VARIoT IoT vulnerabilities database
| VAR-202203-1236 | CVE-2022-24655 | NETGEAR EX6100v1 Stack Overflow Vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0.0.62, which may lead to the execution of arbitrary code without authentication. NETGEAR EX6100v1 is a WiFi range extender from Netgear, USA. An attacker could exploit this vulnerability to execute arbitrary code
| VAR-202203-1220 | CVE-2022-25453 | Tenda AC6 saveParentControlInfo function stack overflow vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function. The Tenda AC6 is a wireless router from the Chinese company Tenda
| VAR-202203-1214 | CVE-2022-25437 | Tenda AC9 Buffer Overflow Vulnerability (CNVD-2022-26242) |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function. The Tenda AC9 is a wireless router from the Chinese company Tenda.
There is a buffer overflow vulnerability in Tenda AC9 version 15.03.2.21. The vulnerability arises from the fact that when the list parameter in the SetVirtualServerCfg function performs operations on memory, the data boundary is not properly verified. An attacker can exploit this vulnerability to cause arbitrary command execution
| VAR-202203-0591 | CVE-2022-25446 | Tenda AC6 openSchedWifi function stack overflow vulnerability (CNVD-2022-23519) |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSchedWifi function. Tenda AC6 is a wireless router.
Tenda AC6 v15.03.05.09_multi has a buffer overflow vulnerability, which can be exploited by attackers to cause arbitrary command execution
| VAR-202203-1216 | CVE-2022-25440 | Tenda AC9 Buffer Overflow Vulnerability (CNVD-2022-26243) |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function. The Tenda AC9 is a wireless router from the Chinese company Tenda.
A buffer overflow vulnerability exists in Tenda AC9 version 15.03.2.21. The vulnerability arises from the fact that when the ntpserver parameter in the SetSysTimeCfg function performs operations on memory, the data boundary is not properly verified. An attacker can exploit this vulnerability to cause arbitrary command execution
| VAR-202203-1219 | CVE-2022-25450 | Stack Overflow Vulnerability in Tenda AC6 SetVirtualServerCfg Function |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function. The Tenda AC6 is a wireless router from the Chinese company Tenda
| VAR-202203-1217 | CVE-2022-25445 | Stack Overflow Vulnerability in Tenda AC6 PowerSaveSet Function |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function. The Tenda AC6 is a wireless router from the Chinese company Tenda
| VAR-202203-1211 | CVE-2022-25429 | Tenda AC9 saveparentcontrolinfo function buffer overflow vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo function. The Tenda AC9 is a wireless router from the Chinese company Tenda
| VAR-202203-1218 | CVE-2022-25448 | Tenda AC6 openSchedWifi function stack overflow vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the day parameter in the openSchedWifi function. Tenda AC6 is a wireless router
| VAR-202203-0588 | CVE-2022-25438 | Tenda AC9 Command Injection Vulnerability (CNVD-2022-26241) |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function. The Tenda AC9 is a wireless router from the Chinese company Tenda. The vulnerability stems from the fact that the dosystemcmd parameter in the sub_a3550 function fails to properly filter the special elements that construct the code segment
| VAR-202203-1209 | CVE-2022-25427 | Tenda AC9 openSchedWifi function stack overflow vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function. The Tenda AC9 is a wireless router from the Chinese company Tenda
| VAR-202203-0598 | CVE-2022-25457 | Tenda AC6 Stack Overflow Vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function. Tenda AC6 is a wireless router.
Tenda AC6 has a security vulnerability that could allow an attacker to corrupt memory or cause a denial of service
| VAR-202203-0587 | CVE-2022-25435 | Tenda AC9 Buffer Overflow Vulnerability (CNVD-2022-26244) |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetStaticRoutecfg function. The Tenda AC9 is a wireless router from the Chinese company Tenda.
