Alibaba Security Advisories · April 2020 — Alibaba Security Advisories
53 advisories 180 CVEs 2 EXPLOITED

Alibaba Cloud Linux 2 advisories and cross-source Alibaba/Aliyun CVEs for 2020-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALINUX2-SA-2020:0071

ALINUX 2Active exploitation (sightings)HIGH2020-04-03

ALINUX2-SA-2020:0071: ImageMagick security, bug fix, and enhancement update (Moderate)

CVEs:CVE-2017-1000476CVE-2017-11166CVE-2017-12805CVE-2017-12806CVE-2017-18251CVE-2017-18252CVE-2017-18254CVE-2017-18271CVE-2017-18273CVE-2018-10177CVE-2018-10804CVE-2018-10805CVE-2018-11656CVE-2018-12599CVE-2018-12600CVE-2018-13153CVE-2018-14434CVE-2018-14435CVE-2018-14436CVE-2018-14437CVE-2018-15607CVE-2018-16328CVE-2018-16749CVE-2018-16750CVE-2018-18544CVE-2018-20467CVE-2018-8804CVE-2018-9133CVE-2019-10131CVE-2019-10650CVE-2019-11470CVE-2019-11472CVE-2019-11597CVE-2019-11598CVE-2019-12974CVE-2019-12975CVE-2019-12976CVE-2019-12978CVE-2019-12979CVE-2019-13133CVE-2019-13134CVE-2019-13135CVE-2019-13295CVE-2019-13297CVE-2019-13300CVE-2019-13301CVE-2019-13304CVE-2019-13305CVE-2019-13306CVE-2019-13307CVE-2019-13309CVE-2019-13310CVE-2019-13311CVE-2019-13454CVE-2019-14980CVE-2019-14981CVE-2019-15139CVE-2019-15140CVE-2019-15141CVE-2019-16708CVE-2019-16709CVE-2019-16710CVE-2019-16711CVE-2019-16712CVE-2019-16713CVE-2019-17540CVE-2019-17541CVE-2019-19948CVE-2019-19949CVE-2019-7175CVE-2019-7397CVE-2019-7398CVE-2019-9956

Affected products

ProductStatusVendorPackageEcosystem
autotrace affected Alibaba Cloud autotrace
emacs affected Alibaba Cloud emacs
ImageMagick affected Alibaba Cloud ImageMagick
inkscape affected Alibaba Cloud inkscape
Upstream advisory

ALINUX2-SA-2020:0067

ALINUX 2Active exploitation (sightings)HIGH2020-04-03

ALINUX2-SA-2020:0067: qemu-kvm-ma security update (Important)

CVEs:CVE-2020-8608

Affected products

ProductStatusVendorPackageEcosystem
qemu-kvm-ma affected Alibaba Cloud qemu-kvm-ma
Upstream advisory

ALINUX2-SA-2020:0074

ALINUX 2Active exploitation (sightings)HIGH2020-04-03

ALINUX2-SA-2020:0074: qemu-kvm security update (Important)

CVEs:CVE-2020-8608

Affected products

ProductStatusVendorPackageEcosystem
qemu-kvm affected Alibaba Cloud qemu-kvm
Upstream advisory

ALINUX2-SA-2020:0060

ALINUX 2Active exploitation (sightings)MEDIUM2020-04-02

ALINUX2-SA-2020:0060: doxygen security and bug fix update (Low)

CVEs:CVE-2016-10245

Affected products

ProductStatusVendorPackageEcosystem
doxygen affected Alibaba Cloud doxygen
Upstream advisory

ALINUX2-SA-2020:0040

ALINUX 2PoC exploitMEDIUM2020-04-01

ALINUX2-SA-2020:0040: gettext security and bug fix update (Low)

CVEs:CVE-2018-18751

Affected products

ProductStatusVendorPackageEcosystem
gettext affected Alibaba Cloud gettext
Upstream advisory

ALINUX2-SA-2020:0072

ALINUX 2PoC exploitHIGH2020-04-03

ALINUX2-SA-2020:0072: qemu-kvm security, bug fix, and enhancement update (Important)

CVEs:CVE-2020-7039

Affected products

ProductStatusVendorPackageEcosystem
qemu-kvm affected Alibaba Cloud qemu-kvm
Upstream advisory

ALINUX2-SA-2020:0064

ALINUX 2PoC exploitHIGH2020-04-02

ALINUX2-SA-2020:0064: net-snmp security and bug fix update (Moderate)

