Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- Gentoo Linux Security Advisory 202401-12[6]
- Authored by Gentoo[7] | Site security.gentoo.org[8]
-
Gentoo Linux Security Advisory 202401-12 - Multiple vulnerabilities have been found in Synapse, the worst of which could result in information leaks. Versions greater than or equal to 1.96.0 are affected.
- systems | linux[9], gentoo[10]
- advisories | CVE-2023-41335[11], CVE-2023-42453[12], CVE-2023-43796[13], CVE-2023-45129[14]
- SHA-256 |
579d26d4cd9cfb85e879b659d92e0932b8578fa7565338d266a3a5c82cb769a2 - Download[15] | Favorite[16] | View[17]
Change Mirror[18] Download[19]
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202401-12
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Low
Title: Synapse: Multiple Vulnerabilities
Date: January 07, 2024
Bugs: #914765, #916609
ID: 202401-12
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilites have been found in Synapse, the worst of which
could result in information leaks.
Background
==========
Synapse is a Matrix homeserver written in Python/Twisted.
Affected packages
=================
Package Vulnerable Unaffected
-------------- ------------ ------------
net-im/synapse < 1.96.0 >= 1.96.0
Description
===========
Multiple vulnerabilities have been discovered in Synapse. Please review
the CVE identifiers referenced below for details.
Impact
======
Please review the referenced CVE identifiers for details.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All Synapse users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/synapse-1.96.0"
References
==========
[ 1 ] CVE-2023-41335
https://nvd.nist.gov/vuln/detail/CVE-2023-41335
[ 2 ] CVE-2023-42453
https://nvd.nist.gov/vuln/detail/CVE-2023-42453
[ 3 ] CVE-2023-43796
https://nvd.nist.gov/vuln/detail/CVE-2023-43796
[ 4 ] CVE-2023-45129
https://nvd.nist.gov/vuln/detail/CVE-2023-45129
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202401-12
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser. or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2024 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
File Tags
- ActiveX[25] (932)
- Advisory[26] (83,632)
- Arbitrary[27] (16,464)
- BBS[28] (2,859)
- Bypass[29] (1,804)
- CGI[30] (1,031)
- Code Execution[31] (7,467)
- Conference[32] (684)
- Cracker[33] (843)
- CSRF[34] (3,355)
- DoS[35] (24,120)
- Encryption[36] (2,375)
- Exploit[37] (52,355)
- File Inclusion[38] (4,236)
- File Upload[39] (982)
- Firewall[40] (822)
- Info Disclosure[41] (2,816)
- Intrusion Detection[42] (900)
- Java[43] (3,091)
- JavaScript[44] (881)
- Kernel[45] (6,868)
- Local[46] (14,600)
- Magazine[47] (586)
- Overflow[48] (12,915)
- Perl[49] (1,428)
- PHP[50] (5,164)
- Proof of Concept[51] (2,355)
- Protocol[52] (3,667)
- Python[53] (1,572)
- Remote[54] (31,121)
- Root[55] (3,609)
- Rootkit[56] (517)
- Ruby[57] (614)
- Scanner[58] (1,645)
- Security Tool[59] (7,940)
- Shell[60] (3,219)
- Shellcode[61] (1,216)
- Sniffer[62] (898)
- Spoof[63] (2,233)
- SQL Injection[64] (16,460)
- TCP[65] (2,419)
- Trojan[66] (687)
- UDP[67] (896)
- Virus[68] (667)
- Vulnerability[69] (32,210)
- Web[70] (9,802)
- Whitepaper[71] (3,761)
- x86[72] (966)
- XSS[73] (18,070)
- Other[74]
File Archives
- January 2024[75]
- December 2023[76]
- November 2023[77]
- October 2023[78]
- September 2023[79]
- August 2023[80]
- July 2023[81]
- June 2023[82]
- May 2023[83]
- April 2023[84]
- March 2023[85]
- February 2023[86]
- Older[87]
Systems
- AIX[88] (429)
- Apple[89] (2,049)
- BSD[90] (375)
- CentOS[91] (57)
- Cisco[92] (1,926)
- Debian[93] (6,941)
- Fedora[94] (1,693)
- FreeBSD[95] (1,246)
- Gentoo[96] (4,408)
- HPUX[97] (880)
- iOS[98] (366)
- iPhone[99] (108)
- IRIX[100] (220)
- Juniper[101] (69)
- Linux[102] (48,098)
- Mac OS X[103] (691)
- Mandriva[104] (3,105)
- NetBSD[105] (256)
- OpenBSD[106] (487)
- RedHat[107] (14,762)
- Slackware[108] (941)
- Solaris[109] (1,611)
- SUSE[110] (1,444)
- Ubuntu[111] (9,189)
- UNIX[112] (9,350)
- UnixWare[113] (187)
- Windows[114] (6,617)
- Other[115]
- Services
- Security Services[126]
- Hosting By
- Rokasec[127]
Read more https://packetstormsecurity.com/files/176412/glsa-202401-12.txt


