Alibaba Security Advisories · October 2019 — Alibaba Security Advisories
67 advisories 225 CVEs 1 EXPLOITED

Alibaba Cloud Linux 2 advisories and cross-source Alibaba/Aliyun CVEs for 2019-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

Advisories

ALINUX2-SA-2019:0103

ALINUX 22019-10-23

ALINUX2-SA-2019:0103: exiv2 security, bug fix, and enhancement update (Low)

CVEs:CVE-2017-17724CVE-2018-10772CVE-2018-10958CVE-2018-10998CVE-2018-11037CVE-2018-12264CVE-2018-12265CVE-2018-14046CVE-2018-17282CVE-2018-17581CVE-2018-18915CVE-2018-19107CVE-2018-19108CVE-2018-19535CVE-2018-19607CVE-2018-20096CVE-2018-20097CVE-2018-20098CVE-2018-20099CVE-2018-8976CVE-2018-8977CVE-2018-9305

Affected products

ProductStatusVendorPackageEcosystem
exiv2 affected Alibaba Cloud exiv2
Upstream advisory

ALINUX2-SA-2019:0104

ALINUX 22019-10-23

ALINUX2-SA-2019:0104: nss, nss-softokn, nss-util, and nspr security, bug fix, and enhancement update (Moderate)

CVEs:CVE-2018-0495CVE-2018-12404

Affected products

ProductStatusVendorPackageEcosystem
nspr affected Alibaba Cloud nspr
nss affected Alibaba Cloud nss
nss-softokn affected Alibaba Cloud nss-softokn
nss-util affected Alibaba Cloud nss-util
Upstream advisory

ALINUX2-SA-2019:0101

ALINUX 2Exploited2019-10-22

ALINUX2-SA-2019:0101: linux-firmware security, bug fix, and enhancement update (Important)

CVEs:CVE-2018-5383

Affected products

ProductStatusVendorPackageEcosystem
linux-firmware affected Alibaba Cloud linux-firmware
Upstream advisory

ALINUX2-SA-2019:0102

ALINUX 22019-10-22

ALINUX2-SA-2019:0102: freerdp and vinagre security, bug fix, and enhancement update (Low)

CVEs:CVE-2018-1000852

Affected products

ProductStatusVendorPackageEcosystem
freerdp affected Alibaba Cloud freerdp
vinagre affected Alibaba Cloud vinagre
Upstream advisory

ALINUX2-SA-2019:0095

ALINUX 22019-10-18

ALINUX2-SA-2019:0095: qt5 security, bug fix, and enhancement update (Moderate)

CVEs:CVE-2018-15518CVE-2018-19869CVE-2018-19870CVE-2018-19871CVE-2018-19873

Affected products

ProductStatusVendorPackageEcosystem
qt5-qt3d affected Alibaba Cloud qt5-qt3d
qt5-qtbase affected Alibaba Cloud qt5-qtbase
qt5-qtcanvas3d affected Alibaba Cloud qt5-qtcanvas3d
qt5-qtconnectivity affected Alibaba Cloud qt5-qtconnectivity
qt5-qtdeclarative affected Alibaba Cloud qt5-qtdeclarative
qt5-qtdoc affected Alibaba Cloud qt5-qtdoc
qt5-qtgraphicaleffects affected Alibaba Cloud qt5-qtgraphicaleffects
qt5-qtimageformats affected Alibaba Cloud qt5-qtimageformats
qt5-qtlocation affected Alibaba Cloud qt5-qtlocation
qt5-qtmultimedia affected Alibaba Cloud qt5-qtmultimedia
qt5-qtquickcontrols affected Alibaba Cloud qt5-qtquickcontrols
qt5-qtquickcontrols2 affected Alibaba Cloud qt5-qtquickcontrols2
qt5-qtscript affected Alibaba Cloud qt5-qtscript
qt5-qtsensors affected Alibaba Cloud qt5-qtsensors
qt5-qtserialbus affected Alibaba Cloud qt5-qtserialbus
qt5-qtserialport affected Alibaba Cloud qt5-qtserialport
qt5-qtsvg affected Alibaba Cloud qt5-qtsvg
qt5-qttools affected Alibaba Cloud qt5-qttools
qt5-qttranslations affected Alibaba Cloud qt5-qttranslations
qt5-qtwayland affected Alibaba Cloud qt5-qtwayland
qt5-qtwebchannel affected Alibaba Cloud qt5-qtwebchannel
qt5-qtwebsockets affected Alibaba Cloud qt5-qtwebsockets
qt5-qtx11extras affected Alibaba Cloud qt5-qtx11extras
qt5-qtxmlpatterns affected Alibaba Cloud qt5-qtxmlpatterns
Upstream advisory

