The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
* bsc#1216423 Cross-References: * CVE-2023-45802
* bsc#1216423 Cross-References: * CVE-2023-45802
https://security-tracker.debian.org/tracker/DSA-5809-1
https://security-tracker.debian.org/tracker/DSA-5808-1
https://security-tracker.debian.org/tracker/DSA-5807-1
https://security-tracker.debian.org/tracker/DSA-5805-1
A heap-based out-of-bounds write vulnerability was discovered in libarchive, a multi-format archive and compression library, which may result in the execution of arbitrary code if a specially crafted RAR archive is processed.
Invalid low-level GF(2^m) parameters can lead to an OOB memory access. (CVE-2024-9143) References: – https://bugs.mageia.org/show_bug.cgi?id=33736
HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. (CVE-2024-45508) HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. (CVE-2024-46478)
In Libheif, insufficient checks in ImageOverlay::parse() while decoding a HEIF file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. (CVE-2024-41311) References:
Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parsing `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A
Permission leak via embed or object elements. (CVE-2024-10458) Use-after-free in layout with accessibility. (CVE-2024-10459) Confusing display of origin for external protocol handler prompt. (CVE-2024-10460) XSS due to Content-Disposition being ignored in
https://security-tracker.debian.org/tracker/DSA-5806-1
https://security-tracker.debian.org/tracker/DSA-5804-1
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The trailblazing scientist shares her reasons for hope in the fight against climate change and how we can tackle seemingly impossible problems and keep going in the face of adversity
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
New upstream build (132.0)
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Update to 128.4.0 https://www.thunderbird.net/en-US/thunderbird/128.4.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-58/
Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0
Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection fix for inline data images #646 Fix count svg #647
Update to 128.4.0 https://www.thunderbird.net/en-US/thunderbird/128.4.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-58/
Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0
Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection fix for inline data images #646 Fix count svg #647
https://security-tracker.debian.org/tracker/DSA-5803-1
https://security-tracker.debian.org/tracker/DSA-5802-1
Election interference, American Water and the Internet Archive breaches, new cybersecurity laws, and more – October saw no shortage of impactful cybersecurity news stories
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, spoofing or information disclosure.
* bsc#1227471 * bsc#1228349 * bsc#1228573 * bsc#1228786
* bsc#1223363 * bsc#1223683 * bsc#1225011 * bsc#1225012 * bsc#1225013
* bsc#1225011 * bsc#1225012 * bsc#1225309 * bsc#1225311 * bsc#1225819
Several security issues were fixed in the Linux kernel.
Have you ever googled yourself? Were you happy with what came up? If not, consider requesting the removal of your personal information from search results.
