From e748ba9741f6540f4675c23e3e37b73e822c13a4 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 31 May 2021 20:59:14 +0100 Subject: gentoo resync : 31.05.2021 --- metadata/glsa/Manifest | 30 ++--- metadata/glsa/Manifest.files.gz | Bin 502928 -> 509049 bytes metadata/glsa/glsa-200503-22.xml | 2 +- metadata/glsa/glsa-200503-33.xml | 2 +- metadata/glsa/glsa-200601-16.xml | 2 +- metadata/glsa/glsa-200603-11.xml | 2 +- metadata/glsa/glsa-200604-09.xml | 2 +- metadata/glsa/glsa-200605-11.xml | 2 +- metadata/glsa/glsa-200606-11.xml | 2 +- metadata/glsa/glsa-200606-19.xml | 2 +- metadata/glsa/glsa-200606-26.xml | 2 +- metadata/glsa/glsa-200608-09.xml | 2 +- metadata/glsa/glsa-200608-23.xml | 2 +- metadata/glsa/glsa-200609-03.xml | 2 +- metadata/glsa/glsa-200609-11.xml | 2 +- metadata/glsa/glsa-200609-17.xml | 2 +- metadata/glsa/glsa-200609-20.xml | 2 +- metadata/glsa/glsa-200611-09.xml | 2 +- metadata/glsa/glsa-200612-18.xml | 2 +- metadata/glsa/glsa-200701-01.xml | 2 +- metadata/glsa/glsa-200701-05.xml | 2 +- metadata/glsa/glsa-200701-09.xml | 2 +- metadata/glsa/glsa-200701-14.xml | 2 +- metadata/glsa/glsa-200702-03.xml | 2 +- metadata/glsa/glsa-200702-05.xml | 2 +- metadata/glsa/glsa-200702-06.xml | 2 +- metadata/glsa/glsa-200703-02.xml | 2 +- metadata/glsa/glsa-200703-03.xml | 2 +- metadata/glsa/glsa-200703-12.xml | 2 +- metadata/glsa/glsa-200703-14.xml | 2 +- metadata/glsa/glsa-200703-27.xml | 2 +- metadata/glsa/glsa-200703-28.xml | 2 +- metadata/glsa/glsa-200704-11.xml | 2 +- metadata/glsa/glsa-200704-13.xml | 2 +- metadata/glsa/glsa-200704-14.xml | 2 +- metadata/glsa/glsa-200704-22.xml | 2 +- metadata/glsa/glsa-200705-04.xml | 2 +- metadata/glsa/glsa-200705-05.xml | 2 +- metadata/glsa/glsa-200705-09.xml | 2 +- metadata/glsa/glsa-200705-24.xml | 2 +- metadata/glsa/glsa-200707-13.xml | 2 +- metadata/glsa/glsa-200708-04.xml | 2 +- metadata/glsa/glsa-200708-14.xml | 2 +- metadata/glsa/glsa-200709-11.xml | 2 +- metadata/glsa/glsa-200710-14.xml | 2 +- metadata/glsa/glsa-200711-09.xml | 2 +- metadata/glsa/glsa-200711-13.xml | 2 +- metadata/glsa/glsa-200711-25.xml | 2 +- metadata/glsa/glsa-200711-31.xml | 2 +- metadata/glsa/glsa-200712-12.xml | 2 +- metadata/glsa/glsa-200712-19.xml | 2 +- metadata/glsa/glsa-200801-04.xml | 2 +- metadata/glsa/glsa-200801-05.xml | 2 +- metadata/glsa/glsa-200801-13.xml | 2 +- metadata/glsa/glsa-200801-16.xml | 2 +- metadata/glsa/glsa-200801-17.xml | 2 +- metadata/glsa/glsa-200801-20.xml | 2 +- metadata/glsa/glsa-200802-08.xml | 2 +- metadata/glsa/glsa-200803-22.xml | 2 +- metadata/glsa/glsa-200803-32.xml | 2 +- metadata/glsa/glsa-200804-02.xml | 2 +- metadata/glsa/glsa-200804-19.xml | 2 +- metadata/glsa/glsa-200804-26.xml | 2 +- metadata/glsa/glsa-200805-05.xml | 2 +- metadata/glsa/glsa-200805-08.xml | 2 +- metadata/glsa/glsa-200805-15.xml | 2 +- metadata/glsa/glsa-200806-08.xml | 2 +- metadata/glsa/glsa-200807-06.xml | 2 +- metadata/glsa/glsa-200808-04.xml | 2 +- metadata/glsa/glsa-200808-05.xml | 2 +- metadata/glsa/glsa-200809-09.xml | 2 +- metadata/glsa/glsa-200809-11.xml | 2 +- metadata/glsa/glsa-200812-03.xml | 2 +- metadata/glsa/glsa-200901-04.xml | 2 +- metadata/glsa/glsa-200901-11.xml | 2 +- metadata/glsa/glsa-200901-15.xml | 2 +- metadata/glsa/glsa-200903-13.xml | 2 +- metadata/glsa/glsa-200903-19.xml | 2 +- metadata/glsa/glsa-200903-40.xml | 2 +- metadata/glsa/glsa-200904-04.xml | 2 +- metadata/glsa/glsa-200904-08.xml | 2 +- metadata/glsa/glsa-200904-10.xml | 2 +- metadata/glsa/glsa-200904-13.xml | 2 +- metadata/glsa/glsa-200905-03.xml | 2 +- metadata/glsa/glsa-200905-06.xml | 2 +- metadata/glsa/glsa-200906-02.xml | 2 +- metadata/glsa/glsa-200907-02.xml | 2 +- metadata/glsa/glsa-200907-05.xml | 2 +- metadata/glsa/glsa-200908-02.xml | 2 +- metadata/glsa/glsa-200908-07.xml | 2 +- metadata/glsa/glsa-200908-08.xml | 2 +- metadata/glsa/glsa-200909-05.xml | 2 +- metadata/glsa/glsa-200909-16.xml | 2 +- metadata/glsa/glsa-201001-01.xml | 2 +- metadata/glsa/glsa-201006-17.xml | 2 +- metadata/glsa/glsa-201009-07.xml | 2 +- metadata/glsa/glsa-201110-07.xml | 2 +- metadata/glsa/glsa-201110-12.xml | 2 +- metadata/glsa/glsa-201110-17.xml | 2 +- metadata/glsa/glsa-201202-03.xml | 2 +- metadata/glsa/glsa-201202-04.xml | 2 +- metadata/glsa/glsa-201202-06.xml | 2 +- metadata/glsa/glsa-201203-04.xml | 2 +- metadata/glsa/glsa-201203-05.xml | 2 +- metadata/glsa/glsa-201203-08.xml | 2 +- metadata/glsa/glsa-201203-13.xml | 2 +- metadata/glsa/glsa-201206-20.xml | 2 +- metadata/glsa/glsa-201207-06.xml | 2 +- metadata/glsa/glsa-201207-07.xml | 2 +- metadata/glsa/glsa-201209-08.xml | 2 +- metadata/glsa/glsa-201209-09.xml | 2 +- metadata/glsa/glsa-201209-12.xml | 2 +- metadata/glsa/glsa-201209-14.xml | 2 +- metadata/glsa/glsa-201209-20.xml | 2 +- metadata/glsa/glsa-201301-06.xml | 2 +- metadata/glsa/glsa-201308-02.xml | 2 +- metadata/glsa/glsa-201309-01.xml | 2 +- metadata/glsa/glsa-201309-03.xml | 2 +- metadata/glsa/glsa-201311-04.xml | 2 +- metadata/glsa/glsa-201311-18.xml | 2 +- metadata/glsa/glsa-201312-15.xml | 2 +- metadata/glsa/glsa-201401-05.xml | 2 +- metadata/glsa/glsa-201401-07.xml | 2 +- metadata/glsa/glsa-201401-34.xml | 2 +- metadata/glsa/glsa-201402-11.xml | 2 +- metadata/glsa/glsa-201402-14.xml | 2 +- metadata/glsa/glsa-201402-25.xml | 2 +- metadata/glsa/glsa-201403-03.xml | 2 +- metadata/glsa/glsa-201403-04.xml | 2 +- metadata/glsa/glsa-201405-02.xml | 2 +- metadata/glsa/glsa-201405-05.xml | 2 +- metadata/glsa/glsa-201405-14.xml | 2 +- metadata/glsa/glsa-201405-16.xml | 2 +- metadata/glsa/glsa-201405-20.xml | 2 +- metadata/glsa/glsa-201405-21.xml | 2 +- metadata/glsa/glsa-201405-24.xml | 2 +- metadata/glsa/glsa-201406-04.xml | 2 +- metadata/glsa/glsa-201406-23.xml | 2 +- metadata/glsa/glsa-201407-01.xml | 2 +- metadata/glsa/glsa-201407-04.xml | 2 +- metadata/glsa/glsa-201408-08.xml | 2 +- metadata/glsa/glsa-201409-02.xml | 2 +- metadata/glsa/glsa-201409-07.xml | 2 +- metadata/glsa/glsa-201409-08.xml | 2 +- metadata/glsa/glsa-201411-07.xml | 2 +- metadata/glsa/glsa-201412-03.xml | 2 +- metadata/glsa/glsa-201412-06.xml | 2 +- metadata/glsa/glsa-201412-16.xml | 2 +- metadata/glsa/glsa-201412-20.xml | 2 +- metadata/glsa/glsa-201412-25.xml | 2 +- metadata/glsa/glsa-201412-27.xml | 2 +- metadata/glsa/glsa-201412-31.xml | 2 +- metadata/glsa/glsa-201412-35.xml | 2 +- metadata/glsa/glsa-201412-36.xml | 2 +- metadata/glsa/glsa-201412-41.xml | 2 +- metadata/glsa/glsa-201412-42.xml | 2 +- metadata/glsa/glsa-201412-46.xml | 2 +- metadata/glsa/glsa-201412-48.xml | 2 +- metadata/glsa/glsa-201502-14.xml | 2 +- metadata/glsa/glsa-201503-02.xml | 2 +- metadata/glsa/glsa-201503-08.xml | 2 +- metadata/glsa/glsa-201507-02.xml | 2 +- metadata/glsa/glsa-201507-03.xml | 2 +- metadata/glsa/glsa-201507-08.xml | 2 +- metadata/glsa/glsa-201507-11.xml | 2 +- metadata/glsa/glsa-201507-12.xml | 2 +- metadata/glsa/glsa-201507-17.xml | 2 +- metadata/glsa/glsa-201508-03.xml | 2 +- metadata/glsa/glsa-201509-05.xml | 2 +- metadata/glsa/glsa-201510-01.xml | 2 +- metadata/glsa/glsa-201512-01.xml | 2 +- metadata/glsa/glsa-201605-03.xml | 2 +- metadata/glsa/glsa-201611-13.xml | 2 +- metadata/glsa/glsa-201611-17.xml | 2 +- metadata/glsa/glsa-201612-12.xml | 2 +- metadata/glsa/glsa-201612-13.xml | 2 +- metadata/glsa/glsa-201701-05.xml | 2 +- metadata/glsa/glsa-201701-26.xml | 2 +- metadata/glsa/glsa-201703-05.xml | 2 +- metadata/glsa/glsa-201706-11.xml | 2 +- metadata/glsa/glsa-201708-08.xml | 2 +- metadata/glsa/glsa-201710-15.xml | 2 +- metadata/glsa/glsa-201811-03.xml | 2 +- metadata/glsa/glsa-201811-07.xml | 2 +- metadata/glsa/glsa-201903-05.xml | 2 +- metadata/glsa/glsa-201904-01.xml | 2 +- metadata/glsa/glsa-201904-08.xml | 2 +- metadata/glsa/glsa-201904-15.xml | 2 +- metadata/glsa/glsa-201908-25.xml | 2 +- metadata/glsa/glsa-202004-08.xml | 2 +- metadata/glsa/glsa-202005-09.xml | 2 +- metadata/glsa/glsa-202011-05.xml | 2 +- metadata/glsa/glsa-202012-21.xml | 53 +++++++++ metadata/glsa/glsa-202104-07.xml | 2 +- metadata/glsa/glsa-202105-02.xml | 51 ++++++++ metadata/glsa/glsa-202105-03.xml | 54 +++++++++ metadata/glsa/glsa-202105-04.xml | 55 +++++++++ metadata/glsa/glsa-202105-05.xml | 66 +++++++++++ metadata/glsa/glsa-202105-06.xml | 48 ++++++++ metadata/glsa/glsa-202105-07.xml | 59 ++++++++++ metadata/glsa/glsa-202105-08.xml | 55 +++++++++ metadata/glsa/glsa-202105-09.xml | 51 ++++++++ metadata/glsa/glsa-202105-10.xml | 55 +++++++++ metadata/glsa/glsa-202105-11.xml | 55 +++++++++ metadata/glsa/glsa-202105-12.xml | 50 ++++++++ metadata/glsa/glsa-202105-13.xml | 49 ++++++++ metadata/glsa/glsa-202105-14.xml | 61 ++++++++++ metadata/glsa/glsa-202105-15.xml | 54 +++++++++ metadata/glsa/glsa-202105-16.xml | 53 +++++++++ metadata/glsa/glsa-202105-17.xml | 51 ++++++++ metadata/glsa/glsa-202105-18.xml | 54 +++++++++ metadata/glsa/glsa-202105-19.xml | 53 +++++++++ metadata/glsa/glsa-202105-20.xml | 54 +++++++++ metadata/glsa/glsa-202105-21.xml | 54 +++++++++ metadata/glsa/glsa-202105-22.xml | 50 ++++++++ metadata/glsa/glsa-202105-23.xml | 68 +++++++++++ metadata/glsa/glsa-202105-24.xml | 55 +++++++++ metadata/glsa/glsa-202105-25.xml | 49 ++++++++ metadata/glsa/glsa-202105-26.xml | 51 ++++++++ metadata/glsa/glsa-202105-27.xml | 247 +++++++++++++++++++++++++++++++++++++++ metadata/glsa/glsa-202105-28.xml | 75 ++++++++++++ metadata/glsa/glsa-202105-29.xml | 49 ++++++++ metadata/glsa/glsa-202105-30.xml | 52 +++++++++ metadata/glsa/glsa-202105-31.xml | 54 +++++++++ metadata/glsa/glsa-202105-32.xml | 92 +++++++++++++++ metadata/glsa/glsa-202105-33.xml | 55 +++++++++ metadata/glsa/glsa-202105-34.xml | 45 +++++++ metadata/glsa/glsa-202105-35.xml | 57 +++++++++ metadata/glsa/glsa-202105-36.xml | 51 ++++++++ metadata/glsa/glsa-202105-37.xml | 50 ++++++++ metadata/glsa/glsa-202105-38.xml | 59 ++++++++++ metadata/glsa/glsa-202105-39.xml | 58 +++++++++ metadata/glsa/timestamp.chk | 2 +- metadata/glsa/timestamp.commit | 2 +- 234 files changed, 2560 insertions(+), 208 deletions(-) create mode 100644 metadata/glsa/glsa-202012-21.xml create mode 100644 metadata/glsa/glsa-202105-02.xml create mode 100644 metadata/glsa/glsa-202105-03.xml create mode 100644 metadata/glsa/glsa-202105-04.xml create mode 100644 metadata/glsa/glsa-202105-05.xml create mode 100644 metadata/glsa/glsa-202105-06.xml create mode 100644 metadata/glsa/glsa-202105-07.xml create mode 100644 metadata/glsa/glsa-202105-08.xml create mode 100644 metadata/glsa/glsa-202105-09.xml create mode 100644 metadata/glsa/glsa-202105-10.xml create mode 100644 metadata/glsa/glsa-202105-11.xml create mode 100644 metadata/glsa/glsa-202105-12.xml create mode 100644 metadata/glsa/glsa-202105-13.xml create mode 100644 metadata/glsa/glsa-202105-14.xml create mode 100644 metadata/glsa/glsa-202105-15.xml create mode 100644 metadata/glsa/glsa-202105-16.xml create mode 100644 metadata/glsa/glsa-202105-17.xml create mode 100644 metadata/glsa/glsa-202105-18.xml create mode 100644 metadata/glsa/glsa-202105-19.xml create mode 100644 metadata/glsa/glsa-202105-20.xml create mode 100644 metadata/glsa/glsa-202105-21.xml create mode 100644 metadata/glsa/glsa-202105-22.xml create mode 100644 metadata/glsa/glsa-202105-23.xml create mode 100644 metadata/glsa/glsa-202105-24.xml create mode 100644 metadata/glsa/glsa-202105-25.xml create mode 100644 metadata/glsa/glsa-202105-26.xml create mode 100644 metadata/glsa/glsa-202105-27.xml create mode 100644 metadata/glsa/glsa-202105-28.xml create mode 100644 metadata/glsa/glsa-202105-29.xml create mode 100644 metadata/glsa/glsa-202105-30.xml create mode 100644 metadata/glsa/glsa-202105-31.xml create mode 100644 metadata/glsa/glsa-202105-32.xml create mode 100644 metadata/glsa/glsa-202105-33.xml create mode 100644 metadata/glsa/glsa-202105-34.xml create mode 100644 metadata/glsa/glsa-202105-35.xml create mode 100644 metadata/glsa/glsa-202105-36.xml create mode 100644 metadata/glsa/glsa-202105-37.xml create mode 100644 metadata/glsa/glsa-202105-38.xml create mode 100644 metadata/glsa/glsa-202105-39.xml (limited to 'metadata/glsa') diff --git a/metadata/glsa/Manifest b/metadata/glsa/Manifest index f007b3c52688..680ba2f5fd43 100644 --- a/metadata/glsa/Manifest +++ b/metadata/glsa/Manifest @@ -1,23 +1,23 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 -MANIFEST Manifest.files.gz 502928 BLAKE2B 4e05777f9b079a42eb84d60a21da4ea6f5360b3577989267141081878f0b732bcb93075e1929366199e18d3e1a21a16ae70ed796931681b1b573aa0b10cc5078 SHA512 c56775c1540b0ebb8f0386f5b352030f212f18222cbbefb95a16fa57a60aae01a7069287ba96443202c19c8e16589238b433d1da54fea1ddc1c44b81ba9fa6b7 -TIMESTAMP 2021-05-22T06:08:56Z +MANIFEST Manifest.files.gz 509049 BLAKE2B e2b5c0e25d30cb613bf6b26a404bdd5c9ecf1ebe0f765c98e65b5c6abb8c3367dc1f4e8d19e68c1568e7e055e9c4617562aea2e0f52899586498178621fa32fa SHA512 460ef918d52020ec8e54fc6c17e54e0f11f0e50117f6c87479422f3fc3f4face3581664544e8cbcb8fc1265b88f7145a0e90a36cd8e1acef5b7908d625bdb379 +TIMESTAMP 2021-05-31T19:38:58Z -----BEGIN PGP SIGNATURE----- -iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAmCon/hfFIAAAAAALgAo +iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAmC1O1JfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEUx RDZBQkI2M0JGQ0ZCNEJBMDJGREYxQ0VDNTkwRUVBQzkxODkyNTAACgkQ7FkO6skY -klAoHQ//W2DDWUiwt+BtixLL2bzvq5T/AIKC8lui5uS8N5rYduFmcqZB0O28p3bg -+FgSCAPlNFQ3CmZKQXmZZxCUsP814cblnBvtPuShBZW34OgY3HcbIlg3K4U7GCAv -HcfxSOq3WhcG4fpHBwqVjv7rIxcNWsH0RqSUkqa+ErAVb6BSGy8MR4FTGAPaZsjC -NDvzA8TsP08rO+YsezcevGZholkvLgJkQ/vS6EseGRy+cw5nBjnqEruQG4BbNNOj -oU9fXkFADtm5JgUOya+mPxiRur5bRv8KU8nZqkubIo7Owi+VxlYQLc0zvP8l+hLQ -ZkSg5+iKqKFULzqKoJaKbUmklXKwWZrhc7I2gyvtxTnCG2R+7YY/LEcfn821uT+n -8XeVbbnQr8eWwPtTr1cmqqvwQXqX/scwJrhRqK1e1NMbuLlP0AtrqiLT+KZN57Aa -PoQjvWotjJhaHul5VAE4zXUYVmGg63ak+RvENcETb+AtXLk9SAC5VQ3MtIM91scC -rfcgtGEyb1KfZ+wEzIUed7Rbn8UDcofTpeMV2EOIboLVzUZ0qGA0WZsZ8aCYQ4qK -eaKRKhAX+qCGx1D0VOeuZI8Deue7r02APSswkUMMgPjafeCqCJlGPvFKkqv4WUq9 -KzViSB9M+nXjEV8SuBgSV4hSA7TWug7ItKfIc38XLhbP1lFWjxk= -=+i6o +klBOkQ/+NQZkfNV2Yzu21GXWlC6VhkaE3hyS24uCfJlI/OhGPcDROAXe+wQyiJjE +vhKbupdIo1m3VsbglC/VKUg5nSAD2dkNU6m2EahzUjiNqRLJlAhUrh3S0wVTbsSF +s6yrPBaXPJmx0MCJvmNuOl9QOfZwYHqKKPHMTexjnyufHbh5NJwIK4vTEEHzr4ST +oPt2rkG9YPnHyQ7xotX/I7fJMH2xVb1cY7MBCSISBGiSzf+Myxl65zcGunzHJaad +rPfWkiIEpL8jauzUtPehm/IQsPwnTSAS9wt7XpriY3ano9A9eK1vuWuL14fCAx1N +PTRfzT7BGAf4vpQlYPjYklgvi95NJr7ws/bDFlNtE/lKQozJ9wYOxm1u0tk+JlcC +TUlHvHJDU2H1WG1s2ms8nN5Ye5xvVMOEBBt/eWM3vxv+IKt2bPsdgX/0XSQ9uvH8 +1kQvUHw3GduEySER17mH1RB3TuMp/AwRJM7wqbcbqJIcIheIcFSiCW53wAEEYXTZ +hNLDRX5K/85ohzu6smYp0MiI055Kk8x/oB89bdrc+wIDbrjIReGujmAK4DzTqlSb +Rhu25h7ug5msRv5HlQ6Ya8wboXYV2lNSqzDTtEF7vHVuqVA+INFv8YPiOSU0tYgo +D2og9Otl2nWXJqmM1ptvPkWNo0Ikda6kwLe25A2XXywavGYpXXw= +=taMy -----END PGP SIGNATURE----- diff --git a/metadata/glsa/Manifest.files.gz b/metadata/glsa/Manifest.files.gz index a665ea17c60d..ae5404fb42ac 100644 Binary files a/metadata/glsa/Manifest.files.gz and b/metadata/glsa/Manifest.files.gz differ diff --git a/metadata/glsa/glsa-200503-22.xml b/metadata/glsa/glsa-200503-22.xml index dcd5c2142e6d..5bedbe96fb3d 100644 --- a/metadata/glsa/glsa-200503-22.xml +++ b/metadata/glsa/glsa-200503-22.xml @@ -1,7 +1,7 @@ - KDE: Local Denial of Service + KDE: Local Denial of service KDE is vulnerable to a local Denial of Service attack. diff --git a/metadata/glsa/glsa-200503-33.xml b/metadata/glsa/glsa-200503-33.xml index c2229fc7fb54..1ef517127346 100644 --- a/metadata/glsa/glsa-200503-33.xml +++ b/metadata/glsa/glsa-200503-33.xml @@ -1,7 +1,7 @@ - IPsec-Tools: racoon Denial of Service + IPsec-Tools: racoon Denial of service IPsec-Tools' racoon is affected by a remote Denial of Service vulnerability. diff --git a/metadata/glsa/glsa-200601-16.xml b/metadata/glsa/glsa-200601-16.xml index ac2bc802e3ac..0c4f4968825e 100644 --- a/metadata/glsa/glsa-200601-16.xml +++ b/metadata/glsa/glsa-200601-16.xml @@ -1,7 +1,7 @@ - MyDNS: Denial of Service + MyDNS: Denial of service MyDNS contains a vulnerability that may lead to a Denial of Service attack. diff --git a/metadata/glsa/glsa-200603-11.xml b/metadata/glsa/glsa-200603-11.xml index 90b33f414faf..0585a3400a31 100644 --- a/metadata/glsa/glsa-200603-11.xml +++ b/metadata/glsa/glsa-200603-11.xml @@ -1,7 +1,7 @@ - Freeciv: Denial of Service + Freeciv: Denial of service A memory allocation bug in Freeciv allows a remote attacker to perform a Denial of Service attack. diff --git a/metadata/glsa/glsa-200604-09.xml b/metadata/glsa/glsa-200604-09.xml index e680ddc0e89a..fb77749e5830 100644 --- a/metadata/glsa/glsa-200604-09.xml +++ b/metadata/glsa/glsa-200604-09.xml @@ -1,7 +1,7 @@ - Cyrus-SASL: DIGEST-MD5 Pre-Authentication Denial of Service + Cyrus-SASL: DIGEST-MD5 Pre-Authentication Denial of service Cyrus-SASL contains a vulnerability in the DIGEST-MD5 process that could lead to a Denial