security update
Tavis Ormandy discovered that under specific microarchitectural circumstances, a vector register in “Zen 2” CPUs may not be written to 0 correctly. This flaw allows an attacker to leak register contents across concurrent processes, hyper threads and virtualized guests.
Several security issues were fixed in Wireshark.
A security issue was discovered in Thunderbird, which could result in spoofing of filenames of email attachments. For Debian 10 buster, this problem has been fixed in version
A security issue was discovered in Thunderbird, which could result in spoofing of filenames of email attachments. For the oldstable distribution (bullseye), this problem has been fixed
SA-CORE-2009-001 ( http://drupal.org/node/358957 ) Remember to log in to your site as the admin user before upgrading this package. After upgrading the package, browse to http://host/drupal/update.php to run the upgrade script.
Tavis Ormandy discovered that under specific microarchitectural circumstances, a vector register in AMD “Zen 2” CPUs may not be written to 0 correctly. This flaw allows an attacker to leak sensitive information across concurrent processes, hyper threads
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
security update
security update
Several security issues were fixed in the Linux kernel.
Update to 3.14. Security fix for CVE-2023-38403
Update to 3.14. Security fix for CVE-2023-38403
OpenShift API for Data Protection (OADP) 1.0.11 is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which
The container bci/openjdk-devel was updated. The following patches have been included in this update:
The container bci/openjdk-devel was updated. The following patches have been included in this update:
The container bci/python was updated. The following patches have been included in this update:
The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:
Security fix for [PUT CVEs HERE]
security update
security update
It was discovered that the domain check in libmail-dkim-perl, a Perl module to cryptographically identify the sender of email, compares i and d tags case sensitive when t=s is set on the DKIM key which causes spurious fails of legitimate messages.
Several security issues were fixed in Open-iSCSI.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in X.Org X Server.
Several security issues were fixed in LLVM Toolchain.
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:
security update
The container bci/rust was updated. The following patches have been included in this update:
The container bci/ruby was updated. The following patches have been included in this update:
The container bci/python was updated. The following patches have been included in this update:
The container bci/python was updated. The following patches have been included in this update:
The container suse/postgres was updated. The following patches have been included in this update:
The container suse/postgres was updated. The following patches have been included in this update:
Avahi could be made to crash if it received specially crafted DBus traffic.
Django could be made to consume resources if it received specially crafted network traffic.
Several security issues were fixed in Graphite-Web.
Sam Wheating discovered that python-git, a Python library to interact with Git repositories, is vulnerable to shell injection due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command.
An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for kernel is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.
Update to latest upstream version, see following page for changes: https://www.mozilla.org/en-US/thunderbird/38.1.0/releasenotes/ This update also should fixed problems with thunderbird-lightning-gdata package. Rebase to Thunderbird 38. By this release thunderbird-lightning (calendar) package has become obsolete, because it is a part of Thunderbird 38 package now. For changes see: https://www.mozilla.org/en-US/thunderbird/38.0.1/releasenotes/ [More…]
Update to latest upstream version, see following page for changes: https://www.mozilla.org/en-US/thunderbird/38.1.0/releasenotes/ This update also should fixed problems with thunderbird-lightning-gdata package. Rebase to Thunderbird 38. By this release thunderbird-lightning (calendar) package has become obsolete, because it is a part of Thunderbird 38 package now. For changes see: https://www.mozilla.org/en-US/thunderbird/38.0.1/releasenotes/ [More…]
OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049) * OpenJDK: array indexing integer overflow issue (8304468) (CVE-2023-22045) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Prepare for the next quarterly OpenJDK upstream releas [More…]
OpenJDK: ZIP file parsing infinite loop (8302483) (CVE-2023-22036) * OpenJDK: weakness in AES implementation (8308682) (CVE-2023-22041) * OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049) * harfbuzz: OpenJDK: O(n^2) growth via consecutive marks (CVE-2023-25193) * OpenJDK: HTTP client insufficient file name validation (8302475) (CVE-2023-220 [More…]
This update provides the upstream 7.0.10 maintenance release that fixes at least the following security vulnerabilities: Vulnerability in the Oracle VM VirtualBox prior to 7.0.10 contains an easily exploitable vulnerability that allows high privileged attacker
security update
Security fix for CVE-2023-38408
The 6.4.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.
The 6.4.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.
The 6.4.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.
The 6.4.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.
fix for CVE-2023-36664 (rhbz#2217805)
Responses generated by ChatGPT about individual people could be misleading or harmful or spill their personal information. What are the takeaways for you as a ChatGPT user?
That ‘employer’ you’re speaking to may in reality be after your personal information, your money or your help with their illegal activities
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2023-37450
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
