Search CVE reports
1 – 10 of 49226 results
[Unknown description]
1 affected package
rpcbind
| Package | 20.04 LTS |
|---|---|
| rpcbind | Needs evaluation |
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the...
1 affected package
octavia
| Package | 20.04 LTS |
|---|---|
| octavia | Needs evaluation |
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before...
1 affected package
octavia
| Package | 20.04 LTS |
|---|---|
| octavia | Needs evaluation |
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past...
1 affected package
fetchmail
| Package | 20.04 LTS |
|---|---|
| fetchmail | Needs evaluation |
Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments,...
1 affected package
libdancer2-perl
| Package | 20.04 LTS |
|---|---|
| libdancer2-perl | Needs evaluation |
Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from each header value but not from the name. A name carrying them therefore reaches the...
1 affected package
libdancer2-perl
| Package | 20.04 LTS |
|---|---|
| libdancer2-perl | Needs evaluation |
Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. A hook that dies fires core.app.hook_exception, then calls cleanup...
1 affected package
libdancer2-perl
| Package | 20.04 LTS |
|---|---|
| libdancer2-perl | Needs evaluation |
Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler. The handler compares the request path against the layout directory name as text,...
1 affected package
libdancer2-perl
| Package | 20.04 LTS |
|---|---|
| libdancer2-perl | Needs evaluation |
Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every...
1 affected package
libemail-sender-perl
| Package | 20.04 LTS |
|---|---|
| libemail-sender-perl | Needs evaluation |
security update
1 affected package
flatpak
| Package | 20.04 LTS |
|---|---|
| flatpak | Needs evaluation |