There is a buffer overflow vulnerability in Tenda AC9 15.03.2.21. The vulnerability arises from the fact that when the list parameter in the SetStaticRoutecfg function performs operations on memory, the data boundary is not properly verified. An attacker can exploit this vulnerability to execute arbitrary commands
| VAR-202203-1210 | CVE-2022-25428 | Tenda AC9 saveparentcontrolinfo function stack overflow vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo function. The Tenda AC9 is a wireless router from the Chinese company Tenda
| VAR-202203-0664 | CVE-2021-25220 | BIND Cache Pollution with Incorrect Records Vulnerability in |
CVSS V2: 4.0 CVSS V3: 6.8 Severity: MEDIUM |
BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients. Bogus NS records supplied by the forwarders may be cached and used by name if it needs to recurse for any reason. This issue causes it to obtain and pass on potentially incorrect answers. (CVE-2021-25220)
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service. (CVE-2022-2795)
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources. (CVE-2022-38177)
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources. (CVE-2022-38178).
For the oldstable distribution (buster), this problem has been fixed
in version 1:9.11.5.P4+dfsg-5.1+deb10u7.
For the stable distribution (bullseye), this problem has been fixed in
version 1:9.16.27-1~deb11u1.
We recommend that you upgrade your bind9 packages.
For the detailed security status of bind9 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/bind9
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmI010UACgkQEMKTtsN8
Tjbp3xAAil38qfAIdNkaIxY2bauvTyZDWzr6KUjph0vzmLEoAFQ3bysVSGlCnZk9
IgdyfPRWQ+Bjau1/dlhNYaTlnQajbeyvCXfJcjRRgtUDCp7abZcOcb1WDu8jWLGW
iRtKsvKKrTKkIou5LgDlyqZyf6OzjgRdwtm86GDPQiCaSEpmbRt+APj5tkIA9R1G
ELWuZsjbIraBU0TsNfOalgNpAWtSBayxKtWB69J8rxUV69JI194A4AJ0wm9SPpFV
G/TzlyHp1dUZJRLNmZOZU/dq4pPsXzh9I4QCg1kJWsVHe2ycAJKho6hr5iy43fNl
MuokfI9YnU6/9SjHrQAWp1X/6MYCR8NieJ933W89/Zb8eTjTZC8EQGo6fkA287G8
glQOrJHMQyV+b97lT67+ioTHNzTEBXTih7ZDeC1TlLqypCNYhRF/ll0Hx/oeiJFU
rbjh2Og9huhD5JH8z8YAvY2g81e7KdPxazuKJnQpxGutqddCuwBvyI9fovYrah9W
bYD6rskLZM2x90RI2LszHisl6FV5k37PaczamlRqGgbbMb9YlnDFjJUbM8rZZgD4
+8u/AkHq2+11pTtZ40NYt1gpdidmIC/gzzha2TfZCHMs44KPMMdH+Fid1Kc6/Cq8
QygtL4M387J9HXUrlN7NDUOrDVuVqfBG+ve3i9GCZzYjwtajTAQ=
=6st2
-----END PGP SIGNATURE-----
. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: bind security update
Advisory ID: RHSA-2023:0402-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2023:0402
Issue date: 2023-01-24
CVE Names: CVE-2021-25220 CVE-2022-2795
====================================================================
1. Summary:
An update for bind is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
3. Description:
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.
Security Fix(es):
* bind: DNS forwarders - cache poisoning vulnerability (CVE-2021-25220)
* bind: processing large delegations may severely degrade resolver
performance (CVE-2022-2795)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the update, the BIND daemon (named) will be restarted
automatically.
