惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
有赞技术团队
有赞技术团队
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
量子位
小众软件
小众软件
The Cloudflare Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
大猫的无限游戏
大猫的无限游戏
C
Check Point Blog
G
Google Developers Blog
博客园 - 叶小钗
H
Help Net Security
Jina AI
Jina AI
Y
Y Combinator Blog
Last Week in AI
Last Week in AI
GbyAI
GbyAI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research
MyScale Blog
MyScale Blog
T
Tailwind CSS Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Vercel News
Vercel News

Cloud Foundry

USN-4436-1: librsvg vulnerabilities USN-4428-1: Python vulnerabilities USN-4431-1: FFmpeg vulnerabilities CVE-2019-15225/15226: Envoy 1.11.1 vulnerability fixes CVE-2019-3801: Java Projects using HTTP to fetch dependencies
USN-4436-2: librsvg regression
Cloud Foundry Foundation Security Team · 2020-08-28 · via Cloud Foundry

Severity

Unknown

Vendor

Canonical Ubuntu

Versions Affected

  • Canonical Ubuntu 18.04

Description

USN-4436-1 fixed a vulnerability in librsvg. The upstream fix caused a regression when parsing certain SVG files. This update backs out the fix pending further investigation.

Original advisory details:

It was discovered that librsvg incorrectly handled parsing certain SVG files. A remote attacker could possibly use this issue to cause librsvg to crash, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-11464)

It was discovered that librsvg incorrectly handled parsing certain SVG files with nested patterns. A remote attacker could possibly use this issue to cause librsvg to consume resources and crash, resulting in a denial of service. (CVE-2019-20446)

Affected Cloud Foundry Products and Versions

Severity is unknown unless otherwise noted.

  • cflinuxfs3
    • All versions prior to 0.202.0
  • CF Deployment
    • All versions prior to v13.12.0

Mitigation

Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:

  • cflinuxfs3
    • Upgrade All versions to 0.202.0 or greater
  • CF Deployment
    • Upgrade All versions to v13.12.0 or greater

History

2020-08-27: Initial vulnerability report published.

Cloud Foundry Foundation Security Team Profile Image

Sign up for the
Cloud Foundry Newsletter today!