DSA-2024-493: Security Update for Dell Enterprise SONiC Distribution Vulnerabilities
Zusammenfassung: Dell Enterprise SONiC remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Auswirkungen
High
Details
| Third-party Component |
CVEs |
More Information |
| setuptools |
CVE-2022-40897, CVE-2024-6345 |
See NVD link below for individual scores for each CVE. |
| gnutls28 |
CVE-2024-28834, CVE-2024-28835 |
See NVD link below for individual scores for each CVE. |
| krb5 |
CVE-2024-37370, CVE-2024-37371 |
See NVD link below for individual scores for each CVE. |
| libxml2 |
CVE-2016-3709, CVE-2022-2309 |
See NVD link below for individual scores for each CVE. |
| frr |
CVE-2022-37035, CVE-2023-46752, CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948, CVE-2024-31949, CVE-2024-44070 |
See NVD link below for individual scores for each CVE. |
| expat |
CVE-2023-52425, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492 |
See NVD link below for individual scores for each CVE. |
| nghttp2 |
CVE-2024-28182 |
See NVD link below for individual scores for each CVE. |
| sqlite3 |
CVE-2021-36690, CVE-2023-7104 |
See NVD link below for individual scores for each CVE. |
| e2fsprogs |
CVE-2022-1304 |
See NVD link below for individual scores for each CVE. |
Betroffene Produkte und Korrektur
| Product |
Affected Versions |
Remediated Versions |
Link |
| Dell Enterprise SONiC Distribution |
Versions prior to 4.4.1 |
Version 4.4.1 or later |
| Product |
Affected Versions |
Remediated Versions |
Link |
| Dell Enterprise SONiC Distribution |
Versions prior to 4.4.1 |
Version 4.4.1 or later |
Revisionsverlauf
|
Revision |
Date |
Description |
|
1.0 |
2024-12-18 |
Initial Release |