e0726edd16f7f8
- https://github.com/python/cpython/commit/40d75c2b7f5c67e254d0a025e0f2e2c7ada7f69f
- https://github.com/python/cpython/commit/895f7e2ac23eff4743143beef0f0c5ac71ea27d3
- https://github.com/python/cpython/commit/ba431579efdcbaed7a96f2ac4ea0775879a332fb
- https://github.com/python/cpython/commit/c62c9e518b784fe44432a3f4fc265fb95b651906
- https://github.com/python/cpython/commit/f86b17ac511e68192ba71f27e752321a3252cee3
- https://github.com/python/cpython/issues/113171
- https://github.com/python/cpython/pull/113179
- https://mail.python.org/archives/list/security-announce@python.org/thread/NRUHDUS2IV2USIZM2CVMSFL6SCKU3RZA/
- https://security.netapp.com/advisory/ntap-20240726-0004/
- https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml
- https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
- Fixed in: 0:3.6.8-69.el8_10
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts ([]
), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.
Remediation
Upgrade Centos:8
platform-python
to version 0:3.6.8-69.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-11168
- https://github.com/python/cpython/commit/29f348e232e82938ba2165843c448c2b291504c5
- https://github.com/python/cpython/commit/b2171a2fd41416cf68afd67460578631d755a550
- https://github.com/python/cpython/issues/103848
- https://github.com/python/cpython/pull/103849
- https://mail.python.org/archives/list/security-announce@python.org/thread/XPWB6XVZ5G5KGEI63M4AWLIEUF5BPH4T/
- https://github.com/python/cpython/commit/634ded45545ce8cbd6fd5d49785613dd7fa9b89e
- https://github.com/python/cpython/commit/ddca2953191c67a12b1f19d6bca41016c6ae7132
- https://security.netapp.com/advisory/ntap-20250411-0004/
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-67.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.
CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-67.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-4032
- http://www.openwall.com/lists/oss-security/2024/06/17/3
- https://github.com/python/cpython/commit/22adf29da8d99933ffed8647d3e0726edd16f7f8
- https://github.com/python/cpython/commit/40d75c2b7f5c67e254d0a025e0f2e2c7ada7f69f
- https://github.com/python/cpython/commit/895f7e2ac23eff4743143beef0f0c5ac71ea27d3
- https://github.com/python/cpython/commit/ba431579efdcbaed7a96f2ac4ea0775879a332fb
- https://github.com/python/cpython/commit/c62c9e518b784fe44432a3f4fc265fb95b651906
- https://github.com/python/cpython/commit/f86b17ac511e68192ba71f27e752321a3252cee3
- https://github.com/python/cpython/issues/113171
- https://github.com/python/cpython/pull/113179
- https://mail.python.org/archives/list/security-announce@python.org/thread/NRUHDUS2IV2USIZM2CVMSFL6SCKU3RZA/
- https://security.netapp.com/advisory/ntap-20240726-0004/
- https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml
- https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
- Fixed in: 0:3.6.8-69.el8_10
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts ([]
), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.
Remediation
Upgrade Centos:8
python3-libs
to version 0:3.6.8-69.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-11168
- https://github.com/python/cpython/commit/29f348e232e82938ba2165843c448c2b291504c5
- https://github.com/python/cpython/commit/b2171a2fd41416cf68afd67460578631d755a550
- https://github.com/python/cpython/issues/103848
- https://github.com/python/cpython/pull/103849
- https://mail.python.org/archives/list/security-announce@python.org/thread/XPWB6XVZ5G5KGEI63M4AWLIEUF5BPH4T/
- https://github.com/python/cpython/commit/634ded45545ce8cbd6fd5d49785613dd7fa9b89e
- https://github.com/python/cpython/commit/ddca2953191c67a12b1f19d6bca41016c6ae7132
- https://security.netapp.com/advisory/ntap-20250411-0004/
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
- Fixed in: 0:2.30-108.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c.
Remediation
Upgrade Centos:8
binutils
to version 0:2.30-108.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210129-0008/
- https://access.redhat.com/security/cve/CVE-2020-35448
- https://sourceware.org/bugzilla/show_bug.cgi?id=26574
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8642dafaef21aa6747cec01df1977e9c52eb4679
- https://access.redhat.com/errata/RHSA-2021:4364
- https://security.gentoo.org/glsa/202107-24
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=8642dafaef21aa6747cec01df1977e9c52eb4679
medium severity
- Vulnerable module: libcap
- Introduced through: libcap@2.26-4.el8
- Fixed in: 0:2.48-5.el8_8
Detailed paths
-
Introduced through: centos@centos8 › libcap@2.26-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcap
package and not the libcap
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
Remediation
Upgrade Centos:8
libcap
to version 0:2.48-5.el8_8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-2602
- https://bugzilla.redhat.com/show_bug.cgi?id=2209114
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZ57ICDLMVYEREXQGZWL4GWI7FRJCRQT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPEGCFMCN5KGCFX5Y2VTKR732TTD4ADW/
- https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdf
medium severity
- Vulnerable module: libsepol
- Introduced through: libsepol@2.9-2.el8
- Fixed in: 0:2.9-3.el8
Detailed paths
-
Introduced through: centos@centos8 › libsepol@2.9-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libsepol
package and not the libsepol
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). This occurs because there is sometimes a lack of checks for invalid statements in an optional block.
Remediation
Upgrade Centos:8
libsepol
to version 0:2.9-3.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-36087
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=32675
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/selinux/OSV-2021-585.yaml
- https://github.com/SELinuxProject/selinux/commit/bad0a746e9f4cf260dedba5828d9645d50176aac
- https://access.redhat.com/errata/RHSA-2021:4513
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR/
- https://lore.kernel.org/selinux/CAEN2sdqJKHvDzPnxS-J8grU8fSf32DDtx=kyh84OsCq_Vm+yaQ@mail.gmail.com/T/
- https://github.com/SELinuxProject/selinux/commit/340f0eb7f3673e8aacaf0a96cbfcd4d12a405521
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR/
- https://lore.kernel.org/selinux/CAEN2sdqJKHvDzPnxS-J8grU8fSf32DDtx=kyh84OsCq_Vm+yaQ%40mail.gmail.com/T/
medium severity
- Vulnerable module: libsepol
- Introduced through: libsepol@2.9-2.el8
- Fixed in: 0:2.9-3.el8
Detailed paths
-
Introduced through: centos@centos8 › libsepol@2.9-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libsepol
package and not the libsepol
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __cil_verify_classpermission and __cil_pre_verify_helper).
Remediation
Upgrade Centos:8
libsepol
to version 0:2.9-3.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-36084
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=31065
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/selinux/OSV-2021-417.yaml
- https://github.com/SELinuxProject/selinux/commit/f34d3d30c8325e4847a6b696fe7a3936a8a361f3
- https://access.redhat.com/errata/RHSA-2021:4513
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR/
medium severity
- Vulnerable module: libsepol
- Introduced through: libsepol@2.9-2.el8
- Fixed in: 0:2.9-3.el8
Detailed paths
-
Introduced through: centos@centos8 › libsepol@2.9-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libsepol
package and not the libsepol
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __verify_map_perm_classperms and hashtab_map).
Remediation
Upgrade Centos:8
libsepol
to version 0:2.9-3.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-36085
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=31124
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/selinux/OSV-2021-421.yaml
- https://github.com/SELinuxProject/selinux/commit/2d35fcc7e9e976a2346b1de20e54f8663e8a6cba
- https://access.redhat.com/errata/RHSA-2021:4513
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR/
medium severity
- Vulnerable module: libsepol
- Introduced through: libsepol@2.9-2.el8
- Fixed in: 0:2.9-3.el8
Detailed paths
-
Introduced through: centos@centos8 › libsepol@2.9-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libsepol
package and not the libsepol
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
Remediation
Upgrade Centos:8
libsepol
to version 0:2.9-3.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-36086
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=32177
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/selinux/OSV-2021-536.yaml
- https://github.com/SELinuxProject/selinux/commit/c49a8ea09501ad66e799ea41b8154b6770fec2c8
- https://access.redhat.com/errata/RHSA-2021:4513
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR/
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
curl 7.7 through 7.76.1 suffers from an information disclosure when the -t
command line option, known as CURLOPT_TELNETOPTIONS
in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-22.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-22898
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/POOC3UV7V6L4CJ5KA2PTWTNUV5Y72T3Q/
- https://curl.se/docs/CVE-2021-22898.html
- https://github.com/curl/curl/commit/39ce47f219b09c380b81f89fe54ac586c8db6bde
- https://hackerone.com/reports/1176461
- https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c@%3Cissues.guacamole.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/08/msg00017.html
- http://www.openwall.com/lists/oss-security/2021/07/21/4
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://access.redhat.com/errata/RHSA-2021:4511
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POOC3UV7V6L4CJ5KA2PTWTNUV5Y72T3Q/
- https://www.debian.org/security/2022/dsa-5197
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
medium severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
curl supports the -t
command line option, known as CURLOPT_TELNETOPTIONS
in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending NEW_ENV
variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-22.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210902-0003/
- https://support.apple.com/kb/HT212804
- https://support.apple.com/kb/HT212805
- https://access.redhat.com/security/cve/CVE-2021-22925
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- http://seclists.org/fulldisclosure/2021/Sep/39
- http://seclists.org/fulldisclosure/2021/Sep/40
- https://hackerone.com/reports/1223882
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://access.redhat.com/errata/RHSA-2021:4511
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://security.gentoo.org/glsa/202212-01
- https://www.oracle.com/security-alerts/cpujan2022.html
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
curl supports the -t
command line option, known as CURLOPT_TELNETOPTIONS
in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending NEW_ENV
variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-22.el8 or higher.
References
- https://security.netapp.com/advisory/ntap-20210902-0003/
- https://support.apple.com/kb/HT212804
- https://support.apple.com/kb/HT212805
- https://access.redhat.com/security/cve/CVE-2021-22925
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- http://seclists.org/fulldisclosure/2021/Sep/39
- http://seclists.org/fulldisclosure/2021/Sep/40
- https://hackerone.com/reports/1223882
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://access.redhat.com/errata/RHSA-2021:4511
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://security.gentoo.org/glsa/202212-01
- https://www.oracle.com/security-alerts/cpujan2022.html
medium severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-22.el8
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
curl 7.7 through 7.76.1 suffers from an information disclosure when the -t
command line option, known as CURLOPT_TELNETOPTIONS
in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-22.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-22898
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/POOC3UV7V6L4CJ5KA2PTWTNUV5Y72T3Q/
- https://curl.se/docs/CVE-2021-22898.html
- https://github.com/curl/curl/commit/39ce47f219b09c380b81f89fe54ac586c8db6bde
- https://hackerone.com/reports/1176461
- https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c@%3Cissues.guacamole.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/08/msg00017.html
- http://www.openwall.com/lists/oss-security/2021/07/21/4
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://access.redhat.com/errata/RHSA-2021:4511
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POOC3UV7V6L4CJ5KA2PTWTNUV5Y72T3Q/
- https://www.debian.org/security/2022/dsa-5197
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
medium severity
- Vulnerable module: glibc
- Introduced through: glibc@2.28-151.el8
- Fixed in: 0:2.28-164.el8
Detailed paths
-
Introduced through: centos@centos8 › glibc@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc
package and not the glibc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c.
Remediation
Upgrade Centos:8
glibc
to version 0:2.28-164.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-27645
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LZNT6KTMCCWPWXEOGSHD3YLYZKUGMH5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I7TS26LIZSOBLGJEZMJX4PXT5BQDE2WS/
- https://sourceware.org/bugzilla/show_bug.cgi?id=27462
- https://access.redhat.com/errata/RHSA-2021:4358
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7LZNT6KTMCCWPWXEOGSHD3YLYZKUGMH5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I7TS26LIZSOBLGJEZMJX4PXT5BQDE2WS/
- https://security.gentoo.org/glsa/202107-07
medium severity
- Vulnerable module: glibc-common
- Introduced through: glibc-common@2.28-151.el8
- Fixed in: 0:2.28-164.el8
Detailed paths
-
Introduced through: centos@centos8 › glibc-common@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-common
package and not the glibc-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c.
Remediation
Upgrade Centos:8
glibc-common
to version 0:2.28-164.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-27645
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LZNT6KTMCCWPWXEOGSHD3YLYZKUGMH5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I7TS26LIZSOBLGJEZMJX4PXT5BQDE2WS/
- https://sourceware.org/bugzilla/show_bug.cgi?id=27462
- https://access.redhat.com/errata/RHSA-2021:4358
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7LZNT6KTMCCWPWXEOGSHD3YLYZKUGMH5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I7TS26LIZSOBLGJEZMJX4PXT5BQDE2WS/
- https://security.gentoo.org/glsa/202107-07
medium severity
- Vulnerable module: glibc-minimal-langpack
- Introduced through: glibc-minimal-langpack@2.28-151.el8
- Fixed in: 0:2.28-164.el8
Detailed paths
-
Introduced through: centos@centos8 › glibc-minimal-langpack@2.28-151.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-minimal-langpack
package and not the glibc-minimal-langpack
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c.
Remediation
Upgrade Centos:8
glibc-minimal-langpack
to version 0:2.28-164.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-27645
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LZNT6KTMCCWPWXEOGSHD3YLYZKUGMH5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I7TS26LIZSOBLGJEZMJX4PXT5BQDE2WS/
- https://sourceware.org/bugzilla/show_bug.cgi?id=27462
- https://access.redhat.com/errata/RHSA-2021:4358
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7LZNT6KTMCCWPWXEOGSHD3YLYZKUGMH5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I7TS26LIZSOBLGJEZMJX4PXT5BQDE2WS/
- https://security.gentoo.org/glsa/202107-07
medium severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
- Fixed in: 0:2.30-108.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Rejected reason: Non Security Issue. See the binutils security policy for more details, https://sourceware.org/cgit/binutils-gdb/tree/binutils/SECURITY.txt
Remediation
Upgrade Centos:8
binutils
to version 0:2.30-108.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3487
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3Z3KSJY3CLAAFFT7FNFCJOMDITPQGN56/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q6V2LF5AVOUTHPYY2O5TRNAIXVMXFDGL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RNBNDMJWZOQYCEZXENHBSM6DBZ332UZZ/
- https://bugzilla.redhat.com/show_bug.cgi?id=1947111
- https://access.redhat.com/errata/RHSA-2021:4364
- https://security.gentoo.org/glsa/202208-30
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3Z3KSJY3CLAAFFT7FNFCJOMDITPQGN56/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q6V2LF5AVOUTHPYY2O5TRNAIXVMXFDGL/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RNBNDMJWZOQYCEZXENHBSM6DBZ332UZZ/
medium severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling a Python object" via a crafted argument. This argument is plausibly an untrusted value from an application's input data that was supposed to contain a name and an e-mail address. NOTE: email.utils.parseaddr is categorized as a Legacy API in the documentation of the Python email package. Applications should instead use the email.parser.BytesParser or email.parser.Parser class. NOTE: the vendor's perspective is that this is neither a vulnerability nor a bug. The email package is intended to have size limits and to throw an exception when limits are exceeded; they were exceeded by the example demonstration code.
Remediation
There is no fixed version for Centos:8
platform-python
.
References
medium severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling a Python object" via a crafted argument. This argument is plausibly an untrusted value from an application's input data that was supposed to contain a name and an e-mail address. NOTE: email.utils.parseaddr is categorized as a Legacy API in the documentation of the Python email package. Applications should instead use the email.parser.BytesParser or email.parser.Parser class. NOTE: the vendor's perspective is that this is neither a vulnerability nor a bug. The email package is intended to have size limits and to throw an exception when limits are exceeded; they were exceeded by the example demonstration code.
Remediation
There is no fixed version for Centos:8
python3-libs
.
References
low severity
- Vulnerable module: ca-certificates
- Introduced through: ca-certificates@2020.2.41-80.0.el8_2
- Fixed in: 0:2024.2.69_v8.0.303-80.0.el8_10
Detailed paths
-
Introduced through: centos@centos8 › ca-certificates@2020.2.41-80.0.el8_2
NVD Description
Note: Versions mentioned in the description apply only to the upstream ca-certificates
package and not the ca-certificates
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
Remediation
Upgrade Centos:8
ca-certificates
to version 0:2024.2.69_v8.0.303-80.0.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-37920
- https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909
- https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7
- https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/
- https://security.netapp.com/advisory/ntap-20240912-0002/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2024-22667
- https://gist.githubusercontent.com/henices/2467e7f22dcc2aa97a2453e197b55a0c/raw/7b54bccc9a129c604fb139266f4497ab7aaa94c7/gistfile1.txt
- https://github.com/vim/vim/commit/b39b240c386a5a29241415541f1c99e2e6b8ce47
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UI44Y4LJLG34D4HNB6NTPLUPZREHAEL7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UIQLVUSYHDN3644K6EFDI7PRZOTIKXM3/
- https://security.netapp.com/advisory/ntap-20240223-0008/
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in file readelf.c.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: python3-pip-wheel
- Introduced through: python3-pip-wheel@9.0.3-19.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-pip-wheel@9.0.3-19.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-pip-wheel
package and not the python3-pip-wheel
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely
Remediation
There is no fixed version for Centos:8
python3-pip-wheel
.