ALINUX2-SA-2019:0088

ALINUX 22019-10-10

ALINUX2-SA-2019:0088: perl-Archive-Tar security update (Moderate)

CVEs:CVE-2018-12015

Affected products

ProductStatusVendorPackageEcosystem
perl-Archive-Tar affected Alibaba Cloud perl-Archive-Tar
Upstream advisory

ALINUX2-SA-2019:0089

ALINUX 22019-10-10

ALINUX2-SA-2019:0089: procps-ng security and bug fix update (Moderate)

CVEs:CVE-2018-1122

Affected products

ProductStatusVendorPackageEcosystem
procps-ng affected Alibaba Cloud procps-ng
Upstream advisory

ALINUX2-SA-2019:0064

ALINUX 22019-10-09

ALINUX2-SA-2019:0064: kde-workspace security and bug fix update (Low)

CVEs:CVE-2018-6790

Affected products

ProductStatusVendorPackageEcosystem
kdelibs affected Alibaba Cloud kdelibs
kde-workspace affected Alibaba Cloud kde-workspace
kmag affected Alibaba Cloud kmag
virtuoso-opensource affected Alibaba Cloud virtuoso-opensource
Upstream advisory

ALINUX2-SA-2019:0065

ALINUX 22019-10-09

ALINUX2-SA-2019:0065: keycloak-httpd-client-install security, bug fix, and enhancement update (Low)

CVEs:CVE-2017-15111CVE-2017-15112

Affected products

ProductStatusVendorPackageEcosystem
keycloak-httpd-client-install affected Alibaba Cloud keycloak-httpd-client-install
Upstream advisory

ALINUX2-SA-2019:0068

ALINUX 22019-10-09

ALINUX2-SA-2019:0068: spice-gtk security and bug fix update (Moderate)

CVEs:CVE-2018-10893

Affected products

ProductStatusVendorPackageEcosystem
libgovirt affected Alibaba Cloud libgovirt
spice-gtk affected Alibaba Cloud spice-gtk
spice-vdagent affected Alibaba Cloud spice-vdagent
virt-viewer affected Alibaba Cloud virt-viewer
Upstream advisory

ALINUX2-SA-2019:0069

ALINUX 22019-10-09

ALINUX2-SA-2019:0069: libguestfs-winsupport security update (Low)

CVEs:CVE-2019-9755

Affected products

ProductStatusVendorPackageEcosystem
libguestfs-winsupport affected Alibaba Cloud libguestfs-winsupport
Upstream advisory

ALINUX2-SA-2019:0076

ALINUX 22019-10-09

ALINUX2-SA-2019:0076: Xorg security and bug fix update (Moderate)

CVEs:CVE-2018-14598CVE-2018-14599CVE-2018-14600CVE-2018-15853CVE-2018-15854CVE-2018-15855CVE-2018-15856CVE-2018-15857CVE-2018-15859CVE-2018-15861CVE-2018-15862CVE-2018-15863CVE-2018-15864

Affected products

ProductStatusVendorPackageEcosystem
gdm affected Alibaba Cloud gdm
libX11 affected Alibaba Cloud libX11
libxkbcommon affected Alibaba Cloud libxkbcommon
mesa-libGLw affected Alibaba Cloud mesa-libGLw
xorg-x11-drv-ati affected Alibaba Cloud xorg-x11-drv-ati
xorg-x11-drv-vesa affected Alibaba Cloud xorg-x11-drv-vesa
xorg-x11-drv-wacom affected Alibaba Cloud xorg-x11-drv-wacom
xorg-x11-server affected Alibaba Cloud xorg-x11-server
Upstream advisory

ALINUX2-SA-2019:0083

ALINUX 22019-10-09

ALINUX2-SA-2019:0083: udisks2 security, bug fix, and enhancement update (Moderate)

CVEs:CVE-2018-17336

Affected products

ProductStatusVendorPackageEcosystem
udisks2 affected Alibaba Cloud udisks2
Upstream advisory

ALINUX2-SA-2019:0057

ALINUX 22019-10-08

ALINUX2-SA-2019:0057: compat-libtiff3 security update (Low)

CVEs:CVE-2018-7456

Affected products

ProductStatusVendorPackageEcosystem
compat-libtiff3 affected Alibaba Cloud compat-libtiff3
Upstream advisory

ALINUX2-SA-2019:0061

ALINUX 22019-10-08

ALINUX2-SA-2019:0061: fence-agents security, bug fix, and enhancement update (Moderate)

CVEs:CVE-2019-10153

Affected products

ProductStatusVendorPackageEcosystem
fence-agents affected Alibaba Cloud fence-agents
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.