5. Bugs fixed (https://bugzilla.redhat.com/):
2064512 - CVE-2021-25220 bind: DNS forwarders - cache poisoning vulnerability
2128584 - CVE-2022-2795 bind: processing large delegations may severely degrade resolver performance
6. Package List:
Red Hat Enterprise Linux Client (v. 7):
Source:
bind-9.11.4-26.P2.el7_9.13.src.rpm
noarch:
bind-license-9.11.4-26.P2.el7_9.13.noarch.rpm
x86_64:
bind-debuginfo-9.11.4-26.P2.el7_9.13.i686.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.i686.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-libs-9.11.4-26.P2.el7_9.13.i686.rpm
bind-libs-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.i686.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-utils-9.11.4-26.P2.el7_9.13.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64:
bind-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-chroot-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.i686.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.i686.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-utils-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-sdb-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-sdb-chroot-9.11.4-26.P2.el7_9.13.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source:
bind-9.11.4-26.P2.el7_9.13.src.rpm
noarch:
bind-license-9.11.4-26.P2.el7_9.13.noarch.rpm
x86_64:
bind-debuginfo-9.11.4-26.P2.el7_9.13.i686.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.i686.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-libs-9.11.4-26.P2.el7_9.13.i686.rpm
bind-libs-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.i686.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-utils-9.11.4-26.P2.el7_9.13.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64:
bind-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-chroot-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.i686.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.i686.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-utils-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-sdb-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-sdb-chroot-9.11.4-26.P2.el7_9.13.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
bind-9.11.4-26.P2.el7_9.13.src.rpm
noarch:
bind-license-9.11.4-26.P2.el7_9.13.noarch.rpm
ppc64:
bind-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-chroot-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.ppc.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.ppc.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-libs-9.11.4-26.P2.el7_9.13.ppc.rpm
bind-libs-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.ppc.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-pkcs11-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.ppc.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-pkcs11-utils-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-utils-9.11.4-26.P2.el7_9.13.ppc64.rpm
ppc64le:
bind-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-chroot-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-libs-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-pkcs11-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-pkcs11-utils-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-utils-9.11.4-26.P2.el7_9.13.ppc64le.rpm
s390x:
bind-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-chroot-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.s390.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.s390.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-libs-9.11.4-26.P2.el7_9.13.s390.rpm
bind-libs-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.s390.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-pkcs11-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.s390.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-pkcs11-utils-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-utils-9.11.4-26.P2.el7_9.13.s390x.rpm
x86_64:
bind-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-chroot-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.i686.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.i686.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-libs-9.11.4-26.P2.el7_9.13.i686.rpm
bind-libs-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.i686.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.i686.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-utils-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-utils-9.11.4-26.P2.el7_9.13.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
ppc64:
bind-debuginfo-9.11.4-26.P2.el7_9.13.ppc.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-devel-9.11.4-26.P2.el7_9.13.ppc.rpm
bind-devel-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.ppc.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.ppc.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.ppc.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-sdb-9.11.4-26.P2.el7_9.13.ppc64.rpm
bind-sdb-chroot-9.11.4-26.P2.el7_9.13.ppc64.rpm
ppc64le:
bind-debuginfo-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-devel-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-sdb-9.11.4-26.P2.el7_9.13.ppc64le.rpm
bind-sdb-chroot-9.11.4-26.P2.el7_9.13.ppc64le.rpm
s390x:
bind-debuginfo-9.11.4-26.P2.el7_9.13.s390.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-devel-9.11.4-26.P2.el7_9.13.s390.rpm
bind-devel-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.s390.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.s390.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.s390.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-sdb-9.11.4-26.P2.el7_9.13.s390x.rpm