References
- https://access.redhat.com/security/cve/CVE-2018-20225
- https://bugzilla.redhat.com/show_bug.cgi?id=1835736
- https://cowlicks.website/posts/arbitrary-code-execution-from-pips-extra-index-url.html
- https://pip.pypa.io/en/stable/news/
- https://lists.apache.org/thread.html/rb1adce798445facd032870d644eb39c4baaf9c4a7dd5477d12bb6ab2@%3Cgithub.arrow.apache.org%3E
- https://lists.apache.org/thread.html/rb1adce798445facd032870d644eb39c4baaf9c4a7dd5477d12bb6ab2%40%3Cgithub.arrow.apache.org%3E
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2124
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- http://seclists.org/fulldisclosure/2022/Oct/45
- https://github.com/vim/vim/commit/2f074f4685897ab7212e25931eeeb0212292829f
- https://huntr.dev/bounties/8e9e056d-f733-4540-98b6-414bf36e0b42
- https://lists.debian.org/debian-lts-announce/2022/06/msg00014.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213443
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2175
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://github.com/vim/vim/commit/6046aded8da002b08d380db29de2ba0268b6616e
- https://huntr.dev/bounties/7f0481c2-8b57-4324-b47c-795d1ea67e55
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-0512
- https://www.cve.org/CVERecord?id=CVE-2023-0512
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/
- http://seclists.org/fulldisclosure/2023/Mar/17
- http://seclists.org/fulldisclosure/2023/Mar/18
- http://seclists.org/fulldisclosure/2023/Mar/21
- https://github.com/vim/vim/commit/870219c58c0804bdc55419b2e455c06ac715a835
- https://huntr.dev/bounties/de83736a-1936-4872-830b-f1e9b0ad2a74
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/
- https://support.apple.com/kb/HT213670
- https://support.apple.com/kb/HT213675
- https://support.apple.com/kb/HT213677
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2125
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- http://seclists.org/fulldisclosure/2022/Oct/45
- https://github.com/vim/vim/commit/0e8e938d497260dd57be67b4966cb27a5f72376f
- https://huntr.dev/bounties/17dab24d-beec-464d-9a72-5b6b11283705
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213443
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2182
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://github.com/vim/vim/commit/f7c7c3fad6d2135d558f3b36d0d1a943118aeb5e
- https://huntr.dev/bounties/238d8650-3beb-4831-a8f7-6f0b597a6fb8
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2207
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://github.com/vim/vim/commit/0971c7a4e537ea120a6bb2195960be8d0815e97b
- https://huntr.dev/bounties/05bc6051-4dc3-483b-ae56-cf23346b97b9
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2284
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UXPO5EHDV6J4B27E65DOQGZFELUFPRSK/
- https://github.com/vim/vim/commit/3d51ce18ab1be4f9f6061568a4e7fabf00b21794
- https://huntr.dev/bounties/571d25ce-8d53-4fa0-b620-27f2a8a14874
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UXPO5EHDV6J4B27E65DOQGZFELUFPRSK/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2343
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://github.com/vim/vim/commit/caea66442d86e7bbba3bf3dc202c3c0d549b9853
- https://huntr.dev/bounties/2ecb4345-2fc7-4e7f-adb0-83a20bb458f5
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2344
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://github.com/vim/vim/commit/baefde14550231f6468ac2ed2ed495bc381c0c92
- https://huntr.dev/bounties/4a095ed9-3125-464a-b656-c31b437e1996
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2522
- https://github.com/vim/vim/commit/5fa9f23a63651a8abdb074b4fc2ec9b1adc6b089
- https://github.com/vim/vim/commit/b9e717367c395490149495cf375911b5d9de889e
- https://huntr.dev/bounties/3a2d83af-9542-4d93-8784-98b115135a22
- https://huntr.dev/bounties/3a2d83af-9542-4d93-8784-98b115135a22/
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2819
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHFAR6OY6G77M6GXCJT75A4KITLNR6GO/
- https://github.com/vim/vim/commit/d1d8f6bacb489036d0fd479c9dd3c0102c988889
- https://huntr.dev/bounties/0a9bd71e-66b8-4eb1-9566-7dfd9b097e59
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHFAR6OY6G77M6GXCJT75A4KITLNR6GO/
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-0433
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EX6N2DB75A73MQGVW3CS4VTNPAYVM2M/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PZWIJBSQX53P7DHV77KRXJIXA4GH7XHC/
- http://seclists.org/fulldisclosure/2023/Mar/17
- http://seclists.org/fulldisclosure/2023/Mar/18
- http://seclists.org/fulldisclosure/2023/Mar/21
- https://github.com/vim/vim/commit/11977f917506d950b7e0cae558bd9189260b253b
- https://huntr.dev/bounties/ae933869-a1ec-402a-bbea-d51764c6618e
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4EX6N2DB75A73MQGVW3CS4VTNPAYVM2M/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZWIJBSQX53P7DHV77KRXJIXA4GH7XHC/
- https://support.apple.com/kb/HT213670
- https://support.apple.com/kb/HT213675
- https://support.apple.com/kb/HT213677
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-4781
- http://seclists.org/fulldisclosure/2023/Oct/24
- https://github.com/vim/vim/commit/f6d28fe2c95c678cc3202cc5dc825a3fcc709e93
- https://huntr.dev/bounties/c867eb0a-aa8b-4946-a621-510350673883
- https://lists.debian.org/debian-lts-announce/2023/09/msg00035.html
- https://support.apple.com/kb/HT213984
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2285
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UXPO5EHDV6J4B27E65DOQGZFELUFPRSK/
- https://github.com/vim/vim/commit/27efc62f5d86afcb2ecb7565587fe8dea4b036fe
- https://huntr.dev/bounties/64574b28-1779-458d-a221-06c434042736
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UXPO5EHDV6J4B27E65DOQGZFELUFPRSK/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-1619
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A6BY5P7ERZS7KXSBCGFCOXLMLGWUUJIH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HIP7KG7TVS5YF3QREAY2GOGUT3YUBZAI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JUN33257RUM4RS2I4GZETKFSAXPETATG/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- https://github.com/vim/vim/commit/ef02f16609ff0a26ffc6e20263523424980898fe
- https://huntr.dev/bounties/b3200483-624e-4c76-a070-e246f62a7450
- https://lists.debian.org/debian-lts-announce/2022/05/msg00022.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A6BY5P7ERZS7KXSBCGFCOXLMLGWUUJIH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HIP7KG7TVS5YF3QREAY2GOGUT3YUBZAI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JUN33257RUM4RS2I4GZETKFSAXPETATG/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
- https://security.netapp.com/advisory/ntap-20220930-0007/
- https://support.apple.com/kb/HT213488
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2126
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- http://seclists.org/fulldisclosure/2022/Oct/45
- https://github.com/vim/vim/commit/156d3911952d73b03d7420dc3540215247db0fe8
- https://huntr.dev/bounties/8d196d9b-3d10-41d2-9f70-8ef0d08c946e
- https://lists.debian.org/debian-lts-announce/2022/06/msg00014.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213443
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2206
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://github.com/vim/vim/commit/e178af5a586ea023622d460779fdcabbbfac0908
- https://huntr.dev/bounties/01d01e74-55d0-4d9e-878e-79ba599be668
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2286
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UXPO5EHDV6J4B27E65DOQGZFELUFPRSK/
- https://github.com/vim/vim/commit/f12129f1714f7d2301935bb21d896609bdac221c
- https://huntr.dev/bounties/fe7681fb-2318-436b-8e65-daf66cd597d8
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UXPO5EHDV6J4B27E65DOQGZFELUFPRSK/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2129
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://github.com/vim/vim/commit/d6211a52ab9f53b82f884561ed43d2fe4d24ff7d
- https://huntr.dev/bounties/3aaf06e7-9ae1-454d-b8ca-8709c98e5352
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2210
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://github.com/vim/vim/commit/c101abff4c6756db4f5e740fde289decb9452efa
- https://huntr.dev/bounties/020845f8-f047-4072-af0f-3726fe1aea25
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-3234
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4QI7AETXBHPC7SGA77Q7O5IEGULWYET7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LSSEWQLK55MCNT4Z2IIJEJYEI5HLCODI/
- https://github.com/vim/vim/commit/c249913edc35c0e666d783bfc21595cf9f7d9e0d
- https://huntr.dev/bounties/90fdf374-bf04-4386-8a23-38c83b88f0da
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4QI7AETXBHPC7SGA77Q7O5IEGULWYET7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSSEWQLK55MCNT4Z2IIJEJYEI5HLCODI/
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-3296
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4QI7AETXBHPC7SGA77Q7O5IEGULWYET7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LSSEWQLK55MCNT4Z2IIJEJYEI5HLCODI/
- https://github.com/vim/vim/commit/96b9bf8f74af8abf1e30054f996708db7dc285be
- https://huntr.dev/bounties/958866b8-526a-4979-9471-39392e0c9077
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4QI7AETXBHPC7SGA77Q7O5IEGULWYET7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSSEWQLK55MCNT4Z2IIJEJYEI5HLCODI/
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-0054
- http://seclists.org/fulldisclosure/2023/Mar/17
- https://github.com/vim/vim/commit/3ac1d97a1d9353490493d30088256360435f7731
- https://huntr.dev/bounties/b289ee0f-fd16-4147-bd01-c6289c45e49d
- https://lists.debian.org/debian-lts-announce/2023/06/msg00015.html
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213670
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use After Free in GitHub repository vim/vim prior to 9.0.0046.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2345
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://github.com/vim/vim/commit/32acf1f1a72ebb9d8942b9c9d80023bf1bb668ea
- https://huntr.dev/bounties/1eed7009-db6d-487b-bc41-8f2fd260483f
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use After Free in GitHub repository vim/vim prior to 9.0.0246.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2946
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C72HDIMR3KTTAO7QGTXWUMPBNFUFIBRD/
- https://github.com/vim/vim/commit/adce965162dd89bf29ee0e5baf53652e7515762c
- https://huntr.dev/bounties/5d389a18-5026-47df-a5d0-1548a9b555d5
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C72HDIMR3KTTAO7QGTXWUMPBNFUFIBRD/
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use After Free in GitHub repository vim/vim prior to 9.0.0322.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-3037
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RY3GEN2Q46ZJKSNHTN2XB6B3VAJBEILN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHJ6LCLHGGVI2U6ZHXHTZ2PYP4STC23N/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWOJOA7PZZAMBI5GFTL6PWHXMWSDLUXL/
- https://github.com/vim/vim/commit/4f1b083be43f351bc107541e7b0c9655a5d2c0bb
- https://huntr.dev/bounties/af4c2f2d-d754-4607-b565-9e92f3f717b5
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RY3GEN2Q46ZJKSNHTN2XB6B3VAJBEILN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHJ6LCLHGGVI2U6ZHXHTZ2PYP4STC23N/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWOJOA7PZZAMBI5GFTL6PWHXMWSDLUXL/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use After Free in GitHub repository vim/vim prior to 9.0.0490.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-3235
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4QI7AETXBHPC7SGA77Q7O5IEGULWYET7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LSSEWQLK55MCNT4Z2IIJEJYEI5HLCODI/
- https://github.com/vim/vim/commit/1c3dd8ddcba63c1af5112e567215b3cec2de11d0
- https://huntr.dev/bounties/96d5f7a0-a834-4571-b73b-0fe523b941af
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4QI7AETXBHPC7SGA77Q7O5IEGULWYET7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSSEWQLK55MCNT4Z2IIJEJYEI5HLCODI/
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use After Free in GitHub repository vim/vim prior to 9.0.0614.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-3352
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4QI7AETXBHPC7SGA77Q7O5IEGULWYET7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LSSEWQLK55MCNT4Z2IIJEJYEI5HLCODI/
- https://github.com/vim/vim/commit/ef976323e770315b5fca544efb6b2faa25674d15
- https://huntr.dev/bounties/d058f182-a49b-40c7-9234-43d4c5a29f60
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4QI7AETXBHPC7SGA77Q7O5IEGULWYET7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSSEWQLK55MCNT4Z2IIJEJYEI5HLCODI/
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use After Free in GitHub repository vim/vim prior to 9.0.0530.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-3256
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4QI7AETXBHPC7SGA77Q7O5IEGULWYET7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LSSEWQLK55MCNT4Z2IIJEJYEI5HLCODI/
- https://github.com/vim/vim/commit/8ecfa2c56b4992c7f067b92488aa9acea5a454ad
- https://huntr.dev/bounties/8336a3df-212a-4f8d-ae34-76ef1f936bb3
- https://lists.debian.org/debian-lts-announce/2022/11/msg00032.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4QI7AETXBHPC7SGA77Q7O5IEGULWYET7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSSEWQLK55MCNT4Z2IIJEJYEI5HLCODI/
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use After Free in GitHub repository vim/vim prior to 9.0.0882.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-4292
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WYC22GGZ6QA66HLNLHCTAJU265TT3O33/
- https://github.com/vim/vim/commit/c3d27ada14acd02db357f2d16347acc22cb17e93
- https://huntr.dev/bounties/da3d4c47-e57a-451e-993d-9df0ed31f57b
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WYC22GGZ6QA66HLNLHCTAJU265TT3O33/
- https://security.gentoo.org/glsa/202305-16
- https://security.netapp.com/advisory/ntap-20230113-0005/
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a crafted mangled symbol.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://access.redhat.com/security/cve/CVE-2021-3826
- https://gcc.gnu.org/git/?p=gcc.git;a=commit;h=5481040197402be6dfee265bd2ff5a4c88e30505
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4MYLS3VR4OPL5ECRWOR4ZHMGXUSCJFZY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6AKZ2DTS3ATVN5PANNVLKLE5OP4OF25Q/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MTEHT3G6YKJ7F7MSGWYSI4UM3XBAYXZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AXFC74WRZ2Q7F2TSUKPYNIL7ZPBWYI6L/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/
- https://gcc.gnu.org/git/?p=gcc.git%3Ba=commit%3Bh=5481040197402be6dfee265bd2ff5a4c88e30505
- https://gcc.gnu.org/pipermail/gcc-patches/2021-September/579987
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4MYLS3VR4OPL5ECRWOR4ZHMGXUSCJFZY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6AKZ2DTS3ATVN5PANNVLKLE5OP4OF25Q/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7MTEHT3G6YKJ7F7MSGWYSI4UM3XBAYXZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AXFC74WRZ2Q7F2TSUKPYNIL7ZPBWYI6L/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/
low severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based buffer overflow in archive_string_append_from_wcs() (archive_string.c) in libarchive-3.4.1dev allows remote attackers to cause a denial of service (out-of-bounds write in heap memory resulting into a crash) via a crafted archive file. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's official releases are unaffected.
Remediation
There is no fixed version for Centos:8
libarchive
.
References
low severity
- Vulnerable module: pcre
- Introduced through: pcre@8.42-4.el8
- Fixed in: 0:8.42-6.el8
Detailed paths
-
Introduced through: centos@centos8 › pcre@8.42-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream pcre
package and not the pcre
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
Remediation
Upgrade Centos:8
pcre
to version 0:8.42-6.el8 or higher.
References
- https://support.apple.com/kb/HT211931
- https://support.apple.com/kb/HT212147
- https://access.redhat.com/security/cve/CVE-2019-20838
- http://seclists.org/fulldisclosure/2020/Dec/32
- http://seclists.org/fulldisclosure/2021/Feb/14
- https://bugs.gentoo.org/717920
- https://www.pcre.org/original/changelog.txt
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E
- https://access.redhat.com/errata/RHSA-2021:4373
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
low severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.
