[ubuntu/focal-security] connman 1.36-2ubuntu0.1 (Accepted)
Fabian Toepfer
fabian.toepfer at canonical.com
Wed Jul 19 08:53:00 UTC 2023
connman (1.36-2ubuntu0.1) focal-security; urgency=medium
* SECURITY UPDATE: Stack-based buffer overflow
- debian/patches/dnsproxy-Add-length-checks-to-prevent-buffer-overflo.patch:
Add length checks to prevent buffer overflow.
- CVE-2021-26675
* SECURITY UPDATE: Sensitive information exposure
- debian/patches/gdhcp-Avoid-reading-invalid-data-in-dhcp_get_option.patch:
Avoid reading invalid data in dhcp_get_option
- debian/patches/gdhcp-Avoid-leaking-stack-data-via-unitiialized-vari.patch:
Avoid leaking stack data via unitiialized variable.
- CVE-2021-26676
* SECURITY UPDATE: Stack-based buffer overflow
- debian/patches/dnsproxy-Check-the-length-of-buffers-before-memcpy.patch:
Check the length of buffers before memcpy.
- CVE-2021-33833
* SECURITY UPDATE: Out-of-bounds read
- debian/patches/dnsproxy-Simplify-udp_server_event.patch:
Simplify udp_server_event()
- debian/patches/dnsproxy-Validate-input-data-before-using-them.patch:
Validate input data before using them.
- CVE-2022-23096
- CVE-2022-23097
* SECURITY UPDATE: Denial-of-service
- debian/patches/dnsproxy-Avoid-100-busy-loop-in-TCP-server-case.patch:
Avoid 100 % busy loop in TCP server case.
- debian/patches/dnsproxy-Keep-timeout-in-TCP-case-even-after-connect.patch:
Keep timeout in TCP case even after connection is established.
- CVE-2022-23098
* SECURITY UPDATE: Heap-based buffer overflow
- debian/patches/gweb-Fix-OOB-write-in-received_data.patch: Fix OOB
write in received_data().
- CVE-2022-32292
* SECURITY UPDATE: Use-after-free
- debian/patches/wispr-Add-reference-counter-to-portal-context.patch:
Add reference counter to portal context.
- debian/patches/wispr-Update-portal-context-references.patch: Update
portal context references.
- CVE-2022-32293
* SECURITY UPDATE: Stack-based buffer overflow
- debian/patches/CVE-2023-28488.patch: Verify and sanitize packet
length first.
- CVE-2023-28488
Date: 2023-07-18 11:34:19.299644+00:00
Changed-By: Fabian Toepfer <fabian.toepfer at canonical.com>
https://launchpad.net/ubuntu/+source/connman/1.36-2ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Focal-changes
mailing list