bind-sdb-chroot-9.11.4-26.P2.el7_9.13.s390x.rpm
x86_64:
bind-debuginfo-9.11.4-26.P2.el7_9.13.i686.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-sdb-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-sdb-chroot-9.11.4-26.P2.el7_9.13.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
bind-9.11.4-26.P2.el7_9.13.src.rpm
noarch:
bind-license-9.11.4-26.P2.el7_9.13.noarch.rpm
x86_64:
bind-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-chroot-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.i686.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.i686.rpm
bind-export-libs-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-libs-9.11.4-26.P2.el7_9.13.i686.rpm
bind-libs-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.i686.rpm
bind-libs-lite-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.i686.rpm
bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-utils-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-utils-9.11.4-26.P2.el7_9.13.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64:
bind-debuginfo-9.11.4-26.P2.el7_9.13.i686.rpm
bind-debuginfo-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-export-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-lite-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.i686.rpm
bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-sdb-9.11.4-26.P2.el7_9.13.x86_64.rpm
bind-sdb-chroot-9.11.4-26.P2.el7_9.13.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2021-25220
https://access.redhat.com/security/cve/CVE-2022-2795
https://access.redhat.com/security/updates/classification/#moderate
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBY9AIs9zjgjWX9erEAQiz9BAAiQvmAQ5DWdOQbHHizPAHBnKnBtNBfCT3
iaAzKQ0Yrpk26N9cdrvcBJwdrHpI28VJ3eemFUxQFseUqtAErsgfL4QqnjPjQgsp
U2qLPjqbzfOrbi1CuruMMIIbtxfwvsdic8OB9Zi7XzfZjWm2X4c6Ima+QXol6x9a
8J2qdzCqhoYUXJgdpVK9nAAGsPtidcnqLYYIcTclJArp6uRSlEEk7EbNJvs2SAbj
MUo5aq5BoVy2TkiMyqhT5voy6K8f4c7WbQYerNieps18541ZSr29fAzWBznr3Yns
gE10Aaoa8uCxlaexFR8EahPVYe6wJAm6R62LBabEWChbzW0oxr7X2DdzX9eiOwl0
wJT0n4GHoFsCGMa+v1yybkjHIUfiW25WC7bC4QDj4fjTpbicVlnttXhQJwCJK5bb
PC27GE6qi7EqwHYJa/jPenbIG38mXj/r2bwIr1qYQMLjQ8BQIneShky3ZWE4l/jd
zTMwGVal8ACBYdCALx/O9QNyzaO92xHLnKl3DIoqaQdjasIfGp/G6Xc1YggKyZAP
VVtXPiOIbReBVNWiBXMH1ZEQeNon4su0/MbMWrmJpwvEzYeXkuWO98LZ4dlLVuim
NG/dJ6RqzT6/aqRNVyOt5s4SLIQ5DrPXoPnZRUBsbpWhP6lxPhESKA0TUg5FYz33
eDGIrZR4jEY=azJw
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
. 9) - aarch64, noarch, ppc64le, s390x, x86_64
3. Description:
The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address. The dhcp packages provide a relay agent and ISC DHCP service
required to enable and administer DHCP on a network.
The following advisory data is extracted from:
https://access.redhat.com/security/data/csaf/v2/advisories/2024/rhsa-2024_2720.json
Red Hat officially shut down their mailing list notifications October 10, 2023. Due to this, Packet Storm has recreated the below data as a reference point to raise awareness. It must be noted that due to an inability to easily track revision updates without crawling Red Hat's archive, these advisories are single notifications and we strongly suggest that you visit the Red Hat provided links to ensure you have the latest information available if the subject matter listed pertains to your environment. 8) - aarch64, ppc64le, s390x, x86_64
3. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202210-25
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Low
Title: ISC BIND: Multiple Vulnerabilities
Date: October 31, 2022
Bugs: #820563, #835439, #872206
ID: 202210-25
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities have been discovered in ISC BIND, the worst of
which could result in denial of service.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-dns/bind < 9.16.33 >= 9.16.33
2 net-dns/bind-tools < 9.16.33 >= 9.16.33
Description
===========
Multiple vulnerabilities have been discovered in ISC BIND. Please review
the CVE identifiers referenced below for details.
Impact
======
Please review the referenced CVE identifiers for details.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All ISC BIND users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-dns/bind-9.16.33"
All ISC BIND-tools users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-dns/bind-tools-9.16.33"
References
==========
[ 1 ] CVE-2021-25219
https://nvd.nist.gov/vuln/detail/CVE-2021-25219
[ 2 ] CVE-2021-25220
https://nvd.nist.gov/vuln/detail/CVE-2021-25220
[ 3 ] CVE-2022-0396
https://nvd.nist.gov/vuln/detail/CVE-2022-0396
[ 4 ] CVE-2022-2795
https://nvd.nist.gov/vuln/detail/CVE-2022-2795
[ 5 ] CVE-2022-2881
https://nvd.nist.gov/vuln/detail/CVE-2022-2881
[ 6 ] CVE-2022-2906
https://nvd.nist.gov/vuln/detail/CVE-2022-2906
[ 7 ] CVE-2022-3080
https://nvd.nist.gov/vuln/detail/CVE-2022-3080
[ 8 ] CVE-2022-38177
https://nvd.nist.gov/vuln/detail/CVE-2022-38177
[ 9 ] CVE-2022-38178
https://nvd.nist.gov/vuln/detail/CVE-2022-38178
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202210-25
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
. ==========================================================================
Ubuntu Security Notice USN-5332-1
March 17, 2022
bind9 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 21.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in Bind.
Software Description:
- bind9: Internet Domain Name Server
Details:
Xiang Li, Baojun Liu, Chaoyi Lu, and Changgen Zou discovered that Bind
incorrectly handled certain bogus NS records when using forwarders. A
remote attacker could possibly use this issue to manipulate cache results.