Remediation
There is no fixed version for Centos:8
sqlite-libs
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-1127
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PDVN5HSWPNVP4QXBPCEGZDLZKURLJWTE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJ6TMKKBXHGVUHWFGM4X46VIJO7ZAG2W/
- https://github.com/vim/vim/commit/e0f869196930ef5f25a0ac41c9215b09c9ce2d3c
- https://huntr.dev/bounties/2d4d309e-4c96-415f-9070-36d0815f1beb
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDVN5HSWPNVP4QXBPCEGZDLZKURLJWTE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ6TMKKBXHGVUHWFGM4X46VIJO7ZAG2W/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-0288
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WYC22GGZ6QA66HLNLHCTAJU265TT3O33/
- http://seclists.org/fulldisclosure/2023/Mar/17
- https://github.com/vim/vim/commit/232bdaaca98c34a99ffadf27bf6ee08be6cc8f6a
- https://huntr.dev/bounties/550a0852-9be0-4abe-906c-f803b34e41d3
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WYC22GGZ6QA66HLNLHCTAJU265TT3O33/
- https://support.apple.com/kb/HT213670
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
vim is vulnerable to Heap-based Buffer Overflow
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://huntr.dev/bounties/9c2b2c82-48bb-4be9-ab8f-a48ea252d1b0
- https://access.redhat.com/security/cve/CVE-2021-3927
- https://github.com/vim/vim/commit/0b5b06cb4777d1401fdf83e7d48d287662236e7e
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BCQWPEY2AEYBELCMJYHYWYCD3PZVD2H7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNXY7T5OORA7UJIMGSJBGHFMU6UZWS6P/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PGW56Z6IN4UVM3E5RXXF4G7LGGTRBI5C/
- http://www.openwall.com/lists/oss-security/2022/01/15/1
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BCQWPEY2AEYBELCMJYHYWYCD3PZVD2H7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNXY7T5OORA7UJIMGSJBGHFMU6UZWS6P/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PGW56Z6IN4UVM3E5RXXF4G7LGGTRBI5C/
- https://security.gentoo.org/glsa/202208-32
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-0049
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3Y752EAVACVC5XY2TMGGOAIU25VQRPDW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T33LLWHLH63XDCO5OME7NWN63RA4U5HF/
- http://seclists.org/fulldisclosure/2023/Mar/17
- https://github.com/vim/vim/commit/7b17eb4b063a234376c1ec909ee293e42cff290c
- https://huntr.dev/bounties/5e6f325c-ba54-4bf0-b050-dca048fd3fd9
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3Y752EAVACVC5XY2TMGGOAIU25VQRPDW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T33LLWHLH63XDCO5OME7NWN63RA4U5HF/
- https://security.gentoo.org/glsa/202305-16
- https://security.netapp.com/advisory/ntap-20250117-0005/
- https://support.apple.com/kb/HT213670
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: openldap
- Introduced through: openldap@2.4.46-16.el8
- Fixed in: 0:2.4.46-19.el8_10
Detailed paths
-
Introduced through: centos@centos8 › openldap@2.4.46-16.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream openldap
package and not the openldap
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
Remediation
Upgrade Centos:8
openldap
to version 0:2.4.46-19.el8_10 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-2953
- http://seclists.org/fulldisclosure/2023/Jul/47
- http://seclists.org/fulldisclosure/2023/Jul/48
- http://seclists.org/fulldisclosure/2023/Jul/52
- https://bugs.openldap.org/show_bug.cgi?id=9904
- https://security.netapp.com/advisory/ntap-20230703-0005/
- https://support.apple.com/kb/HT213843
- https://support.apple.com/kb/HT213844
- https://support.apple.com/kb/HT213845
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
vim is vulnerable to Out-of-bounds Read
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://huntr.dev/bounties/229df5dd-5507-44e9-832c-c70364bdf035
- https://access.redhat.com/security/cve/CVE-2021-4166
- https://github.com/vim/vim/commit/6f98371532fcff911b462d51bc64f2ce8a6ae682
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2EY2VFBU3YGGWI5BW4XKT3F37MYGEQUD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3FH2J57GDA2WMBS6J56F6QQRA6BXQQFZ/
- http://seclists.org/fulldisclosure/2022/Jul/14
- http://seclists.org/fulldisclosure/2022/Mar/29
- http://seclists.org/fulldisclosure/2022/May/35
- http://www.openwall.com/lists/oss-security/2022/01/15/1
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2EY2VFBU3YGGWI5BW4XKT3F37MYGEQUD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3FH2J57GDA2WMBS6J56F6QQRA6BXQQFZ/
- https://security.gentoo.org/glsa/202208-32
- https://support.apple.com/kb/HT213183
- https://support.apple.com/kb/HT213256
- https://support.apple.com/kb/HT213343
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2287
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UXPO5EHDV6J4B27E65DOQGZFELUFPRSK/
- https://github.com/vim/vim/commit/5e59ea54c0c37c2f84770f068d95280069828774
- https://huntr.dev/bounties/654aa069-3a9d-45d3-9a52-c1cf3490c284
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/43Y3VJPOTTY3NTREDIFUPITM2POG4ZLP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UXPO5EHDV6J4B27E65DOQGZFELUFPRSK/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: dbus
- Introduced through: dbus@1:1.12.8-12.el8
Detailed paths
-
Introduced through: centos@centos8 › dbus@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus
package and not the dbus
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors
Remediation
There is no fixed version for Centos:8
dbus
.
References
low severity
- Vulnerable module: dbus-common
- Introduced through: dbus-common@1:1.12.8-12.el8
Detailed paths
-
Introduced through: centos@centos8 › dbus-common@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-common
package and not the dbus-common
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors
Remediation
There is no fixed version for Centos:8
dbus-common
.
References
low severity
- Vulnerable module: dbus-daemon
- Introduced through: dbus-daemon@1:1.12.8-12.el8
Detailed paths
-
Introduced through: centos@centos8 › dbus-daemon@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-daemon
package and not the dbus-daemon
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors
Remediation
There is no fixed version for Centos:8
dbus-daemon
.
References
low severity
- Vulnerable module: dbus-libs
- Introduced through: dbus-libs@1:1.12.8-12.el8
Detailed paths
-
Introduced through: centos@centos8 › dbus-libs@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-libs
package and not the dbus-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors
Remediation
There is no fixed version for Centos:8
dbus-libs
.
References
low severity
- Vulnerable module: dbus-tools
- Introduced through: dbus-tools@1:1.12.8-12.el8
Detailed paths
-
Introduced through: centos@centos8 › dbus-tools@1:1.12.8-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream dbus-tools
package and not the dbus-tools
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors
Remediation
There is no fixed version for Centos:8
dbus-tools
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version 9.0.0805 is able to address this issue. The name of the patch is d0fab10ed2a86698937e3c3fed2f10bd9bb5e731. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-212324.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-3705
- http://seclists.org/fulldisclosure/2023/Jan/19
- https://github.com/vim/vim/commit/d0fab10ed2a86698937e3c3fed2f10bd9bb5e731
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4JCW33NOLMELTTTDJH7WGDIFJZ5YEEMK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JYEK5RNMH7MVQH6RPBKLSCCA6NMIKHDV/
- https://security.netapp.com/advisory/ntap-20221223-0004/
- https://support.apple.com/kb/HT213605
- https://vuldb.com/?id.212324
- https://security.gentoo.org/glsa/202305-16
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JCW33NOLMELTTTDJH7WGDIFJZ5YEEMK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTBVD4J2SKVSWK4VBN5JP5OEVK6GDS3N/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYEK5RNMH7MVQH6RPBKLSCCA6NMIKHDV/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use After Free in GitHub repository vim/vim prior to 9.0.1858.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-4752
- http://seclists.org/fulldisclosure/2023/Oct/24
- https://github.com/vim/vim/commit/ee9166eb3b41846661a39b662dc7ebe8b5e15139
- https://huntr.dev/bounties/85f62dd7-ed84-4fa2-b265-8a369a318757
- https://lists.debian.org/debian-lts-announce/2023/09/msg00035.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I56ITJAFMFAQ2G3BMGTCGM3GS62V2DTR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ITRVK4FB74RZDIGTZJXOZMUW6X6F4TNF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PFE3LDFRZ7EGWA5AU7YHYL62ELBOFZWQ/
- https://support.apple.com/kb/HT213984
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use After Free in GitHub repository vim/vim prior to 9.0.1857.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-4750
- http://seclists.org/fulldisclosure/2023/Oct/24
- https://github.com/vim/vim/commit/fc68299d436cf87453e432daa77b6d545df4d7ed
- https://huntr.dev/bounties/1ab3ebdf-fe7d-4436-b483-9a586e03b0ea
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I56ITJAFMFAQ2G3BMGTCGM3GS62V2DTR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ITRVK4FB74RZDIGTZJXOZMUW6X6F4TNF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PFE3LDFRZ7EGWA5AU7YHYL62ELBOFZWQ/
- https://support.apple.com/kb/HT213984
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use After Free in GitHub repository vim/vim prior to 9.0.1840.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-4733
- http://seclists.org/fulldisclosure/2023/Oct/24
- https://github.com/vim/vim/commit/e1dc9a627536304bc4f738c21e909ad9fcf3974c
- https://huntr.dev/bounties/1ce1fd8c-050a-4373-8004-b35b61590217
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I56ITJAFMFAQ2G3BMGTCGM3GS62V2DTR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ITRVK4FB74RZDIGTZJXOZMUW6X6F4TNF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PFE3LDFRZ7EGWA5AU7YHYL62ELBOFZWQ/
- https://support.apple.com/kb/HT213984
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-0351
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- https://github.com/vim/vim/commit/fe6fb267e6ee5c5da2f41889e4e0e0ac5bf4b89d
- https://huntr.dev/bounties/8b36db58-b65c-4298-be7f-40b9e37fd161
- https://lists.debian.org/debian-lts-announce/2022/05/msg00022.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://security.gentoo.org/glsa/202208-32
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
low severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.
Remediation
There is no fixed version for Centos:8
glib2
.
References
- https://access.redhat.com/security/cve/CVE-2023-32611
- https://bugzilla.redhat.com/show_bug.cgi?id=2211829
- https://gitlab.gnome.org/GNOME/glib/-/issues/2797
- https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html
- https://security.gentoo.org/glsa/202311-18
- https://security.netapp.com/advisory/ntap-20231027-0005/
low severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.
Remediation
There is no fixed version for Centos:8
glib2
.
References
- https://access.redhat.com/security/cve/CVE-2023-32665
- https://bugzilla.redhat.com/show_bug.cgi?id=2211827
- https://gitlab.gnome.org/GNOME/glib/-/issues/2121
- https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html
- https://security.gentoo.org/glsa/202311-18
- https://security.netapp.com/advisory/ntap-20240426-0006/
low severity
- Vulnerable module: gnutls
- Introduced through: gnutls@3.6.14-7.el8_3
Detailed paths
-
Introduced through: centos@centos8 › gnutls@3.6.14-7.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnutls
package and not the gnutls
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.
Remediation
There is no fixed version for Centos:8
gnutls
.
References
- https://access.redhat.com/security/cve/CVE-2021-4209
- https://bugzilla.redhat.com/show_bug.cgi?id=2044156
- https://gitlab.com/gnutls/gnutls/-/commit/3db352734472d851318944db13be73da61300568
- https://gitlab.com/gnutls/gnutls/-/issues/1306
- https://gitlab.com/gnutls/gnutls/-/merge_requests/1503
- https://security.netapp.com/advisory/ntap-20220915-0005/
low severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Remediation
There is no fixed version for Centos:8
ncurses-base
.
References
- https://access.redhat.com/security/cve/CVE-2020-19187
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc3.md
- https://security.netapp.com/advisory/ntap-20231006-0005/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Remediation
There is no fixed version for Centos:8
ncurses-base
.
References
- https://access.redhat.com/security/cve/CVE-2020-19189
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc5.md
- https://lists.debian.org/debian-lts-announce/2023/09/msg00033.html
- https://security.netapp.com/advisory/ntap-20231006-0005/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Remediation
There is no fixed version for Centos:8
ncurses-base
.
References
- https://access.redhat.com/security/cve/CVE-2020-19185
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc1.md
- https://security.netapp.com/advisory/ntap-20231006-0005/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Remediation
There is no fixed version for Centos:8
ncurses-base
.
References
- https://access.redhat.com/security/cve/CVE-2020-19190
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc6.md
- https://security.netapp.com/advisory/ntap-20231006-0005/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Remediation
There is no fixed version for Centos:8
ncurses-base
.
References
- https://access.redhat.com/security/cve/CVE-2020-19186
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc2.md
- https://security.netapp.com/advisory/ntap-20231006-0005/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().
Remediation
There is no fixed version for Centos:8
ncurses-base
.
References
- https://access.redhat.com/security/cve/CVE-2023-50495
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/
- https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html
- https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html
- https://security.netapp.com/advisory/ntap-20240119-0008/
low severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Remediation
There is no fixed version for Centos:8
ncurses-base
.
References
- https://access.redhat.com/security/cve/CVE-2020-19188
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc4.md
- https://security.netapp.com/advisory/ntap-20231006-0005/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Remediation
There is no fixed version for Centos:8
ncurses-libs
.
References
- https://access.redhat.com/security/cve/CVE-2020-19187
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc3.md
- https://security.netapp.com/advisory/ntap-20231006-0005/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Remediation
There is no fixed version for Centos:8
ncurses-libs
.
References
- https://access.redhat.com/security/cve/CVE-2020-19189
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc5.md
- https://lists.debian.org/debian-lts-announce/2023/09/msg00033.html
- https://security.netapp.com/advisory/ntap-20231006-0005/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Remediation
There is no fixed version for Centos:8
ncurses-libs
.
References
- https://access.redhat.com/security/cve/CVE-2020-19185
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc1.md
- https://security.netapp.com/advisory/ntap-20231006-0005/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Remediation
There is no fixed version for Centos:8
ncurses-libs
.
References
- https://access.redhat.com/security/cve/CVE-2020-19190
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc6.md
- https://security.netapp.com/advisory/ntap-20231006-0005/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Remediation
There is no fixed version for Centos:8
ncurses-libs
.
References
- https://access.redhat.com/security/cve/CVE-2020-19186
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc2.md
- https://security.netapp.com/advisory/ntap-20231006-0005/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().
Remediation
There is no fixed version for Centos:8
ncurses-libs
.
References
- https://access.redhat.com/security/cve/CVE-2023-50495
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/
- https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html
- https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html
- https://security.netapp.com/advisory/ntap-20240119-0008/
low severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Remediation
There is no fixed version for Centos:8
ncurses-libs
.
References
- https://access.redhat.com/security/cve/CVE-2020-19188
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc4.md
- https://security.netapp.com/advisory/ntap-20231006-0005/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow.
Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service.
An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. OBJ_obj2txt() may be used to translate an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL type ASN1_OBJECT) to its canonical numeric text form, which are the sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by periods.
When one of the sub-identifiers in the OBJECT IDENTIFIER is very large (these are sizes that are seen as absurdly large, taking up tens or hundreds of KiBs), the translation to a decimal number in text may take a very long time. The time complexity is O(n^2) with 'n' being the size of the sub-identifiers in bytes (*).
With OpenSSL 3.0, support to fetch cryptographic algorithms using names / identifiers in string form was introduced. This includes using OBJECT IDENTIFIERs in canonical numeric text form as identifiers for fetching algorithms.
Such OBJECT IDENTIFIERs may be received through the ASN.1 structure AlgorithmIdentifier, which is commonly used in multiple protocols to specify what cryptographic algorithm should be used to sign or verify, encrypt or decrypt, or digest passed data.
Applications that call OBJ_obj2txt() directly with untrusted data are affected, with any version of OpenSSL. If the use is for the mere purpose of display, the severity is considered low.
In OpenSSL 3.0 and newer, this affects the subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS. It also impacts anything that processes X.509 certificates, including simple things like verifying its signature.
The impact on TLS is relatively low, because all versions of OpenSSL have a 100KiB limit on the peer's certificate chain. Additionally, this only impacts clients, or servers that have explicitly enabled client authentication.
In OpenSSL 1.1.1 and 1.0.2, this only affects displaying diverse objects, such as X.509 certificates. This is assumed to not happen in such a way that it would cause a Denial of Service, so these versions are considered not affected by this issue in such a way that it would be cause for concern, and the severity is therefore considered low.
Remediation
There is no fixed version for Centos:8
openssl-libs
.
References
- https://access.redhat.com/security/cve/CVE-2023-2650
- http://www.openwall.com/lists/oss-security/2023/05/30/1
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=423a2bc737a908ad0c77bda470b2b59dc879936b
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=853c5e56ee0b8650c73140816bb8b91d6163422c
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9e209944b35cf82368071f160a744b6178f9b098
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db779b0e10b047f2585615e0b8f2acdf21f8544a
- https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0009
- https://security.gentoo.org/glsa/202402-08
- https://security.netapp.com/advisory/ntap-20230703-0001/
- https://security.netapp.com/advisory/ntap-20231027-0009/
- https://www.debian.org/security/2023/dsa-5417
- https://www.openssl.org/news/secadv/20230530.txt
low severity
- Vulnerable module: tpm2-tss
- Introduced through: tpm2-tss@2.3.2-3.el8
- Fixed in: 0:2.3.2-5.el8
Detailed paths
-
Introduced through: centos@centos8 › tpm2-tss@2.3.2-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream tpm2-tss
package and not the tpm2-tss
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In affected versions Tss2_RC_SetHandler
and Tss2_RC_Decode
both index into layer_handler
with an 8 bit layer number, but the array only has TPM2_ERROR_TSS2_RC_LAYER_COUNT
entries, so trying to add a handler for higher-numbered layers or decode a response code with such a layer number reads/writes past the end of the buffer. This Buffer overrun, could result in arbitrary code execution. An example attack would be a MiTM bus attack that returns 0xFFFFFFFF for the RC. Given the common use case of TPM modules an attacker must have local access to the target machine with local system privileges which allows access to the TPM system. Usually TPM access requires administrative privilege.
Remediation
Upgrade Centos:8
tpm2-tss
to version 0:2.3.2-5.el8 or higher.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.