of Service. diff --git a/metadata/glsa/glsa-200605-11.xml b/metadata/glsa/glsa-200605-11.xml index 62de66a80b05..3cee0b37eff0 100644 --- a/metadata/glsa/glsa-200605-11.xml +++ b/metadata/glsa/glsa-200605-11.xml @@ -1,7 +1,7 @@ - Ruby: Denial of Service + Ruby: Denial of service Ruby WEBrick and XMLRPC servers are vulnerable to Denial of Service. diff --git a/metadata/glsa/glsa-200606-11.xml b/metadata/glsa/glsa-200606-11.xml index a58e8de97308..c4ad483ce0c7 100644 --- a/metadata/glsa/glsa-200606-11.xml +++ b/metadata/glsa/glsa-200606-11.xml @@ -1,7 +1,7 @@ - JPEG library: Denial of Service + JPEG library: Denial of service The JPEG library is vulnerable to a Denial of Service. diff --git a/metadata/glsa/glsa-200606-19.xml b/metadata/glsa/glsa-200606-19.xml index c0fec98a63a9..1c54e139b692 100644 --- a/metadata/glsa/glsa-200606-19.xml +++ b/metadata/glsa/glsa-200606-19.xml @@ -1,7 +1,7 @@ - Sendmail: Denial of Service + Sendmail: Denial of service Faulty multipart MIME messages can cause forked Sendmail processes to crash. diff --git a/metadata/glsa/glsa-200606-26.xml b/metadata/glsa/glsa-200606-26.xml index 22e4caf92ed8..ce147a2f36f9 100644 --- a/metadata/glsa/glsa-200606-26.xml +++ b/metadata/glsa/glsa-200606-26.xml @@ -1,7 +1,7 @@ - EnergyMech: Denial of Service + EnergyMech: Denial of service A Denial of Service vulnerability was discovered in EnergyMech that is easily exploitable via IRC. diff --git a/metadata/glsa/glsa-200608-09.xml b/metadata/glsa/glsa-200608-09.xml index ba8779a96cad..85072294a7e0 100644 --- a/metadata/glsa/glsa-200608-09.xml +++ b/metadata/glsa/glsa-200608-09.xml @@ -1,7 +1,7 @@ - MySQL: Denial of Service + MySQL: Denial of service An authenticated user can crash MySQL through invalid parameters to the date_format function. diff --git a/metadata/glsa/glsa-200608-23.xml b/metadata/glsa/glsa-200608-23.xml index a93902eb2ecf..2fc97981e5fa 100644 --- a/metadata/glsa/glsa-200608-23.xml +++ b/metadata/glsa/glsa-200608-23.xml @@ -1,7 +1,7 @@ - Heartbeat: Denial of Service + Heartbeat: Denial of service Heartbeat is vulnerable to a Denial of Service which can be triggered by a remote attacker without authentication. diff --git a/metadata/glsa/glsa-200609-03.xml b/metadata/glsa/glsa-200609-03.xml index bfc902174321..92a3af875a88 100644 --- a/metadata/glsa/glsa-200609-03.xml +++ b/metadata/glsa/glsa-200609-03.xml @@ -1,7 +1,7 @@ - OpenTTD: Remote Denial of Service + OpenTTD: Remote Denial of service The OpenTTD server is vulnerable to a remote Denial of Service. diff --git a/metadata/glsa/glsa-200609-11.xml b/metadata/glsa/glsa-200609-11.xml index 2ac89d018fbd..bc717d55702f 100644 --- a/metadata/glsa/glsa-200609-11.xml +++ b/metadata/glsa/glsa-200609-11.xml @@ -1,7 +1,7 @@ - BIND: Denial of Service + BIND: Denial of service ISC BIND contains two vulnerabilities allowing a Denial of Service under certain conditions. diff --git a/metadata/glsa/glsa-200609-17.xml b/metadata/glsa/glsa-200609-17.xml index 7533659d3e1f..3a4a79d4b484 100644 --- a/metadata/glsa/glsa-200609-17.xml +++ b/metadata/glsa/glsa-200609-17.xml @@ -1,7 +1,7 @@ - OpenSSH: Denial of Service + OpenSSH: Denial of service A flaw in the OpenSSH daemon allows remote unauthenticated attackers to cause a Denial of Service. diff --git a/metadata/glsa/glsa-200609-20.xml b/metadata/glsa/glsa-200609-20.xml index 2764e38d940c..d1b853bc63d5 100644 --- a/metadata/glsa/glsa-200609-20.xml +++ b/metadata/glsa/glsa-200609-20.xml @@ -1,7 +1,7 @@ - DokuWiki: Shell command injection and Denial of Service + DokuWiki: Shell command injection and Denial of service DokuWiki is vulnerable to shell command injection and Denial of Service attacks when using ImageMagick. diff --git a/metadata/glsa/glsa-200611-09.xml b/metadata/glsa/glsa-200611-09.xml index e92010198547..1dec8d5fbb4e 100644 --- a/metadata/glsa/glsa-200611-09.xml +++ b/metadata/glsa/glsa-200611-09.xml @@ -1,7 +1,7 @@ - libpng: Denial of Service + libpng: Denial of service A vulnerability in libpng may allow a remote attacker to crash applications that handle untrusted images. diff --git a/metadata/glsa/glsa-200612-18.xml b/metadata/glsa/glsa-200612-18.xml index 1a43445064da..5ed634ad43aa 100644 --- a/metadata/glsa/glsa-200612-18.xml +++ b/metadata/glsa/glsa-200612-18.xml @@ -1,7 +1,7 @@ - ClamAV: Denial of Service + ClamAV: Denial of service ClamAV is vulnerable to Denial of Service. diff --git a/metadata/glsa/glsa-200701-01.xml b/metadata/glsa/glsa-200701-01.xml index 7f9efc3a29ae..2671dcd8090a 100644 --- a/metadata/glsa/glsa-200701-01.xml +++ b/metadata/glsa/glsa-200701-01.xml @@ -1,7 +1,7 @@ - DenyHosts: Denial of Service + DenyHosts: Denial of service DenyHosts does not correctly parse log entries, potentially causing a remote Denial of Service. diff --git a/metadata/glsa/glsa-200701-05.xml b/metadata/glsa/glsa-200701-05.xml index 48768ef29606..37c4f19e0402 100644 --- a/metadata/glsa/glsa-200701-05.xml +++ b/metadata/glsa/glsa-200701-05.xml @@ -1,7 +1,7 @@ - KDE kfile JPEG info plugin: Denial of Service + KDE kfile JPEG info plugin: Denial of service The KDE kfile JPEG info plugin of kdegraphics could enter an endless loop leading to a Denial of Service. diff --git a/metadata/glsa/glsa-200701-09.xml b/metadata/glsa/glsa-200701-09.xml index 35197acf508b..c2c0ae1fe2c8 100644 --- a/metadata/glsa/glsa-200701-09.xml +++ b/metadata/glsa/glsa-200701-09.xml @@ -1,7 +1,7 @@ - oftpd: Denial of Service + oftpd: Denial of service An assertion in oftpd could lead to a denial of service vulnerability. diff --git a/metadata/glsa/glsa-200701-14.xml b/metadata/glsa/glsa-200701-14.xml index f3dff2ebb727..8fc60c481f9d 100644 --- a/metadata/glsa/glsa-200701-14.xml +++ b/metadata/glsa/glsa-200701-14.xml @@ -1,7 +1,7 @@ - Mod_auth_kerb: Denial of Service + Mod_auth_kerb: Denial of service Mod_auth_kerb is vulnerable to a buffer overflow possibly allowing a Denial of Service. diff --git a/metadata/glsa/glsa-200702-03.xml b/metadata/glsa/glsa-200702-03.xml index 22952e849340..11a93ad71602 100644 --- a/metadata/glsa/glsa-200702-03.xml +++ b/metadata/glsa/glsa-200702-03.xml @@ -1,7 +1,7 @@ - Snort: Denial of Service + Snort: Denial of service Snort contains a vulnerability in the rule matching algorithm that could result in a Denial of Service. diff --git a/metadata/glsa/glsa-200702-05.xml b/metadata/glsa/glsa-200702-05.xml index 0f8a14baba3d..98d513b6fd6a 100644 --- a/metadata/glsa/glsa-200702-05.xml +++ b/metadata/glsa/glsa-200702-05.xml @@ -1,7 +1,7 @@ - Fail2ban: Denial of Service + Fail2ban: Denial of service A flaw in Fail2ban may allow remote attackers to deny access to arbitrary hosts. diff --git a/metadata/glsa/glsa-200702-06.xml b/metadata/glsa/glsa-200702-06.xml index 3e3f503e4e3a..1f3c0b9369f7 100644 --- a/metadata/glsa/glsa-200702-06.xml +++ b/metadata/glsa/glsa-200702-06.xml @@ -1,7 +1,7 @@ - BIND: Denial of Service + BIND: Denial of service ISC BIND contains two vulnerabilities allowing a Denial of Service under certain conditions. diff --git a/metadata/glsa/glsa-200703-02.xml b/metadata/glsa/glsa-200703-02.xml index 9785ebf3dc25..7c75cc5b2b0f 100644 --- a/metadata/glsa/glsa-200703-02.xml +++ b/metadata/glsa/glsa-200703-02.xml @@ -1,7 +1,7 @@ - SpamAssassin: Long URI Denial of Service + SpamAssassin: Long URI Denial of service SpamAssassin is vulnerable to a Denial of Service attack. diff --git a/metadata/glsa/glsa-200703-03.xml b/metadata/glsa/glsa-200703-03.xml index 8a543ec90f9d..408b8fb5cf27 100644 --- a/metadata/glsa/glsa-200703-03.xml +++ b/metadata/glsa/glsa-200703-03.xml @@ -1,7 +1,7 @@ - ClamAV: Denial of Service + ClamAV: Denial of service ClamAV contains two vulnerabilities allowing a Denial of Service. diff --git a/metadata/glsa/glsa-200703-12.xml b/metadata/glsa/glsa-200703-12.xml index be1d5010c77b..c6ed3db7e650 100644 --- a/metadata/glsa/glsa-200703-12.xml +++ b/metadata/glsa/glsa-200703-12.xml @@ -1,7 +1,7 @@ - SILC Server: Denial of Service + SILC Server: Denial of service SILC Server is affected by a Denial of Service vulnerability. diff --git a/metadata/glsa/glsa-200703-14.xml b/metadata/glsa/glsa-200703-14.xml index b2fcc2b2d9e4..49cc182ad3a4 100644 --- a/metadata/glsa/glsa-200703-14.xml +++ b/metadata/glsa/glsa-200703-14.xml @@ -1,7 +1,7 @@ - Asterisk: SIP Denial of Service + Asterisk: SIP Denial of service Asterisk is vulnerable to Denial of Service in the SIP channel. diff --git a/metadata/glsa/glsa-200703-27.xml b/metadata/glsa/glsa-200703-27.xml index 4f7898a76ee2..5d1bddf411ee 100644 --- a/metadata/glsa/glsa-200703-27.xml +++ b/metadata/glsa/glsa-200703-27.xml @@ -1,7 +1,7 @@ - Squid: Denial of Service + Squid: Denial of service Squid is affected by a Denial of Service vulnerability. diff --git a/metadata/glsa/glsa-200703-28.xml b/metadata/glsa/glsa-200703-28.xml index 1004180daada..5e2265c33171 100644 --- a/metadata/glsa/glsa-200703-28.xml +++ b/metadata/glsa/glsa-200703-28.xml @@ -1,7 +1,7 @@ - CUPS: Denial of Service + CUPS: Denial of service CUPS incorrectly handles partially-negotiated SSL connections allowing for a Denial of Service. diff --git a/metadata/glsa/glsa-200704-11.xml b/metadata/glsa/glsa-200704-11.xml index 3f9ab070a191..c8ff587f0f63 100644 --- a/metadata/glsa/glsa-200704-11.xml +++ b/metadata/glsa/glsa-200704-11.xml @@ -1,7 +1,7 @@ - Vixie Cron: Denial of Service + Vixie Cron: Denial of service The Gentoo implementation of Vixie Cron is vulnerable to a local Denial of Service. diff --git a/metadata/glsa/glsa-200704-13.xml b/metadata/glsa/glsa-200704-13.xml index e41f921b22eb..28ebd44ba71a 100644 --- a/metadata/glsa/glsa-200704-13.xml +++ b/metadata/glsa/glsa-200704-13.xml @@ -1,7 +1,7 @@ - File: Denial of Service + File: Denial of service A vulnerability has been discovered in file allowing for a denial of service. diff --git a/metadata/glsa/glsa-200704-14.xml b/metadata/glsa/glsa-200704-14.xml index e4e6fe5c7030..5c7ec666f40c 100644 --- a/metadata/glsa/glsa-200704-14.xml +++ b/metadata/glsa/glsa-200704-14.xml @@ -1,7 +1,7 @@ - FreeRADIUS: Denial of Service + FreeRADIUS: Denial of service A memory leak has been discovered in FreeRADIUS, possibly allowing for a Denial of Service. diff --git a/metadata/glsa/glsa-200704-22.xml b/metadata/glsa/glsa-200704-22.xml index d8e3e96f325c..3a176a3c6fb7 100644 --- a/metadata/glsa/glsa-200704-22.xml +++ b/metadata/glsa/glsa-200704-22.xml @@ -1,7 +1,7 @@ - BEAST: Denial of Service + BEAST: Denial of service A vulnerability has been discovered in BEAST allowing for a Denial of Service. diff --git a/metadata/glsa/glsa-200705-04.xml b/metadata/glsa/glsa-200705-04.xml index 5978092a4c61..30a453228359 100644 --- a/metadata/glsa/glsa-200705-04.xml +++ b/metadata/glsa/glsa-200705-04.xml @@ -1,7 +1,7 @@ - Apache mod_perl: Denial of Service + Apache mod_perl: Denial of service The mod_perl Apache module is vulnerable to a Denial of Service when processing regular expressions. diff --git a/metadata/glsa/glsa-200705-05.xml b/metadata/glsa/glsa-200705-05.xml index 6d950b3cfef8..18bccf17f9d3 100644 --- a/metadata/glsa/glsa-200705-05.xml +++ b/metadata/glsa/glsa-200705-05.xml @@ -1,7 +1,7 @@ - Quagga: Denial of Service + Quagga: Denial of service A vulnerability has been discovered in Quagga allowing for a Denial of Service. diff --git a/metadata/glsa/glsa-200705-09.xml b/metadata/glsa/glsa-200705-09.xml index 577098b4b9ee..65861b5fe67e 100644 --- a/metadata/glsa/glsa-200705-09.xml +++ b/metadata/glsa/glsa-200705-09.xml @@ -1,7 +1,7 @@ - IPsec-Tools: Denial of Service + IPsec-Tools: Denial of service IPsec-Tools contains a vulnerability that allows a remote attacker to crash the IPsec tunnel. diff --git a/metadata/glsa/glsa-200705-24.xml b/metadata/glsa/glsa-200705-24.xml index 6479d816edf4..de581b3b95c7 100644 --- a/metadata/glsa/glsa-200705-24.xml +++ b/metadata/glsa/glsa-200705-24.xml @@ -1,7 +1,7 @@ - libpng: Denial of Service + libpng: Denial of service A vulnerability in libpng may allow a remote attacker to crash applications that handle untrusted images. diff --git a/metadata/glsa/glsa-200707-13.xml b/metadata/glsa/glsa-200707-13.xml index ce5738fe4381..b45386622549 100644 --- a/metadata/glsa/glsa-200707-13.xml +++ b/metadata/glsa/glsa-200707-13.xml @@ -1,7 +1,7 @@ - Fail2ban: Denial of Service + Fail2ban: Denial of service Fail2ban is vulnerable to a Denial of Service attack. diff --git a/metadata/glsa/glsa-200708-04.xml b/metadata/glsa/glsa-200708-04.xml index 6a40c425140e..6dfe88cabe89 100644 --- a/metadata/glsa/glsa-200708-04.xml +++ b/metadata/glsa/glsa-200708-04.xml @@ -1,7 +1,7 @@ - ClamAV: Denial of Service + ClamAV: Denial of service A vulnerability has been discovered in ClamAV, allowing for a Denial of Service. diff --git a/metadata/glsa/glsa-200708-14.xml b/metadata/glsa/glsa-200708-14.xml index c508dda3b743..99f8ebbbac13 100644 --- a/metadata/glsa/glsa-200708-14.xml +++ b/metadata/glsa/glsa-200708-14.xml @@ -1,7 +1,7 @@ - NVIDIA drivers: Denial of Service + NVIDIA drivers: Denial of service A vulnerability has been discovered in the NVIDIA graphic drivers, allowing for a Denial of Service. diff --git a/metadata/glsa/glsa-200709-11.xml b/metadata/glsa/glsa-200709-11.xml index 08bd14227daa..9eafab06f7b3 100644 --- a/metadata/glsa/glsa-200709-11.xml +++ b/metadata/glsa/glsa-200709-11.xml @@ -1,7 +1,7 @@ - GDM: Local Denial of Service + GDM: Local Denial of service GDM can be crashed by a local user, preventing it from managing future displays. diff --git a/metadata/glsa/glsa-200710-14.xml b/metadata/glsa/glsa-200710-14.xml index 43b9e66728ca..62556ffae5c1 100644 --- a/metadata/glsa/glsa-200710-14.xml +++ b/metadata/glsa/glsa-200710-14.xml @@ -1,7 +1,7 @@ - DenyHosts: Denial of Service + DenyHosts: Denial of service DenyHosts does not correctly parse log entries, potentially causing a remote Denial of Service. diff --git a/metadata/glsa/glsa-200711-09.xml b/metadata/glsa/glsa-200711-09.xml index 74f22b4a6197..d1157db45683 100644 --- a/metadata/glsa/glsa-200711-09.xml +++ b/metadata/glsa/glsa-200711-09.xml @@ -1,7 +1,7 @@ - MadWifi: Denial of Service + MadWifi: Denial of service MadWifi does not correctly process beacon frames which can lead to a remotely triggered Denial of Service. diff --git a/metadata/glsa/glsa-200711-13.xml b/metadata/glsa/glsa-200711-13.xml index 173e6eee7242..b5fae92bd609 100644 --- a/metadata/glsa/glsa-200711-13.xml +++ b/metadata/glsa/glsa-200711-13.xml @@ -1,7 +1,7 @@ - 3proxy: Denial of Service + 3proxy: Denial of service A vulnerability has been discovered in 3proxy, possibly resulting in a Denial of Service. diff --git a/metadata/glsa/glsa-200711-25.xml b/metadata/glsa/glsa-200711-25.xml index 76d1de6e64af..2f8d6ecd0695 100644 --- a/metadata/glsa/glsa-200711-25.xml +++ b/metadata/glsa/glsa-200711-25.xml @@ -1,7 +1,7 @@ - MySQL: Denial of Service + MySQL: Denial of service A Denial of Service vulnerability was found in MySQL. diff --git a/metadata/glsa/glsa-200711-31.xml b/metadata/glsa/glsa-200711-31.xml index 648863f135b3..c2ad71fe7458 100644 --- a/metadata/glsa/glsa-200711-31.xml +++ b/metadata/glsa/glsa-200711-31.xml @@ -1,7 +1,7 @@ - Net-SNMP: Denial of Service + Net-SNMP: Denial of service A Denial of Service vulnerability has been discovered in Net-SNMP when processing GETBULK requests. diff --git a/metadata/glsa/glsa-200712-12.xml b/metadata/glsa/glsa-200712-12.xml index 7c3efd5ec3d3..80c56b18117f 100644 --- a/metadata/glsa/glsa-200712-12.xml +++ b/metadata/glsa/glsa-200712-12.xml @@ -1,7 +1,7 @@ - IRC Services: Denial of Service + IRC Services: Denial of service A Denial of Service vulnerability has been reported in IRC Services. diff --git a/metadata/glsa/glsa-200712-19.xml b/metadata/glsa/glsa-200712-19.xml index 0f6a2b97d9db..0068fec39b4f 100644 --- a/metadata/glsa/glsa-200712-19.xml +++ b/metadata/glsa/glsa-200712-19.xml @@ -1,7 +1,7 @@ - Syslog-ng: Denial of Service + Syslog-ng: Denial of service A Denial of Service vulnerability has been discovered in Syslog-ng. diff --git a/metadata/glsa/glsa-200801-04.xml b/metadata/glsa/glsa-200801-04.xml index d3e4a272fcae..8cfc9c9fd331 100644 --- a/metadata/glsa/glsa-200801-04.xml +++ b/metadata/glsa/glsa-200801-04.xml @@ -1,7 +1,7 @@ - OpenAFS: Denial of Service + OpenAFS: Denial of service A Denial of Service vulnerability has been discovered in OpenAFS. diff --git a/metadata/glsa/glsa-200801-05.xml b/metadata/glsa/glsa-200801-05.xml index b859a1c011ad..f24ca70c440e 100644 --- a/metadata/glsa/glsa-200801-05.xml +++ b/metadata/glsa/glsa-200801-05.xml @@ -1,7 +1,7 @@ - Squid: Denial of Service + Squid: Denial of service A Denial of Service vulnerability has been reported in Squid. diff --git a/metadata/glsa/glsa-200801-13.xml b/metadata/glsa/glsa-200801-13.xml index 3ebdb971b514..387976aae92a 100644 --- a/metadata/glsa/glsa-200801-13.xml +++ b/metadata/glsa/glsa-200801-13.xml @@ -1,7 +1,7 @@ - ngIRCd: Denial of Service + ngIRCd: Denial of service ngIRCd does not properly sanitize commands sent by users, allowing for a Denial of Service. diff --git a/metadata/glsa/glsa-200801-16.xml b/metadata/glsa/glsa-200801-16.xml index 875199ea735d..1613eb45402a 100644 --- a/metadata/glsa/glsa-200801-16.xml +++ b/metadata/glsa/glsa-200801-16.xml @@ -1,7 +1,7 @@ - MaraDNS: CNAME Denial of Service + MaraDNS: CNAME Denial of service MaraDNS is prone to a Denial of Service vulnerability impacting CNAME resolution. diff --git a/metadata/glsa/glsa-200801-17.xml b/metadata/glsa/glsa-200801-17.xml index 9e4f8f009df0..641d7c5e38eb 100644 --- a/metadata/glsa/glsa-200801-17.xml +++ b/metadata/glsa/glsa-200801-17.xml @@ -1,7 +1,7 @@ - Netkit FTP Server: Denial of Service + Netkit FTP Server: Denial of service Netkit FTP Server contains a Denial of Service vulnerability. diff --git a/metadata/glsa/glsa-200801-20.xml b/metadata/glsa/glsa-200801-20.xml index d46c67897e1a..a69133598099 100644 --- a/metadata/glsa/glsa-200801-20.xml +++ b/metadata/glsa/glsa-200801-20.xml @@ -1,7 +1,7 @@ - libxml2: Denial of Service + libxml2: Denial of service A Denial of Service vulnerability has been reported in libxml2. diff --git a/metadata/glsa/glsa-200802-08.xml b/metadata/glsa/glsa-200802-08.xml index 60f2a9054fb0..34f5fae29037 100644 --- a/metadata/glsa/glsa-200802-08.xml +++ b/metadata/glsa/glsa-200802-08.xml @@ -1,7 +1,7 @@ - Boost: Denial of Service + Boost: Denial of service Two vulnerabilities have been reported in Boost, each one possibly resulting in a Denial of Service. diff --git a/metadata/glsa/glsa-200803-22.xml b/metadata/glsa/glsa-200803-22.xml index 00c1b30f8e06..9e0f0c951545 100644 --- a/metadata/glsa/glsa-200803-22.xml +++ b/metadata/glsa/glsa-200803-22.xml @@ -1,7 +1,7 @@ - LIVE555 Media Server: Denial of Service + LIVE555 Media Server: Denial of service A Denial of Service vulnerability has been reported in LIVE555 Media Server. diff --git a/metadata/glsa/glsa-200803-32.xml b/metadata/glsa/glsa-200803-32.xml index cc5d432c4425..daa30e74884b 100644 --- a/metadata/glsa/glsa-200803-32.xml +++ b/metadata/glsa/glsa-200803-32.xml @@ -1,7 +1,7 @@ - Wireshark: Denial of Service + Wireshark: Denial of service Multiple Denial of Service vulnerabilities have been discovered in Wireshark. diff --git a/metadata/glsa/glsa-200804-02.xml b/metadata/glsa/glsa-200804-02.xml index 29c40528257a..c6f4d547caf2 100644 --- a/metadata/glsa/glsa-200804-02.xml +++ b/metadata/glsa/glsa-200804-02.xml @@ -1,7 +1,7 @@ - bzip2: Denial of Service + bzip2: Denial of service A buffer overread vulnerability has been discovered in Bzip2. diff --git a/metadata/glsa/glsa-200804-19.xml b/metadata/glsa/glsa-200804-19.xml index ec5409c1e7c5..44b2e4776143 100644 --- a/metadata/glsa/glsa-200804-19.xml +++ b/metadata/glsa/glsa-200804-19.xml @@ -1,7 +1,7 @@ - PHP Toolkit: Data disclosure and Denial of Service + PHP Toolkit: Data disclosure and Denial of service PHP Toolkit does not quote parameters, allowing for PHP source code disclosure on Apache, and a Denial of Service. diff --git a/metadata/glsa/glsa-200804-26.xml b/metadata/glsa/glsa-200804-26.xml index 152bb1ead851..9ef461493335 100644 --- a/metadata/glsa/glsa-200804-26.xml +++ b/metadata/glsa/glsa-200804-26.xml @@ -1,7 +1,7 @@ - Openfire: Denial of Service + Openfire: Denial of service A design error in Openfire might lead to a Denial of Service. diff --git a/metadata/glsa/glsa-200805-05.xml b/metadata/glsa/glsa-200805-05.xml index e10026a9b88b..ee55e151f114 100644 --- a/metadata/glsa/glsa-200805-05.xml +++ b/metadata/glsa/glsa-200805-05.xml @@ -1,7 +1,7 @@ - Wireshark: Denial of Service + Wireshark: Denial of service Multiple Denial of Service vulnerabilities have been discovered in Wireshark. diff --git a/metadata/glsa/glsa-200805-08.xml b/metadata/glsa/glsa-200805-08.xml index b966afc4e59d..02e9b524981b 100644 --- a/metadata/glsa/glsa-200805-08.xml +++ b/metadata/glsa/glsa-200805-08.xml @@ -1,7 +1,7 @@ - InspIRCd: Denial of Service + InspIRCd: Denial of service A buffer overflow in InspIRCd allows remote attackers to cause a Denial of Service. diff --git a/metadata/glsa/glsa-200805-15.xml b/metadata/glsa/glsa-200805-15.xml index 8b7c2bfc9fb2..96643bbef636 100644 --- a/metadata/glsa/glsa-200805-15.xml +++ b/metadata/glsa/glsa-200805-15.xml @@ -1,7 +1,7 @@ - libid3tag: Denial of Service + libid3tag: Denial of service A Denial of Service vulnerability was found in libid3tag. diff --git a/metadata/glsa/glsa-200806-08.xml b/metadata/glsa/glsa-200806-08.xml index 07c01edbacde..d0c5a77a546c 100644 --- a/metadata/glsa/glsa-200806-08.xml +++ b/metadata/glsa/glsa-200806-08.xml @@ -1,7 +1,7 @@ - OpenSSL: Denial of Service + OpenSSL: Denial of service Two vulnerabilities might allow for a Denial of Service of daemons using OpenSSL. diff --git a/metadata/glsa/glsa-200807-06.xml b/metadata/glsa/glsa-200807-06.xml index 6febbf8e29f7..4c8f81534f99 100644 --- a/metadata/glsa/glsa-200807-06.xml +++ b/metadata/glsa/glsa-200807-06.xml @@ -1,7 +1,7 @@ - Apache: Denial of Service + Apache: Denial of service Multiple vulnerabilities in Apache might lead to a Denial of Service. diff --git a/metadata/glsa/glsa-200808-04.xml b/metadata/glsa/glsa-200808-04.xml index 65dc75fa103e..56e32abcfdd5 100644 --- a/metadata/glsa/glsa-200808-04.xml +++ b/metadata/glsa/glsa-200808-04.xml @@ -1,7 +1,7 @@ - Wireshark: Denial of Service + Wireshark: Denial of service Multiple Denial of Service vulnerabilities have been discovered in Wireshark. diff --git a/metadata/glsa/glsa-200808-05.xml b/metadata/glsa/glsa-200808-05.xml index 7ca04ba842bc..eb4a3291baf8 100644 --- a/metadata/glsa/glsa-200808-05.xml +++ b/metadata/glsa/glsa-200808-05.xml @@ -1,7 +1,7 @@ - ISC DHCP: Denial of Service + ISC DHCP: Denial of service A Denial of Service vulnerability was discovered in ISC DHCP. diff --git a/metadata/glsa/glsa-200809-09.xml b/metadata/glsa/glsa-200809-09.xml index 86b8b82925b1..dbcb6a4033c7 100644 --- a/metadata/glsa/glsa-200809-09.xml +++ b/metadata/glsa/glsa-200809-09.xml @@ -1,7 +1,7 @@ - Postfix: Denial of Service + Postfix: Denial of service A memory leak in Postfix might allow local users to cause a Denial of Service. diff --git a/metadata/glsa/glsa-200809-11.xml b/metadata/glsa/glsa-200809-11.xml index d2b3e8b6ed4f..d52daa78b562 100644 --- a/metadata/glsa/glsa-200809-11.xml +++ b/metadata/glsa/glsa-200809-11.xml @@ -1,7 +1,7 @@ - HAVP: Denial of Service + HAVP: Denial of service A Denial of Service vulnerability has been reported in HAVP. diff --git a/metadata/glsa/glsa-200812-03.xml b/metadata/glsa/glsa-200812-03.xml index 64a9b2625c2a..18468b710ee8 100644 --- a/metadata/glsa/glsa-200812-03.xml +++ b/metadata/glsa/glsa-200812-03.xml @@ -1,7 +1,7 @@ - IPsec-Tools: racoon Denial of Service + IPsec-Tools: racoon Denial of service IPsec-Tools' racoon is affected by a remote Denial of Service vulnerability. diff --git a/metadata/glsa/glsa-200901-04.xml b/metadata/glsa/glsa-200901-04.xml index db1df4fc4468..216cca9b518a 100644 --- a/metadata/glsa/glsa-200901-04.xml +++ b/metadata/glsa/glsa-200901-04.xml @@ -1,7 +1,7 @@ - D-Bus: Denial of Service + D-Bus: Denial of service An error condition can cause D-Bus to crash. diff --git a/metadata/glsa/glsa-200901-11.xml b/metadata/glsa/glsa-200901-11.xml index 3321fd6e7ec3..4a5984b72073 100644 --- a/metadata/glsa/glsa-200901-11.xml +++ b/metadata/glsa/glsa-200901-11.xml @@ -1,7 +1,7 @@ - Avahi: Denial of Service + Avahi: Denial of service A Denial of Service vulnerability has been discovered in Avahi. diff --git a/metadata/glsa/glsa-200901-15.xml b/metadata/glsa/glsa-200901-15.xml index 41fba986c05b..f76b93c35a96 100644 --- a/metadata/glsa/glsa-200901-15.xml +++ b/metadata/glsa/glsa-200901-15.xml @@ -1,7 +1,7 @@ - Net-SNMP: Denial of Service + Net-SNMP: Denial of service A vulnerability in Net-SNMP could lead to a Denial of Service. diff --git a/metadata/glsa/glsa-200903-13.xml b/metadata/glsa/glsa-200903-13.xml index d80632989601..fc0f88cdaa94 100644 --- a/metadata/glsa/glsa-200903-13.xml +++ b/metadata/glsa/glsa-200903-13.xml @@ -1,7 +1,7 @@ - MPFR: Denial of Service + MPFR: Denial of service Multiple buffer overflows in MPFR might lead to a Denial of Service. diff --git a/metadata/glsa/glsa-200903-19.xml b/metadata/glsa/glsa-200903-19.xml index ad6e89cfac94..695675b08787 100644 --- a/metadata/glsa/glsa-200903-19.xml +++ b/metadata/glsa/glsa-200903-19.xml @@ -1,7 +1,7 @@ - Xerces-C++: Denial of Service + Xerces-C++: Denial of service An error in Xerces-C++ allows for a Denial of Service via malicious XML schema files. diff --git a/metadata/glsa/glsa-200903-40.xml b/metadata/glsa/glsa-200903-40.xml index 5f8c75c50b8c..2cebd0751ef6 100644 --- a/metadata/glsa/glsa-200903-40.xml +++ b/metadata/glsa/glsa-200903-40.xml @@ -1,7 +1,7 @@ - Analog: Denial of Service + Analog: Denial of service A Denial of Service vulnerability was discovered in Analog. diff --git a/metadata/glsa/glsa-200904-04.xml b/metadata/glsa/glsa-200904-04.xml index 6c52deb11a50..872ca9feab6c 100644 --- a/metadata/glsa/glsa-200904-04.xml +++ b/metadata/glsa/glsa-200904-04.xml @@ -1,7 +1,7 @@ - WeeChat: Denial of Service + WeeChat: Denial of service A processing error in WeeChat might lead to a Denial of Service. diff --git a/metadata/glsa/glsa-200904-08.xml b/metadata/glsa/glsa-200904-08.xml index f3139bf89b68..fc552913629c 100644 --- a/metadata/glsa/glsa-200904-08.xml +++ b/metadata/glsa/glsa-200904-08.xml @@ -1,7 +1,7 @@ - OpenSSL: Denial of Service + OpenSSL: Denial of service An error in OpenSSL might allow for a Denial of Service when printing certificate details. diff --git a/metadata/glsa/glsa-200904-10.xml b/metadata/glsa/glsa-200904-10.xml index 193c67427b65..fcb96cd0ec23 100644 --- a/metadata/glsa/glsa-200904-10.xml +++ b/metadata/glsa/glsa-200904-10.xml @@ -1,7 +1,7 @@ - Avahi: Denial of Service + Avahi: Denial of service An error in Avahi might lead to a Denial of Service via network and CPU consumption. diff --git a/metadata/glsa/glsa-200904-13.xml b/metadata/glsa/glsa-200904-13.xml index 9764bf941537..ae0a94d91eaf 100644 --- a/metadata/glsa/glsa-200904-13.xml +++ b/metadata/glsa/glsa-200904-13.xml @@ -1,7 +1,7 @@ - Ventrilo: Denial of Service + Ventrilo: Denial of service A vulnerability has been discovered in Ventrilo, allowing for a Denial of Service. diff --git a/metadata/glsa/glsa-200905-03.xml b/metadata/glsa/glsa-200905-03.xml index 75e027433cf4..df09584c4182 100644 --- a/metadata/glsa/glsa-200905-03.xml +++ b/metadata/glsa/glsa-200905-03.xml @@ -1,7 +1,7 @@ - IPSec Tools: Denial of Service + IPSec Tools: Denial of service Multiple errors in the IPSec Tools racoon daemon might allow remote attackers to cause a Denial of Service. diff --git a/metadata/glsa/glsa-200905-06.xml b/metadata/glsa/glsa-200905-06.xml index f0daa27a2704..714676172cbe 100644 --- a/metadata/glsa/glsa-200905-06.xml +++ b/metadata/glsa/glsa-200905-06.xml @@ -1,7 +1,7 @@ - acpid: Denial of Service + acpid: Denial of service An error in acpid might allow remote attackers to cause a Denial of Service. diff --git a/metadata/glsa/glsa-200906-02.xml b/metadata/glsa/glsa-200906-02.xml index 9a9e750e1aa2..257a1415bd69 100644 --- a/metadata/glsa/glsa-200906-02.xml +++ b/metadata/glsa/glsa-200906-02.xml @@ -1,7 +1,7 @@ - Ruby: Denial of Service + Ruby: Denial of service A flaw in the Ruby standard library might allow remote attackers to cause a Denial of Service attack. diff --git a/metadata/glsa/glsa-200907-02.xml b/metadata/glsa/glsa-200907-02.xml index d9211d2c82bc..beec6bcaba1b 100644 --- a/metadata/glsa/glsa-200907-02.xml +++ b/metadata/glsa/glsa-200907-02.xml @@ -1,7 +1,7 @@ - ModSecurity: Denial of Service + ModSecurity: Denial of service Two vulnerabilities in ModSecurity might lead to a Denial of Service. diff --git a/metadata/glsa/glsa-200907-05.xml b/metadata/glsa/glsa-200907-05.xml index 265b7af3e63c..d506ec04c3a6 100644 --- a/metadata/glsa/glsa-200907-05.xml +++ b/metadata/glsa/glsa-200907-05.xml @@ -1,7 +1,7 @@ - git: git-daemon Denial of Service + git: git-daemon Denial of service An error in git-daemon might lead to a Denial of Service via resource consumption. diff --git a/metadata/glsa/glsa-200908-02.xml b/metadata/glsa/glsa-200908-02.xml index 71c2cc9cba59..77eac4fc16cb 100644 --- a/metadata/glsa/glsa-200908-02.xml +++ b/metadata/glsa/glsa-200908-02.xml @@ -1,7 +1,7 @@ - BIND: Denial of Service + BIND: Denial of service Dynamic Update packets can cause a Denial of Service in the BIND daemon. diff --git a/metadata/glsa/glsa-200908-07.xml b/metadata/glsa/glsa-200908-07.xml index d6fea11da9bc..5a3d87de1b7c 100644 --- a/metadata/glsa/glsa-200908-07.xml +++ b/metadata/glsa/glsa-200908-07.xml @@ -1,7 +1,7 @@ - Perl Compress::Raw modules: Denial of Service + Perl Compress::Raw modules: Denial of service An off-by-one error in Compress::Raw::Zlib and Compress::Raw::Bzip2 might lead to a Denial of Service. diff --git a/metadata/glsa/glsa-200908-08.xml b/metadata/glsa/glsa-200908-08.xml index 0ccedf026c92..4b5a418e2861 100644 --- a/metadata/glsa/glsa-200908-08.xml +++ b/metadata/glsa/glsa-200908-08.xml @@ -1,7 +1,7 @@ - ISC DHCP: dhcpd Denial of Service + ISC DHCP: dhcpd Denial of service dhcpd as included in the ISC DHCP implementation does not properly handle special conditions, leading to a Denial of Service. diff --git a/metadata/glsa/glsa-200909-05.xml b/metadata/glsa/glsa-200909-05.xml index 40704e5ada01..a398bc011ea5 100644 --- a/metadata/glsa/glsa-200909-05.xml +++ b/metadata/glsa/glsa-200909-05.xml @@ -1,7 +1,7 @@ - Openswan: Denial of Service + Openswan: Denial of service Multiple vulnerabilities in the pluto IKE daemon of Openswan might allow remote attackers to cause a Denial of Service. diff --git a/metadata/glsa/glsa-200909-16.xml b/metadata/glsa/glsa-200909-16.xml index 851049fae14b..64761d810ec6 100644 --- a/metadata/glsa/glsa-200909-16.xml +++ b/metadata/glsa/glsa-200909-16.xml @@ -1,7 +1,7 @@ - Wireshark: Denial of Service + Wireshark: Denial of service Multiple vulnerabilities have been discovered in Wireshark which allow for Denial of Service. diff --git a/metadata/glsa/glsa-201001-01.xml b/metadata/glsa/glsa-201001-01.xml index fb7fd3c0c5b1..a46349146899 100644 --- a/metadata/glsa/glsa-201001-01.xml +++ b/metadata/glsa/glsa-201001-01.xml @@ -1,7 +1,7 @@ - NTP: Denial of Service + NTP: Denial of service A Denial of Service condition in ntpd can cause excessive CPU or bandwidth consumption. diff --git a/metadata/glsa/glsa-201006-17.xml b/metadata/glsa/glsa-201006-17.xml index ab4d122e4506..32888ad18ae2 100644 --- a/metadata/glsa/glsa-201006-17.xml +++ b/metadata/glsa/glsa-201006-17.xml @@ -1,7 +1,7 @@ - lighttpd: Denial of Service + lighttpd: Denial of service A processing error in lighttpd might result in a Denial of Service condition. diff --git a/metadata/glsa/glsa-201009-07.xml b/metadata/glsa/glsa-201009-07.xml index 46008757c7cf..1500716099c6 100644 --- a/metadata/glsa/glsa-201009-07.xml +++ b/metadata/glsa/glsa-201009-07.xml @@ -1,7 +1,7 @@ - libxml2: Denial of Service + libxml2: Denial of service Multiple Denial of Services vulnerabilities were found in libxml2. diff --git a/metadata/glsa/glsa-201110-07.xml b/metadata/glsa/glsa-201110-07.xml index 9a25d95636cd..8d7182803f22 100644 --- a/metadata/glsa/glsa-201110-07.xml +++ b/metadata/glsa/glsa-201110-07.xml @@ -1,7 +1,7 @@ - vsftpd: Denial of Service + vsftpd: Denial of service A Denial of Service vulnerability was found in vsftpd. vsftpd 2011-10-10 diff --git a/metadata/glsa/glsa-201110-12.xml b/metadata/glsa/glsa-201110-12.xml index 7062b518450b..90c706220115 100644 --- a/metadata/glsa/glsa-201110-12.xml +++ b/metadata/glsa/glsa-201110-12.xml @@ -1,7 +1,7 @@ - Unbound: Denial of Service + Unbound: Denial of service Multiple Denial of Service vulnerabilities were found in Unbound. unbound 2011-10-15 diff --git a/metadata/glsa/glsa-201110-17.xml b/metadata/glsa/glsa-201110-17.xml index ea0e65c2c6b5..47fefb9d0311 100644 --- a/metadata/glsa/glsa-201110-17.xml +++ b/metadata/glsa/glsa-201110-17.xml @@ -1,7 +1,7 @@ - Avahi: Denial of Service + Avahi: Denial of service Multiple vulnerabilities were found in Avahi, allowing for Denial of Service. diff --git a/metadata/glsa/glsa-201202-03.xml b/metadata/glsa/glsa-201202-03.xml index 3baeb6dd9e4b..0da4cebd6ca4 100644 --- a/metadata/glsa/glsa-201202-03.xml +++ b/metadata/glsa/glsa-201202-03.xml @@ -1,7 +1,7 @@ - MaraDNS: Denial of Service + MaraDNS: Denial of service A hash collision vulnerability in MaraDNS allows remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201202-04.xml b/metadata/glsa/glsa-201202-04.xml index 280556e84d85..96096d809071 100644 --- a/metadata/glsa/glsa-201202-04.xml +++ b/metadata/glsa/glsa-201202-04.xml @@ -1,7 +1,7 @@ - PowerDNS: Denial of Service + PowerDNS: Denial of service A vulnerability in PowerDNS could allow a remote attacker to create a Denial of Service condition. diff --git a/metadata/glsa/glsa-201202-06.xml b/metadata/glsa/glsa-201202-06.xml index 18e40c3c20ff..f840c259f877 100644 --- a/metadata/glsa/glsa-201202-06.xml +++ b/metadata/glsa/glsa-201202-06.xml @@ -1,7 +1,7 @@ - Asterisk: Denial of Service + Asterisk: Denial of service A vulnerability in Asterisk could allow a remote attacker to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201203-04.xml b/metadata/glsa/glsa-201203-04.xml index 0c57f9328661..a7d5a7b85283 100644 --- a/metadata/glsa/glsa-201203-04.xml +++ b/metadata/glsa/glsa-201203-04.xml @@ -1,7 +1,7 @@ - libxml2: Denial of Service + libxml2: Denial of service A hash collision vulnerability in libxml2 allows remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201203-05.xml b/metadata/glsa/glsa-201203-05.xml index 95ac56dff1c5..17d12d9339ed 100644 --- a/metadata/glsa/glsa-201203-05.xml +++ b/metadata/glsa/glsa-201203-05.xml @@ -1,7 +1,7 @@ - Rack: Denial of Service + Rack: Denial of service A hash collision vulnerability in Rack allows remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201203-08.xml b/metadata/glsa/glsa-201203-08.xml index 0911c0469772..bba0509f08e8 100644 --- a/metadata/glsa/glsa-201203-08.xml +++ b/metadata/glsa/glsa-201203-08.xml @@ -1,7 +1,7 @@ - libxslt: Denial of Service + libxslt: Denial of service A vulnerability in libxslt could result in Denial of Service. libxslt 2012-03-06 diff --git a/metadata/glsa/glsa-201203-13.xml b/metadata/glsa/glsa-201203-13.xml index b276e279908d..98d1f6edf966 100644 --- a/metadata/glsa/glsa-201203-13.xml +++ b/metadata/glsa/glsa-201203-13.xml @@ -1,7 +1,7 @@ - Openswan: Denial of Service + Openswan: Denial of service Multiple vulnerabilities in Openswan may create a Denial of Service condition. diff --git a/metadata/glsa/glsa-201206-20.xml b/metadata/glsa/glsa-201206-20.xml index aeda09bcb145..ac53364d11b2 100644 --- a/metadata/glsa/glsa-201206-20.xml +++ b/metadata/glsa/glsa-201206-20.xml @@ -1,7 +1,7 @@ - gdk-pixbuf: Denial of Service + gdk-pixbuf: Denial of service Multiple vulnerabilities in gdk-pixbuf may create a Denial of Service condition. diff --git a/metadata/glsa/glsa-201207-06.xml b/metadata/glsa/glsa-201207-06.xml index fc5aef2fcaa8..3e4ce1c21d84 100644 --- a/metadata/glsa/glsa-201207-06.xml +++ b/metadata/glsa/glsa-201207-06.xml @@ -1,7 +1,7 @@ - JRuby: Denial of Service + JRuby: Denial of service A hash collision vulnerability in JRuby allows remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201207-07.xml b/metadata/glsa/glsa-201207-07.xml index b7b19be392a4..1dbaabc34817 100644 --- a/metadata/glsa/glsa-201207-07.xml +++ b/metadata/glsa/glsa-201207-07.xml @@ -1,7 +1,7 @@ - Keepalived: Denial of Service + Keepalived: Denial of service Keepalived uses world-writable PID files, allowing a local attacker to kill arbitrary processes. diff --git a/metadata/glsa/glsa-201209-08.xml b/metadata/glsa/glsa-201209-08.xml index 320c8db03717..e051dc3d8bb5 100644 --- a/metadata/glsa/glsa-201209-08.xml +++ b/metadata/glsa/glsa-201209-08.xml @@ -1,7 +1,7 @@ - SquidClamav: Denial of Service + SquidClamav: Denial of service A vulnerability in SquidClamav may result in Denial of Service. squidclamav 2012-09-24 diff --git a/metadata/glsa/glsa-201209-09.xml b/metadata/glsa/glsa-201209-09.xml index 516acf6ab69e..33a7516c26cc 100644 --- a/metadata/glsa/glsa-201209-09.xml +++ b/metadata/glsa/glsa-201209-09.xml @@ -1,7 +1,7 @@ - Atheme IRC Services: Denial of Service + Atheme IRC Services: Denial of service A vulnerability has been found in Atheme which may lead to Denial of Service or a bypass of security restrictions. diff --git a/metadata/glsa/glsa-201209-12.xml b/metadata/glsa/glsa-201209-12.xml index 6d3624bc4366..8fefa8855908 100644 --- a/metadata/glsa/glsa-201209-12.xml +++ b/metadata/glsa/glsa-201209-12.xml @@ -1,7 +1,7 @@ - Libtasn1: Denial of Service + Libtasn1: Denial of service A vulnerability in Libtasn1 might cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201209-14.xml b/metadata/glsa/glsa-201209-14.xml index 2e41c9e63e78..16c0ffb00f44 100644 --- a/metadata/glsa/glsa-201209-14.xml +++ b/metadata/glsa/glsa-201209-14.xml @@ -1,7 +1,7 @@ - file: Denial of Service + file: Denial of service A vulnerability in file could result in Denial of Service. file 2012-09-26 diff --git a/metadata/glsa/glsa-201209-20.xml b/metadata/glsa/glsa-201209-20.xml index 19cf6109fea6..69c91c77d8ec 100644 --- a/metadata/glsa/glsa-201209-20.xml +++ b/metadata/glsa/glsa-201209-20.xml @@ -1,7 +1,7 @@ - mod_rpaf: Denial of Service + mod_rpaf: Denial of service A vulnerability in mod_rpaf may result in Denial of Service. mod_rpaf 2012-09-27 diff --git a/metadata/glsa/glsa-201301-06.xml b/metadata/glsa/glsa-201301-06.xml index c51e55f944cb..612b1dbab7e7 100644 --- a/metadata/glsa/glsa-201301-06.xml +++ b/metadata/glsa/glsa-201301-06.xml @@ -1,7 +1,7 @@ - ISC DHCP: Denial of Service + ISC DHCP: Denial of service Multiple vulnerabilities have been found in ISC DHCP, the worst of which may allow remote Denial of Service. diff --git a/metadata/glsa/glsa-201308-02.xml b/metadata/glsa/glsa-201308-02.xml index bab7fa6e14c0..f5a0b5daebb0 100644 --- a/metadata/glsa/glsa-201308-02.xml +++ b/metadata/glsa/glsa-201308-02.xml @@ -1,7 +1,7 @@ - D-Bus: Denial of Service + D-Bus: Denial of service A vulnerability has been found in D-Bus which allows a local user to cause a Denial of Service. diff --git a/metadata/glsa/glsa-201309-01.xml b/metadata/glsa/glsa-201309-01.xml index 1bf4114b17b2..658ec5e207ff 100644 --- a/metadata/glsa/glsa-201309-01.xml +++ b/metadata/glsa/glsa-201309-01.xml @@ -1,7 +1,7 @@ - Cyrus-SASL: Denial of Service + Cyrus-SASL: Denial of service A NULL pointer dereference in Cyrus-SASL may allow remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201309-03.xml b/metadata/glsa/glsa-201309-03.xml index 983ce843dd94..8625528ca7c5 100644 --- a/metadata/glsa/glsa-201309-03.xml +++ b/metadata/glsa/glsa-201309-03.xml @@ -1,7 +1,7 @@ - Xlockmore: Denial of Service + Xlockmore: Denial of service A buffer overflow in Xlockmore might allow remote attackers to cause a Denial of Service. diff --git a/metadata/glsa/glsa-201311-04.xml b/metadata/glsa/glsa-201311-04.xml index e1730eca2635..f32c058f879f 100644 --- a/metadata/glsa/glsa-201311-04.xml +++ b/metadata/glsa/glsa-201311-04.xml @@ -1,7 +1,7 @@ - Vixie cron: Denial of Service + Vixie cron: Denial of service A vulnerability has been found in Vixie cron, allowing local attackers to conduct symlink attacks. diff --git a/metadata/glsa/glsa-201311-18.xml b/metadata/glsa/glsa-201311-18.xml index 799c3ecf5650..7d4c35954ae4 100644 --- a/metadata/glsa/glsa-201311-18.xml +++ b/metadata/glsa/glsa-201311-18.xml @@ -1,7 +1,7 @@ - Unbound: Denial of Service + Unbound: Denial of service Multiple Denial of Service vulnerabilities have been found in Unbound. diff --git a/metadata/glsa/glsa-201312-15.xml b/metadata/glsa/glsa-201312-15.xml index 88f6a6288a04..027a038d19b9 100644 --- a/metadata/glsa/glsa-201312-15.xml +++ b/metadata/glsa/glsa-201312-15.xml @@ -1,7 +1,7 @@ - Tinyproxy: Denial of Service + Tinyproxy: Denial of service A vulnerability has been found in Tinyproxy, allows remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201401-05.xml b/metadata/glsa/glsa-201401-05.xml index 2e856e71a1ae..e0504d2e700a 100644 --- a/metadata/glsa/glsa-201401-05.xml +++ b/metadata/glsa/glsa-201401-05.xml @@ -1,7 +1,7 @@ - ISC DHCP: Denial of Service + ISC DHCP: Denial of service A memory exhaustion vulnerability in ISC DHCP could lead to Denial of Service. diff --git a/metadata/glsa/glsa-201401-07.xml b/metadata/glsa/glsa-201401-07.xml index c0e733e08325..d7b49ab80cf5 100644 --- a/metadata/glsa/glsa-201401-07.xml +++ b/metadata/glsa/glsa-201401-07.xml @@ -1,7 +1,7 @@ - libxslt: Denial of Service + libxslt: Denial of service Multiple Denial of Service vulnerabilities have been found in libxslt. diff --git a/metadata/glsa/glsa-201401-34.xml b/metadata/glsa/glsa-201401-34.xml index bba64bbbcf34..9c7660a1ef4c 100644 --- a/metadata/glsa/glsa-201401-34.xml +++ b/metadata/glsa/glsa-201401-34.xml @@ -1,7 +1,7 @@ - BIND: Denial of Service + BIND: Denial of service Multiple vulnerabilities have been found in BIND, possibly resulting in Denial of Service. diff --git a/metadata/glsa/glsa-201402-11.xml b/metadata/glsa/glsa-201402-11.xml index 3b42a11ed900..32b8a6329541 100644 --- a/metadata/glsa/glsa-201402-11.xml +++ b/metadata/glsa/glsa-201402-11.xml @@ -1,7 +1,7 @@ - Links: Denial of Service + Links: Denial of service An integer overflow in Links might allow remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201402-14.xml b/metadata/glsa/glsa-201402-14.xml index f1c8a0032b98..ffb27ce0e459 100644 --- a/metadata/glsa/glsa-201402-14.xml +++ b/metadata/glsa/glsa-201402-14.xml @@ -1,7 +1,7 @@ - International Components for Unicode: Denial of Service + International Components for Unicode: Denial of service Two vulnerabilities in International Components for Unicode might allow remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201402-25.xml b/metadata/glsa/glsa-201402-25.xml index e4bd8e090e1a..927714d1a986 100644 --- a/metadata/glsa/glsa-201402-25.xml +++ b/metadata/glsa/glsa-201402-25.xml @@ -1,7 +1,7 @@ - OpenSSL: Denial of Service + OpenSSL: Denial of service A vulnerability in OpenSSL's handling of TLS handshakes could result in a Denial of Service condition. diff --git a/metadata/glsa/glsa-201403-03.xml b/metadata/glsa/glsa-201403-03.xml index 4d1dd97ce594..b951172bdde8 100644 --- a/metadata/glsa/glsa-201403-03.xml +++ b/metadata/glsa/glsa-201403-03.xml @@ -1,7 +1,7 @@ - file: Denial of Service + file: Denial of service A vulnerability in file could result in Denial of Service. file 2014-03-13 diff --git a/metadata/glsa/glsa-201403-04.xml b/metadata/glsa/glsa-201403-04.xml index 9c88b3663438..fddfad7996cb 100644 --- a/metadata/glsa/glsa-201403-04.xml +++ b/metadata/glsa/glsa-201403-04.xml @@ -1,7 +1,7 @@ - QtCore: Denial of Service + QtCore: Denial of service A vulnerability in QXmlSimpleReader class can be used to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201405-02.xml b/metadata/glsa/glsa-201405-02.xml index feb538b9f1c1..ca980569f658 100644 --- a/metadata/glsa/glsa-201405-02.xml +++ b/metadata/glsa/glsa-201405-02.xml @@ -1,7 +1,7 @@ - libSRTP: Denial of Service + libSRTP: Denial of service A vulnerability in libSRTP can result in a Denial of Service condition. diff --git a/metadata/glsa/glsa-201405-05.xml b/metadata/glsa/glsa-201405-05.xml index 4d4d968a9a81..314dac66473d 100644 --- a/metadata/glsa/glsa-201405-05.xml +++ b/metadata/glsa/glsa-201405-05.xml @@ -1,7 +1,7 @@ - Asterisk: Denial of Service + Asterisk: Denial of service Multiple buffer overflows in Asterisk might allow remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201405-14.xml b/metadata/glsa/glsa-201405-14.xml index 5983113bd598..cd8bcad2f577 100644 --- a/metadata/glsa/glsa-201405-14.xml +++ b/metadata/glsa/glsa-201405-14.xml @@ -1,7 +1,7 @@ - Ruby OpenID: Denial of Service + Ruby OpenID: Denial of service A vulnerability in Ruby OpenID may lead to Denial of Service. ruby-openid 2014-05-17 diff --git a/metadata/glsa/glsa-201405-16.xml b/metadata/glsa/glsa-201405-16.xml index 229014a3a906..744a1d2bc46f 100644 --- a/metadata/glsa/glsa-201405-16.xml +++ b/metadata/glsa/glsa-201405-16.xml @@ -1,7 +1,7 @@ - Mono: Denial of Service + Mono: Denial of service A hash collision vulnerability in Mono allows remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201405-20.xml b/metadata/glsa/glsa-201405-20.xml index 8ed494ebb41f..c889f9dfe189 100644 --- a/metadata/glsa/glsa-201405-20.xml +++ b/metadata/glsa/glsa-201405-20.xml @@ -1,7 +1,7 @@ - JBIG-KIT: Denial of Service + JBIG-KIT: Denial of service A stack-based buffer overflow in JBIG-KIT might allow remote attackers to cause a Denial of Service. diff --git a/metadata/glsa/glsa-201405-21.xml b/metadata/glsa/glsa-201405-21.xml index 342671e4105d..f95cfa4e1719 100644 --- a/metadata/glsa/glsa-201405-21.xml +++ b/metadata/glsa/glsa-201405-21.xml @@ -1,7 +1,7 @@ - Charybdis, ShadowIRCd: Denial of Service + Charybdis, ShadowIRCd: Denial of service A vulnerability has been found in Charybdis and ShadowIRCd, possibly resulting in remote Denial of Service. diff --git a/metadata/glsa/glsa-201405-24.xml b/metadata/glsa/glsa-201405-24.xml index 069f8d1f85f2..412fdc38ca6e 100644 --- a/metadata/glsa/glsa-201405-24.xml +++ b/metadata/glsa/glsa-201405-24.xml @@ -1,7 +1,7 @@ - Apache Portable Runtime, APR Utility Library: Denial of Service + Apache Portable Runtime, APR Utility Library: Denial of service Memory consumption errors in Apache Portable Runtime and APR Utility Library could result in Denial of Service. diff --git a/metadata/glsa/glsa-201406-04.xml b/metadata/glsa/glsa-201406-04.xml index 958e65c665bf..a99c235d5a1f 100644 --- a/metadata/glsa/glsa-201406-04.xml +++ b/metadata/glsa/glsa-201406-04.xml @@ -1,7 +1,7 @@ - SystemTap: Denial of Service + SystemTap: Denial of service A vulnerability in SystemTap could allow a local attacker to create a Denial of Service condition. diff --git a/metadata/glsa/glsa-201406-23.xml b/metadata/glsa/glsa-201406-23.xml index 8e64dae79bdf..e80c53dc8e7b 100644 --- a/metadata/glsa/glsa-201406-23.xml +++ b/metadata/glsa/glsa-201406-23.xml @@ -1,7 +1,7 @@ - DenyHosts: Denial of Service + DenyHosts: Denial of service A vulnerability in DenyHosts could allow a remote attacker to create a Denial of Service condition. diff --git a/metadata/glsa/glsa-201407-01.xml b/metadata/glsa/glsa-201407-01.xml index 10697913e884..4a84a78e2233 100644 --- a/metadata/glsa/glsa-201407-01.xml +++ b/metadata/glsa/glsa-201407-01.xml @@ -1,7 +1,7 @@ - OpenTTD: Denial of Service + OpenTTD: Denial of service A vulnerability in OpenTTD could allow a remote attacker to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201407-04.xml b/metadata/glsa/glsa-201407-04.xml index 4b478172bfa2..92f3af8d0116 100644 --- a/metadata/glsa/glsa-201407-04.xml +++ b/metadata/glsa/glsa-201407-04.xml @@ -1,7 +1,7 @@ - GnuPG: Denial of Service + GnuPG: Denial of service A vulnerability in GnuPG can lead to a Denial of Service condition. GnuPG. 