The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5706-1
USN-6567-1 introduced a regression in QEMU.
Update to upstream 1.3.2, including fix for CVE-2024-3727
Several security issues were fixed in OpenJDK 21.
Several security issues were fixed in OpenJDK 17.
Several security issues were fixed in OpenJDK 11.
Several security issues were fixed in OpenJDK 8.
* bsc#1225070 Cross-References: * CVE-2024-36039
Fix CVE-2024-36048
This is the May 2024 release for .NET 8. This is a security update for .NET 8. Release notes: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.5/8.0.5.md
Qt 5.15.14 bugfix update. Fix CVE-2024-36048
Qt 5.15.14 bugfix update. Fix CVE-2024-36048
Qt 5.15.14 bugfix update. Fix CVE-2024-36048
https://security-tracker.debian.org/tracker/DSA-5705-1
https://security-tracker.debian.org/tracker/DSA-5704-1
* bsc#1217405 Cross-References: * CVE-2023-22084
* bsc#1202031 * bsc#1202033 * bsc#1203643 * bsc#1219823 * bsc#1219826
An update that fixes one vulnerability is now available.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
* bsc#1225417 Cross-References: * CVE-2024-33427
* bsc#1212233 Cross-References: * CVE-2023-3164
* bsc#1224806 Cross-References: * CVE-2024-4453
* bsc#1219823 * bsc#1219826 * bsc#1219851 Cross-References:
* bsc#1221940 * bsc#1223423 * bsc#1223424 * bsc#1223425
fix CVE-2023-36308
update to 125.0.6422.141 High CVE-2024-5493: Heap buffer overflow in WebRTC High CVE-2024-5494: Use after free in Dawn High CVE-2024-5495: Use after free in Dawn High CVE-2024-5496: Use after free in Media Session
CVE-2024-36041
Security fix for CVE-2024-21501
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority
https://security-tracker.debian.org/tracker/DSA-5703-1
Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.
The updated packages fix security vulnerabilities: Excessive time spent checking DSA keys and parameters. (CVE-2024-4603) Use After Free with SSL_free_buffers. (CVE-2024-4741) References:
It was discovered that Jinja2 incorrectly handled certain HTML attributes that were accepted by the xmlattr filter. An attacker could use this issue to inject arbitrary HTML attribute keys and values to potentially execute a cross-site scripting (XSS) attack.
Several security issues were fixed in GNU C Library.
A woman in London has been misidentified as a shoplifter by a facial recognition system amid fresh concerns over the technology’s accuracy and reliability
An integer overflow in the EXIF metadata parsing was discovered in the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed file is processed.
https://security-tracker.debian.org/tracker/DSA-5702-1