Remediation
There is no fixed version for Centos:8
glib2
.
References
- https://access.redhat.com/security/cve/CVE-2023-29499
- https://bugzilla.redhat.com/show_bug.cgi?id=2211828
- https://gitlab.gnome.org/GNOME/glib/-/issues/2794
- https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html
- https://security.gentoo.org/glsa/202311-18
- https://security.netapp.com/advisory/ntap-20231103-0001/
low severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.
Remediation
There is no fixed version for Centos:8
glib2
.
References
low severity
- Vulnerable module: gnupg2
- Introduced through: gnupg2@2.2.20-2.el8
Detailed paths
-
Introduced through: centos@centos8 › gnupg2@2.2.20-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnupg2
package and not the gnupg2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.
Remediation
There is no fixed version for Centos:8
gnupg2
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://security.netapp.com/advisory/ntap-20210212-0007/
- https://access.redhat.com/security/cve/CVE-2020-35494
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/
- https://bugzilla.redhat.com/show_bug.cgi?id=1911439
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/
- https://security.gentoo.org/glsa/202107-24
low severity
- Vulnerable module: gawk
- Introduced through: gawk@4.2.1-2.el8
Detailed paths
-
Introduced through: centos@centos8 › gawk@4.2.1-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream gawk
package and not the gawk
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.
Remediation
There is no fixed version for Centos:8
gawk
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-1720
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- http://seclists.org/fulldisclosure/2022/Oct/45
- https://github.com/vim/vim/commit/395bd1f6d3edc9f7edb5d1f2d7deaf5a9e3ab93c
- https://huntr.dev/bounties/5ccfb386-7eb9-46e5-98e5-243ea4b358a8
- https://lists.debian.org/debian-lts-announce/2022/06/msg00014.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
- https://support.apple.com/kb/HT213443
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When asked to both use a .netrc
file for credentials and to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.
Remediation
There is no fixed version for Centos:8
curl
.
References
- https://access.redhat.com/security/cve/CVE-2024-11053
- https://curl.se/docs/CVE-2024-11053.html
- https://curl.se/docs/CVE-2024-11053.json
- https://hackerone.com/reports/2829063
- http://www.openwall.com/lists/oss-security/2024/12/11/1
- https://security.netapp.com/advisory/ntap-20250124-0012/
- https://security.netapp.com/advisory/ntap-20250131-0003/
low severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-30.el8
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use after free vulnerability exists in curl <7.87.0. Curl can be asked to tunnel virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-30.el8 or higher.
References
low severity
- Vulnerable module: krb5-libs
- Introduced through: krb5-libs@1.18.2-8.el8
- Fixed in: 0:1.18.2-27.el8_10
Detailed paths
-
Introduced through: centos@centos8 › krb5-libs@1.18.2-8.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream krb5-libs
package and not the krb5-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
Remediation
Upgrade Centos:8
krb5-libs
to version 0:1.18.2-27.el8_10 or higher.
References
low severity
- Vulnerable module: krb5-libs
- Introduced through: krb5-libs@1.18.2-8.el8
- Fixed in: 0:1.18.2-27.el8_10
Detailed paths
-
Introduced through: centos@centos8 › krb5-libs@1.18.2-8.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream krb5-libs
package and not the krb5-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
Remediation
Upgrade Centos:8
krb5-libs
to version 0:1.18.2-27.el8_10 or higher.
References
low severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
- Fixed in: 0:3.3.3-5.el8
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."
Remediation
Upgrade Centos:8
libarchive
to version 0:3.3.3-5.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-36227
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V67OO2UUQAUJS3IK4JZPF6F3LUCBU6IS/
- https://bugs.gentoo.org/882521
- https://github.com/libarchive/libarchive/blob/v3.0.0a/libarchive/archive_write.c#L215
- https://github.com/libarchive/libarchive/issues/1754
- https://lists.debian.org/debian-lts-announce/2023/01/msg00034.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V67OO2UUQAUJS3IK4JZPF6F3LUCBU6IS/
- https://security.gentoo.org/glsa/202309-14
low severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When asked to both use a .netrc
file for credentials and to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.
Remediation
There is no fixed version for Centos:8
libcurl-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2024-11053
- https://curl.se/docs/CVE-2024-11053.html
- https://curl.se/docs/CVE-2024-11053.json
- https://hackerone.com/reports/2829063
- http://www.openwall.com/lists/oss-security/2024/12/11/1
- https://security.netapp.com/advisory/ntap-20250124-0012/
- https://security.netapp.com/advisory/ntap-20250131-0003/
low severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-30.el8
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A use after free vulnerability exists in curl <7.87.0. Curl can be asked to tunnel virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-30.el8 or higher.
References
low severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."
Remediation
There is no fixed version for Centos:8
libxml2
.
References
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.
Remediation
There is no fixed version for Centos:8
openssl-libs
.
References
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-14.el8_6
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent to the peer.
Impact summary: A buffer overread can have a range of potential consequences such as unexpected application beahviour or a crash. In particular this issue could result in up to 255 bytes of arbitrary private data from memory being sent to the peer leading to a loss of confidentiality. However, only applications that directly call the SSL_select_next_proto function with a 0 length list of supported client protocols are affected by this issue. This would normally never be a valid scenario and is typically not under attacker control but may occur by accident in the case of a configuration or programming error in the calling application.
The OpenSSL API function SSL_select_next_proto is typically used by TLS applications that support ALPN (Application Layer Protocol Negotiation) or NPN (Next Protocol Negotiation). NPN is older, was never standardised and is deprecated in favour of ALPN. We believe that ALPN is significantly more widely deployed than NPN. The SSL_select_next_proto function accepts a list of protocols from the server and a list of protocols from the client and returns the first protocol that appears in the server list that also appears in the client list. In the case of no overlap between the two lists it returns the first item in the client list. In either case it will signal whether an overlap between the two lists was found. In the case where SSL_select_next_proto is called with a zero length client list it fails to notice this condition and returns the memory immediately following the client list pointer (and reports that there was no overlap in the lists).
This function is typically called from a server side application callback for ALPN or a client side application callback for NPN. In the case of ALPN the list of protocols supplied by the client is guaranteed by libssl to never be zero in length. The list of server protocols comes from the application and should never normally be expected to be of zero length. In this case if the SSL_select_next_proto function has been called as expected (with the list supplied by the client passed in the client/client_len parameters), then the application will not be vulnerable to this issue. If the application has accidentally been configured with a zero length server list, and has accidentally passed that zero length server list in the client/client_len parameters, and has additionally failed to correctly handle a "no overlap" response (which would normally result in a handshake failure in ALPN) then it will be vulnerable to this problem.
In the case of NPN, the protocol permits the client to opportunistically select a protocol when there is no overlap. OpenSSL returns the first client protocol in the no overlap case in support of this. The list of client protocols comes from the application and should never normally be expected to be of zero length. However if the SSL_select_next_proto function is accidentally called with a client_len of 0 then an invalid memory pointer will be returned instead. If the application uses this output as the opportunistic protocol then the loss of confidentiality will occur.
This issue has been assessed as Low severity because applications are most likely to be vulnerable if they are using NPN instead of ALPN - but NPN is not widely used. It also requires an application configuration or programming error. Finally, this issue would not typically be under attacker control making active exploitation unlikely.
The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.
Due to the low severity of this issue we are not issuing new releases of OpenSSL at this time. The fix will be included in the next releases when they become available.
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-14.el8_6 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-5535
- http://www.openwall.com/lists/oss-security/2024/08/15/1
- http://www.openwall.com/lists/oss-security/2024/06/27/1
- http://www.openwall.com/lists/oss-security/2024/06/28/4
- https://security.netapp.com/advisory/ntap-20240712-0005/
- https://github.com/openssl/openssl/commit/4ada436a1946cbb24db5ab4ca082b69c1bc10f37
- https://github.com/openssl/openssl/commit/99fb785a5f85315b95288921a321a935ea29a51e
- https://github.com/openssl/openssl/commit/cf6f91f6121f4db167405db2f0de410a456f260c
- https://github.com/openssl/openssl/commit/e86ac436f0bd54d4517745483e2315650fae7b2c
- https://github.openssl.org/openssl/extended-releases/commit/9947251413065a05189a63c9b7a6c1d4e224c21c
- https://github.openssl.org/openssl/extended-releases/commit/b78ec0824da857223486660177d3b1f255c65d87
- https://www.openssl.org/news/secadv/20240627.txt
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-12.el8_9
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https://github.com/openssl/openssl/pull/13817 (rsa_pkcs1_implicit_rejection). These changes are part of OpenSSL 3.2 and have also been backported to stable versions of various Linux distributions, as well as to the PHP builds provided for Windows since the previous release. All distributors and builders should ensure that this version is used to prevent PHP from being vulnerable.
PHP Windows builds for the versions 8.1.29, 8.2.20 and 8.3.8 and above include OpenSSL patches that fix the vulnerability.
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-12.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2024-2408
- https://github.com/php/php-src/security/advisories/GHSA-hh26-4ppw-5864
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/
- https://security.netapp.com/advisory/ntap-20250321-0008/
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A security vulnerability has been identified in all supported versions
of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems.
Policy processing is disabled by default but can be enabled by passing
the -policy' argument to the command line utilities or by calling the
X509_VERIFY_PARAM_set1_policies()' function.
Remediation
There is no fixed version for Centos:8
openssl-libs
.
References
- https://access.redhat.com/security/cve/CVE-2023-0464
- https://security.netapp.com/advisory/ntap-20230406-0006/
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2017771e2db3e2b96f89bbe8766c3209f6a99545
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2dcd4f1e3115f38cefa43e3efbe9b801c27e642e
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=879f7080d7e141f415c79eaa3a8ac4a3dad0348b
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=959c59c7a0164117e7f8366466a32bb1f8d77ff1
- https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html
- https://security.gentoo.org/glsa/202402-08
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://www.couchbase.com/alerts/
- https://www.debian.org/security/2023/dsa-5417
- https://www.openssl.org/news/secadv/20230322.txt
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations
Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, only applications that directly call the SSL_free_buffers function are affected by this issue. Applications that do not call this function are not vulnerable. Our investigations indicate that this function is rarely used by applications.
The SSL_free_buffers function is used to free the internal OpenSSL buffer used when processing an incoming record from the network. The call is only expected to succeed if the buffer is not currently in use. However, two scenarios have been identified where the buffer is freed even when still in use.
The first scenario occurs where a record header has been received from the network and processed by OpenSSL, but the full record body has not yet arrived. In this case calling SSL_free_buffers will succeed even though a record has only been partially processed and the buffer is still in use.
The second scenario occurs where a full record containing application data has been received and processed by OpenSSL but the application has only read part of this data. Again a call to SSL_free_buffers will succeed even though the buffer is still in use.
While these scenarios could occur accidentally during normal operation a malicious attacker could attempt to engineer a stituation where this occurs. We are not aware of this issue being actively exploited.
The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.
Remediation
There is no fixed version for Centos:8
openssl-libs
.
References
- https://access.redhat.com/security/cve/CVE-2024-4741
- https://github.com/openssl/openssl/commit/704f725b96aa373ee45ecfb23f6abfe8be8d9177
- https://github.com/openssl/openssl/commit/b3f0eb0a295f58f16ba43ba99dad70d4ee5c437d
- https://github.com/openssl/openssl/commit/c88c3de51020c37e8706bf7a682a162593053aac
- https://github.com/openssl/openssl/commit/e5093133c35ca82874ad83697af76f4b0f7e3bd8
- https://github.openssl.org/openssl/extended-releases/commit/f7a045f3143fc6da2ee66bf52d8df04829590dd4
- https://www.openssl.org/news/secadv/20240528.txt
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption problem caused by the cplus_demangle_type function making recursive calls to itself in certain scenarios involving many 'P' characters.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://access.redhat.com/security/cve/CVE-2018-17985
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87335
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://usn.ubuntu.com/4326-1/
- https://usn.ubuntu.com/4336-1/
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://access.redhat.com/security/cve/CVE-2022-38533
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6AKZ2DTS3ATVN5PANNVLKLE5OP4OF25Q/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MTEHT3G6YKJ7F7MSGWYSI4UM3XBAYXZ/
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=45d92439aebd0386ef8af76e1796d08cfe457e1d
- https://github.com/bminor/binutils-gdb/commit/45d92439aebd0386ef8af76e1796d08cfe457e1d
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6AKZ2DTS3ATVN5PANNVLKLE5OP4OF25Q/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7MTEHT3G6YKJ7F7MSGWYSI4UM3XBAYXZ/
- https://security.gentoo.org/glsa/202309-15
- https://security.netapp.com/advisory/ntap-20221104-0007/
- https://sourceware.org/bugzilla/show_bug.cgi?id=29482
- https://sourceware.org/bugzilla/show_bug.cgi?id=29482#c2
- https://sourceware.org/bugzilla/show_bug.cgi?id=29495
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=45d92439aebd0386ef8af76e1796d08cfe457e1d
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://security.netapp.com/advisory/ntap-20210212-0007/
- https://access.redhat.com/security/cve/CVE-2020-35493
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/
- https://bugzilla.redhat.com/show_bug.cgi?id=1911437
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/
- https://security.gentoo.org/glsa/202107-24
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw affects binutils versions prior to 2.34.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://security.netapp.com/advisory/ntap-20210212-0007/
- https://access.redhat.com/security/cve/CVE-2020-35496
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/
- https://bugzilla.redhat.com/show_bug.cgi?id=1911444
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/
- https://security.gentoo.org/glsa/202107-24
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://security.netapp.com/advisory/ntap-20210212-0007/
- https://access.redhat.com/security/cve/CVE-2020-35495
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/
- https://bugzilla.redhat.com/show_bug.cgi?id=1911441
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/
- https://security.gentoo.org/glsa/202107-24
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. There is a heap-based buffer over-read in _bfd_doprnt in bfd.c because elf_object_p in elfcode.h mishandles an e_shstrndx section of type SHT_GROUP by omitting a trailing '\0' character.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/108903
- https://access.redhat.com/security/cve/CVE-2019-12972
- https://security.gentoo.org/glsa/202007-39
- https://sourceware.org/bugzilla/show_bug.cgi?id=24689
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=890f750a3b053532a4b839a2dd6243076de12031
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html
- https://usn.ubuntu.com/4336-1/
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=890f750a3b053532a4b839a2dd6243076de12031
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered function parse_stab_struct_fields in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: libgcc
- Introduced through: libgcc@8.4.1-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libgcc@8.4.1-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libgcc
package and not the libgcc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
Remediation
There is no fixed version for Centos:8
libgcc
.
References
- https://access.redhat.com/security/cve/CVE-2022-27943
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/
- https://sourceware.org/bugzilla/show_bug.cgi?id=28995
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/
low severity
- Vulnerable module: libstdc++
- Introduced through: libstdc++@8.4.1-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libstdc++@8.4.1-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libstdc++
package and not the libstdc++
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
Remediation
There is no fixed version for Centos:8
libstdc++
.
References
- https://access.redhat.com/security/cve/CVE-2022-27943
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/
- https://sourceware.org/bugzilla/show_bug.cgi?id=28995
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/
low severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.
Remediation
There is no fixed version for Centos:8
libxml2
.
References
- https://access.redhat.com/security/cve/CVE-2024-34459
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/720
- https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.11.8
- https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.12.7
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5HVUXKYTBWT3G5DEEQX62STJQBY367NL/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/INKSSLW5VMZIXHRPZBAW4TJUX5SQKARG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VRDJCNQP32LV56KESUQ5SNZKAJWSZZRI/
low severity
- Vulnerable module: libzstd
- Introduced through: libzstd@1.4.4-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libzstd@1.4.4-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libzstd
package and not the libzstd
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.
Remediation
There is no fixed version for Centos:8
libzstd
.
References
low severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
Remediation
There is no fixed version for Centos:8
ncurses-base
.
References
- https://access.redhat.com/security/cve/CVE-2021-39537
- http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup
- https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html
- https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- http://seclists.org/fulldisclosure/2022/Oct/45
- https://support.apple.com/kb/HT213443
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
- https://security.netapp.com/advisory/ntap-20230427-0012/
- https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html
low severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
Remediation
There is no fixed version for Centos:8
ncurses-libs
.
References
- https://access.redhat.com/security/cve/CVE-2021-39537
- http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup
- https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html
- https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- http://seclists.org/fulldisclosure/2022/Oct/43
- http://seclists.org/fulldisclosure/2022/Oct/45
- https://support.apple.com/kb/HT213443
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
- https://security.netapp.com/advisory/ntap-20230427-0012/
- https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack
Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly.
A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue.
OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass().
We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant.
The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue.
Remediation
There is no fixed version for Centos:8
openssl-libs
.
