Alibaba Security Advisories · December 2020 — Alibaba Security Advisories
10 advisories 45 CVEs 1 EXPLOITED

Alibaba Cloud Linux 2 advisories and cross-source Alibaba/Aliyun CVEs for 2020-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALINUX2-SA-2020:0198

ALINUX 2Active exploitation (sightings)MEDIUM2020-12-29

ALINUX2-SA-2020:0198: cloud-kernel bugfix, enhancement and security update (Important)

CVEs:CVE-2019-18808CVE-2019-19462CVE-2019-19770CVE-2019-3874CVE-2020-0543CVE-2020-10757CVE-2020-10766CVE-2020-10767CVE-2020-10781CVE-2020-13974CVE-2020-14351CVE-2020-16166CVE-2020-25211CVE-2020-25284CVE-2020-25285CVE-2020-25643CVE-2020-25645CVE-2020-25656CVE-2020-25668CVE-2020-25704CVE-2020-25705CVE-2020-28974CVE-2020-8694

Affected products

ProductStatusVendorPackageEcosystem
kernel affected Alibaba Cloud kernel
Upstream advisory

ALINUX2-SA-2020:0197

ALINUX 2PoC exploitMEDIUM2020-12-18

ALINUX2-SA-2020:0197: openssl security update (Important)

CVEs:CVE-2020-1971

Affected products

ProductStatusVendorPackageEcosystem
openssl affected Alibaba Cloud openssl
Upstream advisory

ALINUX2-SA-2020:0191

ALINUX 2PoC exploitCRITICAL2020-12-15

ALINUX2-SA-2020:0191: libexif security update (Important)

CVEs:CVE-2020-0452

Affected products

ProductStatusVendorPackageEcosystem
libexif affected Alibaba Cloud libexif
Upstream advisory

ALINUX2-SA-2020:0195

ALINUX 2EPSS <= 49%MEDIUM2020-12-16

ALINUX2-SA-2020:0195: python-rtslib security update (Moderate)

CVEs:CVE-2020-14019

Affected products

ProductStatusVendorPackageEcosystem
python-rtslib affected Alibaba Cloud python-rtslib
Upstream advisory

ALINUX2-SA-2020:0193

ALINUX 2EPSS <= 49%MEDIUM2020-12-16

ALINUX2-SA-2020:0193: targetcli security update (Moderate)

CVEs:CVE-2020-13867

Affected products

ProductStatusVendorPackageEcosystem
targetcli affected Alibaba Cloud targetcli
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.