CVEs:CVE-2018-18066

Affected products

ProductStatusVendorPackageEcosystem
net-snmp affected Alibaba Cloud net-snmp
Upstream advisory

ALINUX2-SA-2020:0059

ALINUX 2PoC exploitMEDIUM2020-04-02

ALINUX2-SA-2020:0059: evolution security and bug fix update (Moderate)

CVEs:CVE-2018-15587CVE-2019-3890

Affected products

ProductStatusVendorPackageEcosystem
atk affected Alibaba Cloud atk
evolution affected Alibaba Cloud evolution
evolution-data-server affected Alibaba Cloud evolution-data-server
evolution-ews affected Alibaba Cloud evolution-ews
Upstream advisory

ALINUX2-SA-2020:0039

ALINUX 2PoC exploitMEDIUM2020-04-01

ALINUX2-SA-2020:0039: polkit security and bug fix update (Low)

CVEs:CVE-2018-1116

Affected products

ProductStatusVendorPackageEcosystem
polkit affected Alibaba Cloud polkit
Upstream advisory

ALINUX2-SA-2020:0070

ALINUX 2PoC exploitMEDIUM2020-04-03

ALINUX2-SA-2020:0070: GNOME security, bug fix, and enhancement update (Moderate)

CVEs:CVE-2019-3820

Affected products

ProductStatusVendorPackageEcosystem
accountsservice affected Alibaba Cloud accountsservice
colord affected Alibaba Cloud colord
control-center affected Alibaba Cloud control-center
gdm affected Alibaba Cloud gdm
gnome-online-accounts affected Alibaba Cloud gnome-online-accounts
gnome-settings-daemon affected Alibaba Cloud gnome-settings-daemon
gnome-shell affected Alibaba Cloud gnome-shell
gnome-shell-extensions affected Alibaba Cloud gnome-shell-extensions
gnome-tweak-tool affected Alibaba Cloud gnome-tweak-tool
gsettings-desktop-schemas affected Alibaba Cloud gsettings-desktop-schemas
gtk3 affected Alibaba Cloud gtk3
libcanberra affected Alibaba Cloud libcanberra
libgweather affected Alibaba Cloud libgweather
LibRaw affected Alibaba Cloud LibRaw
mutter affected Alibaba Cloud mutter
nautilus affected Alibaba Cloud nautilus
osinfo-db affected Alibaba Cloud osinfo-db
shared-mime-info affected Alibaba Cloud shared-mime-info
tracker affected Alibaba Cloud tracker
xchat affected Alibaba Cloud xchat
Upstream advisory

ALINUX2-SA-2020:0061

ALINUX 2EPSS <= 49%HIGH2020-04-02

ALINUX2-SA-2020:0061: libsndfile security update (Moderate)

CVEs:CVE-2018-13139

Affected products

ProductStatusVendorPackageEcosystem
libsndfile affected Alibaba Cloud libsndfile
Upstream advisory

ALINUX2-SA-2020:0043

ALINUX 2EPSS <= 49%MEDIUM2020-04-02

ALINUX2-SA-2020:0043: python-twisted-web security update (Moderate)

CVEs:CVE-2019-12387

Affected products

ProductStatusVendorPackageEcosystem
python-twisted-web affected Alibaba Cloud python-twisted-web
Upstream advisory

ALINUX2-SA-2020:0058

ALINUX 2EPSS <= 49%MEDIUM2020-04-02

ALINUX2-SA-2020:0058: advancecomp security update (Moderate)

CVEs:CVE-2019-9210

Affected products

ProductStatusVendorPackageEcosystem
advancecomp affected Alibaba Cloud advancecomp
Upstream advisory

ALINUX2-SA-2020:0062

ALINUX 2EPSS <= 49%MEDIUM2020-04-02

ALINUX2-SA-2020:0062: mod_auth_mellon security and bug fix update (Moderate)

CVEs:CVE-2019-13038

Affected products

ProductStatusVendorPackageEcosystem
mod_auth_mellon affected Alibaba Cloud mod_auth_mellon
Upstream advisory

ALINUX2-SA-2020:0053

ALINUX 2EPSS <= 49%LOW2020-04-02

ALINUX2-SA-2020:0053: libosinfo security and bug fix update (Low)

CVEs:CVE-2019-13313

Affected products

ProductStatusVendorPackageEcosystem
libosinfo affected Alibaba Cloud libosinfo
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.