(CVE-2021-25220)
It was discovered that Bind incorrectly handled certain crafted TCP
streams. A remote attacker could possibly use this issue to cause Bind to
consume resources, leading to a denial of service. This issue only affected
Ubuntu 21.10. (CVE-2022-0396)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 21.10:
bind9 1:9.16.15-1ubuntu1.2
Ubuntu 20.04 LTS:
bind9 1:9.16.1-0ubuntu2.10
Ubuntu 18.04 LTS:
bind9 1:9.11.3+dfsg-1ubuntu1.17
In general, a standard system update will make all the necessary changes
| VAR-202203-0653 | CVE-2021-44262 | Vulnerability related to lack of authentication for important functions in multiple NETGEAR products |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device. of netgear mbr1517 firmware, wnce3001 firmware, WAC104 Firmware has a lack of authentication vulnerability for critical functionality.Information may be obtained. Netgear W104 is a wireless access point from Netgear Corporation of the United States
| VAR-202203-1262 | CVE-2021-44259 | WAVLINK of wl-wn531g3 Vulnerability related to lack of authentication for critical functions in firmware |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When an unauthorized user accesses this page directly, it connects to this device as a friend of the device owner. WAVLINK of wl-wn531g3 Firmware has a lack of authentication vulnerability for critical functionality.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. WAVLINK AC1200 is a dual-band high-power wireless router from China WAVLINK
| VAR-202203-1267 | CVE-2022-24424 | Dell's Dell EMC AppSync Past traversal vulnerability in |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application. DELL EMC AppSync is a replication data management software of Dell (DELL). Provides a simple, SLA-driven, self-service way to protect, restore and clone critical Microsoft and Oracle applications and VMware environments
| VAR-202203-0651 | CVE-2021-44261 | Vulnerability related to lack of authentication for important functions in multiple NETGEAR products |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version information for the device. WAC104 firmware, R7450 firmware, R6900 Multiple NETGEAR products, such as firmware, have vulnerabilities related to lack of authentication for important functions.Information may be obtained. Netgear W104 is a wireless access point from Netgear Corporation of the United States. The vulnerability stems from the lack of protection and permission restrictions for sensitive information on the BRS_top.html page
| VAR-202203-0925 | CVE-2022-24761 | Agendaless Consulting of Waitress in products from other multiple vendors HTTP Request Smuggling Vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behind a proxy that does not properly validate the incoming HTTP request matches the RFC7230 standard, Waitress and the frontend proxy may disagree on where one request starts and where it ends. This would allow requests to be smuggled via the front-end proxy to waitress and later behavior. There are two classes of vulnerability that may lead to request smuggling that are addressed by this advisory: The use of Python's `int()` to parse strings into integers, leading to `+10` to be parsed as `10`, or `0x01` to be parsed as `1`, where as the standard specifies that the string should contain only digits or hex digits; and Waitress does not support chunk extensions, however it was discarding them without validating that they did not contain illegal characters. This vulnerability has been patched in Waitress 2.1.1. A workaround is available. When deploying a proxy in front of waitress, turning on any and all functionality to make sure that the request matches the RFC7230 standard. Certain proxy servers may not have this functionality though and users are encouraged to upgrade to the latest version of waitress instead. Agendaless Consulting of Waitress For products from other vendors, HTTP There is a vulnerability related to request smuggling.Information may be tampered with. No detailed vulnerability details are currently provided. =========================================================================
Ubuntu Security Notice USN-5364-1
April 05, 2022
waitress vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 21.10
- Ubuntu 20.04 LTS
Summary:
waitress could be made to expose sensitive information if it received
a specially crafted request.
Software Description:
- waitress: production-quality pure-Python WSGI server (documentation)
Details:
It was discovered that Waitress incorrectly handled certain requests.
An attacker could possibly use this issue to expose sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 21.10:
python3-waitress 1.4.4-1.1ubuntu0.1
Ubuntu 20.04 LTS:
python3-waitress 1.4.1-1ubuntu0.1
In general, a standard system update will make all the necessary changes. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: OpenShift Container Platform 4.10.10 bug fix and security update
Advisory ID: RHSA-2022:1356-01
Product: Red Hat OpenShift Enterprise
Advisory URL: https://access.redhat.com/errata/RHSA-2022:1356
Issue date: 2022-04-21
CVE Names: CVE-2022-0778 CVE-2022-21698 CVE-2022-24761
====================================================================
1. Summary:
Red Hat OpenShift Container Platform release 4.10.10 is now available with
updates to packages and images that fix several bugs and add enhancements.
