* bsc#1230353 Cross-References: * CVE-2023-29483
* bsc#1230353 Cross-References: * CVE-2023-29483
Several security issues were fixed in the Linux kernel.
A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. An attacker could generate a malicious dump file which could execute shell commands from the MariaDB client.
* bsc#1227378 * bsc#1227999 * bsc#1228780 * bsc#1229596
* bsc#1228780 Cross-References: * CVE-2024-6923
An update that solves four vulnerabilities and has one errata is now available.
A new stable version was released for galera-4, a synchronous multimaster replication engine for MySQL and MariaDB. This fixes several issues detailed at:
Several security issues were fixed in libxmltok.
Several security issues were fixed in ClamAV.
Several security issues were fixed in DCMTK.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
An update that fixes four vulnerabilities is now available.
* bsc#1176447 * bsc#1195668 * bsc#1195928 * bsc#1195957 * bsc#1196018
* bsc#1229907 * bsc#1230372 Cross-References: * CVE-2024-8250
* bsc#1082555 * bsc#1190317 * bsc#1196516 * bsc#1205462 * bsc#1210629
* bsc#1082555 * bsc#1190317 * bsc#1196516 * bsc#1205462 * bsc#1210629
OpenSSH could be made to crash or run programs as your login if it received a specially crafted input.
Update to 1.0.7 CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files. CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser
flatpak 1.15.10 and bubblewrap 0.10.0 updates, which together fix CVE-2024-42472 in Flatpak.
flatpak 1.15.10 and bubblewrap 0.10.0 updates, which together fix CVE-2024-42472 in Flatpak.
Update to 1.15.10 (CVE-2024-42472)
https://security-tracker.debian.org/tracker/DSA-5769-1
Node.js a JavaScript runtime environment that executes JavaScript code outside a web browser (server side) was vulnerable. CVE-2023-30589
New libarchive packages are available for Slackware 15.0 and -current to fix security issues.
ESET research also finds that CosmicBeetle attempts to exploit the notoriety of the LockBit ransomware gang to advance its own ends
update to 128.0.6613.137 * High CVE-2024-8636: Heap buffer overflow in Skia * High CVE-2024-8637: Use after free in Media Router * High CVE-2024-8638: Type Confusion in V8 * High CVE-2024-8639: Use after free in Autofill
Update to expat-2.6.3.
Update to 1.0.7 CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files. CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser
Update to 115.15.0 https://www.thunderbird.net/en-US/thunderbird/115.15.0esr/releasenotes/
Update to expat-2.6.3.
Update to 3.6.1 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-3.6.1 Update to 3.6.0
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5768-1
Learn about the main tactics used by scammers impersonating Best Buy’s tech support arm and how to avoid falling for their tricks
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in libxmltok.
Several security issues were fixed in Expat.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