References
- https://access.redhat.com/security/cve/CVE-2024-0727
- http://www.openwall.com/lists/oss-security/2024/03/11/1
- https://security.netapp.com/advisory/ntap-20240208-0006/
- https://github.com/openssl/openssl/commit/09df4395b5071217b76dc7d3d2e630eb8c5a79c2
- https://github.com/openssl/openssl/commit/775acfdbd0c6af9ac855f34969cdab0c0c90844a
- https://github.com/openssl/openssl/commit/d135eeab8a5dbf72b3da5240bab9ddb7678dbd2c
- https://github.openssl.org/openssl/extended-releases/commit/03b3941d60c4bce58fab69a0c22377ab439bc0e8
- https://github.openssl.org/openssl/extended-releases/commit/aebaa5883e31122b404e450732dc833dc9dee539
- https://www.openssl.org/news/secadv/20240125.txt
low severity
- Vulnerable module: systemd
- Introduced through: systemd@239-45.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd
package and not the systemd
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.
Remediation
There is no fixed version for Centos:8
systemd
.
References
low severity
- Vulnerable module: systemd-libs
- Introduced through: systemd-libs@239-45.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd-libs@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-libs
package and not the systemd-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.
Remediation
There is no fixed version for Centos:8
systemd-libs
.
References
low severity
- Vulnerable module: systemd-pam
- Introduced through: systemd-pam@239-45.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd-pam@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-pam
package and not the systemd-pam
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.
Remediation
There is no fixed version for Centos:8
systemd-pam
.
References
low severity
- Vulnerable module: systemd-udev
- Introduced through: systemd-udev@239-45.el8
Detailed paths
-
Introduced through: centos@centos8 › systemd-udev@239-45.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd-udev
package and not the systemd-udev
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.
Remediation
There is no fixed version for Centos:8
systemd-udev
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-2610
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PCLJN4QINITA3ZASKLEJ64C5TFNKELMO/
- https://github.com/vim/vim/commit/ab9a2d884b3a4abe319606ea95a5a6d6b01cd73a
- https://huntr.dev/bounties/31e67340-935b-4f6c-a923-f7246bc29c7d
- https://lists.debian.org/debian-lts-announce/2023/06/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PCLJN4QINITA3ZASKLEJ64C5TFNKELMO/
- https://security.netapp.com/advisory/ntap-20241129-0006/
- https://support.apple.com/kb/HT213844
- https://support.apple.com/kb/HT213845
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2923
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C72HDIMR3KTTAO7QGTXWUMPBNFUFIBRD/
- https://github.com/vim/vim/commit/6669de1b235843968e88844ca6d3c8dec4b01a9e
- https://huntr.dev/bounties/fd3a3ab8-ab0f-452f-afea-8c613e283fd2
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C72HDIMR3KTTAO7QGTXWUMPBNFUFIBRD/
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2980
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWOJOA7PZZAMBI5GFTL6PWHXMWSDLUXL/
- https://github.com/vim/vim/commit/80525751c5ce9ed82c41d83faf9ef38667bf61b1
- https://huntr.dev/bounties/6e7b12a5-242c-453d-b39e-9625d563b0ea
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWOJOA7PZZAMBI5GFTL6PWHXMWSDLUXL/
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-1264
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DIAKPMKJ4OZ6NYRZJO7YWMNQL2BICLYV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X4KDAU76Z7QNSPKZX2JAJ6O7KIEOXWTL/
- https://github.com/vim/vim/commit/7ac5023a5f1a37baafbe1043645f97ba3443d9f6
- https://huntr.dev/bounties/b2989095-88f3-413a-9a39-c1c58a6e6815
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DIAKPMKJ4OZ6NYRZJO7YWMNQL2BICLYV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X4KDAU76Z7QNSPKZX2JAJ6O7KIEOXWTL/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-2609
- https://github.com/vim/vim/commit/d1ae8366aff286d41e7f5bc513cc0a1af5130aad
- https://huntr.dev/bounties/1679be5a-565f-4a44-a430-836412a0b622
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PCLJN4QINITA3ZASKLEJ64C5TFNKELMO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PCLJN4QINITA3ZASKLEJ64C5TFNKELMO/
- https://support.apple.com/kb/HT213844
- https://support.apple.com/kb/HT213845
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
vim 8.2.2348 is affected by null pointer dereference, allows local attackers to cause a denial of service (DoS) via the ex_buffer_all method.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-5441
- https://github.com/vim/vim/commit/20d161ace307e28690229b68584f2d84556f8960
- https://huntr.dev/bounties/b54cbdf5-3e85-458d-bb38-9ea2c0b669f2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VDDWD25AZIHBAA44HQT75OWLQ5UMDKU3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VGTVLUV7UCXXCZAIQIUCLG6JXAVYT3HE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XPT7NMYJRLBPIALGSE24UWTY6F774GZW/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: cpio
- Introduced through: cpio@2.12-10.el8
Detailed paths
-
Introduced through: centos@centos8 › cpio@2.12-10.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream cpio
package and not the cpio
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.
Remediation
There is no fixed version for Centos:8
cpio
.
References
low severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libcurl's ASN1 parser code has the GTime2str()
function, used for parsing an
ASN.1 Generalized Time field. If given an syntactically incorrect field, the
parser might end up using -1 for the length of the time fraction, leading to
a strlen()
getting performed on a pointer to a heap buffer area that is not
(purposely) null terminated.
This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when CURLINFO_CERTINFO is used.
Remediation
There is no fixed version for Centos:8
curl
.
References
- https://access.redhat.com/security/cve/CVE-2024-7264
- https://curl.se/docs/CVE-2024-7264.html
- https://curl.se/docs/CVE-2024-7264.json
- https://hackerone.com/reports/2629968
- http://www.openwall.com/lists/oss-security/2024/07/31/1
- https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519
- https://security.netapp.com/advisory/ntap-20240828-0008/
low severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libcurl's ASN1 parser code has the GTime2str()
function, used for parsing an
ASN.1 Generalized Time field. If given an syntactically incorrect field, the
parser might end up using -1 for the length of the time fraction, leading to
a strlen()
getting performed on a pointer to a heap buffer area that is not
(purposely) null terminated.
This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when CURLINFO_CERTINFO is used.
Remediation
There is no fixed version for Centos:8
libcurl-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2024-7264
- https://curl.se/docs/CVE-2024-7264.html
- https://curl.se/docs/CVE-2024-7264.json
- https://hackerone.com/reports/2629968
- http://www.openwall.com/lists/oss-security/2024/07/31/1
- https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519
- https://security.netapp.com/advisory/ntap-20240828-0008/
low severity
- Vulnerable module: libgcc
- Introduced through: libgcc@8.4.1-1.el8
- Fixed in: 0:8.5.0-3.el8
Detailed paths
-
Introduced through: centos@centos8 › libgcc@8.4.1-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libgcc
package and not the libgcc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.
Remediation
Upgrade Centos:8
libgcc
to version 0:8.5.0-3.el8 or higher.
References
low severity
- Vulnerable module: libstdc++
- Introduced through: libstdc++@8.4.1-1.el8
- Fixed in: 0:8.5.0-3.el8
Detailed paths
-
Introduced through: centos@centos8 › libstdc++@8.4.1-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libstdc++
package and not the libstdc++
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.
Remediation
Upgrade Centos:8
libstdc++
to version 0:8.5.0-3.el8 or higher.
References
low severity
- Vulnerable module: lua-libs
- Introduced through: lua-libs@5.3.4-11.el8
- Fixed in: 0:5.3.4-12.el8
Detailed paths
-
Introduced through: centos@centos8 › lua-libs@5.3.4-11.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream lua-libs
package and not the lua-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
Remediation
Upgrade Centos:8
lua-libs
to version 0:5.3.4-12.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2020-24370
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E6KONNG6UEI3FMEOY67NDZC32NBGBI44/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QXYMCIUNGK26VHAYHGP5LPW56G2KWOHQ/
- http://lua-users.org/lists/lua-l/2020-07/msg00324.html
- https://github.com/lua/lua/commit/a585eae6e7ada1ca9271607a4f48dfb17868ab7b
- https://lists.debian.org/debian-lts-announce/2020/09/msg00019.html
- https://access.redhat.com/errata/RHSA-2021:4510
- https://lists.debian.org/debian-lts-announce/2023/06/msg00031.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E6KONNG6UEI3FMEOY67NDZC32NBGBI44/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QXYMCIUNGK26VHAYHGP5LPW56G2KWOHQ/
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-12.el8_9
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Issue summary: Checking excessively long DH keys or parameters may be very slow.
Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service.
The function DH_check() performs various checks on DH parameters. After fixing CVE-2023-3446 it was discovered that a large q parameter value can also trigger an overly long computation during some of these checks. A correct q value, if present, cannot be larger than the modulus p parameter, thus it is unnecessary to perform these checks if q is larger than p.
An application that calls DH_check() and supplies a key or parameters obtained from an untrusted source could be vulnerable to a Denial of Service attack.
The function DH_check() is itself called by a number of other OpenSSL functions. An application calling any of those other functions may similarly be affected. The other functions affected by this are DH_check_ex() and EVP_PKEY_param_check().
Also vulnerable are the OpenSSL dhparam and pkeyparam command line applications when using the "-check" option.
The OpenSSL SSL/TLS implementation is not affected by this issue.
The OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-12.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-3817
- http://seclists.org/fulldisclosure/2023/Jul/43
- http://www.openwall.com/lists/oss-security/2023/07/31/1
- http://www.openwall.com/lists/oss-security/2023/09/22/11
- http://www.openwall.com/lists/oss-security/2023/09/22/9
- http://www.openwall.com/lists/oss-security/2023/11/06/2
- https://lists.debian.org/debian-lts-announce/2023/08/msg00019.html
- https://security.gentoo.org/glsa/202402-08
- https://security.netapp.com/advisory/ntap-20230818-0014/
- https://security.netapp.com/advisory/ntap-20231027-0008/
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=6a1eb62c29db6cb5eec707f9338aee00f44e26f5
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=869ad69aadd985c7b8ca6f4e5dd0eb274c9f3644
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9002fd07327a91f35ba6c1307e71fa6fd4409b7f
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=91ddeba0f2269b017dc06c46c993a788974b1aa5
- https://www.openssl.org/news/secadv/20230731.txt
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks.
Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether.
Policy processing is disabled by default but can be enabled by passing
the -policy' argument to the command line utilities or by calling the
X509_VERIFY_PARAM_set1_policies()' function.
Remediation
There is no fixed version for Centos:8
openssl-libs
.
References
- https://access.redhat.com/security/cve/CVE-2023-0465
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=10325176f3d3e98c6e2b3bf5ab1e3b334de6947a
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1dd43e0709fece299b15208f36cc7c76209ba0bb
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=b013765abfa80036dc779dd0e50602c57bb3bf95
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=facfb1ab745646e97a1920977ae4a9965ea61d5c
- https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html
- https://security.gentoo.org/glsa/202402-08
- https://security.netapp.com/advisory/ntap-20230414-0001/
- https://www.debian.org/security/2023/dsa-5417
- https://www.openssl.org/news/secadv/20230328.txt
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-12.el8_9
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow.
Impact summary: Applications that use the functions DH_generate_key() to generate an X9.42 DH key may experience long delays. Likewise, applications that use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check() to check an X9.42 DH key or X9.42 DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service.
While DH_check() performs all the necessary checks (as of CVE-2023-3817), DH_check_pub_key() doesn't make any of these checks, and is therefore vulnerable for excessively large P and Q parameters.
Likewise, while DH_generate_key() performs a check for an excessively large P, it doesn't check for an excessively large Q.
An application that calls DH_generate_key() or DH_check_pub_key() and supplies a key or parameters obtained from an untrusted source could be vulnerable to a Denial of Service attack.
DH_generate_key() and DH_check_pub_key() are also called by a number of other OpenSSL functions. An application calling any of those other functions may similarly be affected. The other functions affected by this are DH_check_pub_key_ex(), EVP_PKEY_public_check(), and EVP_PKEY_generate().
Also vulnerable are the OpenSSL pkey command line application when using the "-pubcheck" option, as well as the OpenSSL genpkey command line application.
The OpenSSL SSL/TLS implementation is not affected by this issue.
The OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-12.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-5678
- http://www.openwall.com/lists/oss-security/2023/11/06/2
- http://www.openwall.com/lists/oss-security/2024/03/11/1
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6
- https://security.netapp.com/advisory/ntap-20231130-0010/
- https://www.openssl.org/news/secadv/20231106.txt
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
- Fixed in: 1:1.1.1k-12.el8_9
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Issue summary: Checking excessively long DH keys or parameters may be very slow.
Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service.
The function DH_check() performs various checks on DH parameters. One of those checks confirms that the modulus ('p' parameter) is not too large. Trying to use a very large modulus is slow and OpenSSL will not normally use a modulus which is over 10,000 bits in length.
However the DH_check() function checks numerous aspects of the key or parameters that have been supplied. Some of those checks use the supplied modulus value even if it has already been found to be too large.
An application that calls DH_check() and supplies a key or parameters obtained from an untrusted source could be vulernable to a Denial of Service attack.
The function DH_check() is itself called by a number of other OpenSSL functions. An application calling any of those other functions may similarly be affected. The other functions affected by this are DH_check_ex() and EVP_PKEY_param_check().
Also vulnerable are the OpenSSL dhparam and pkeyparam command line applications when using the '-check' option.
The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.
Remediation
Upgrade Centos:8
openssl-libs
to version 1:1.1.1k-12.el8_9 or higher.
References
- https://access.redhat.com/security/cve/CVE-2023-3446
- http://www.openwall.com/lists/oss-security/2023/07/19/4
- http://www.openwall.com/lists/oss-security/2023/07/19/5
- http://www.openwall.com/lists/oss-security/2023/07/19/6
- http://www.openwall.com/lists/oss-security/2023/07/31/1
- http://www.openwall.com/lists/oss-security/2024/05/16/1
- https://lists.debian.org/debian-lts-announce/2023/08/msg00019.html
- https://security.gentoo.org/glsa/202402-08
- https://security.netapp.com/advisory/ntap-20230803-0011/
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1fa20cf2f506113c761777127a38bce5068740eb
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8780a896543a654e757db1b9396383f9d8095528
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9a0a4d3c1e7138915563c0df4fe6a3f9377b839c
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fc9867c1e03c22ebf56943be205202e576aabf23
- https://www.openssl.org/news/secadv/20230719.txt
low severity
- Vulnerable module: pcre
- Introduced through: pcre@8.42-4.el8
- Fixed in: 0:8.42-6.el8
Detailed paths
-
Introduced through: centos@centos8 › pcre@8.42-4.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream pcre
package and not the pcre
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
Remediation
Upgrade Centos:8
pcre
to version 0:8.42-6.el8 or higher.
References
- https://about.gitlab.com/releases/2020/07/01/security-release-13-1-2-release/
- https://support.apple.com/kb/HT211931
- https://support.apple.com/kb/HT212147
- https://access.redhat.com/security/cve/CVE-2020-14155
- http://seclists.org/fulldisclosure/2020/Dec/32
- http://seclists.org/fulldisclosure/2021/Feb/14
- https://bugs.gentoo.org/717920
- https://www.pcre.org/original/changelog.txt
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E
- https://access.redhat.com/errata/RHSA-2021:4373
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
- https://security.netapp.com/advisory/ntap-20221028-0010/
- https://www.oracle.com/security-alerts/cpuapr2022.html
low severity
- Vulnerable module: pcre2
- Introduced through: pcre2@10.32-2.el8
Detailed paths
-
Introduced through: centos@centos8 › pcre2@10.32-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream pcre2
package and not the pcre2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.
Remediation
There is no fixed version for Centos:8
pcre2
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-1170
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DIAKPMKJ4OZ6NYRZJO7YWMNQL2BICLYV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X4KDAU76Z7QNSPKZX2JAJ6O7KIEOXWTL/
- https://github.com/vim/vim/commit/1c73b65229c25e3c1fd8824ba958f7cc4d604f9c
- https://huntr.dev/bounties/286e0090-e654-46d2-ac60-29f81799d0a4
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DIAKPMKJ4OZ6NYRZJO7YWMNQL2BICLYV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X4KDAU76Z7QNSPKZX2JAJ6O7KIEOXWTL/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-5344
- http://seclists.org/fulldisclosure/2023/Dec/10
- http://seclists.org/fulldisclosure/2023/Dec/11
- http://seclists.org/fulldisclosure/2023/Dec/9
- https://github.com/vim/vim/commit/3bd7fa12e146c6051490d048a4acbfba974eeb04
- https://huntr.dev/bounties/530cb762-899e-48d7-b50e-dad09eb775bf
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4W665GQBN6S6ZDMYWVF4X7KMFI7AQKJL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XPT7NMYJRLBPIALGSE24UWTY6F774GZW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZOXBUJLJ5VSPN3YXWN7XZA4JDYKNE7GZ/
- https://support.apple.com/kb/HT214036
- https://support.apple.com/kb/HT214037
- https://support.apple.com/kb/HT214038
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-1175
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DIAKPMKJ4OZ6NYRZJO7YWMNQL2BICLYV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X4KDAU76Z7QNSPKZX2JAJ6O7KIEOXWTL/
- https://github.com/vim/vim/commit/c99cbf8f289bdda5d4a77d7ec415850a520330ba
- https://huntr.dev/bounties/7e93fc17-92eb-4ae7-b01a-93bb460b643e
- https://lists.debian.org/debian-lts-announce/2023/06/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DIAKPMKJ4OZ6NYRZJO7YWMNQL2BICLYV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X4KDAU76Z7QNSPKZX2JAJ6O7KIEOXWTL/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a denial of service (application crash), related to screen.c, state.c, and vterm.c.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: nm --without-symbol-version
function.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.
