https://security-tracker.debian.org/tracker/DSA-5841-1
The fix for CVE-2024-6923 in the python3.9 source package which was released as part of a suite of updates in DLA 3980-1 [0] introduced safer processing of input in the email module to order to increase the security around email header injection attacks.
Several vulnerabilities were discovered in OpenAFS, an implementation of the AFS distributed filesystem, which may result in theft of credentials in Unix client PAGs (CVE-2024-10394), fileserver crashes and information leak on StoreACL/FetchACL (CVE-2024-10396) or buffer overflows in XDR
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or privilege escalation.
Important: kernel-rt security update
Important: webkit2gtk3 security update
* jsc#PED-11136 Cross-References: * CVE-2024-12678 * CVE-2024-25131
* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:
* bsc#1234991 Cross-References: * CVE-2025-0237 * CVE-2025-0238
https://security-tracker.debian.org/tracker/DSA-5839-1
* bsc#1235029 Cross-References: * CVE-2024-56826
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
xfpt could be made to crash or run programs if it opened a specially crafted file.
Thunderbird could be made to bypass security restrictions.
Several security issues were fixed in Firefox.
Updated to latest upstream (134.0)
https://security-tracker.debian.org/tracker/DSA-5840-1
* bsc#1082555 * bsc#1176081 * bsc#1206344 * bsc#1213034 * bsc#1218562
* bsc#1082555 * bsc#1157160 * bsc#1218644 * bsc#1221977 * bsc#1222364
Tinyproxy could be made to crash or run programs if it received specially crafted input.
* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:
Several security issues were fixed in HTMLDOC.
* bsc#1234809 Cross-References: * CVE-2024-56326
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
In today’s digital-first world, small and medium-sized businesses (SMBs) face cybersecurity challenges that grow more complex by the day. SMBs are prime targets for attackers hoping to gain a foothold inside any organization that doesn’t have extensive security measures. As threats increase, so does the need for comprehensive, reliable, and accessible protection. This is where […]
* bsc#1234809 Cross-References: * CVE-2024-56326
* bsc#1234718 Cross-References: * CVE-2024-11614
* bsc#1202473 * bsc#1205224 * bsc#1211507 Cross-References:
tinyproxy could be made to expose sensitive information.
Vulnerabilities were found in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are prior to 7.0.22 and prior to 7.1.2. A difficult to exploit vulnerability allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise an Oracle
The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many ` `. (CVE-2024-39908)