2014-07-16 diff --git a/metadata/glsa/glsa-201408-08.xml b/metadata/glsa/glsa-201408-08.xml index 1a9f4a94adc9..a5e640f0f807 100644 --- a/metadata/glsa/glsa-201408-08.xml +++ b/metadata/glsa/glsa-201408-08.xml @@ -1,7 +1,7 @@ - file: Denial of Service + file: Denial of service A vulnerability in file could result in Denial of Service. file 2014-08-26 diff --git a/metadata/glsa/glsa-201409-02.xml b/metadata/glsa/glsa-201409-02.xml index 54ad07f110da..8fd46bf3bab9 100644 --- a/metadata/glsa/glsa-201409-02.xml +++ b/metadata/glsa/glsa-201409-02.xml @@ -1,7 +1,7 @@ - Net-SNMP: Denial of Service + Net-SNMP: Denial of service Multiple vulnerabilities have been found in Net-SNMP which could allow remote attackers to cause Denial of Service. diff --git a/metadata/glsa/glsa-201409-07.xml b/metadata/glsa/glsa-201409-07.xml index 6265fadea682..d67dc7b8101b 100644 --- a/metadata/glsa/glsa-201409-07.xml +++ b/metadata/glsa/glsa-201409-07.xml @@ -1,7 +1,7 @@ - c-icap: Denial of Service + c-icap: Denial of service A vulnerability in c-icap could result in Denial of Service. c-icap,DoS 2014-09-19 diff --git a/metadata/glsa/glsa-201409-08.xml b/metadata/glsa/glsa-201409-08.xml index 6c07d082ac20..8fa255a5fbee 100644 --- a/metadata/glsa/glsa-201409-08.xml +++ b/metadata/glsa/glsa-201409-08.xml @@ -1,7 +1,7 @@ - libxml2: Denial of Service + libxml2: Denial of service A vulnerability in libxml2 allows a remote attacker to cause Denial of Service. diff --git a/metadata/glsa/glsa-201411-07.xml b/metadata/glsa/glsa-201411-07.xml index 90a31b3b8872..626953bd8ccb 100644 --- a/metadata/glsa/glsa-201411-07.xml +++ b/metadata/glsa/glsa-201411-07.xml @@ -1,7 +1,7 @@ - Openswan: Denial of Service + Openswan: Denial of service A NULL pointer dereference in Openswan may allow remote attackers to cause Denial of Service. diff --git a/metadata/glsa/glsa-201412-03.xml b/metadata/glsa/glsa-201412-03.xml index 26a12152e17a..d43330517284 100644 --- a/metadata/glsa/glsa-201412-03.xml +++ b/metadata/glsa/glsa-201412-03.xml @@ -1,7 +1,7 @@ - Dovecot: Denial of Service + Dovecot: Denial of service A vulnerability in Dovecot could allow a remote attacker to create a Denial of Service condition. diff --git a/metadata/glsa/glsa-201412-06.xml b/metadata/glsa/glsa-201412-06.xml index a01b6e448b47..c993e4d34892 100644 --- a/metadata/glsa/glsa-201412-06.xml +++ b/metadata/glsa/glsa-201412-06.xml @@ -1,7 +1,7 @@ - libxml2: Denial of Service + libxml2: Denial of service A vulnerability in libxml2 could result in Denial of Service. libxml2 2014-12-10 diff --git a/metadata/glsa/glsa-201412-16.xml b/metadata/glsa/glsa-201412-16.xml index 9952692321c9..cb189790d79d 100644 --- a/metadata/glsa/glsa-201412-16.xml +++ b/metadata/glsa/glsa-201412-16.xml @@ -1,7 +1,7 @@ - CouchDB: Denial of Service + CouchDB: Denial of service A vulnerability in CouchDB could result in Denial of Service. couchdb 2014-12-13 diff --git a/metadata/glsa/glsa-201412-20.xml b/metadata/glsa/glsa-201412-20.xml index 88ee9b5c9853..80222f85754b 100644 --- a/metadata/glsa/glsa-201412-20.xml +++ b/metadata/glsa/glsa-201412-20.xml @@ -1,7 +1,7 @@ - GNUstep Base library: Denial of Service + GNUstep Base library: Denial of service A vulnerability in GNUstep Base library could lead to Denial of Service. diff --git a/metadata/glsa/glsa-201412-25.xml b/metadata/glsa/glsa-201412-25.xml index 58d21454aed1..59936b32dce3 100644 --- a/metadata/glsa/glsa-201412-25.xml +++ b/metadata/glsa/glsa-201412-25.xml @@ -1,7 +1,7 @@ - QtGui: Denial of Service + QtGui: Denial of service A NULL pointer dereference in QtGui could lead to Denial of Service. diff --git a/metadata/glsa/glsa-201412-27.xml b/metadata/glsa/glsa-201412-27.xml index 227cffd10672..5fa51c8a8165 100644 --- a/metadata/glsa/glsa-201412-27.xml +++ b/metadata/glsa/glsa-201412-27.xml @@ -1,7 +1,7 @@ - Ruby: Denial of Service + Ruby: Denial of service Multiple vulnerabilities have been found in Ruby, allowing context-dependent attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201412-31.xml b/metadata/glsa/glsa-201412-31.xml index afba26975529..9cd7dee0126e 100644 --- a/metadata/glsa/glsa-201412-31.xml +++ b/metadata/glsa/glsa-201412-31.xml @@ -1,7 +1,7 @@ - ZNC: Denial of Service + ZNC: Denial of service Multiple vulnerabilities in ZNC could lead to Denial of Service. znc 2014-12-19 diff --git a/metadata/glsa/glsa-201412-35.xml b/metadata/glsa/glsa-201412-35.xml index e260519fd008..18211d95da93 100644 --- a/metadata/glsa/glsa-201412-35.xml +++ b/metadata/glsa/glsa-201412-35.xml @@ -1,7 +1,7 @@ - RSYSLOG: Denial of Service + RSYSLOG: Denial of service Multiple vulnerabilities have been found in RSYSLOG, allowing attackers to cause Denial of Service. diff --git a/metadata/glsa/glsa-201412-36.xml b/metadata/glsa/glsa-201412-36.xml index 54314591da1d..b654cff79b00 100644 --- a/metadata/glsa/glsa-201412-36.xml +++ b/metadata/glsa/glsa-201412-36.xml @@ -1,7 +1,7 @@ - libvirt: Denial of Service + libvirt: Denial of service Multiple vulnerabilities have been found in libvirt, worst of which allows context-dependent attackers to cause Denial of Service. diff --git a/metadata/glsa/glsa-201412-41.xml b/metadata/glsa/glsa-201412-41.xml index 0e4423b9b5fc..d7c4486aebaa 100644 --- a/metadata/glsa/glsa-201412-41.xml +++ b/metadata/glsa/glsa-201412-41.xml @@ -1,7 +1,7 @@ - OpenVPN: Denial of Service + OpenVPN: Denial of service A vulnerability in OpenVPN could lead to Denial of Service. openvpn 2014-12-26 diff --git a/metadata/glsa/glsa-201412-42.xml b/metadata/glsa/glsa-201412-42.xml index b9ef0229df6a..d0c8d9c3f85e 100644 --- a/metadata/glsa/glsa-201412-42.xml +++ b/metadata/glsa/glsa-201412-42.xml @@ -1,7 +1,7 @@ - Xen: Denial of Service + Xen: Denial of service Multiple vulnerabilities have been found in Xen, possibly resulting in Denial of Service. diff --git a/metadata/glsa/glsa-201412-46.xml b/metadata/glsa/glsa-201412-46.xml index 973ec5a5ac22..6dda6c616e29 100644 --- a/metadata/glsa/glsa-201412-46.xml +++ b/metadata/glsa/glsa-201412-46.xml @@ -1,7 +1,7 @@ - LittleCMS: Denial of Service + LittleCMS: Denial of service Multiple buffer overflow flaws and a parser error in LittleCMS could cause Denial of Service. diff --git a/metadata/glsa/glsa-201412-48.xml b/metadata/glsa/glsa-201412-48.xml index 62aec4732ba5..be51de898fa4 100644 --- a/metadata/glsa/glsa-201412-48.xml +++ b/metadata/glsa/glsa-201412-48.xml @@ -1,7 +1,7 @@ - file: Denial of Service + file: Denial of service A vulnerability in file could allow a context-dependent attack to create a Denial of Service condition. diff --git a/metadata/glsa/glsa-201502-14.xml b/metadata/glsa/glsa-201502-14.xml index 8abef79d55b7..6f94fb697306 100644 --- a/metadata/glsa/glsa-201502-14.xml +++ b/metadata/glsa/glsa-201502-14.xml @@ -1,7 +1,7 @@ - grep: Denial of Service + grep: Denial of service A vulnerability in grep could result in Denial of Service. grep,dos 2015-02-25 diff --git a/metadata/glsa/glsa-201503-02.xml b/metadata/glsa/glsa-201503-02.xml index 8665dc717d91..28f58b933d39 100644 --- a/metadata/glsa/glsa-201503-02.xml +++ b/metadata/glsa/glsa-201503-02.xml @@ -1,7 +1,7 @@ - D-Bus: Denial of Service + D-Bus: Denial of service A vulnerability has been found in D-Bus, possibly resulting in local Denial of Service. diff --git a/metadata/glsa/glsa-201503-08.xml b/metadata/glsa/glsa-201503-08.xml index 48633c2dacf0..d38e5342a11f 100644 --- a/metadata/glsa/glsa-201503-08.xml +++ b/metadata/glsa/glsa-201503-08.xml @@ -1,7 +1,7 @@ - file: Denial of Service + file: Denial of service Vulnerabilities in file could allow a context-dependent attack to create a Denial of Service condition. diff --git a/metadata/glsa/glsa-201507-02.xml b/metadata/glsa/glsa-201507-02.xml index 5ebfd72e89e8..6f71d87dd7da 100644 --- a/metadata/glsa/glsa-201507-02.xml +++ b/metadata/glsa/glsa-201507-02.xml @@ -1,7 +1,7 @@ - Tor: Denial of Service + Tor: Denial of service Two vulnerabilities have been found in Tor, the worst of which can allow remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201507-03.xml b/metadata/glsa/glsa-201507-03.xml index 14eb3aa499e9..aa82322b4b1b 100644 --- a/metadata/glsa/glsa-201507-03.xml +++ b/metadata/glsa/glsa-201507-03.xml @@ -1,7 +1,7 @@ - Exiv2: Denial of Service + Exiv2: Denial of service A vulnerability in Exiv2 could lead to Denial of Service condition. exiv2 2015-07-07 diff --git a/metadata/glsa/glsa-201507-08.xml b/metadata/glsa/glsa-201507-08.xml index 678c5f652b60..9f3a3e7b3d20 100644 --- a/metadata/glsa/glsa-201507-08.xml +++ b/metadata/glsa/glsa-201507-08.xml @@ -1,7 +1,7 @@ - libxml2: Denial of Service + libxml2: Denial of service A vulnerability in libxml2 allows a remote attacker to cause Denial of Service. diff --git a/metadata/glsa/glsa-201507-11.xml b/metadata/glsa/glsa-201507-11.xml index d6b145118660..805038e6bdc2 100644 --- a/metadata/glsa/glsa-201507-11.xml +++ b/metadata/glsa/glsa-201507-11.xml @@ -1,7 +1,7 @@ - Perl: Denial of Service + Perl: Denial of service A vulnerability in Perl allows a remote attacker to cause Denial of Service. diff --git a/metadata/glsa/glsa-201507-12.xml b/metadata/glsa/glsa-201507-12.xml index 9f9381c92dab..fbf1efc92dc1 100644 --- a/metadata/glsa/glsa-201507-12.xml +++ b/metadata/glsa/glsa-201507-12.xml @@ -1,7 +1,7 @@ - libCapsiNetwork: Denial of Service + libCapsiNetwork: Denial of service A buffer overflow in libcapsinetwork might allow remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201507-17.xml b/metadata/glsa/glsa-201507-17.xml index 917f618700fc..40006ead8406 100644 --- a/metadata/glsa/glsa-201507-17.xml +++ b/metadata/glsa/glsa-201507-17.xml @@ -1,7 +1,7 @@ - SNMP: Denial of Service + SNMP: Denial of service A vulnerability in SNMP could lead to a Denial of Service condition. diff --git a/metadata/glsa/glsa-201508-03.xml b/metadata/glsa/glsa-201508-03.xml index 918d6488611c..f6d9915d493b 100644 --- a/metadata/glsa/glsa-201508-03.xml +++ b/metadata/glsa/glsa-201508-03.xml @@ -1,7 +1,7 @@ - Icecast: Denial of Service + Icecast: Denial of service A bug in the Icecast code handling source client URL authentication causes a Denial of Service condition. diff --git a/metadata/glsa/glsa-201509-05.xml b/metadata/glsa/glsa-201509-05.xml index 10f969848090..df4c34083751 100644 --- a/metadata/glsa/glsa-201509-05.xml +++ b/metadata/glsa/glsa-201509-05.xml @@ -1,7 +1,7 @@ - NetworkManager: Denial of Service + NetworkManager: Denial of service Improper handling of Router Advertisements in NetworkManager could cause a Denial of Service condition in IPv6 network stacks. diff --git a/metadata/glsa/glsa-201510-01.xml b/metadata/glsa/glsa-201510-01.xml index 52af9d49c609..902f3e35796d 100644 --- a/metadata/glsa/glsa-201510-01.xml +++ b/metadata/glsa/glsa-201510-01.xml @@ -1,7 +1,7 @@ - BIND: Denial of Service + BIND: Denial of service A vulnerability in BIND could lead to a Denial of Service condition. diff --git a/metadata/glsa/glsa-201512-01.xml b/metadata/glsa/glsa-201512-01.xml index b38f18f341e8..43c0c782d7b2 100644 --- a/metadata/glsa/glsa-201512-01.xml +++ b/metadata/glsa/glsa-201512-01.xml @@ -1,7 +1,7 @@ - Dnsmasq: Denial of Service + Dnsmasq: Denial of service A vulnerability in Dnsmasq can lead to a Denial of Service condition. diff --git a/metadata/glsa/glsa-201605-03.xml b/metadata/glsa/glsa-201605-03.xml index addc04e39f54..74310dab6092 100644 --- a/metadata/glsa/glsa-201605-03.xml +++ b/metadata/glsa/glsa-201605-03.xml @@ -1,7 +1,7 @@ - libfpx: Denial of Service + libfpx: Denial of service A double free vulnerability has been discovered in libfpx that allows remote attackers to cause a Denial of Service. diff --git a/metadata/glsa/glsa-201611-13.xml b/metadata/glsa/glsa-201611-13.xml index c4b6a2dd4173..340f93f10c7d 100644 --- a/metadata/glsa/glsa-201611-13.xml +++ b/metadata/glsa/glsa-201611-13.xml @@ -1,7 +1,7 @@ - MongoDB: Denial of Service + MongoDB: Denial of service A vulnerability in MongoDB can lead to a Denial of Service condition. diff --git a/metadata/glsa/glsa-201611-17.xml b/metadata/glsa/glsa-201611-17.xml index 0b744a3719ed..06918e18c19c 100644 --- a/metadata/glsa/glsa-201611-17.xml +++ b/metadata/glsa/glsa-201611-17.xml @@ -1,7 +1,7 @@ - RPCBind: Denial of Service + RPCBind: Denial of service A buffer overflow in RPCBind might allow remote attackers to cause a Denial of Service. diff --git a/metadata/glsa/glsa-201612-12.xml b/metadata/glsa/glsa-201612-12.xml index 7c87051e4ada..bed37652846e 100644 --- a/metadata/glsa/glsa-201612-12.xml +++ b/metadata/glsa/glsa-201612-12.xml @@ -1,7 +1,7 @@ - Patch: Denial of Service + Patch: Denial of service Patch is vulnerable to a locally generated Denial of Service condition. diff --git a/metadata/glsa/glsa-201612-13.xml b/metadata/glsa/glsa-201612-13.xml index 2a94b8945daf..bbd016eb7ed8 100644 --- a/metadata/glsa/glsa-201612-13.xml +++ b/metadata/glsa/glsa-201612-13.xml @@ -1,7 +1,7 @@ - nghttp2: Denial of Service + nghttp2: Denial of service Nghttp2 is vulnerable to a Denial of Service attack. nghttp2 2016-12-05 diff --git a/metadata/glsa/glsa-201701-05.xml b/metadata/glsa/glsa-201701-05.xml index 86c9150d5b4c..7dc6c70320a1 100644 --- a/metadata/glsa/glsa-201701-05.xml +++ b/metadata/glsa/glsa-201701-05.xml @@ -1,7 +1,7 @@ - BusyBox: Denial of Service + BusyBox: Denial of service A vulnerability in BusyBox might allow remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201701-26.xml b/metadata/glsa/glsa-201701-26.xml index 8004eafa664f..7a8fc557c10b 100644 --- a/metadata/glsa/glsa-201701-26.xml +++ b/metadata/glsa/glsa-201701-26.xml @@ -1,7 +1,7 @@ - BIND: Denial of Service + BIND: Denial of service A vulnerability in BIND might allow remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201703-05.xml b/metadata/glsa/glsa-201703-05.xml index e1637abc9d05..6b0df1ab9a0d 100644 --- a/metadata/glsa/glsa-201703-05.xml +++ b/metadata/glsa/glsa-201703-05.xml @@ -1,7 +1,7 @@ - GNU Libtasn1: Denial of Service + GNU Libtasn1: Denial of service A vulnerability in Libtasn1 allows remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201706-11.xml b/metadata/glsa/glsa-201706-11.xml index 48a4c273b816..e520317c30a4 100644 --- a/metadata/glsa/glsa-201706-11.xml +++ b/metadata/glsa/glsa-201706-11.xml @@ -1,7 +1,7 @@ - PCRE library: Denial of Service + PCRE library: Denial of service A vulnerability in PCRE library allows remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201708-08.xml b/metadata/glsa/glsa-201708-08.xml index 1ca006521ced..9e374ef5653f 100644 --- a/metadata/glsa/glsa-201708-08.xml +++ b/metadata/glsa/glsa-201708-08.xml @@ -1,7 +1,7 @@ - bzip2: Denial of Service + bzip2: Denial of service An use-after-free vulnerability has been found in bzip2 that could allow remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201710-15.xml b/metadata/glsa/glsa-201710-15.xml index 3955bb67f151..34aff01db167 100644 --- a/metadata/glsa/glsa-201710-15.xml +++ b/metadata/glsa/glsa-201710-15.xml @@ -1,7 +1,7 @@ - GnuTLS: Denial of Service + GnuTLS: Denial of service A null pointer dereference in GnuTLS might allow attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201811-03.xml b/metadata/glsa/glsa-201811-03.xml index cbf256a1d569..9da180929463 100644 --- a/metadata/glsa/glsa-201811-03.xml +++ b/metadata/glsa/glsa-201811-03.xml @@ -1,7 +1,7 @@ - OpenSSL: Denial of Service + OpenSSL: Denial of service A vulnerability in OpenSSL might allow remote attackers to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201811-07.xml b/metadata/glsa/glsa-201811-07.xml index a8cd2f63051d..4980d7d7f9f6 100644 --- a/metadata/glsa/glsa-201811-07.xml +++ b/metadata/glsa/glsa-201811-07.xml @@ -1,7 +1,7 @@ - Pango: Denial of Service + Pango: Denial of service A vulnerability in Pango could result in a Denial of Service condition. diff --git a/metadata/glsa/glsa-201903-05.xml b/metadata/glsa/glsa-201903-05.xml index 106046f3f707..6c9b92914889 100644 --- a/metadata/glsa/glsa-201903-05.xml +++ b/metadata/glsa/glsa-201903-05.xml @@ -1,7 +1,7 @@ - Tar: Denial of Service + Tar: Denial of service A vulnerability in Tar could led to a Denial of Service condition. tar 2019-03-10 diff --git a/metadata/glsa/glsa-201904-01.xml b/metadata/glsa/glsa-201904-01.xml index 413cf96f361e..9ad5f7e37d8c 100644 --- a/metadata/glsa/glsa-201904-01.xml +++ b/metadata/glsa/glsa-201904-01.xml @@ -1,7 +1,7 @@ - Cairo: Denial of Service + Cairo: Denial of service Multiple vulnerabilities were found in Cairo, the worst of which could cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-201904-08.xml b/metadata/glsa/glsa-201904-08.xml index 9a634deb75e5..8f0c6a0299e7 100644 --- a/metadata/glsa/glsa-201904-08.xml +++ b/metadata/glsa/glsa-201904-08.xml @@ -1,7 +1,7 @@ - Subversion: Denial of Service + Subversion: Denial of service A vulnerability in Subversion could lead to a Denial of Service condition. diff --git a/metadata/glsa/glsa-201904-15.xml b/metadata/glsa/glsa-201904-15.xml index 5c645f5aecf1..d0357f915f4f 100644 --- a/metadata/glsa/glsa-201904-15.xml +++ b/metadata/glsa/glsa-201904-15.xml @@ -1,7 +1,7 @@ - libTIFF: Denial of Service + libTIFF: Denial of service A vulnerability in libTIFF could lead to a Denial of Service condition. diff --git a/metadata/glsa/glsa-201908-25.xml b/metadata/glsa/glsa-201908-25.xml index 7f2c146a9229..700154a2602a 100644 --- a/metadata/glsa/glsa-201908-25.xml +++ b/metadata/glsa/glsa-201908-25.xml @@ -1,7 +1,7 @@ - hostapd and wpa_supplicant: Denial of Service + hostapd and wpa_supplicant: Denial of service A vulnerability in hostapd and wpa_supplicant could lead to a Denial of Service condition. diff --git a/metadata/glsa/glsa-202004-08.xml b/metadata/glsa/glsa-202004-08.xml index 2bccb96214e5..fcb9f3e073ae 100644 --- a/metadata/glsa/glsa-202004-08.xml +++ b/metadata/glsa/glsa-202004-08.xml @@ -1,7 +1,7 @@ - libssh: Denial of Service + libssh: Denial of service A vulnerability in libssh could allow a remote attacker to cause a Denial of Service condition. diff --git a/metadata/glsa/glsa-202005-09.xml b/metadata/glsa/glsa-202005-09.xml index 0968323af7b0..7b7322c0b6f5 100644 --- a/metadata/glsa/glsa-202005-09.xml +++ b/metadata/glsa/glsa-202005-09.xml @@ -1,7 +1,7 @@ - Python: Denial of Service + Python: Denial of service A vulnerability in Python could lead to a Denial of Service condition. diff --git a/metadata/glsa/glsa-202011-05.xml b/metadata/glsa/glsa-202011-05.xml index 3301038aa721..e33d8909d045 100644 --- a/metadata/glsa/glsa-202011-05.xml +++ b/metadata/glsa/glsa-202011-05.xml @@ -1,7 +1,7 @@ - libssh: Denial of Service + libssh: Denial of service A vulnerability in libssh could lead to a Denial of Service condition. diff --git a/metadata/glsa/glsa-202012-21.xml b/metadata/glsa/glsa-202012-21.xml new file mode 100644 index 000000000000..3baa8cb1d47d --- /dev/null +++ b/metadata/glsa/glsa-202012-21.xml @@ -0,0 +1,53 @@ + + + + Mozilla Network Security Service (NSS): Denial of service + A vulnerability in NSS might allow remote attackers to cause a + Denial of Service condition. + + nss + 2020-12-23 + 2020-12-23 + 750254 + remote + + + 3.58 + 3.58 + + + +

