ASA-201910-13 - log back

ASA-201910-13 edited at 23 Oct 2019 14:20:35
Workaround
For CVE-2019-18182:
Ensure `XferCommand` is commented out in `/etc/pacman.conf`
For CVE-2019-18183:
Ensure `UseDelta` is commented out in `/etc/pacman.conf`
ASA-201910-13 edited at 23 Oct 2019 14:18:22
Impact
- An remote attacker is able to execute arbitrary commands on the host with a specially crafted database and a package or delta file.
+ A remote attacker is able to execute arbitrary commands on the host with a specially crafted database and a package or delta file.
ASA-201910-13 edited at 23 Oct 2019 10:57:35
Impact
- An remote attacker is able to execute arbitrary commands on the host with a specially crafted database, package or delta file.
+ An remote attacker is able to execute arbitrary commands on the host with a specially crafted database and a package or delta file.
ASA-201910-13 edited at 23 Oct 2019 10:22:15
Impact
- An remote attacker is able to execute arbitrary code on the host with a specially crafted database, package or delta file.
+ An remote attacker is able to execute arbitrary commands on the host with a specially crafted database, package or delta file.
ASA-201910-13 edited at 23 Oct 2019 10:21:41
Workaround
+ For CVE-2019-18182:
+ Ensure `XferCommand` is commented out in `/etc/pacman.conf`
+
+ For CVE-2019-18183:
+ Ensure `UseDelta` is commented out in `/etc/pacman.conf`
ASA-201910-13 edited at 23 Oct 2019 10:19:16
Impact
+ An remote attacker is able to execute arbitrary code on the host with a specially crafted database, package or delta file.
ASA-201910-13 created at 23 Oct 2019 10:18:02