Log

AVG-1947 edited at 15 Jun 2021 07:58:48
Advisory qualified
- Yes
+ No
AVG-2072 edited at 15 Jun 2021 07:57:47
Severity
- Unknown
+ Low
CVE-2019-19451 edited at 15 Jun 2021 07:57:47
Severity
- Unknown
+ Low
Remote
- Unknown
+ Local
Type
- Unknown
+ Denial of service
Description
+ When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to disk via the system's logging facility (potentially with elevated privileges), thus filling up the disk and eventually rendering the system unusable. (The filename can be for a nonexistent file.)
References
+ https://gitlab.gnome.org/GNOME/dia/-/issues/428
+ https://gitlab.gnome.org/GNOME/dia/-/merge_requests/50
+ https://gitlab.gnome.org/GNOME/dia/-/commit/baa2df853f9fb770eedcf3d94c7f5becebc90bb9
Notes
AVG-2072 created at 15 Jun 2021 07:54:17
Packages
+ dia
Issues
+ CVE-2019-19451
Status
+ Fixed
Severity
+ Unknown
Affected
+ 0.97.3-7
Fixed
+ 0.97.3-8
Ticket
+ 71257
Advisory qualified
+ Yes
References
Notes
CVE-2019-19451 created at 15 Jun 2021 07:54:17
AVG-1741 edited at 15 Jun 2021 07:48:55
Issues
CVE-2020-26555
CVE-2020-26556
CVE-2020-26557
CVE-2020-26559
CVE-2020-26560
CVE-2021-3542
CVE-2021-3564
CVE-2021-22543
CVE-2021-29648
CVE-2021-30178
+ CVE-2021-34693
AVG-1881 edited at 15 Jun 2021 07:48:49
Issues
CVE-2020-26555
CVE-2020-26556
CVE-2020-26557
CVE-2020-26559
CVE-2020-26560
CVE-2021-3542
CVE-2021-3564
CVE-2021-22543
+ CVE-2021-34693
AVG-1880 edited at 15 Jun 2021 07:48:44
Issues
CVE-2020-26555
CVE-2020-26556
CVE-2020-26557
CVE-2020-26559
CVE-2020-26560
CVE-2021-3542
CVE-2021-3564
CVE-2021-22543
+ CVE-2021-34693
CVE-2021-34693 edited at 15 Jun 2021 07:48:27
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Information disclosure
Description
+ net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.
References
+ https://lore.kernel.org/netdev/trinity-87eaea25-2a7d-4aa9-92a5-269b822e5d95-1623609211076@3c-app-gmx-bs04/T/
AVG-1879 edited at 15 Jun 2021 07:47:54
Issues
CVE-2020-26555
CVE-2020-26556
CVE-2020-26557
CVE-2020-26559
CVE-2020-26560
CVE-2021-3542
CVE-2021-3564
CVE-2021-22543
+ CVE-2021-34693
CVE-2021-34693 created at 15 Jun 2021 07:47:54
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes
AVG-1629 edited at 14 Jun 2021 11:25:47
Status
- Testing
+ Fixed
AVG-1941 edited at 14 Jun 2021 08:44:31
Affected
- 4.0.0-2
+ 4.1.0-1