New libpcap packages are available for Slackware 15.0 and -current to fix security issues.
Update to upstream 2.1-44. 20240813 Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision 0x5003605 up to 0x5003707; Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002802 up to 0x7002904;
Security fix for CVE-2024-8088
error handling in x86 IOMMU identity mapping [XSA-460, CVE-2024-31145] PCI device pass-through with shared resources [XSA-461, CVE-2024-31146]
error handling in x86 IOMMU identity mapping [XSA-460, CVE-2024-31145] PCI device pass-through with shared resources [XSA-461, CVE-2024-31146]
https://security-tracker.debian.org/tracker/DSA-5761-1
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-4558
An update that fixes four vulnerabilities is now available.
The discovery of the NGate malware by ESET Research is another example of how sophisticated Android threats have become
Demystifying CVE-2024-7262 and CVE-2024-7263
An update that fixes three vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
* bsc#1227052 Cross-References: * CVE-2024-6104
An update that fixes four vulnerabilities is now available.
Security fix for CVE-2024-8088
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
https://security-tracker.debian.org/tracker/DSA-5763-1
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
* bsc#1227353 Cross-References: * CVE-2024-39884
Security fix for CVE-2024-32487 – less with LESSOPEN mishandles n in paths
https://security-tracker.debian.org/tracker/DSA-5760-1
Several security issues were fixed in the Linux kernel.
* bsc#1228696 * bsc#1228697 * bsc#1228698 Cross-References:
CVE-2024-23184: A large number of address headers in email resulted in excessive CPU usage. CVE-2024-23185: Abnormally large email headers are now truncated or discarded, with a limit of 10MB on a single header and 50MB for all the headers of all the parts of an email.
CVE-2024-23184: A large number of address headers in email resulted in excessive CPU usage. CVE-2024-23185: Abnormally large email headers are now truncated or discarded, with a limit of 10MB on a single header and 50MB for all the headers of all the parts of an email.
* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059
* bsc#1225202 * bsc#1225302 Cross-References: * CVE-2021-47378
* bsc#1210619 * bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225202
* bsc#1226463 * bsc#1227138 Cross-References: * CVE-2024-5535
* bsc#1225202 Cross-References: * CVE-2021-47378
* bsc#1225202 * bsc#1225302 Cross-References: * CVE-2021-47378
Multiple security issues were discovered in Python, a high-level, interactive, object-oriented language: CVE-2024-0397
* bsc#1225983 Cross-References: * CVE-2024-21096
* bsc#1225202 Cross-References: * CVE-2021-47378
https://security-tracker.debian.org/tracker/DSA-5759-1
* bsc#1027519 * bsc#1227355 * bsc#1228574 * bsc#1228575
Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in denial of service or request smuggling.
Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.