The Mozilla Network Security Service (NSS) is a library implementing + security features like SSL v.2/v.3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS + #12, S/MIME and X.509 certificates. +

+
+ +

A flaw was found in the way Mozilla Network Security Service (NSS) + handled CCS (ChangeCipherSpec) messages in TLS 1.3. +

+
+ +

A remote attacker could send multiple crafted CSS messages in row after + ClientHello message to a server application linked against NSS library, + possibly resulting in a Denial of Service condition. +

+
+ +

Disable TLS 1.3 protocol.

+
+ +

All NSS users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-libs/nss-3.58" + + +
+ + CVE-2020-25648 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202104-07.xml b/metadata/glsa/glsa-202104-07.xml index bd3937bee365..31900cf33c40 100644 --- a/metadata/glsa/glsa-202104-07.xml +++ b/metadata/glsa/glsa-202104-07.xml @@ -1,7 +1,7 @@ - ClamAV: Denial of Service + ClamAV: Denial of service A vulnerability in ClamAV could lead to a Denial of Service condition. diff --git a/metadata/glsa/glsa-202105-02.xml b/metadata/glsa/glsa-202105-02.xml new file mode 100644 index 000000000000..6033d073253a --- /dev/null +++ b/metadata/glsa/glsa-202105-02.xml @@ -0,0 +1,51 @@ + + + + stunnel: Improper certificate validation + Stunnel was not properly verifying TLS certificates, possibly + allowing an integrity/confidentiality compromise. + + stunnel + 2021-05-26 + 2021-05-26 + 772146 + local, remote + + + 5.58 + 5.58 + + + +

The stunnel program is designed to work as an SSL/TLS encryption wrapper + between a client and a local or remote server. +

+
+ +

It was discovered that stunnel did not correctly verified the client + certificate when options “redirect” and “verifyChain” are used. +

+
+ +

A remote attacker could send a specially crafted certificate, possibly + resulting in a breach of integrity or confidentiality. +

+
+ +

There is no known workaround at this time.

+
+ +

All stunnel users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/stunnel-5.58" + + +
+ + CVE-2021-20230 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-03.xml b/metadata/glsa/glsa-202105-03.xml new file mode 100644 index 000000000000..f866dd062401 --- /dev/null +++ b/metadata/glsa/glsa-202105-03.xml @@ -0,0 +1,54 @@ + + + + GPT fdisk: Integer underflow + An integer underflow in sgdisk from GPT fdisk package might allow + local attacker(s) to escalate privileges. + + gptfdisk + 2021-05-26 + 2021-05-26 + 768762 + local + + + 1.0.6 + 1.0.6 + + + +

GPT fdisk (consisting of the gdisk, cgdisk, sgdisk, and fixparts + programs) is a set of text-mode partitioning tools for Linux, FreeBSD, + Mac OS X, and Windows. +

+
+ +

It was discovered that ReadLogicalParts() function in basicmbr.cc was + missing a bounds check. +

+
+ +

A local attacker could entice a user to insert a malicious formatted + block device (USB stick or SD card for example), that, when processed + with sgdisk, possibly resulting in local escalation of privileges or a + Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All GPT fdisk users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/gptfdisk-1.0.6" + + +
+ + CVE-2021-0308 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-04.xml b/metadata/glsa/glsa-202105-04.xml new file mode 100644 index 000000000000..6c92bcfc9a59 --- /dev/null +++ b/metadata/glsa/glsa-202105-04.xml @@ -0,0 +1,55 @@ + + + + Boost: Buffer overflow + A buffer overflow in Boost might allow remote attacker(s) to + execute arbitrary code. + + boost + 2021-05-26 + 2021-05-26 + 620468 + local, remote + + + 1.74.0-r2 + 1.74.0-r2 + + + +

Boost is a set of C++ libraries, including the Boost.Regex library to + process regular expressions. +

+
+ +

It was discovered that Boost incorrectly sanitized ‘next_size’ and + ‘max_size’ parameter in ordered_malloc() function when allocating + memory. +

+
+ +

A remote attacker could provide a specially crafted application-specific + file (requiring runtime memory allocation to be processed correctly), + that, when opened with an application using Boost C++ source libraries, + possibly resulting in execution of arbitrary code with the privileges of + the process or a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All Boost users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-libs/boost-1.74.0-r2" + + +
+ + CVE-2012-2677 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-05.xml b/metadata/glsa/glsa-202105-05.xml new file mode 100644 index 000000000000..1473c2d8928d --- /dev/null +++ b/metadata/glsa/glsa-202105-05.xml @@ -0,0 +1,66 @@ + + + + Mutt, NeoMutt: Denial of service + A vulnerability in Mutt and NeoMutt could lead to a Denial of + Service condition. + + mutt,neomutt + 2021-05-26 + 2021-05-26 + 788388 + 788391 + remote + + + 2.0.7 + 2.0.7 + + + 20210205-r1 + 20210205-r1 + + + +

Mutt is a small but very powerful text-based mail client.

+ +

NeoMutt is a command line mail reader (or MUA). It’s a fork of Mutt + with added features. +

+
+ +

It was discovered that Mutt, and NeoMutt did not properly handle certain + situations where an IMAP sequence set ends with a comma. +

+
+ +

A remote attacker could entice a user to connect to a malicious IMAP + server to cause a Denial of Service condition, or other unspecified + impacts. +

+
+ +

There is no known workaround at this time.

+
+ +

All Mutt users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=mail-client/mutt-2.0.7" + + +

All NeoMutt users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=mail-client/neomutt-20210205-r1" + + +
+ + CVE-2021-32055 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-06.xml b/metadata/glsa/glsa-202105-06.xml new file mode 100644 index 000000000000..84a6f01bc263 --- /dev/null +++ b/metadata/glsa/glsa-202105-06.xml @@ -0,0 +1,48 @@ + + + + Smarty: Multiple vulnerabilities + Multiple vulnerabilities in the Smarty template engine might allow + remote attackers to execute arbitrary PHP code. + + smarty + 2021-05-26 + 2021-05-26 + 772206 + local, remote + + + 3.1.39 + 3.1.39 + + + +

Smarty is a template engine for PHP.

+
+ +

Multiple vulnerabilities have been discovered in Smarty template engine. + Please review the CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Smarty template engine users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-php/smarty-3.1.39" + + +
+ + CVE-2021-26119 + CVE-2021-26120 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-07.xml b/metadata/glsa/glsa-202105-07.xml new file mode 100644 index 000000000000..500983dbb936 --- /dev/null +++ b/metadata/glsa/glsa-202105-07.xml @@ -0,0 +1,59 @@ + + + + Telegram: Security bypass + An insufficient session expiration has been reported in Telegram. + telegram + 2021-05-26 + 2021-05-26 + 771684 + remote + + + 2.4.11 + 2.4.11 + + + 2.4.11 + 2.4.11 + + + +

Telegram is a cloud-based mobile and desktop messaging app with a focus + on security and speed. +

+
+ +

It was discovered that Telegram failed to invalidate a recently active + session. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Telegram users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-im/telegram-desktop-2.4.11" + + +

All Telegram binary users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=net-im/telegram-desktop-bin-2.4.11" + + +
+ + CVE-2021-27351 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-08.xml b/metadata/glsa/glsa-202105-08.xml new file mode 100644 index 000000000000..72e5c500070c --- /dev/null +++ b/metadata/glsa/glsa-202105-08.xml @@ -0,0 +1,55 @@ + + + + ICU: Multiple vulnerabilities + Multiple vulnerabilities have been found in ICU, the worst of which + could cause a Denial of Service condition. + + icu + 2021-05-26 + 2021-05-26 + 755704 + local, remote + + + 68.2 + 68.2 + + + +

ICU is a mature, widely used set of C/C++ and Java libraries providing + Unicode and Globalization support for software applications. +

+
+ +

Multiple vulnerabilities have been discovered in ICU. Please review the + upstream bugs referenced below for details. +

+
+ +

Remote attackers could cause a Denial of Service condition or possibly + have other unspecified impacts via unspecified vectors. +

+
+ +

There is no known workaround at this time.

