https://security-tracker.debian.org/tracker/DSA-5673-1
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service or information disclosure. For Debian 10 buster, these problems have been fixed in version
Pillow could be made to crash or run programs as an administrator if it opened a specially crafted file.
percona-xtrabackup could be made to run programs as your login if it opened a specially crafted file.
* bsc#1221793 * bsc#1221797 Cross-References: * CVE-2024-29131
* bsc#1198101 * bsc#1205588 * bsc#1205855 * bsc#1210382 * bsc#1213945
* bsc#1219435 Cross-References: * CVE-2024-1086
https://security-tracker.debian.org/tracker/DSA-5672-1
https://security-tracker.debian.org/tracker/DSA-5671-1
https://security-tracker.debian.org/tracker/DSA-5670-1
https://security-tracker.debian.org/tracker/DSA-5669-1
Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.
What are the risks and consequences of having your health data exposed and what are the steps to take if it happens to you?
What are some of the most common giveaway signs that the person behind the screen or on the other end of the line isn’t who they claim to be?
From promoting questionable content to posing security risks, inappropriate ads present multiple dangers for children. Here’s how to help them stay safe.
Almost 400 people in India and Pakistan have fallen victim to an ongoing Android espionage campaign called eXotic Visit
Here’s how cybercriminals target cryptocurrencies and how you can keep your bitcoin or other crypto safe
Should children’s apps come with ‘warning labels’? Here’s how to make sure your children’s digital playgrounds are safe places to play and learn.
Temu’s cash giveaway where people were asked to hand over vast amounts of their personal data to the platform puts the spotlight on the data-slurping practices of online services today
update to 124.0.6367.60 High CVE-2024-3832: Object corruption in V8 High CVE-2024-3833: Object corruption in WebAssembly High CVE-2024-3914: Use after free in V8 High CVE-2024-3834: Use after free in Downloads
New upstream release (125.0)
Security fix for CVE-2023-5752
Update to 1.15.8 Fixes CVE-2024-32462
Security fix for CVE-2024-27316
https://security-tracker.debian.org/tracker/DSA-5667-1
Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.
Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.
Security fixes for CVE-2024-27351 Potential regular expression DOS in django.utils.text.Truncator.words() CVE-2024-24680 denial-of-service in intcomma template filter CVE-2023-43665 Denial-of-service possibility in django.utils.text.Truncator
fix CONTINUATION frames DoS (CVE-2024-28182)
This update includes several bug fixes from the upstream glibc release branch, including a fix for CVE-2024-2961.
Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.
https://security-tracker.debian.org/tracker/DSA-5668-1
* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982
* bsc#1220181 Cross-References: * CVE-2024-24476
* bsc#1222535 Cross-References: * CVE-2024-2609 * CVE-2024-3302
* bsc#1219491 Cross-References: * CVE-2023-46045
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or clickjacking.
WordPress 6.4.4 Security Release Security updates included in this release A cross-site scripting (XSS) vulnerability affecting the Avatar block type; reported by John Blackbourn of the WordPress security team. Many thanks to Mat Rollings for assisting with the research.
https://security-tracker.debian.org/tracker/DSA-5666-1
https://security-tracker.debian.org/tracker/DSA-5665-1
https://security-tracker.debian.org/tracker/DSA-5664-1
https://security-tracker.debian.org/tracker/DSA-5663-1
GNU C Library could be made to crash or run programs if it processed specially crafted data.
* bsc#1194869 * bsc#1200465 * bsc#1205316 * bsc#1207948 * bsc#1209635
This update includes the changes in tzdata 2024a for the Perl bindings. For the list of changes, see DLA-3789-1. For Debian 10 buster, this problem has been fixed in version
This update includes the changes in tzdata 2024a. Notable changes are: – – Kazakhstan unifies on UTC+5 beginning 2024-03-01.
sosreport: Fix command injection with crafted report names [CVE-2024-2947]
Fix for CVE-2024-31497
https://security-tracker.debian.org/tracker/DSA-5655-2
* bsc#1200599 * bsc#1209635 * bsc#1212514 * bsc#1213456 * bsc#1217987
* bsc#1194869 * bsc#1200465 * bsc#1205316 * bsc#1207948 * bsc#1209635
New upstream release (125.0)
The 6.8.6 stable kernel update contains a number of important fixes across the tree.
Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791; Security fix for CVE-2024-25713
New version 4.2.4. Includes a fix for CVE-2024-2955