Remediation
There is no fixed version for Centos:8
platform-python
.
References
- https://access.redhat.com/security/cve/CVE-2024-0397
- http://www.openwall.com/lists/oss-security/2024/06/17/2
- https://github.com/python/cpython/commit/01c37f1d0714f5822d34063ca7180b595abf589d
- https://github.com/python/cpython/commit/29c97287d205bf2f410f4895ebce3f43b5160524
- https://github.com/python/cpython/commit/37324b421b72b7bc9934e27aba85d48d4773002e
- https://github.com/python/cpython/commit/542f3272f56f31ed04e74c40635a913fbc12d286
- https://github.com/python/cpython/commit/b228655c227b2ca298a8ffac44d14ce3d22f6faa
- https://github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766ab
- https://github.com/python/cpython/issues/114572
- https://github.com/python/cpython/pull/114573
- https://mail.python.org/archives/list/security-announce@python.org/thread/BMAK5BCGKYWNJOACVUSLUF6SFGBIM4VP/
- https://security.netapp.com/advisory/ntap-20250411-0006/
low severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.
Remediation
There is no fixed version for Centos:8
python3-libs
.
References
- https://access.redhat.com/security/cve/CVE-2024-0397
- http://www.openwall.com/lists/oss-security/2024/06/17/2
- https://github.com/python/cpython/commit/01c37f1d0714f5822d34063ca7180b595abf589d
- https://github.com/python/cpython/commit/29c97287d205bf2f410f4895ebce3f43b5160524
- https://github.com/python/cpython/commit/37324b421b72b7bc9934e27aba85d48d4773002e
- https://github.com/python/cpython/commit/542f3272f56f31ed04e74c40635a913fbc12d286
- https://github.com/python/cpython/commit/b228655c227b2ca298a8ffac44d14ce3d22f6faa
- https://github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766ab
- https://github.com/python/cpython/issues/114572
- https://github.com/python/cpython/pull/114573
- https://mail.python.org/archives/list/security-announce@python.org/thread/BMAK5BCGKYWNJOACVUSLUF6SFGBIM4VP/
- https://security.netapp.com/advisory/ntap-20250411-0006/
low severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module.
When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.
Remediation
There is no fixed version for Centos:8
platform-python
.
References
- https://access.redhat.com/security/cve/CVE-2024-7592
- https://github.com/python/cpython/issues/123067
- https://github.com/python/cpython/pull/123075
- https://mail.python.org/archives/list/security-announce@python.org/thread/HXJAAAALNUNGCQUS2W7WR6GFIZIHFOOK/
- https://github.com/python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621
- https://github.com/python/cpython/commit/44e458357fca05ca0ae2658d62c8c595b048b5ef
- https://github.com/python/cpython/commit/a77ab24427a18bff817025adb03ca920dc3f1a06
- https://github.com/python/cpython/commit/b2f11ca7667e4d57c71c1c88b255115f16042d9a
- https://github.com/python/cpython/commit/d4ac921a4b081f7f996a5d2b101684b67ba0ed7f
- https://github.com/python/cpython/commit/d662e2db2605515a767f88ad48096b8ac623c774
- https://github.com/python/cpython/commit/dcc3eaef98cd94d6cb6cb0f44bd1c903d04f33b1
- https://security.netapp.com/advisory/ntap-20241018-0006/
low severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module.
When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.
Remediation
There is no fixed version for Centos:8
python3-libs
.
References
- https://access.redhat.com/security/cve/CVE-2024-7592
- https://github.com/python/cpython/issues/123067
- https://github.com/python/cpython/pull/123075
- https://mail.python.org/archives/list/security-announce@python.org/thread/HXJAAAALNUNGCQUS2W7WR6GFIZIHFOOK/
- https://github.com/python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621
- https://github.com/python/cpython/commit/44e458357fca05ca0ae2658d62c8c595b048b5ef
- https://github.com/python/cpython/commit/a77ab24427a18bff817025adb03ca920dc3f1a06
- https://github.com/python/cpython/commit/b2f11ca7667e4d57c71c1c88b255115f16042d9a
- https://github.com/python/cpython/commit/d4ac921a4b081f7f996a5d2b101684b67ba0ed7f
- https://github.com/python/cpython/commit/d662e2db2605515a767f88ad48096b8ac623c774
- https://github.com/python/cpython/commit/dcc3eaef98cd94d6cb6cb0f44bd1c903d04f33b1
- https://security.netapp.com/advisory/ntap-20241018-0006/
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in Binutils. The field the_bfd
of asymbol
struct is uninitialized in the bfd_mach_o_get_synthetic_symtab
function, which may lead to an application crash and local denial of service.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://access.redhat.com/security/cve/CVE-2023-25588
- https://bugzilla.redhat.com/show_bug.cgi?id=2167505
- https://security.netapp.com/advisory/ntap-20231103-0003/
- https://sourceware.org/bugzilla/show_bug.cgi?id=29677
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d12f8998d2d086f0a6606589e5aedb7147e6f2f1
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://access.redhat.com/security/cve/CVE-2023-25585
- https://bugzilla.redhat.com/show_bug.cgi?id=2167498
- https://security.netapp.com/advisory/ntap-20231103-0003/
- https://sourceware.org/bugzilla/show_bug.cgi?id=29892
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=65cf035b8dc1df5d8020e0b1449514a3c42933e7
low severity
- Vulnerable module: kexec-tools
- Introduced through: kexec-tools@2.0.20-46.el8
- Fixed in: 0:2.0.20-57.el8
Detailed paths
-
Introduced through: centos@centos8 › kexec-tools@2.0.20-46.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream kexec-tools
package and not the kexec-tools
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability is to confidentiality. This flaw affects kexec-tools shipped by Fedora versions prior to 2.0.21-8 and RHEL versions prior to 2.0.20-47.
Remediation
Upgrade Centos:8
kexec-tools
to version 0:2.0.20-57.el8 or higher.
References
low severity
- Vulnerable module: ncurses-base
- Introduced through: ncurses-base@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-base@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base
package and not the ncurses-base
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.
Remediation
There is no fixed version for Centos:8
ncurses-base
.
References
low severity
- Vulnerable module: ncurses-libs
- Introduced through: ncurses-libs@6.1-7.20180224.el8
Detailed paths
-
Introduced through: centos@centos8 › ncurses-libs@6.1-7.20180224.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-libs
package and not the ncurses-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.
Remediation
There is no fixed version for Centos:8
ncurses-libs
.
References
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation.
Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast network connection with low latency.
There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This can happen with significant probability only for some of the supported elliptic curves. In particular the NIST P-521 curve is affected. To be able to measure this leak, the attacker process must either be located in the same physical computer or must have a very fast network connection with low latency. For that reason the severity of this vulnerability is Low.
The FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.
Remediation
There is no fixed version for Centos:8
openssl-libs
.
References
- https://access.redhat.com/security/cve/CVE-2024-13176
- https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844
- https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467
- https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902
- https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65
- https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f
- https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded
- https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86
- https://openssl-library.org/news/secadv/20250120.txt
- http://www.openwall.com/lists/oss-security/2025/01/20/2
- https://security.netapp.com/advisory/ntap-20250124-0005/
- https://security.netapp.com/advisory/ntap-20250418-0010/
- https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html
low severity
- Vulnerable module: shadow-utils
- Introduced through: shadow-utils@2:4.6-12.el8
- Fixed in: 2:4.6-19.el8
Detailed paths
-
Introduced through: centos@centos8 › shadow-utils@2:4.6-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream shadow-utils
package and not the shadow-utils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.
Remediation
Upgrade Centos:8
shadow-utils
to version 2:4.6-19.el8 or higher.
References
low severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
Remediation
There is no fixed version for Centos:8
sqlite-libs
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a :s
command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive :s
call causes free-ing of memory which may later then be accessed by the initial :s
command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-48706
- http://www.openwall.com/lists/oss-security/2023/11/22/3
- https://github.com/gandalf4a/crash_report/blob/main/vim/vim_huaf
- https://github.com/vim/vim/commit/26c11c56888d01e298cd8044caf860f3c26f57bb
- https://github.com/vim/vim/pull/13552
- https://github.com/vim/vim/security/advisories/GHSA-c8qm-x72m-q53q
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DNMFS3IH74KEMMESOA3EOB6MZ56TWGFF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IVA7K73WHQH4KVFDJQ7ELIUD2WK5ZT5E/
- https://security.netapp.com/advisory/ntap-20240105-0001/
low severity
- Vulnerable module: python3-pip-wheel
- Introduced through: python3-pip-wheel@9.0.3-19.el8
- Fixed in: 0:9.0.3-20.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-pip-wheel@9.0.3-19.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-pip-wheel
package and not the python3-pip-wheel
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
Remediation
Upgrade Centos:8
python3-pip-wheel
to version 0:9.0.3-20.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-3572
- https://access.redhat.com/errata/RHSA-2021:4455
- https://bugzilla.redhat.com/show_bug.cgi?id=1962856
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an improved version of the unix vi text editor. When flushing the typeahead buffer, Vim moves the current position in the typeahead buffer but does not check whether there is enough space left in the buffer to handle the next characters. So this may lead to the tb_off position within the typebuf variable to point outside of the valid buffer size, which can then later lead to a heap-buffer overflow in e.g. ins_typebuf(). Therefore, when flushing the typeahead buffer, check if there is enough space left before advancing the off position. If not, fall back to flush current typebuf contents. It's not quite clear yet, what can lead to this situation. It seems to happen when error messages occur (which will cause Vim to flush the typeahead buffer) in comnination with several long mappgins and so it may eventually move the off position out of a valid buffer size. Impact is low since it is not easily reproducible and requires to have several mappings active and run into some error condition. But when this happens, this will cause a crash. The issue has been fixed as of Vim patch v9.1.0697. Users are advised to upgrade. There are no known workarounds for this issue.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that the cursor position always points inside a line and does not become invalid by pointing beyond the end of a line. Back then we assumed this loop is unnecessary. However, this change made it possible that the cursor position stays invalid and points beyond the end of a line, which would eventually cause a heap-buffer-overflow when trying to access the line pointer at the specified cursor position. It's not quite clear yet, what can lead to this situation that the cursor points to an invalid position. That's why patch v9.1.0707 does not include a test case. The only observed impact has been a program crash. This issue has been addressed in with the patch v9.1.0707. All users are advised to upgrade.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: file-libs
- Introduced through: file-libs@5.33-16.el8_3.1
Detailed paths
-
Introduced through: centos@centos8 › file-libs@5.33-16.el8_3.1
NVD Description
Note: Versions mentioned in the description apply only to the upstream file-libs
package and not the file-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
Remediation
There is no fixed version for Centos:8
file-libs
.
References
- https://support.apple.com/kb/HT209599
- https://support.apple.com/kb/HT209600
- https://support.apple.com/kb/HT209601
- https://support.apple.com/kb/HT209602
- https://access.redhat.com/security/cve/CVE-2019-8906
- https://bugs.astron.com/view.php?id=64
- https://github.com/file/file/commit/2858eaf99f6cc5aae129bcbf1e24ad160240185f
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html
- https://usn.ubuntu.com/3911-1/
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there is a stack consumption problem caused by recursive stack frames: cplus_demangle_type, d_bare_function_type, d_function_type.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/105693
- https://access.redhat.com/security/cve/CVE-2018-18484
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87636
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://usn.ubuntu.com/4326-1/
- https://usn.ubuntu.com/4336-1/
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions next_is_type_qual() and cplus_demangle_type() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions d_name(), d_encoding(), and d_local_name() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc.c, _warc_read() that can result in DoS - quasi-infinite run time and disk usage from tiny file. This attack appear to be exploitable via the victim must open a specially crafted WARC file.
Remediation
There is no fixed version for Centos:8
libarchive
.
References
- http://www.securityfocus.com/bid/106324
- https://access.redhat.com/security/cve/CVE-2018-1000880
- https://www.debian.org/security/2018/dsa-4360
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/
- https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909
- https://github.com/libarchive/libarchive/pull/1105
- https://github.com/libarchive/libarchive/pull/1105/commits/9c84b7426660c09c18cc349f6d70b5f8168b5680
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html
- https://usn.ubuntu.com/3859-1/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/
low severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c, archive_acl_from_text_l() that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted archive file.
Remediation
There is no fixed version for Centos:8
libarchive
.
References
- http://www.securityfocus.com/bid/106324
- https://access.redhat.com/security/cve/CVE-2018-1000879
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/
- https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909
- https://github.com/libarchive/libarchive/pull/1105
- https://github.com/libarchive/libarchive/pull/1105/commits/15bf44fd2c1ad0e3fd87048b3fcc90c4dcff1175
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset for overlong lines and smooth scrolling is enabled and the cpo-settings include the 'n' flag. This may happen when a window border is present and when the wrapped line continues on the next physical line directly in the window border because the 'cpo' setting includes the 'n' flag. Only users with non-default settings are affected and the exception should only result in a crash. This issue has been addressed in commit cb0b99f0
which has been included in release version 9.0.2107. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-48232
- http://www.openwall.com/lists/oss-security/2023/11/16/1
- https://github.com/vim/vim/commit/cb0b99f0672d8446585d26e998343dceca17d1ce
- https://github.com/vim/vim/security/advisories/GHSA-f6cx-x634-hqpw
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4UJAK2W5S7G75ETDAEM3BDUCVSXCEGRD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M3VQF7CL3V6FGSEW37WNDFBRRILR65AK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VNRNYLWXZOGTYWE5HMFNQ5FVE3HBUHF6/
- https://security.netapp.com/advisory/ntap-20231227-0006/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source command line text editor. When using the z= command, the user may overflow the count with values larger
than MAX_INT. Impact is low, user interaction is required and a crash may not even happen in all situations. This vulnerability has been addressed in commit 73b2d379
which has been included in release version 9.0.2111. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-48236
- http://www.openwall.com/lists/oss-security/2023/11/16/1
- https://github.com/vim/vim/commit/73b2d3790cad5694fc0ed0db2926e4220c48d968
- https://github.com/vim/vim/security/advisories/GHSA-pr4c-932v-8hx5
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4UJAK2W5S7G75ETDAEM3BDUCVSXCEGRD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M3VQF7CL3V6FGSEW37WNDFBRRILR65AK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VNRNYLWXZOGTYWE5HMFNQ5FVE3HBUHF6/
- https://security.netapp.com/advisory/ntap-20231227-0002/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source command line text editor. If the count after the :s command is larger than what fits into a (signed) long variable, abort with e_value_too_large. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has been addressed in commit ac6378773
which has been included in release version 9.0.2108. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-48233
- http://www.openwall.com/lists/oss-security/2023/11/16/1
- https://github.com/vim/vim/commit/ac63787734fda2e294e477af52b3bd601517fa78
- https://github.com/vim/vim/security/advisories/GHSA-3xx4-hcq6-r2vj
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4UJAK2W5S7G75ETDAEM3BDUCVSXCEGRD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M3VQF7CL3V6FGSEW37WNDFBRRILR65AK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VNRNYLWXZOGTYWE5HMFNQ5FVE3HBUHF6/
- https://security.netapp.com/advisory/ntap-20231227-0003/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for large counts given. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has been addressed in commit 58f9befca1
which has been included in release version 9.0.2109. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-48234
- http://www.openwall.com/lists/oss-security/2023/11/16/1
- https://github.com/vim/vim/commit/58f9befca1fa172068effad7f2ea5a9d6a7b0cca
- https://github.com/vim/vim/security/advisories/GHSA-59gw-c949-6phq
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4UJAK2W5S7G75ETDAEM3BDUCVSXCEGRD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M3VQF7CL3V6FGSEW37WNDFBRRILR65AK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VNRNYLWXZOGTYWE5HMFNQ5FVE3HBUHF6/
- https://security.netapp.com/advisory/ntap-20231227-0004/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source command line text editor. When parsing relative ex addresses one may unintentionally cause an
overflow. Ironically this happens in the existing overflow check, because the line number becomes negative and LONG_MAX - lnum will cause the overflow. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has been addressed in commit 060623e
which has been included in release version 9.0.2110. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-48235
- http://www.openwall.com/lists/oss-security/2023/11/16/1
- https://github.com/vim/vim/commit/060623e4a3bc72b011e7cd92bedb3bfb64e06200
- https://github.com/vim/vim/security/advisories/GHSA-6g74-hr6q-pr8g
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4UJAK2W5S7G75ETDAEM3BDUCVSXCEGRD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M3VQF7CL3V6FGSEW37WNDFBRRILR65AK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VNRNYLWXZOGTYWE5HMFNQ5FVE3HBUHF6/
- https://security.netapp.com/advisory/ntap-20231227-0007/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and using a very large value, it may be possible to overflow the size of integer. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has been addressed in commit 6bf131888
which has been included in version 9.0.2112. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-48237
- http://www.openwall.com/lists/oss-security/2023/11/16/1
- https://github.com/vim/vim/commit/6bf131888a3d1de62bbfa8a7ea03c0ddccfd496e
- https://github.com/vim/vim/security/advisories/GHSA-f2m2-v387-gv87
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4UJAK2W5S7G75ETDAEM3BDUCVSXCEGRD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M3VQF7CL3V6FGSEW37WNDFBRRILR65AK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VNRNYLWXZOGTYWE5HMFNQ5FVE3HBUHF6/
- https://security.netapp.com/advisory/ntap-20231227-0005/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source command line text editor. When closing a window, vim may try to access already freed window structure. Exploitation beyond crashing the application has not been shown to be viable. This issue has been addressed in commit 25aabc2b
which has been included in release version 9.0.2106. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-48231
- http://www.openwall.com/lists/oss-security/2023/11/16/1
- https://github.com/vim/vim/commit/25aabc2b8ee1e19ced6f4da9d866cf9378fc4c5a
- https://github.com/vim/vim/security/advisories/GHSA-8g46-v9ff-c765
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4UJAK2W5S7G75ETDAEM3BDUCVSXCEGRD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M3VQF7CL3V6FGSEW37WNDFBRRILR65AK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VNRNYLWXZOGTYWE5HMFNQ5FVE3HBUHF6/
- https://security.netapp.com/advisory/ntap-20231227-0008/
low severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
Remediation
There is no fixed version for Centos:8
platform-python
.
