Important: thunderbird security update
Important: raptor2 security update
Important: rsync security update
https://security-tracker.debian.org/tracker/DSA-5843-2
https://security-tracker.debian.org/tracker/DSA-5845-1
The update for rsync announced in DSA 5843-1 introduced a regression when using the -H option to preserve hard links. Updated packages are now available to correct this issue.
* bsc#1235856 Cross-References: * CVE-2024-56374
* bsc#1220145 * bsc#1221302 * bsc#1222882 * bsc#1223059 * bsc#1223363
USN-7206-1 caused some regression in rsync.
* bsc#1228693 Cross-References: * CVE-2024-40779
* bsc#1232637 * bsc#1233712 Cross-References: * CVE-2022-48956
* bsc#1210619 * bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225202
* bsc#1235600 * bsc#1235601 Cross-References: * CVE-2024-50349
* bsc#1214954 * bsc#1216813 * bsc#1220773 * bsc#1224095 * bsc#1224726
* bsc#1234100 * bsc#1234101 * bsc#1234102 * bsc#1234103 * bsc#1234104
https://security-tracker.debian.org/tracker/DSA-5844-1
* bsc#1233712 Cross-References: * CVE-2024-50264
* bsc#1225819 * bsc#1228349 * bsc#1228786 * bsc#1229273 * bsc#1229553
* bsc#1225819 * bsc#1233712 Cross-References: * CVE-2023-52752
* bsc#1228573 * bsc#1229273 * bsc#1229553 * bsc#1232637 * bsc#1233712
* bsc#1229553 * bsc#1232637 * bsc#1233712 Cross-References:
* bsc#1210619 * bsc#1220537 * bsc#1223363 * bsc#1223683 * bsc#1225011
https://security-tracker.debian.org/tracker/DSA-5843-1
In today’s cyber threat landscape, good enough is no longer good enough. Cyberattacks don’t clock out at 5 PM, and neither can your security strategy. For Managed Service Providers (MSPs), offering customers 24/7 cybersecurity protection and response isn’t just a competitive advantage—it’s an essential service for business continuity, customer trust, and staying ahead of attackers. […]
Several security issues were fixed in snapd.
Several security issues were fixed in libxmltok.
https://security-tracker.debian.org/tracker/DSA-5842-1
An issue has been found in gnuchess, a tool to play a game of chess, either against the user or against itself. The issue is related to arbitrary code execution via crafted PGN (Portable
Out of Bounds Memory Read/Write in libjxl. (CVE-2024-11403) Resource exhaustion via Stack overflow in libjxl. (CVE-2024-11498) References: – https://bugs.mageia.org/show_bug.cgi?id=33818
Avahi wide-area dns uses constant source port. (CVE-2024-52615) Avahi wide-area dns predictable transaction ids. (CVE-2024-52616) References: – https://bugs.mageia.org/show_bug.cgi?id=33829
Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function. (CVE-2024-29645) References:
Command injection via RzBinInfo bclass due legacy code. (CVE-2022-1207) References: – https://bugs.mageia.org/show_bug.cgi?id=33895 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/YNDCM5TGWRLSMIJ74ZI6LMNSCCH5DBPL/
Various security, performance, accuracy, and stability issues have been fixed.
work around debugedit bug to fix aarch64 builds xen-hypervisor %post doesn’t load all needed grub2 modules update to xen-4.19.1 which includes Deadlock in x86 HVM standard VGA handling [XSA-463, CVE-2024-45818] libxl leaks data to PVH guests via ACPI tables [XSA-464, CVE-2024-45819]
