An update that fixes one vulnerability is now available.
Multiple vulnerabilities have been fixed in DCMTK, a collection of libraries and applications implementing large parts the DICOM standard for medical images.
Vanilla upstream kernel version 6.6.74 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33968
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5854-1
https://security-tracker.debian.org/tracker/DSA-5853-1
* bsc#1236518 Cross-References: * CVE-2023-45288
* bsc#1228770 Cross-References: * CVE-2013-4235
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
Tomcat could be made to run programs if it received specially crafted network traffic.
Several security issues were fixed in jinja2.
VLC could be made to crash or run programs if it received specially crafted network traffic.
https://security-tracker.debian.org/tracker/DSA-5856-1
https://security-tracker.debian.org/tracker/DSA-5855-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5851-1
* bsc#1214612 * bsc#1215807 * bsc#1215926 * bsc#1217828 * bsc#1221677
Multiple vulnerabilities were discovered in git, a fast, scalable and distributed revision control system. CVE-2024-50349
FRR could be made to crash or exhibit degraded performance if it received specially crafted network traffic.
Quagga could be made to crash if it received specially crafted network traffic.
* bsc#1225819 * bsc#1227369 * bsc#1227781 * bsc#1227784 * bsc#1228349
* bsc#1226324 Cross-References: * CVE-2024-36971
* bsc#1226324 * bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553
An update that fixes two vulnerabilities is now available.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size. (CVE-2025-0395)
Timing side-channel in ECDSA signature computation. (CVE-2024-13176) References: – https://bugs.mageia.org/show_bug.cgi?id=33942 – https://openssl-library.org/news/secadv/20250120.txt
Update to 132.0.6834.110 High CVE-2025-0611: Object corruption in V8 High CVE-2025-0612: Out of bounds memory access in V8
https://lists.wikimedia.org/hyperkitty/list/wikitech- l@lists.wikimedia.org/thread/PFTE5RHUERS6KTUGGRZO7XXV5THNJ77E/ https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/5NYC4UZLY3MWQZ6DYJAUQRJG2ZHZFBJ6/
Update to 132.0.6834.110 High CVE-2025-0611: Object corruption in V8 High CVE-2025-0612: Out of bounds memory access in V8