+
+ +

All ICU users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-libs/icu-68.2" + + +
+ + + Chromium Change-Id Iad839ac77d487d5e1b396bcdbc29bc7cd58a7ef8 + + ICU-21383 + ICU-21385 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-09.xml b/metadata/glsa/glsa-202105-09.xml new file mode 100644 index 000000000000..404c19997660 --- /dev/null +++ b/metadata/glsa/glsa-202105-09.xml @@ -0,0 +1,51 @@ + + + + BusyBox: Denial of service + A vulnerability in BusyBox might allow remote attackers to cause a + Denial of Service condition. + + busybox + 2021-05-26 + 2021-05-26 + 777255 + local, remote + + + 1.32.1 + 1.32.1 + + + +

BusyBox is a set of tools for embedded systems and is a replacement for + GNU Coreutils. +

+
+ +

It was discovered that BusyBox mishandled the error bit on the + huft_build result pointer when decompressing GZIP compressed data. +

+
+ +

A remote attacker could entice a user to open a specially crafted GZIP + file using BusyBox, possibly resulting in a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All BusyBox users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/busybox-1.32.1" + + +
+ + CVE-2021-28831 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-10.xml b/metadata/glsa/glsa-202105-10.xml new file mode 100644 index 000000000000..aa151c4e9f25 --- /dev/null +++ b/metadata/glsa/glsa-202105-10.xml @@ -0,0 +1,55 @@ + + + + GNOME Autoar: User-assisted execution of arbitrary code + A vulnerability has been found in GNOME Autoar that could allow a + remote attacker to execute arbitrary code. + + gnome-autoar + 2021-05-26 + 2021-05-26 + 768828 + 777126 + local, remote + + + 0.3.1 + 0.3.1 + + + +

GNOME Autoar provides functions and widgets for GNOME applications which + want to use archives as a method to transfer directories over the + internet. +

+
+ +

It was discovered that GNOME Autoar could extract files outside of the + intended directory. +

+
+ +

A remote attacker could entice a user to open a specially crafted + archive using GNOME Autoar, possibly resulting in execution of arbitrary + code with the privileges of the process or a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All GNOME Autoar users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-arch/gnome-autoar-0.3.1" + + +
+ + CVE-2020-36241 + CVE-2021-28650 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-11.xml b/metadata/glsa/glsa-202105-11.xml new file mode 100644 index 000000000000..548f498d4d3a --- /dev/null +++ b/metadata/glsa/glsa-202105-11.xml @@ -0,0 +1,55 @@ + + + + GNU Screen: User-assisted execution of arbitrary code + A vulnerability in GNU screen may allow a remote attacker to + execute arbitrary code. + + screen + 2021-05-26 + 2021-05-26 + 769770 + local, remote + + + 4.8.0-r2 + 4.8.0-r2 + + + +

GNU Screen is a full-screen window manager that multiplexes a physical + terminal between several processes, typically interactive shells. +

+
+ +

It was discovered that GNU screen did not properly handle certain UTF-8 + character sequences. +

+
+ +

A remote attacker could entice a user to run a program where attacker + controls the output inside a GNU screen session, possibly resulting in + execution of arbitrary code with the privileges of the process or a + Denial of Service condition. +

+
+ +

This vulnerability can be mitigated by disabling UTF-8 processing in + .screenrc. +

+
+ +

All GNU screen users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-misc/screen-4.8.0-r2" + + +
+ + CVE-2021-26937 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-12.xml b/metadata/glsa/glsa-202105-12.xml new file mode 100644 index 000000000000..ad904d7afd3b --- /dev/null +++ b/metadata/glsa/glsa-202105-12.xml @@ -0,0 +1,50 @@ + + + + OpenSMTPD: Multiple vulnerabilities + Multiple vulnerabilities have been found in OpenSMTPD, the worst of + which could result in a Denial of Service condition. + + opensmtpd + 2021-05-26 + 2021-05-26 + 761945 + local, remote + + + 6.8.0_p2 + 6.8.0_p2 + + + +

OpenSMTPD is a lightweight but featured SMTP daemon from OpenBSD.

+
+ +

Multiple vulnerabilities have been discovered in OpenSMTPD. Please + review the CVE identifiers referenced below for details. +

+
+ +

A remote attacker, by connecting to the SMTP listener daemon, could + possibly cause a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All OpenSMTPD users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=mail-mta/opensmtpd-6.8.0_p2" + + +
+ + CVE-2020-35679 + CVE-2020-35680 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-13.xml b/metadata/glsa/glsa-202105-13.xml new file mode 100644 index 000000000000..6638a5a6dd58 --- /dev/null +++ b/metadata/glsa/glsa-202105-13.xml @@ -0,0 +1,49 @@ + + + + Mumble: User-assisted execution of arbitrary code + A vulnerability has been found in Mumble that could allow a remote + attacker to execute arbitrary code. + + mumble + 2021-05-26 + 2021-05-26 + 770973 + remote + + + 1.3.4 + 1.3.4 + + + +

Mumble is low-latency voice chat software intended for use with gaming.

+
+ +

Please review the CVE identifiers referenced below for details.

+
+ +

A remote attacker could entice a user to open a specially crafted server + list (web page) using Mumble, possibly resulting in execution of + arbitrary code with the privileges of the process or a Denial of Service + condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All Mumble users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=media-sound/mumble-1.3.4" + + +
+ + CVE-2021-27229 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-14.xml b/metadata/glsa/glsa-202105-14.xml new file mode 100644 index 000000000000..2469e2a8a654 --- /dev/null +++ b/metadata/glsa/glsa-202105-14.xml @@ -0,0 +1,61 @@ + + + + Squid: Multiple vulnerabilities + Multiple vulnerabilities have been found in Squid, the worst of + which could result in a Denial of Service condition. + + squid + 2021-05-26 + 2021-05-26 + 775194 + 789309 + remote + + + 4.15 + 4.15 + + + +

Squid is a full-featured Web proxy cache designed to run on Unix + systems. It supports proxying and caching of HTTP, FTP, and other URLs, + as well as SSL support, cache hierarchies, transparent caching, access + control lists and many other features. +

+
+ +

Multiple vulnerabilities have been discovered in Squid. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker could send a specially crafted request, possibly + resulting in a Denial of Service condition or information leak. +

+
+ +

There is no known workaround at this time.

+
+ +

All Squid users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-proxy/squid-4.15" + + +
+ + CVE-2020-25097 + CVE-2021-28116 + CVE-2021-28651 + CVE-2021-28652 + CVE-2021-28662 + CVE-2021-31806 + CVE-2021-31807 + CVE-2021-31808 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-15.xml b/metadata/glsa/glsa-202105-15.xml new file mode 100644 index 000000000000..5f2b4e50cd67 --- /dev/null +++ b/metadata/glsa/glsa-202105-15.xml @@ -0,0 +1,54 @@ + + + + Prosŏdy IM: Multiple vulnerabilities + Multiple vulnerabilities have been found in Prosŏdy IM, the worst + of which could result in a Denial of Service condition. + + prosody + 2021-05-26 + 2021-05-26 + 771144 + 789969 + remote + + + 0.11.9 + 0.11.9 + + + +

Prosŏdy IM is a modern XMPP communication server. It aims to be easy to + set up and configure, and efficient with system resources. +

+
+ +

Multiple vulnerabilities have been discovered in Prosŏdy IM. Please + review the CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Prosŏdy IM users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-im/prosody-0.11.9" + + +
+ + CVE-2021-32917 + CVE-2021-32918 + CVE-2021-32919 + CVE-2021-32920 + CVE-2021-32921 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-16.xml b/metadata/glsa/glsa-202105-16.xml new file mode 100644 index 000000000000..7d7d41ac76c5 --- /dev/null +++ b/metadata/glsa/glsa-202105-16.xml @@ -0,0 +1,53 @@ + + + + X.Org X11 library: Denial of service + A vulnerability in X.Org X11 library could lead to a Denial of + Service condition. + + libx11 + 2021-05-26 + 2021-05-26 + 790824 + remote + + + 1.7.1 + 1.7.1 + + + +

X.Org is an implementation of the X Window System. The X.Org X11 library + provides the X11 protocol library files. +

+
+ +

It was discovered that XLookupColor() and other X.Org X11 library + functions lacked proper validation of the length of their string + parameters. +

+
+ +

An attacker could emit arbitrary X protocol requests to the X server + through malicious crafted string parameters in applications linked + against X.Org X11 library. +

+
+ +

There is no known workaround at this time.

+
+ +

All X.Org X11 library users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=x11-libs/libX11-1.7.1" + + +
+ + CVE-2021-31535 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-17.xml b/metadata/glsa/glsa-202105-17.xml new file mode 100644 index 000000000000..17d191c8e5a6 --- /dev/null +++ b/metadata/glsa/glsa-202105-17.xml @@ -0,0 +1,51 @@ + + + + rxvt-unicode: User-assisted execution of arbitrary code + A vulnerability in rxvt-unicode may allow a remote attacker to + execute arbitrary code. + + rxvt-unicode + 2021-05-26 + 2021-05-26 + 790782 + local, remote + + + 9.22-r9 + 9.22-r9 + + + +

rxvt-unicode (urxvt) is a clone of the rxvt terminal emulator.

+
+ +

It was discovered that rxvt-unicode did not properly handle certain + escape sequences. +

+
+ +

A remote attacker could entice a user to run a program where attacker + controls the output inside a rxvt terminal window, possibly resulting in + execution of arbitrary code with the privileges of the process or a + Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All rxvt-unicode users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=x11-terms/rxvt-unicode-9.22-r9" + + +
+ + CVE-2021-33477 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-18.xml b/metadata/glsa/glsa-202105-18.xml new file mode 100644 index 000000000000..4e7c5707c1f1 --- /dev/null +++ b/metadata/glsa/glsa-202105-18.xml @@ -0,0 +1,54 @@ + + + + LittleCMS: User-assisted execution of arbitrary code + A heap-based buffer overflow in LittleCMS might allow remote + attackers to execute arbitrary code. + + lcms + 2021-05-26 + 2021-05-26 + 761418 + local, remote + + + 2.10 + 2.10 + + + +

LittleCMS, or short lcms, is a color management system for working with + ICC profiles. It is used by many applications including GIMP, Firefox and + Chromium. +

+
+ +

It was discovered that LittleCMS (aka Little Color Management System) + had an integer overflow in the AllocateDataSet function in cmscgats.c. +

+
+ +

A remote attacker could entice a user or automated system to open a + specially crafted file containing malicious color data, possibly + resulting in execution of arbitrary code with the privileges of the + process or a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All LittleCMS users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=media-libs/lcms-2.10" + + +
+ + CVE-2018-16435 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-19.xml b/metadata/glsa/glsa-202105-19.xml new file mode 100644 index 000000000000..79e89f0c9fe9 --- /dev/null +++ b/metadata/glsa/glsa-202105-19.xml @@ -0,0 +1,53 @@ + + + + Firejail: Privilege escalation + A vulnerability was discovered in Firejail which may allow local + attackers to gain root privileges. + + firejail + 2021-05-26 + 2021-05-26 + 769542 + local + + + 0.9.64.4 + 0.9.64.4 + + + +

A SUID program that reduces the risk of security breaches by restricting + the running environment of untrusted applications using Linux namespaces + and seccomp-bpf. +

+
+ +

It was discovered that a flaw in Firejail’s OverlayFS code allowed + restricted programs to escape sandbox. +

+
+ +

A local attacker could obtain arbitrary file system access via an + application running within a Firejail sandbox, possibly resulting in + privilege escalation. +

+
+ +

There is no known workaround at this time.

+
+ +

All Firejail users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/firejail-0.9.64.4" + + +
+ + CVE-2021-26910 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-20.xml b/metadata/glsa/glsa-202105-20.xml new file mode 100644 index 000000000000..359b42aa3759 --- /dev/null +++ b/metadata/glsa/glsa-202105-20.xml @@ -0,0 +1,54 @@ + + + + Dnsmasq: DNS cache poisoning + Use of insufficient randomness in Dnsmasq might lead to DNS Cache + Poisoning. + + dnsmasq + 2021-05-26 + 2021-05-26 + 782130 + local, remote + + + 2.85 + 2.85 + + + +

Dnsmasq is a lightweight and easily-configurable DNS forwarder and DHCP + server. +

+
+ +

It was discovered that Dnsmasq, when configured with + --server=<address>@ or similar (e.g. through dbus), + configured a fixed UDP port for all outgoing queries to the specified + upstream DNS server. + +

+
+ +

An attacker, by sending malicious crafted DNS responses, could perform a + DNS Cache Poisoning attack. +

+
+ +

There is no known workaround at this time.

+
+ +

All Dnsmasq users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-dns/dnsmasq-2.85" + + +
+ + CVE-2021-3448 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-21.xml b/metadata/glsa/glsa-202105-21.xml new file mode 100644 index 000000000000..899bd2ffa0eb --- /dev/null +++ b/metadata/glsa/glsa-202105-21.xml @@ -0,0 +1,54 @@ + + + + Tcpreplay: Multiple vulnerabilities + Multiple vulnerabilities have been found in Tcpreplay, the worst of + which could result in a Denial of Service condition. + + tcpreplay + 2021-05-26 + 2021-05-26 + 750344 + local + + + 4.3.4 + 4.3.4 + + + +

Tcpreplay is a suite of utilities for UNIX systems for editing and + replaying network traffic which was previously captured by tools like + tcpdump and ethereal/wireshark. +

+
+ +

Multiple vulnerabilities have been discovered in Tcpreplay. Please + review the CVE identifiers referenced below for details. +

+
+ +

A remote attacker could entice a user to open a specially crafted + network capture file using Tcpreplay, possibly resulting in a Denial of + Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All Tcpreplay users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-analyzer/tcpreplay-4.3.4" + + +
+ + CVE-2020-24265 + CVE-2020-24266 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-22.xml b/metadata/glsa/glsa-202105-22.xml new file mode 100644 index 000000000000..3d44f02e434e --- /dev/null +++ b/metadata/glsa/glsa-202105-22.xml @@ -0,0 +1,50 @@ + + + + Samba: Multiple vulnerabilities + Multiple vulnerabilities have been found in Samba, the worst of + which could result in a Denial of Service condition. + + samba + 2021-05-26 + 2021-05-26 + 778026 + 786825 + local, remote + + + 4.13.8 + 4.13.8 + + + +

Samba is a suite of SMB and CIFS client/server programs.

+
+ +

Multiple vulnerabilities have been discovered in Samba. Please review + the CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Samba users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-fs/samba-4.13.8" + + +
+ + CVE-2020-27840 + CVE-2021-20254 + CVE-2021-20277 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-23.xml b/metadata/glsa/glsa-202105-23.xml new file mode 100644 index 000000000000..a763f0658803 --- /dev/null +++ b/metadata/glsa/glsa-202105-23.xml @@ -0,0 +1,68 @@ + + + + PHP: Multiple vulnerabilities + Multiple vulnerabilities have been found in PHP, the worst of which + could result in a Denial of Service condition. + + php + 2021-05-26 + 2021-05-26 + 764314 + 768756 + 788892 + local, remote + + + 7.3.28 + 7.4.19 + 8.0.6 + 8.0.6 + + + +

PHP is an open source general-purpose scripting language that is + especially suited for web development. +

+
+ +

Multiple vulnerabilities have been discovered in PHP. Please review the + CVE identifiers and bugs referenced below for details. +

+
+ +

Please review the referenced CVE identifiers and bugs for details.

+
+ +

There is no known workaround at this time.

+
+ +

All PHP 7.3.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-lang/php-7.3.28:7.3" + + +

All PHP 7.4.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-lang/php-7.4.19:7.4" + + +

All PHP 8.0.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-lang/php-8.0.6:8.0" + + +
+ + CVE-2020-7071 + CVE-2021-21702 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-24.xml b/metadata/glsa/glsa-202105-24.xml new file mode 100644 index 000000000000..8075a96b41bf --- /dev/null +++ b/metadata/glsa/glsa-202105-24.xml @@ -0,0 +1,55 @@ + + + + FFmpeg: Multiple vulnerabilities + Multiple vulnerabilities have been found in FFmpeg, the worst of + which could result in the arbitrary execution of code. + + ffmpeg + 2021-05-26 + 2021-05-26 + 763315 + 781146 + local, remote + + + 4.4 + 4.4 + + + +

FFmpeg is a complete, cross-platform solution to record, convert and + stream audio and video. +

+
+ +

Multiple vulnerabilities have been discovered in FFmpeg. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker could entice a user to open a specially crafted media + file using FFmpeg, possibly resulting in execution of arbitrary code with + the privileges of the process or a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All FFmpeg users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=media-video/ffmpeg-4.4" + + +
+ + CVE-2020-35964 + CVE-2020-35965 + CVE-2021-30123 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-25.xml b/metadata/glsa/glsa-202105-25.xml new file mode 100644 index 000000000000..da213f1833fc --- /dev/null +++ b/metadata/glsa/glsa-202105-25.xml @@ -0,0 +1,49 @@ + + + + OpenVPN: Authentication bypass + A vulnerability has been found in OpenVPN, allowing attackers to + bypass the authentication process. + + openvpn + 2021-05-26 + 2021-05-26 + 785115 + remote + + + 2.5.2 + 2.5.2 + + + +

OpenVPN is a multi-platform, full-featured SSL VPN solution.

+
+ +

It was discovered that OpenVPN incorrectly handled deferred + authentication. +

+
+ +

A remote attacker could bypass authentication and access control channel + data and trigger further information leaks. +

+
+ +

Configure OpenVPN server to not use deferred authentication.

+
+ +

All OpenVPN users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-vpn/openvpn-2.5.2" + + +
+ + CVE-2020-15078 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-26.xml b/metadata/glsa/glsa-202105-26.xml new file mode 100644 index 000000000000..70c75a3efabd --- /dev/null +++ b/metadata/glsa/glsa-202105-26.xml @@ -0,0 +1,51 @@ + + + + SpamAssassin: Arbitrary command execution + A vulnerability in SpamAssassin might allow remote attackers to + execute arbitrary commands. + + SpamAssassin + 2021-05-26 + 2021-05-26 + 778002 + local, remote + + + 3.4.5 + 3.4.5 + + + +

SpamAssassin is an extensible email filter used to identify junk email.