This release includes a security update for Red Hat OpenShift Container
Platform 4.10.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Description:
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the container images for Red Hat OpenShift Container
Platform 4.10.10. See the following advisory for the RPM packages for this
release:
https://access.redhat.com/errata/RHBA-2022:1355
Space precludes documenting all of the container images in this advisory.
See the following Release Notes documentation, which will be updated
shortly for this release, for details about these changes:
https://docs.openshift.com/container-platform/4.10/release_notes/ocp-4-10-release-notes.html
Security Fix(es):
* prometheus/client_golang: Denial of service using
InstrumentHandlerCounter (CVE-2022-21698)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s)
listed in the References section.
You may download the oc tool and use it to inspect release image metadata
as follows:
(For x86_64 architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.10.10-x86_64
The image digest is
sha256:39efe13ef67cb4449f5e6cdd8a26c83c07c6a2ce5d235dfbc3ba58c64418fcf3
(For s390x architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.10.10-s390x
The image digest is
sha256:49b63b22bc221e29e804fc3cc769c6eff97c655a1f5017f429aa0dad2593a0a8
(For ppc64le architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.10.10-ppc64le
The image digest is
sha256:0d34e1198679a500a3af7acbdfba7864565f7c4f5367ca428d34dee9a9912c9c
(For aarch64 architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.10.10-aarch64
The image digest is
sha256:ddf6cb04e74ac88874793a3c0538316c9ac8ff154267984c8a4ea7047913e1db
All OpenShift Container Platform 4.10 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift Console
or the CLI oc command. Instructions for upgrading a cluster are available
at
https://docs.openshift.com/container-platform/4.10/updating/updating-cluster-cli.html
3. Solution:
For OpenShift Container Platform 4.10 see the following documentation,
which will be updated shortly for this release, for important instructions
on how to upgrade your cluster and fully apply this asynchronous errata
update:
https://docs.openshift.com/container-platform/4.10/release_notes/ocp-4-10-release-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.10/updating/updating-cluster-cli.html
4. Bugs fixed (https://bugzilla.redhat.com/):
2045880 - CVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounter
2050118 - 4.10: oVirt CSI driver should use the trusted CA bundle when cluster proxy is configured
2052414 - Start last run action should contain current user name in the started-by annotation of the PLR
2054404 - ip-reconcile job is failing consistently
2054767 - [ovn] Missing lr-policy-list and snat rules for egressip when new pods are added
2054808 - MetaLLB: Validation Webhook: BGPPeer hold time is allowed to be set to less than 3s
2055661 - migrate loadbalancers from amphora to ovn not working
2057881 - MetalLB: speaker metrics is not updated when deleting a service
2059347 - FSyncControllerDegraded latches True, even after fsync latency recovers on all members
2059945 - MetalLB: Move CI config files to metallb repo from dev-scripts repo
2060362 - Openshift registry starts to segfault after S3 storage configuration
2060586 - [4.10.z] [RFE] use /dev/ptp_hyperv on Azure/AzureStack
2064204 - Cachito request failure with vendor directory is out of sync with go.mod/go.sum