References
- https://security.netapp.com/advisory/ntap-20200221-0003/
- https://access.redhat.com/security/cve/CVE-2019-9674
- https://bugs.python.org/issue36260
- https://bugs.python.org/issue36462
- https://github.com/python/cpython/blob/master/Lib/zipfile.py
- https://python-security.readthedocs.io/security.html#archives-and-zip-bomb
- https://www.python.org/news/security/
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html
- https://usn.ubuntu.com/4428-1/
low severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
Remediation
There is no fixed version for Centos:8
python3-libs
.
References
- https://security.netapp.com/advisory/ntap-20200221-0003/
- https://access.redhat.com/security/cve/CVE-2019-9674
- https://bugs.python.org/issue36260
- https://bugs.python.org/issue36462
- https://github.com/python/cpython/blob/master/Lib/zipfile.py
- https://python-security.readthedocs.io/security.html#archives-and-zip-bomb
- https://www.python.org/news/security/
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html
- https://usn.ubuntu.com/4428-1/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow, because Vim does not properly end visual mode and therefore may try to access beyond the end of a line in a buffer. In Patch 9.1.1003 Vim will correctly reset the visual mode before opening other windows and buffers and therefore fix this bug. In addition it does verify that it won't try to access a position if the position is greater than the corresponding buffer line. Impact is medium since the user must have switched on visual mode when executing the :all ex command. The Vim project would like to thank github user gandalf4a for reporting this issue. The issue has been fixed as of Vim patch v9.1.1003
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2025-22134
- https://github.com/vim/vim/commit/c9a1e257f1630a0866447e53a564f7ff96a80ead
- https://github.com/vim/vim/security/advisories/GHSA-5rgf-26wj-48v8
- http://www.openwall.com/lists/oss-security/2025/01/11/1
- https://security.netapp.com/advisory/ntap-20250314-0004/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by feeding some binary characters to Vim. The function that handles the scrolling however may be triggering a redraw, which will access the ScreenLines pointer, even so this variable hasn't been allocated (since there is no screen). This vulnerability is fixed in 9.1.1043.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2025-24014
- https://github.com/vim/vim/commit/9d1bed5eccdbb46a26b8a484f5e9163c40e63919
- https://github.com/vim/vim/security/advisories/GHSA-j3g9-wg22-v955
- http://www.openwall.com/lists/oss-security/2025/01/20/4
- http://www.openwall.com/lists/oss-security/2025/01/21/1
- https://security.netapp.com/advisory/ntap-20250314-0005/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However, when setting the buffer name to Unnamed, Vim will falsely free a pointer twice, leading to a double-free and possibly later to a heap-use-after-free, which can lead to a crash. The issue has been fixed as of Vim patch v9.1.0648.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the :redir
ex command to register, variables and files. It also allows to show the contents of registers using the :registers
or :display
ex command. When redirecting the output of :display
to a register, Vim will free the register content before storing the new content in the register. Now when redirecting the :display
command to a register that is being displayed, Vim will free the content while shortly afterwards trying to access it, which leads to a use-after-free. Vim pre 9.1.1115 checks in the ex_display() function, that it does not try to redirect to a register while displaying this register at the same time. However this check is not complete, and so Vim does not check the +
and *
registers (which typically donate the X11/clipboard registers, and when a clipboard connection is not possible will fall back to use register 0 instead. In Patch 9.1.1115 Vim will therefore skip outputting to register zero when trying to redirect to the clipboard registers *
or +
. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: elfutils-default-yama-scope
- Introduced through: elfutils-default-yama-scope@0.182-3.el8
Detailed paths
-
Introduced through: centos@centos8 › elfutils-default-yama-scope@0.182-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream elfutils-default-yama-scope
package and not the elfutils-default-yama-scope
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
Remediation
There is no fixed version for Centos:8
elfutils-default-yama-scope
.
References
low severity
- Vulnerable module: elfutils-libelf
- Introduced through: elfutils-libelf@0.182-3.el8
Detailed paths
-
Introduced through: centos@centos8 › elfutils-libelf@0.182-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream elfutils-libelf
package and not the elfutils-libelf
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
Remediation
There is no fixed version for Centos:8
elfutils-libelf
.
References
low severity
- Vulnerable module: elfutils-libs
- Introduced through: elfutils-libs@0.182-3.el8
Detailed paths
-
Introduced through: centos@centos8 › elfutils-libs@0.182-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream elfutils-libs
package and not the elfutils-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
Remediation
There is no fixed version for Centos:8
elfutils-libs
.
References
low severity
- Vulnerable module: libtasn1
- Introduced through: libtasn1@4.13-3.el8
Detailed paths
-
Introduced through: centos@centos8 › libtasn1@4.13-3.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libtasn1
package and not the libtasn1
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.
Remediation
There is no fixed version for Centos:8
libtasn1
.
References
- http://www.securityfocus.com/bid/105151
- https://gitlab.com/gnutls/libtasn1/issues/4
- https://access.redhat.com/security/cve/CVE-2018-1000654
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00018.html
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function ga_grow_inner
in in the file src/alloc.c
at line 748, which is freed in the file src/ex_docmd.c
in the function do_cmdline
at line 1010 and then used again in src/cmdhist.c
at line 759. When using the :history
command, it's possible that the provided argument overflows the accepted value. Causing an Integer Overflow and potentially later an use-after-free. This vulnerability has been patched in version 9.0.2068.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-46246
- https://github.com/vim/vim/commit/9198c1f2b1ddecde22af918541e0de2a32f0f45a
- https://github.com/vim/vim/security/advisories/GHSA-q22m-h7m2-9mgm
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DNMFS3IH74KEMMESOA3EOB6MZ56TWGFF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IVA7K73WHQH4KVFDJQ7ELIUD2WK5ZT5E/
- https://security.netapp.com/advisory/ntap-20231208-0006/
low severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.
Remediation
There is no fixed version for Centos:8
libarchive
.
References
low severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive.
Remediation
There is no fixed version for Centos:8
libarchive
.
References
low severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
Remediation
There is no fixed version for Centos:8
libarchive
.
References
low severity
- Vulnerable module: procps-ng
- Introduced through: procps-ng@3.3.15-6.el8
Detailed paths
-
Introduced through: centos@centos8 › procps-ng@3.3.15-6.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream procps-ng
package and not the procps-ng
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng's utilities by exploiting a race condition in reading /proc/PID entries. This vulnerability affects procps and procps-ng up to version 3.3.15, newer versions might be affected also.
Remediation
There is no fixed version for Centos:8
procps-ng
.
References
- http://www.securityfocus.com/bid/104214
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1121
- https://access.redhat.com/security/cve/CVE-2018-1121
- https://www.exploit-db.com/exploits/44806/
- https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt
- http://seclists.org/oss-sec/2018/q2/122
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
low severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde () character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /2/foo while accessing a server with a specific user.
Remediation
There is no fixed version for Centos:8
curl
.
References
- https://access.redhat.com/security/cve/CVE-2023-27534
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
- https://hackerone.com/reports/1892351
- https://lists.debian.org/debian-lts-announce/2024/03/msg00016.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
- https://security.gentoo.org/glsa/202310-12
- https://security.netapp.com/advisory/ntap-20230420-0012/
low severity
new
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.
Remediation
There is no fixed version for Centos:8
glib2
.
References
low severity
- Vulnerable module: glib2
- Introduced through: glib2@2.56.4-9.el8
Detailed paths
-
Introduced through: centos@centos8 › glib2@2.56.4-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream glib2
package and not the glib2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.
Remediation
There is no fixed version for Centos:8
glib2
.
References
low severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde () character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /2/foo while accessing a server with a specific user.
Remediation
There is no fixed version for Centos:8
libcurl-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-27534
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
- https://hackerone.com/reports/1892351
- https://lists.debian.org/debian-lts-announce/2024/03/msg00016.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
- https://security.gentoo.org/glsa/202310-12
- https://security.netapp.com/advisory/ntap-20230420-0012/
low severity
- Vulnerable module: openssl-libs
- Introduced through: openssl-libs@1:1.1.1g-15.el8_3
Detailed paths
-
Introduced through: centos@centos8 › openssl-libs@1:1.1.1g-15.el8_3
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl-libs
package and not the openssl-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions
Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service
This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation.
This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients.
The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL 1.0.2 is also not affected by this issue.
Remediation
There is no fixed version for Centos:8
openssl-libs
.
References
- https://access.redhat.com/security/cve/CVE-2024-2511
- http://www.openwall.com/lists/oss-security/2024/04/08/5
- https://security.netapp.com/advisory/ntap-20240503-0013/
- https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce
- https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d
- https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08
- https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640
- https://www.openssl.org/news/secadv/20240408.txt
low severity
- Vulnerable module: shadow-utils
- Introduced through: shadow-utils@2:4.6-12.el8
Detailed paths
-
Introduced through: centos@centos8 › shadow-utils@2:4.6-12.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream shadow-utils
package and not the shadow-utils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.
Remediation
There is no fixed version for Centos:8
shadow-utils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/109354
- https://security.netapp.com/advisory/ntap-20190822-0002/
- https://access.redhat.com/security/cve/CVE-2019-14250
- https://security.gentoo.org/glsa/202007-39
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=90924
- https://gcc.gnu.org/ml/gcc-patches/2019-07/msg01003.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00056.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00057.html
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00058.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html
- https://usn.ubuntu.com/4326-1/
- https://usn.ubuntu.com/4336-1/
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/106144
- https://security.netapp.com/advisory/ntap-20190221-0004/
- https://access.redhat.com/security/cve/CVE-2018-19932
- https://security.gentoo.org/glsa/201908-01
- https://sourceware.org/bugzilla/show_bug.cgi?id=23932
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=beab453223769279cc1cef68a1622ab8978641f7
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://usn.ubuntu.com/4336-1/
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=beab453223769279cc1cef68a1622ab8978641f7
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://access.redhat.com/security/cve/CVE-2025-3198
- https://sourceware.org/bugzilla/show_bug.cgi?id=32716#c0
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d
- https://vuldb.com/?ctiid.303151
- https://vuldb.com/?id.303151
- https://vuldb.com/?submit.545773
- https://www.gnu.org/
- https://sourceware.org/bugzilla/show_bug.cgi?id=32716
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/104538
- https://access.redhat.com/security/cve/CVE-2018-12697
- https://security.gentoo.org/glsa/201908-01
- https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763102
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85454
- https://sourceware.org/bugzilla/show_bug.cgi?id=23057
- https://access.redhat.com/errata/RHSA-2019:2075
- https://usn.ubuntu.com/4326-1/
- https://usn.ubuntu.com/4336-1/
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in elf_link_input_bfd when used for finding STT_TLS symbols without any TLS section. A specially crafted ELF allows remote attackers to cause a denial of service, as demonstrated by ld.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/105754
- https://security.netapp.com/advisory/ntap-20190307-0003/
- https://access.redhat.com/security/cve/CVE-2018-18607
- https://sourceware.org/bugzilla/show_bug.cgi?id=23805
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=102def4da826b3d9e169741421e5e67e8731909a
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://usn.ubuntu.com/4336-1/
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=102def4da826b3d9e169741421e5e67e8731909a
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in _bfd_add_merge_section when attempting to merge sections with large alignments. A specially crafted ELF allows remote attackers to cause a denial of service, as demonstrated by ld.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/105754
- https://security.netapp.com/advisory/ntap-20190307-0003/
- https://access.redhat.com/security/cve/CVE-2018-18606
- https://sourceware.org/bugzilla/show_bug.cgi?id=23806
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=45a0eaf77022963d639d6d19871dbab7b79703fc
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://usn.ubuntu.com/4336-1/
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=45a0eaf77022963d639d6d19871dbab7b79703fc
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with no program headers. A specially crafted ELF file allows remote attackers to cause a denial of service, as demonstrated by ld.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/106440
- https://support.f5.com/csp/article/K38336243
- https://access.redhat.com/security/cve/CVE-2018-20651
- https://security.gentoo.org/glsa/201908-01
- https://sourceware.org/bugzilla/show_bug.cgi?id=24041
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=54025d5812ff100f5f0654eb7e1ffd50f2e37f5f
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://usn.ubuntu.com/4336-1/
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=54025d5812ff100f5f0654eb7e1ffd50f2e37f5f
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory address dereference was discovered in read_reloc in reloc.c. The vulnerability causes a segmentation fault and application crash, which leads to denial of service, as demonstrated by objdump, because of missing _bfd_clear_contents bounds checking.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/105692
- https://access.redhat.com/security/cve/CVE-2018-18309
- https://sourceware.org/bugzilla/show_bug.cgi?id=23770
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=0930cb3021b8078b34cf216e79eb8608d017864f
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://usn.ubuntu.com/4336-1/
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=0930cb3021b8078b34cf216e79eb8608d017864f
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, because _bfd_add_merge_section mishandles section merges when size is not a multiple of entsize. A specially crafted ELF allows remote attackers to cause a denial of service, as demonstrated by ld.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/105754
- https://security.netapp.com/advisory/ntap-20190307-0003/
- https://access.redhat.com/security/cve/CVE-2018-18605
- https://sourceware.org/bugzilla/show_bug.cgi?id=23804
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ab419ddbb2cdd17ca83618990f2cacf904ce1d61
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://usn.ubuntu.com/4336-1/
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=ab419ddbb2cdd17ca83618990f2cacf904ce1d61
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The elf_parse_notes function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (out-of-bounds read and segmentation violation) via a note with a large alignment.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/103103
- https://sourceware.org/bugzilla/show_bug.cgi?id=22788
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=commit;h=ef135d4314fd4c2d7da66b9d7b59af4a85b0f7e6
- https://access.redhat.com/security/cve/CVE-2018-6872
- https://security.gentoo.org/glsa/201811-17
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Ba=commit%3Bh=ef135d4314fd4c2d7da66b9d7b59af4a85b0f7e6
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/104539
- https://access.redhat.com/security/cve/CVE-2018-12698
- https://security.gentoo.org/glsa/201908-01
- https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763102
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85454
- https://sourceware.org/bugzilla/show_bug.cgi?id=23057
- https://usn.ubuntu.com/4326-1/
- https://usn.ubuntu.com/4336-1/
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumption), as demonstrated by nm.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/106142
- https://security.netapp.com/advisory/ntap-20190221-0004/
- https://support.f5.com/csp/article/K62602089
- https://access.redhat.com/security/cve/CVE-2018-20002
- https://security.gentoo.org/glsa/201908-01
- https://sourceware.org/bugzilla/show_bug.cgi?id=23952
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=c2f5dc30afa34696f2da0081c4ac50b958ecb0e9
- https://usn.ubuntu.com/4336-1/
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=c2f5dc30afa34696f2da0081c4ac50b958ecb0e9
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_arm_hp_template, demangle_class_name, demangle_fund_type, do_type, do_arg, demangle_args, and demangle_nested_args. This can occur during execution of nm-new.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://access.redhat.com/security/cve/CVE-2018-12641
- https://security.gentoo.org/glsa/201908-01
- https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763099
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85452
- https://sourceware.org/bugzilla/show_bug.cgi?id=23058
- https://access.redhat.com/errata/RHSA-2019:2075
- https://usn.ubuntu.com/4326-1/
- https://usn.ubuntu.com/4336-1/
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a stack consumption issue in d_count_templates_scopes in cp-demangle.c after many recursive calls.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- http://www.securityfocus.com/bid/107147
- https://security.netapp.com/advisory/ntap-20190314-0003/
- https://support.f5.com/csp/article/K02884135
- https://access.redhat.com/security/cve/CVE-2019-9071
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=89394
- https://sourceware.org/bugzilla/show_bug.cgi?id=24227
- https://usn.ubuntu.com/4326-1/
- https://usn.ubuntu.com/4336-1/
- https://security.gentoo.org/glsa/202107-24
low severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Remediation
There is no fixed version for Centos:8
libarchive
.
