* bsc#1218255 Cross-References: * CVE-2023-6932
* bsc#1217522 * bsc#1218255 Cross-References: * CVE-2023-6176
* bsc#1210619 * bsc#1218255 Cross-References: * CVE-2023-1829
* bsc#1210619 Cross-References: * CVE-2023-1829
https://security-tracker.debian.org/tracker/DSA-5616-1
* bsc#1217522 * bsc#1218255 Cross-References: * CVE-2023-6176
The 6.7.3 stable kernel rebase contains new features, improved hardware support, and a number of important fixes across the tree.
The 6.7.3 stable kernel rebase contains new features, improved hardware support, and a number of important fixes across the tree.
QtWebEngine 5.15.16 bugfix update.
The 6.7.3 stable kernel rebase contains new features, improved hardware support, and a number of important fixes across the tree.
The 6.7.3 stable kernel rebase contains new features, improved hardware support, and a number of important fixes across the tree.
Fixes CVE-2023-52339. No API or ABI changes.
update to 121.0.6167.139 * High CVE-2024-1060: Use after free in Canvas * High CVE-2024-1059: Use after free in WebRTC * High CVE-2024-1077: Use after free in Network
Update to 2.15.1.
Combined update for several fixes as well as security fix for CVE-2023-4001 “` Mon Jan 15 2024 Nicolas Frayer – 2.06-114 grub- core/commands: add flag to only search root dev Resolves: #2223437 Resolves: #2224951 Resolves: #2258096 Resolves: CVE-2023-4001 Sat Jan 13 2024 Hector Martin – 2.06-113 Switch memdisk compression to lzop
Fixes CVE-2023-52339. No API or ABI changes.
Security update for CVE-2024-23334 and CVE-2024-23829 https://github.com/aio- libs/aiohttp/releases/tag/v3.9.2 https://github.com/aio- libs/aiohttp/releases/tag/v3.9.3
Multiple vulnerabilities have been found in NBD Tools, the worst of which could result in arbitary code execution.
Multiple out-of-bounds read vulnerabilities have been discovered in Wireshark.
Multiple vulnerabilities have been found in OpenSSL, the worst of which could result in denial of service.
Multiple vulnerabilities have been found in Xen, the worst of which can lead to arbitrary code execution.
The updated packages fix security vulnerabilities: A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program
Out of bounds write in ANGLE. (CVE-2024-0741) Failure to update user input timestamp. (CVE-2024-0742) Crash when listing printers on Linux. (CVE-2024-0746)
https://security-tracker.debian.org/tracker/DSA-5615-1
The banking trojan, which targeted mostly Brazil, Mexico and Spain, blocked the victim’s screen, logged keystrokes, simulated mouse and keyboard activity and displayed fake pop-up windows
Sudo, a program designed to allow a sysadmin to give limited root privileges to users and log root activity, was vulnerable. CVE-2023-7090
Multiple vulnerabilities have been discovered in FreeType, the worst of which can lead to remote code execution.
Multiple vulnerabilities have been discovered in Microsoft Edge, the worst of which could lead to remote code execution.
A vulnerability has been discovered in GNAT Ada Suite which can lead to remote code execution.
Multiple vulnerabilities have been discovered in QtGui which can lead to remote code execution.
A vulnerability has been discovered in SDDM which can lead to privilege escalation.
https://security-tracker.debian.org/tracker/DSA-5614-1
https://security-tracker.debian.org/tracker/DSA-5613-1
* bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053
* bsc#1140772 * bsc#1157446 * bsc#1170452 * bsc#1171862 * bsc#1215669
* bsc#1068950 * bsc#1081527 * bsc#1211052 * jsc#PED-6584
* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051
* bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053
* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051
An AI chatbot inadvertently kindles a cybercrime boom, ransomware bandits plunder organizations without deploying ransomware, and a new botnet enslaves Android TV boxes
ESET provided technical analysis, statistical information, known C&C servers and was able to get a glimpse of the victimology
* bsc#1217654 * bsc#1219131 Cross-References: * CVE-2023-50269
* bsc#1218894 Cross-References: * CVE-2024-21626
* bsc#1218894 Cross-References: * CVE-2024-21626
Security fix for CVE-2023-6246, CVE-2023-6779, and CVE-2023-6780. CVE-2023-6246: __vsyslog_internal did not handle a case where printing a SYSLOG_HEADER containing a long program name failed to update the required buffer size, leading to the allocation and overflow of a too-small buffer on the heap. CVE-2023-6779: __vsyslog_internal used the return value of
Update to 115.7.0 * https://www.mozilla.org/en- US/security/advisories/mfsa2024-04/ * https://www.thunderbird.net/en- US/thunderbird/115.7.0/releasenotes/
Security fix for CVE-2023-6246, CVE-2023-6779, and CVE-2023-6780. CVE-2023-6246: __vsyslog_internal did not handle a case where printing a SYSLOG_HEADER containing a long program name failed to update the required buffer size, leading to the allocation and overflow of a too-small buffer on the heap. CVE-2023-6779: __vsyslog_internal used the return value of
https://security-tracker.debian.org/tracker/DSA-5612-1