2064988 - Fix the hubUrl docs link in pipeline quicksearch modal
2065488 - ip-reconciler job does not complete, halts node drain
2065832 - oc mirror hangs when processing the Red Hat 4.10 catalog
2067311 - PPT event source is lost when received by the consumer
2067719 - Update channels information link is taking to a 404 error page
2069095 - cluster-autoscaler-default will fail when automated etcd defrag is running on large scale OpenShift Container Platform 4 - Cluster
2069913 - Disabling community tasks is not working
2070131 - Installation of Openshift virtualization fails with error service "hco-webhook-service" not found
2070492 - [4.10.z backport] On OCP 4.10+ using OVNK8s on BM IPI, nodes register as localhost.localdomain
2070525 - [OCPonRHV]- after few days that cluster is alive we got error in storage operator
2071479 - Thanos Querier high CPU and memory usage till OOM
2072191 - [4.10] cluster storage operator AWS credentialsrequest lacks KMS privileges
2072440 - Pipeline builder makes too many (100+) API calls upfront
2072928 - mapi_current_pending_csr is always set to 1 on OpenShift Container Platform
5. References:
https://access.redhat.com/security/cve/CVE-2022-0778
https://access.redhat.com/security/cve/CVE-2022-21698
https://access.redhat.com/security/cve/CVE-2022-24761
https://access.redhat.com/security/updates/classification/#moderate
6. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYmKAiNzjgjWX9erEAQgHWBAAqLcu1AIPSmb6HQhgFAZZikkCO03Lp/7U
rx3bU0VboglkT+H/Y5aInA4O25WvaU0U+DsmnHduOJY1XKifVgdMSwZSqek6NGxl
abQhbNwWbgNAaE69MQdiosSeDNnpqd9WMCLUWS7hj5Bc0Ry69UzS+dK0RcKUblTM
UXG+Sun3pphJ9fZ4dL9J20lO3iFiYcgGRv8jcOsujx/yhtdbIHgxmjaZOccRNTCH
gYCRUX93A/ReKQBJuQJKyfWpN8jmJAZaDak1VlokZJURFQE7VN45dPFQA6xtAe03
6WVSvmBR1K9QmTJq6AwTe50uIQfITcjWwspd3fygCSIn14Z2t6U77y3EbzsIS5dM
XWVJo0CLDVfel9cH76WjYX4GixcfR1uhuNl+twalxb2COZmFkq7X7tzAvfyFWF/S
GMDCAAMleN2x/WTX+ZOTrte6hdvSaiZBsWRX++yX/vIlU9mgHs7e7NwZA56o9Flq
UlFk8Pc6cZq50aifANU4l+nLrRrV/WlOqCxTz6tGwzgllbLgfQ9XZDbjCse9zrL8
F36ynyc5GItFG66etS9KrBVMLaIyhM4Fok4HQNE1yGLHYOT9NQNZsKs4ud7Y1Rzw
h7AATArTVib7QU0B+keHW3A3Rm2KYsbzBHsbDBntr3PU8Knl4rAR2OA1lYfMLW67
lYpMfdzvmvo=qbsg
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
.
For the oldstable distribution (buster), this problem has been fixed
in version 1.2.0~b2-2+deb10u1.
For the stable distribution (bullseye), this problem has been fixed in
version 1.4.4-1.1+deb11u1.
We recommend that you upgrade your waitress packages.
For the detailed security status of waitress please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/waitress
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmKD8WsACgkQEMKTtsN8
Tjb1Bw//WO0r4iACwUTMxAPD5EowBLhLcywGHly+MDEN1/2HHBq/wRhJK5J7HNt+
wdeYcbeJe8Jjm0iKnN8uetu+vr4wWRF33pDXj8GrT06chctnCwv4hEKpMTZLOZuw
2CaW5c80eKMGM7MVVjSYzCXGZ2Xp8pJml3J4T3u8V9KgW6QzPX6vKVzeQkWEpXFP
4uN35ZcPTgDWmBdtKaH76DwxB8roaN98ZgPQGsvhs6OLHqifDIik5q03zZPylJD2
Ji81zKIjBhQbsyOnE8lrtE4h7RvgjTldl5dkzK9QQYnRFq8B8lLJHZdnZGlfGvD8
/dccVQT+UJWdV14fe5amlMBsbbs2gn0QwQmHLYYACVdQXo6dY7VQgy9uIUO8CaR+
QHEJYZFz4ddaPOkjfq7MyjPPXzM4RnbG2Vbr73hrfhnSFPmZfzc0hqjHKJVqBAOK
ZU3mYEr0whU2CqG5ERRspQCdgSckV1rmtw8odWdkP8nmj4ZgCMtbScJCkfPEpwP2
83FPPh8+P9Rudom8RQvduHjr/3HweVvYGfmcws2QV+ffGiz7rwaiKZPG+fjFyXrq
UUBrFeseVsgaCEmq0x5S3r9XgL0YI7zXqNyTDZKDF5SrbRC7FVuPOzR1/kzZo2l2
DE5bBtA+ViL7Oqqo0AkAy1rLh6gTMnmwLBKz6okgCkgRQYefrrg=
=zbZ1
-----END PGP SIGNATURE-----