debian-security-support, the Debian security support coverage checker, has been updated in bullseye-security to mark the end of life of the following packages: * pdns-recursor: See https://bugs.debian.org/1070176
Two vulnerabilities have been fixed in the SQLite database. CVE-2021-36690
Flatpak could be made to read and write files in locations it would not normally have access to.
Simone Margaritelli reported that cups, the Common UNIX Printing System, does not properly sanitize IPP attributes when creating PPD files, which may result in the execution of arbitrary code.
An update that fixes four vulnerabilities is now available.
* bsc#1196018 * bsc#1196823 * bsc#1202346 * bsc#1209636 * bsc#1209799
Multiple vulnerabilities have been fixed in the network traffic analyzer Wireshark. CVE-2021-4181
Simone Margaritelli reported several vulnerabilities in cups-filters. Missing validation of IPP attributes returned from an IPP server and multiple bugs in the cups-browsed component can result in the execution
Simone Margaritelli reported that cups, the Common UNIX Printing System, does not properly sanitize IPP attributes when creating PPD files, which may result in the execution of arbitrary code.
Two vulnerabilities were discovered in unbound, a validating, recursive, caching DNS resolver. Specially crafted input could cause a heap-buffer-overflow leading to memory corruption and potentially causing the application to crash or allowing arbitrary code execution
Update to new upstream version (closes rhbz#2237124)
https://security-tracker.debian.org/tracker/DSA-5779-1
https://security-tracker.debian.org/tracker/DSA-5778-1
Multiple vulnerabilities have been fixed in ruby-rails-html-sanitizer, a Ruby library for sanitizing HTML fragments in Rails applications. CVE-2022-23517
Multiple vulnerabilities have been fixed in ruby-loofah, a Ruby library for manipulating and transforming HTML/XML documents and fragments. CVE-2022-23514
ESET research examines the group’s malicious wares as used to spy on targets in Ukraine in the past two years
multipart/form-data request tampering has been fixed in ruby-httparty, a Ruby library for using Web-based APIs and related services. For Debian 11 bullseye, this problem has been fixed in version
Multiple vulnerabilities have been discovered in nginx, the worst of which could result in denial of service.
Multiple vulnerabilities have been found in Apache HTTPD, the worst of which could result in denial of service.
Multiple vulnerabilities have been found in yt-dlp, the worst of which could result in arbitrary code execution.
Multiple vulnerabilities have been discovered in Docker, the worst of which could result in denial of service.
Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service.
Keep your cool, arm yourself with the right knowledge, and other tips for staying unshaken by fraudsters’ scare tactics
An update that fixes four vulnerabilities is now available.
* bsc#1202346 * bsc#1227985 * bsc#1228002 * bsc#1228938 * bsc#1228959
* bsc#1225099 * bsc#1228349 Cross-References: * CVE-2023-52846
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
In today’s world, both small businesses and everyday consumers face a growing number of cyber threats. From ransomware attacks to phishing scams, hackers are becoming more sophisticated. OpenText’s 2024 Threat Hunter Perspective sheds light on what’s coming next and how to protect yourself. Whether you’re running a small business or managing personal data at home, […]
https://security-tracker.debian.org/tracker/DSA-5777-1
https://security-tracker.debian.org/tracker/DSA-5776-1
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
The CA certificates in the ca-certificates package were updated.
Several security issues were fixed in the Linux kernel.
OpenJPEG could be made to crash if it opened a specially crafted file.
The system could be made to expose sensitive information.
https://security-tracker.debian.org/tracker/DSA-5775-1
* bsc#1230366 Cross-References: * CVE-2024-45817
* bsc#1202023 * bsc#1229438 * bsc#1230866 Cross-References:
Several security issues were fixed in the Linux kernel.
Multiple vulnerabilities have been found in Xpdf, the worst of which could result in denial of service.
Several security issues were fixed in Intel Microcode.
* bsc#1069468 * bsc#1079798 * bsc#1079799 * bsc#1079800 * bsc#1079801