References
low severity
- Vulnerable module: libgcc
- Introduced through: libgcc@8.4.1-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libgcc@8.4.1-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libgcc
package and not the libgcc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.
Remediation
There is no fixed version for Centos:8
libgcc
.
References
- http://www.securityfocus.com/bid/109354
- https://security.netapp.com/advisory/ntap-20190822-0002/
- https://access.redhat.com/security/cve/CVE-2019-14250
- https://security.gentoo.org/glsa/202007-39
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=90924
- https://gcc.gnu.org/ml/gcc-patches/2019-07/msg01003.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00056.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00057.html
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00058.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html
- https://usn.ubuntu.com/4326-1/
- https://usn.ubuntu.com/4336-1/
low severity
- Vulnerable module: libgcc
- Introduced through: libgcc@8.4.1-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libgcc@8.4.1-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libgcc
package and not the libgcc
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.
Remediation
There is no fixed version for Centos:8
libgcc
.
References
low severity
- Vulnerable module: libsolv
- Introduced through: libsolv@0.7.16-2.el8
- Fixed in: 0:0.7.19-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libsolv@0.7.16-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libsolv
package and not the libsolv
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
Remediation
Upgrade Centos:8
libsolv
to version 0:0.7.19-1.el8 or higher.
References
low severity
- Vulnerable module: libstdc++
- Introduced through: libstdc++@8.4.1-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libstdc++@8.4.1-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libstdc++
package and not the libstdc++
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.
Remediation
There is no fixed version for Centos:8
libstdc++
.
References
- http://www.securityfocus.com/bid/109354
- https://security.netapp.com/advisory/ntap-20190822-0002/
- https://access.redhat.com/security/cve/CVE-2019-14250
- https://security.gentoo.org/glsa/202007-39
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=90924
- https://gcc.gnu.org/ml/gcc-patches/2019-07/msg01003.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00056.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00057.html
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00058.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html
- https://usn.ubuntu.com/4326-1/
- https://usn.ubuntu.com/4336-1/
low severity
- Vulnerable module: libstdc++
- Introduced through: libstdc++@8.4.1-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libstdc++@8.4.1-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libstdc++
package and not the libstdc++
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.
Remediation
There is no fixed version for Centos:8
libstdc++
.
References
low severity
- Vulnerable module: procps-ng
- Introduced through: procps-ng@3.3.15-6.el8
- Fixed in: 0:3.3.15-14.el8
Detailed paths
-
Introduced through: centos@centos8 › procps-ng@3.3.15-6.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream procps-ng
package and not the procps-ng
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.
Remediation
Upgrade Centos:8
procps-ng
to version 0:3.3.15-14.el8 or higher.
References
low severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.
Remediation
There is no fixed version for Centos:8
sqlite-libs
.
References
- http://www.securityfocus.com/bid/107562
- https://security.netapp.com/advisory/ntap-20190416-0005/
- https://access.redhat.com/security/cve/CVE-2019-9936
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/
- https://security.gentoo.org/glsa/201908-09
- https://sqlite.org/src/info/b3fa58dd7403dbd4
- https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114382.html
- https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114394.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html
- https://usn.ubuntu.com/4019-1/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114382.html
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114394.html
low severity
- Vulnerable module: sqlite-libs
- Introduced through: sqlite-libs@3.26.0-13.el8
Detailed paths
-
Introduced through: centos@centos8 › sqlite-libs@3.26.0-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream sqlite-libs
package and not the sqlite-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.
Remediation
There is no fixed version for Centos:8
sqlite-libs
.
References
- http://www.securityfocus.com/bid/107562
- https://security.netapp.com/advisory/ntap-20190416-0005/
- https://access.redhat.com/security/cve/CVE-2019-9937
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/
- https://security.gentoo.org/glsa/201908-09
- https://sqlite.org/src/info/45c73deb440496e8
- https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114383.html
- https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114393.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html
- https://usn.ubuntu.com/4019-1/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114383.html
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114393.html
low severity
- Vulnerable module: tar
- Introduced through: tar@2:1.30-5.el8
Detailed paths
-
Introduced through: centos@centos8 › tar@2:1.30-5.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream tar
package and not the tar
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
Remediation
There is no fixed version for Centos:8
tar
.
References
low severity
- Vulnerable module: tar
- Introduced through: tar@2:1.30-5.el8
Detailed paths
-
Introduced through: centos@centos8 › tar@2:1.30-5.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream tar
package and not the tar
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
Remediation
There is no fixed version for Centos:8
tar
.
References
- https://access.redhat.com/security/cve/CVE-2019-9923
- http://git.savannah.gnu.org/cgit/tar.git/commit/?id=cb07844454d8cc9fb21f53ace75975f91185a120
- http://savannah.gnu.org/bugs/?55369
- https://bugs.launchpad.net/ubuntu/+source/tar/+bug/1810241
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00077.html
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
low severity
- Vulnerable module: tar
- Introduced through: tar@2:1.30-5.el8
Detailed paths
-
Introduced through: centos@centos8 › tar@2:1.30-5.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream tar
package and not the tar
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
Remediation
There is no fixed version for Centos:8
tar
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2208
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://github.com/vim/vim/commit/cd38bb4d83c942c4bad596835c6766cbf32e5195
- https://huntr.dev/bounties/7bfe3d5b-568f-4c34-908f-a39909638cc1
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2183
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://github.com/vim/vim/commit/8eba2bd291b347e3008aa9e565652d51ad638cfa
- https://huntr.dev/bounties/d74ca3f9-380d-4c0a-b61c-11113cc98975
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFD2A4YLBR7OIRHTL7CK6YNMEIQ264CN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U743FMJGFQ35GBPCQ6OWMVZEJPDFVEWM/
- https://security.gentoo.org/glsa/202208-32
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Use After Free in GitHub repository vim/vim prior to v9.0.2010.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2023-5535
- https://github.com/vim/vim/commit/41e6f7d6ba67b61d911f9b1d76325cd79224753d
- https://huntr.dev/bounties/2c2d85a7-1171-4014-bf7f-a2451745861f
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VDDWD25AZIHBAA44HQT75OWLQ5UMDKU3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VGTVLUV7UCXXCZAIQIUCLG6JXAVYT3HE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XPT7NMYJRLBPIALGSE24UWTY6F774GZW/
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers Buf*
autocommands. If in such an autocommand the buffer that was just opened is closed (including the window where it is shown), this causes the window structure to be freed which contains a reference to the argument list that we are actually modifying. Once the autocommands are completed, the references to the window and argument list are no longer valid and as such cause an use-after-free. Impact is low since the user must either intentionally add some unusual autocommands that wipe a buffer during creation (either manually or by sourcing a malicious plugin), but it will crash Vim. The issue has been fixed as of Vim patch v9.1.0678.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2024-43374
- https://github.com/vim/vim/commit/0a6e57b09bc8c76691b367a5babfb79b31b770e8
- https://github.com/vim/vim/security/advisories/GHSA-2w8m-443v-cgvw
- http://www.openwall.com/lists/oss-security/2024/08/15/6
- https://security.netapp.com/advisory/ntap-20240920-0004/
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.
Remediation
There is no fixed version for Centos:8
binutils
.
References
- https://access.redhat.com/security/cve/CVE-2025-1153
- https://sourceware.org/bugzilla/show_bug.cgi?id=32603
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150
- https://vuldb.com/?ctiid.295057
- https://vuldb.com/?id.295057
- https://vuldb.com/?submit.489991
- https://www.gnu.org/
- https://security.netapp.com/advisory/ntap-20250404-0005/
low severity
- Vulnerable module: curl
- Introduced through: curl@7.61.1-18.el8
- Fixed in: 0:7.61.1-30.el8
Detailed paths
-
Introduced through: centos@centos8 › curl@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
Remediation
Upgrade Centos:8
curl
to version 0:7.61.1-30.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-35252
- http://seclists.org/fulldisclosure/2023/Jan/20
- http://seclists.org/fulldisclosure/2023/Jan/21
- https://hackerone.com/reports/1613943
- https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220930-0005/
- https://support.apple.com/kb/HT213603
- https://support.apple.com/kb/HT213604
low severity
- Vulnerable module: libcurl-minimal
- Introduced through: libcurl-minimal@7.61.1-18.el8
- Fixed in: 0:7.61.1-30.el8
Detailed paths
-
Introduced through: centos@centos8 › libcurl-minimal@7.61.1-18.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libcurl-minimal
package and not the libcurl-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
Remediation
Upgrade Centos:8
libcurl-minimal
to version 0:7.61.1-30.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2022-35252
- http://seclists.org/fulldisclosure/2023/Jan/20
- http://seclists.org/fulldisclosure/2023/Jan/21
- https://hackerone.com/reports/1613943
- https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html
- https://security.gentoo.org/glsa/202212-01
- https://security.netapp.com/advisory/ntap-20220930-0005/
- https://support.apple.com/kb/HT213603
- https://support.apple.com/kb/HT213604
low severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
Remediation
There is no fixed version for Centos:8
libxml2
.
References
low severity
- Vulnerable module: platform-python
- Introduced through: platform-python@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › platform-python@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream platform-python
package and not the platform-python
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers.
Remediation
There is no fixed version for Centos:8
platform-python
.
References
- https://access.redhat.com/security/cve/CVE-2025-1795
- https://github.com/python/cpython/issues/100884
- https://github.com/python/cpython/pull/100885
- https://github.com/python/cpython/pull/119099
- https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48
- https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593
- https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74
- https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/
low severity
- Vulnerable module: python3-libs
- Introduced through: python3-libs@3.6.8-37.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-libs@3.6.8-37.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-libs
package and not the python3-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers.
Remediation
There is no fixed version for Centos:8
python3-libs
.
References
- https://access.redhat.com/security/cve/CVE-2025-1795
- https://github.com/python/cpython/issues/100884
- https://github.com/python/cpython/pull/100885
- https://github.com/python/cpython/pull/119099
- https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48
- https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593
- https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74
- https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/
low severity
- Vulnerable module: python3-rpm
- Introduced through: python3-rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-19.el8
Detailed paths
-
Introduced through: centos@centos8 › python3-rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-rpm
package and not the python3-rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
Remediation
Upgrade Centos:8
python3-rpm
to version 0:4.14.3-19.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-20266
- https://bugzilla.redhat.com/show_bug.cgi?id=1927741
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://access.redhat.com/errata/RHSA-2021:4489
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://security.gentoo.org/glsa/202107-43
low severity
- Vulnerable module: rpm
- Introduced through: rpm@4.14.3-13.el8
- Fixed in: 0:4.14.3-19.el8
Detailed paths
-
Introduced through: centos@centos8 › rpm@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm
package and not the rpm
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
Remediation
Upgrade Centos:8
rpm
to version 0:4.14.3-19.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-20266
- https://bugzilla.redhat.com/show_bug.cgi?id=1927741
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://access.redhat.com/errata/RHSA-2021:4489
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://security.gentoo.org/glsa/202107-43
low severity
- Vulnerable module: rpm-build-libs
- Introduced through: rpm-build-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-19.el8
Detailed paths
-
Introduced through: centos@centos8 › rpm-build-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-build-libs
package and not the rpm-build-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
Remediation
Upgrade Centos:8
rpm-build-libs
to version 0:4.14.3-19.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-20266
- https://bugzilla.redhat.com/show_bug.cgi?id=1927741
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://access.redhat.com/errata/RHSA-2021:4489
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://security.gentoo.org/glsa/202107-43
low severity
- Vulnerable module: rpm-libs
- Introduced through: rpm-libs@4.14.3-13.el8
- Fixed in: 0:4.14.3-19.el8
Detailed paths
-
Introduced through: centos@centos8 › rpm-libs@4.14.3-13.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream rpm-libs
package and not the rpm-libs
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
Remediation
Upgrade Centos:8
rpm-libs
to version 0:4.14.3-19.el8 or higher.
References
- https://access.redhat.com/security/cve/CVE-2021-20266
- https://bugzilla.redhat.com/show_bug.cgi?id=1927741
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://access.redhat.com/errata/RHSA-2021:4489
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
- https://security.gentoo.org/glsa/202107-43
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
vim is vulnerable to Use After Free
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://huntr.dev/bounties/e402cb2c-8ec4-4828-a692-c95f8e0de6d4
- https://access.redhat.com/security/cve/CVE-2021-3974
- https://github.com/vim/vim/commit/64066b9acd9f8cffdf4840f797748f938a13f2d6
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNXY7T5OORA7UJIMGSJBGHFMU6UZWS6P/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IH2LS2DXBTYOCWGAKFMBF3HTWWXPBEFL/
- http://www.openwall.com/lists/oss-security/2022/01/15/1
- https://lists.debian.org/debian-lts-announce/2022/03/msg00018.html
- https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNXY7T5OORA7UJIMGSJBGHFMU6UZWS6P/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IH2LS2DXBTYOCWGAKFMBF3HTWWXPBEFL/
- https://security.gentoo.org/glsa/202208-32
low severity
- Vulnerable module: libarchive
- Introduced through: libarchive@3.3.3-1.el8
Detailed paths
-
Introduced through: centos@centos8 › libarchive@3.3.3-1.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libarchive
package and not the libarchive
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation.
Remediation
There is no fixed version for Centos:8
libarchive
.
References
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2845
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C72HDIMR3KTTAO7QGTXWUMPBNFUFIBRD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWOJOA7PZZAMBI5GFTL6PWHXMWSDLUXL/
- https://github.com/vim/vim/commit/e98c88c44c308edaea5994b8ad4363e65030968c
- https://huntr.dev/bounties/3e1d31ac-1cfd-4a9f-bc5c-213376b69445
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C72HDIMR3KTTAO7QGTXWUMPBNFUFIBRD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWOJOA7PZZAMBI5GFTL6PWHXMWSDLUXL/
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2022-2849
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWOJOA7PZZAMBI5GFTL6PWHXMWSDLUXL/
- https://github.com/vim/vim/commit/f6d39c31d2177549a986d170e192d8351bd571e2
- https://huntr.dev/bounties/389aeccd-deb9-49ae-9b6a-24c12d79b02e
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWOJOA7PZZAMBI5GFTL6PWHXMWSDLUXL/
- https://security.gentoo.org/glsa/202305-16
low severity
- Vulnerable module: vim-minimal
- Introduced through: vim-minimal@2:8.0.1763-15.el8
Detailed paths
-
Introduced through: centos@centos8 › vim-minimal@2:8.0.1763-15.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream vim-minimal
package and not the vim-minimal
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade the affected component.
Remediation
There is no fixed version for Centos:8
vim-minimal
.
References
- https://access.redhat.com/security/cve/CVE-2025-1215
- https://github.com/vim/vim/commit/c5654b84480822817bb7b69ebc97c174c91185e9
- https://github.com/vim/vim/releases/tag/v9.1.1097
- https://vuldb.com/?ctiid.295174
- https://vuldb.com/?id.295174
- https://security.netapp.com/advisory/ntap-20250321-0005/
- https://github.com/vim/vim/issues/16606
- https://vuldb.com/?submit.497546
low severity
- Vulnerable module: gnupg2
- Introduced through: gnupg2@2.2.20-2.el8
Detailed paths
-
Introduced through: centos@centos8 › gnupg2@2.2.20-2.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream gnupg2
package and not the gnupg2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."
Remediation
There is no fixed version for Centos:8
gnupg2
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
Remediation
There is no fixed version for Centos:8
binutils
.
References
low severity
- Vulnerable module: libxml2
- Introduced through: libxml2@2.9.7-9.el8
Detailed paths
-
Introduced through: centos@centos8 › libxml2@2.9.7-9.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxml2
package and not the libxml2
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
Remediation
There is no fixed version for Centos:8
libxml2
.
References
low severity
- Vulnerable module: binutils
- Introduced through: binutils@2.30-93.el8
- Fixed in: 0:2.30-125.el8_10
Detailed paths
-
Introduced through: centos@centos8 › binutils@2.30-93.el8
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
Remediation
Upgrade Centos:8
binutils
to version 0:2.30-125.el8_10 or higher.
References
- http://www.securityfocus.com/bid/104540
- https://access.redhat.com/security/cve/CVE-2018-12699
- https://security.gentoo.org/glsa/201908-01
- https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763102
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85454
- https://sourceware.org/bugzilla/show_bug.cgi?id=23057
- https://usn.ubuntu.com/4336-1/