+
+ +

It was discovered that SpamAssassin incorrectly handled certain CF + files. +

+
+ +

A remote attacker could entice a user or automated system to process a + specially crafted CF file using SpamAssassin, possibly resulting in + execution of arbitrary commands with the privileges of the process or a + Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All SpamAssassin users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=mail-filter/spamassassin-3.4.5" + + +
+ + CVE-2020-1946 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-27.xml b/metadata/glsa/glsa-202105-27.xml new file mode 100644 index 000000000000..030bb9ed2a0a --- /dev/null +++ b/metadata/glsa/glsa-202105-27.xml @@ -0,0 +1,247 @@ + + + + MySQL: Multiple vulnerabilities + Multiple vulnerabilities have been found in MySQL, the worst of + which could result in the arbitrary execution of code. + + mysql + 2021-05-26 + 2021-05-26 + 699876 + 708090 + 717628 + 732974 + 766339 + 789243 + local, remote + + + 5.7.34 + 8.0.24 + 8.0.24 + + + 8.0.24 + 8.0.24 + + + +

MySQL is a popular multi-threaded, multi-user SQL server.

+
+ +

Multiple vulnerabilities have been discovered in MySQL. Please review + the CVE identifiers referenced below for details. +

+
+ +

An attacker could possibly execute arbitrary code with the privileges of + the process, escalate privileges, gain access to critical data or + complete access to all MySQL server accessible data, or cause a Denial of + Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All MySQL users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/mysql-5.7.34" + + +

All mysql users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/mysql-8.0.24" + + +
+ + CVE-2019-2938 + CVE-2019-2974 + CVE-2020-14539 + CVE-2020-14540 + CVE-2020-14547 + CVE-2020-14550 + CVE-2020-14553 + CVE-2020-14559 + CVE-2020-14564 + CVE-2020-14567 + CVE-2020-14568 + CVE-2020-14575 + CVE-2020-14576 + CVE-2020-14586 + CVE-2020-14591 + CVE-2020-14597 + CVE-2020-14614 + CVE-2020-14619 + CVE-2020-14620 + CVE-2020-14623 + CVE-2020-14624 + CVE-2020-14626 + CVE-2020-14631 + CVE-2020-14632 + CVE-2020-14633 + CVE-2020-14634 + CVE-2020-14641 + CVE-2020-14643 + CVE-2020-14651 + CVE-2020-14654 + CVE-2020-14656 + CVE-2020-14663 + CVE-2020-14672 + CVE-2020-14678 + CVE-2020-14680 + CVE-2020-14697 + CVE-2020-14702 + CVE-2020-14725 + CVE-2020-14760 + CVE-2020-14765 + CVE-2020-14769 + CVE-2020-14771 + CVE-2020-14773 + CVE-2020-14775 + CVE-2020-14776 + CVE-2020-14777 + CVE-2020-14785 + CVE-2020-14786 + CVE-2020-14789 + CVE-2020-14790 + CVE-2020-14791 + CVE-2020-14793 + CVE-2020-14794 + CVE-2020-14799 + CVE-2020-14800 + CVE-2020-14804 + CVE-2020-14809 + CVE-2020-14812 + CVE-2020-14814 + CVE-2020-14821 + CVE-2020-14827 + CVE-2020-14828 + CVE-2020-14829 + CVE-2020-14830 + CVE-2020-14836 + CVE-2020-14837 + CVE-2020-14838 + CVE-2020-14839 + CVE-2020-14844 + CVE-2020-14845 + CVE-2020-14846 + CVE-2020-14848 + CVE-2020-14852 + CVE-2020-14853 + CVE-2020-14860 + CVE-2020-14861 + CVE-2020-14866 + CVE-2020-14867 + CVE-2020-14868 + CVE-2020-14869 + CVE-2020-14870 + CVE-2020-14873 + CVE-2020-14878 + CVE-2020-14888 + CVE-2020-14891 + CVE-2020-14893 + CVE-2020-2570 + CVE-2020-2572 + CVE-2020-2573 + CVE-2020-2574 + CVE-2020-2577 + CVE-2020-2579 + CVE-2020-2580 + CVE-2020-2584 + CVE-2020-2588 + CVE-2020-2589 + CVE-2020-2627 + CVE-2020-2660 + CVE-2020-2679 + CVE-2020-2686 + CVE-2020-2694 + CVE-2020-2752 + CVE-2020-2759 + CVE-2020-2760 + CVE-2020-2761 + CVE-2020-2762 + CVE-2020-2763 + CVE-2020-2765 + CVE-2020-2768 + CVE-2020-2770 + CVE-2020-2774 + CVE-2020-2779 + CVE-2020-2780 + CVE-2020-2790 + CVE-2020-2804 + CVE-2020-2806 + CVE-2020-2812 + CVE-2020-2814 + CVE-2020-2853 + CVE-2020-2875 + CVE-2020-2892 + CVE-2020-2893 + CVE-2020-2895 + CVE-2020-2896 + CVE-2020-2897 + CVE-2020-2898 + CVE-2020-2901 + CVE-2020-2903 + CVE-2020-2904 + CVE-2020-2921 + CVE-2020-2922 + CVE-2020-2923 + CVE-2020-2924 + CVE-2020-2925 + CVE-2020-2926 + CVE-2020-2928 + CVE-2020-2930 + CVE-2020-2933 + CVE-2020-2934 + CVE-2021-1998 + CVE-2021-2001 + CVE-2021-2002 + CVE-2021-2006 + CVE-2021-2007 + CVE-2021-2009 + CVE-2021-2010 + CVE-2021-2011 + CVE-2021-2012 + CVE-2021-2014 + CVE-2021-2016 + CVE-2021-2019 + CVE-2021-2020 + CVE-2021-2021 + CVE-2021-2022 + CVE-2021-2024 + CVE-2021-2028 + CVE-2021-2030 + CVE-2021-2031 + CVE-2021-2032 + CVE-2021-2036 + CVE-2021-2038 + CVE-2021-2042 + CVE-2021-2046 + CVE-2021-2048 + CVE-2021-2055 + CVE-2021-2056 + CVE-2021-2058 + CVE-2021-2060 + CVE-2021-2061 + CVE-2021-2065 + CVE-2021-2070 + CVE-2021-2072 + CVE-2021-2076 + CVE-2021-2081 + CVE-2021-2087 + CVE-2021-2088 + CVE-2021-2122 + CVE-2021-2154 + CVE-2021-2166 + CVE-2021-2180 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-28.xml b/metadata/glsa/glsa-202105-28.xml new file mode 100644 index 000000000000..f020be913511 --- /dev/null +++ b/metadata/glsa/glsa-202105-28.xml @@ -0,0 +1,75 @@ + + + + MariaDB: Multiple vulnerabilities + Multiple vulnerabilities have been found in MariaDB, the worst of + which could result in the arbitrary execution of code. + + mariadb + 2021-05-26 + 2021-05-26 + 777786 + 789240 + local, remote + + + 10.2.38 + 10.3.29 + 10.4.19 + 10.5.10 + 10.5.10 + + + +

MariaDB is an enhanced, drop-in replacement for MySQL.

+
+ +

Multiple vulnerabilities have been discovered in MariaDB. Please review + the CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All MariaDB 10.2.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.2.38:10.2" + + +

All MariaDB 10.3.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.3.29:10.3" + + +

All MariaDB 10.3.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.4.19:10.4" + + +

All MariaDB 10.5.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.5.10:10.5" + + +
+ + CVE-2021-2154 + CVE-2021-2166 + CVE-2021-2180 + CVE-2021-27928 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-29.xml b/metadata/glsa/glsa-202105-29.xml new file mode 100644 index 000000000000..e2507b22b90b --- /dev/null +++ b/metadata/glsa/glsa-202105-29.xml @@ -0,0 +1,49 @@ + + + + Tar: Denial of service + A vulnerability in Tar could lead to a Denial of Service condition. + tar + 2021-05-26 + 2021-05-26 + 778548 + local, remote + + + 1.34 + 1.34 + + + +

The Tar program provides the ability to create and manipulate tar + archives. +

+
+ +

It was discovered that GNU Tar had a memory leak when processing archive + headers. +

+
+ +

A remote attacker could entice a user to open a specially crafted + archive using Tar, possibly resulting in a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All Tar users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-arch/tar-1.34" + + +
+ + CVE-2021-20193 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-30.xml b/metadata/glsa/glsa-202105-30.xml new file mode 100644 index 000000000000..4cbf0070e7eb --- /dev/null +++ b/metadata/glsa/glsa-202105-30.xml @@ -0,0 +1,52 @@ + + + + MuPDF: Multiple vulnerabilities + Multiple vulnerabilities have been found in MuPDF, the worst of + which could result in a Denial of Service condition. + + mupdf + 2021-05-26 + 2021-05-26 + 747151 + 772311 + local, remote + + + 1.18.0-r3 + 1.18.0-r3 + + + +

MuPDF is a lightweight PDF viewer and toolkit written in portable C.

+
+ +

Multiple vulnerabilities have been discovered in MuPDF. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker could entice a user to open a specially crafted PDF + document using MuPDF, possibly resulting in a Denial of Service condition + or have other unspecified impact. +

+
+ +

There is no known workaround at this time.

+
+ +

All MuPDF users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-text/mupdf-1.18.0-r3" + + +
+ + CVE-2020-26519 + CVE-2021-3407 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-31.xml b/metadata/glsa/glsa-202105-31.xml new file mode 100644 index 000000000000..05d9ce89b585 --- /dev/null +++ b/metadata/glsa/glsa-202105-31.xml @@ -0,0 +1,54 @@ + + + + Nettle: Denial of service + A vulnerability in Nettle could lead to a Denial of Service + condition. + + nettle + 2021-05-26 + 2021-05-26 + 780483 + local, remote + + + 3.7.2 + 3.7.2 + + + +

Nettle is a cryptographic library that is designed to fit easily in + almost any context: In cryptographic toolkits for object-oriented + languages, such as C++, Python, or Pike, in applications like lsh or + GnuPG, or even in kernel space. +

+
+ +

It was discovered that Nettle incorrectly handled signature + verification. +

+
+ +

A remote attacker could send a specially crafted valid-looking input + signature, possibly resulting in a Denial of Service condition or force + an invalid signature. +

+
+ +

There is no known workaround at this time.

+
+ +

All Nettle users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-libs/nettle-3.7.2" + + +
+ + CVE-2021-20305 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-32.xml b/metadata/glsa/glsa-202105-32.xml new file mode 100644 index 000000000000..44edeaa40bfd --- /dev/null +++ b/metadata/glsa/glsa-202105-32.xml @@ -0,0 +1,92 @@ + + + + PostgreSQL: Multiple vulnerabilities + Multiple vulnerabilities have been found in PostgreSQL, the worst + of which could result in information disclosure. + + postgresql + 2021-05-26 + 2021-05-26 + 771942 + local, remote + + + 9.5.25 + 9.6.21 + 10.16 + 11.11 + 12.6 + 13.2 + 13.2 + + + +

PostgreSQL is an open source object-relational database management + system. +

+
+ +

Multiple vulnerabilities have been discovered in PostgreSQL. Please + review the CVE identifiers referenced below for details. +

+
+ +

An authenticated remote attacker, by executing malicious crafted + queries, could possibly disclose sensitive information. +

+
+ +

There is no known workaround at this time.

+
+ +

All PostgreSQL 9.5.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/postgresql-9.5.25:9.5" + + +

All PostgreSQL 9.6.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/postgresql-9.6.21:9.6" + + +

All PostgreSQL 10.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/postgresql-10.16:10" + + +

All PostgreSQL 11.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/postgresql-11.11:11" + + +

All PostgreSQL 12.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/postgresql-12.6:12" + + +

All PostgreSQL 13.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/postgresql-13.2:13" + + +
+ + CVE-2021-20229 + CVE-2021-3393 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-33.xml b/metadata/glsa/glsa-202105-33.xml new file mode 100644 index 000000000000..dddf99d66910 --- /dev/null +++ b/metadata/glsa/glsa-202105-33.xml @@ -0,0 +1,55 @@ + + + + containerd: Multiple vulnerabilities + Multiple vulnerabilities have been found in containerd, the worst + of which could result in privilege escalation. + + containerd + 2021-05-26 + 2021-05-26 + 758137 + 775329 + local + + + 1.4.4 + 1.4.4 + + + +

Containerd is a daemon with an API and a command line client, to manage + containers on one machine. It uses runC to run containers according to + the OCI specification. +

+
+ +

Multiple vulnerabilities have been discovered in containerd. Please + review the CVE identifiers referenced below for details. +

+
+ +

A local attacker, able to run a malicious container in the same network + namespace as the shim, could possibly escalate privileges. Furthermore, + an attacker could disclose sensitive information. +

+
+ +

There is no known workaround at this time.

+
+ +

All containerd users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-emulation/containerd-1.4.4" + + +
+ + CVE-2020-15257 + CVE-2021-21334 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-34.xml b/metadata/glsa/glsa-202105-34.xml new file mode 100644 index 000000000000..31c7e3ef7065 --- /dev/null +++ b/metadata/glsa/glsa-202105-34.xml @@ -0,0 +1,45 @@ + + + + Bash: Privilege escalation + A vulnerability in Bash may allow users to escalate privileges. + bash + 2021-05-26 + 2021-05-26 + 702488 + local + + + 5.0_p11-r1 + 5.0_p11-r1 + + + +

Bash is the standard GNU Bourne Again SHell.

+
+ +

It was discovered that Bash incorrectly dropped privileges by setting + its effective UID to its real UID. +

+
+ +

A local attacker could possibly escalate privileges.

+
+ +

There is no known workaround at this time.

+
+ +

All Bash users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-shells/bash-5.0_p11-r1" + + +
+ + CVE-2019-18276 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-35.xml b/metadata/glsa/glsa-202105-35.xml new file mode 100644 index 000000000000..33ff95b8cb20 --- /dev/null +++ b/metadata/glsa/glsa-202105-35.xml @@ -0,0 +1,57 @@ + + + + OpenSSH: Multiple vulnerabilities + Multiple vulnerabilities have been found in OpenSSH, the worst of + which could allow a remote attacker to execute arbitrary code. + + openssh + 2021-05-26 + 2021-05-26 + 763048 + 774090 + local, remote + + + 8.5_p1 + 8.5_p1 + + + +

OpenSSH is a complete SSH protocol implementation that includes SFTP + client and server support. +

+
+ +

Multiple vulnerabilities have been discovered in OpenSSH. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker, able to access the socket of the forwarding agent, + might be able to execute arbitrary code with the privileges of the + process or cause a Denial of Service condition. + Furthermore, a remote attacker might conduct a man-in-the-middle attack + targeting initial connection attempts where no host key for the server + has been cached by client yet. +

+
+ +

There is no known workaround at this time.

+
+ +

All OpenSSH users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/openssh-8.5_p1" + + +
+ + CVE-2020-14145 + CVE-2021-28041 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-36.xml b/metadata/glsa/glsa-202105-36.xml new file mode 100644 index 000000000000..21839569513f --- /dev/null +++ b/metadata/glsa/glsa-202105-36.xml @@ -0,0 +1,51 @@ + + + + cURL: Multiple vulnerabilities + Multiple vulnerabilities have been found in cURL, the worst of + which could result in the arbitrary execution of code. + + curl + 2021-05-26 + 2021-05-26 + 779535 + 792192 + local, remote + + + 7.77.0 + 7.77.0 + + + +

A command line tool and library for transferring data with URLs.

+
+ +

Multiple vulnerabilities have been discovered in cURL. Please review the + CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All cURL users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/curl-7.77.0" + + +
+ + CVE-2021-22876 + CVE-2021-22890 + CVE-2021-22898 + CVE-2021-22901 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-37.xml b/metadata/glsa/glsa-202105-37.xml new file mode 100644 index 000000000000..207f833941a9 --- /dev/null +++ b/metadata/glsa/glsa-202105-37.xml @@ -0,0 +1,50 @@ + + + + Nextcloud Desktop Client: User-assisted execution of arbitrary code + A vulnerability in Nextcloud Desktop Client could allow a remote + attacker to execute arbitrary commands. + + nextcloud-client + 2021-05-26 + 2021-05-26 + 783531 + remote + + + 3.1.3 + 3.1.3 + + + +

The Nextcloud Desktop Client is a tool to synchronize files from + Nextcloud Server with your computer. +

+
+ +

It was discovered that Nextcloud Desktop Client did not validate URLs.

+
+ +

A remote attacker could entice a user to connect to a malicious + Nextcloud server to cause the execution of arbitrary commands with the + privileges of the user running the Nextcloud Desktop Client application. +

+
+ +

There is no known workaround at this time.

+
+ +

All Nextcloud Desktop Client users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/nextcloud-client-3.1.3" + + +
+ + CVE-2021-22879 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-38.xml b/metadata/glsa/glsa-202105-38.xml new file mode 100644 index 000000000000..d5c53fccdbba --- /dev/null +++ b/metadata/glsa/glsa-202105-38.xml @@ -0,0 +1,59 @@ + + + + nginx: Remote code execution + A vulnerability in nginx could lead to remote code execution. + nginx + 2021-05-26 + 2021-05-26 + 792087 + remote + + + 1.20.1 + 1.21.0 + 1.21.0 + + + +

nginx is a robust, small, and high performance HTTP and reverse proxy + server. +

+
+ +

It was discovered that nginx did not properly handle DNS responses when + “resolver” directive is used. +

+
+ +

A remote attacker, able to provide DNS responses to a nginx instance, + could cause the execution of arbitrary code with the privileges of the + process or a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All nginx users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-servers/nginx-1.20.1" + + +

All nginx mainline users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=www-servers/nginx-1.21.0:mainline" + + +
+ + CVE-2021-23017 + + whissi + whissi +
diff --git a/metadata/glsa/glsa-202105-39.xml b/metadata/glsa/glsa-202105-39.xml new file mode 100644 index 000000000000..83c8ceab4fca --- /dev/null +++ b/metadata/glsa/glsa-202105-39.xml @@ -0,0 +1,58 @@ + + + + Ceph: Multiple vulnerabilities + Multiple vulnerabilities have been found in Ceph, the worst of + which could result in privilege escalation. + + ceph + 2021-05-26 + 2021-05-26 + 760824 + 761969 + 783486 + 791253 + remote + + + 14.2.21 + 14.2.21 + + + +

Ceph is a distributed network file system designed to provide excellent + performance, reliability, and scalability. +

+
+ +

Multiple vulnerabilities have been discovered in Ceph. Please review the + CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Ceph users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-cluster/ceph-14.2.21" + + +
+ + CVE-2020-10753 + CVE-2020-1759 + CVE-2020-1760 + CVE-2020-25660 + CVE-2020-25678 + CVE-2020-27781 + CVE-2021-20288 + + whissi + whissi +
diff --git a/metadata/glsa/timestamp.chk b/metadata/glsa/timestamp.chk index 8244f040aa63..54a66ae57890 100644 --- a/metadata/glsa/timestamp.chk +++ b/metadata/glsa/timestamp.chk @@ -1 +1 @@ -Sat, 22 May 2021 06:08:53 +0000 +Mon, 31 May 2021 19:38:54 +0000 diff --git a/metadata/glsa/timestamp.commit b/metadata/glsa/timestamp.commit index 785900450f6b..46585d116878 100644 --- a/metadata/glsa/timestamp.commit +++ b/metadata/glsa/timestamp.commit @@ -1 +1 @@ -ce41c6125acff2a3d4d5dec0069d73d86997778a 1620156660 2021-05-04T19:31:00+00:00 +7711e73ed3ea72c507190aff24d27f011094dffd 1622062693 2021-05-26T20:58:13+00:00 -- cgit v1.2.3