Antonio Morales discovered an out-of-bounds write in the MMRDecoder::scanruns method in djvulibre, a library and set of tools to handle documents in the DjVu format, which may result in the execution of arbitrary code if a specially crafted document is processed.
* bsc#1243061 * bsc#1243804 * bsc#1243913 Cross-References:
5.2.0 release
Integer overflow on 32-bit systems has been fixed in the XMedCon toolkit for medical image conversion. For Debian 11 bullseye, this problem has been fixed in version
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in
Update to 3.6.4 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-3.6.4
https://security-tracker.debian.org/tracker/DSA-5959-1
PGSQL: Fixed GHSA-hrwm-9436-5mv3 (pgsql extension does not check for errors during escaping). (CVE-2025-1735) SOAP: Fixed GHSA-453j-q27h-5p8x (NULL Pointer Dereference in PHP SOAP
A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in the xls2csv utility version 0.95. (CVE-2024-48877) An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. (CVE-2024-52035)
* bsc#1243314 * bsc#1243332 * bsc#1243422 * bsc#1243423
* bsc#1236931 * bsc#1239119 Cross-References: * CVE-2025-30258
Cracking the code of a successful cybersecurity career starts here. Hear from ESET’s Robert Lipovsky as he reveals how to break into and thrive in this fast-paced field.
Some schemes might sound unbelievable, but they’re easier to fall for than you think. Here’s how to avoid getting played by gamified job scams.
Update bundled pbkdf2 library.
* bsc#1245309 * bsc#1245310 * bsc#1245311 * bsc#1245314
* bsc#1238063 * bsc#1244136 Cross-References: * CVE-2025-0620
Deep cuts in cybersecurity spending risk creating ripple effects that will put many organizations at a higher risk of falling victim to cyberattacks
* bsc#1244704 Cross-References: * CVE-2025-6196
Multiple vulnerabilities are discovered in jpeg-xl, the JPEG XL (“JXL”) image coding library, including out of bounds read/write and stack based buffer overflow, which may cause excessive memory usage and denial of service attacks.
Backport fix for CVE-2025-6199.
5.2.0 release
https://security-tracker.debian.org/tracker/DSA-5958-1
ESET Research analyzes Gamaredon’s updated cyberespionage toolset, new stealth-focused techniques, and aggressive spearphishing operations observed throughout 2024
The embedded copy of pjproject is affected by a buffer overflow vulnerability, which affects applications that use PJSIP DNS resolver. For the stable distribution (bookworm), this problem has been fixed in
Several security issues were fixed in pcs.
Several security issues were fixed in Flask-CORS.
Several security issues were fixed in mongo-c-driver.
Several security issues were fixed in logback.
https://security-tracker.debian.org/tracker/DSA-5957-1
https://security-tracker.debian.org/tracker/DSA-5956-1
CVE-2025-6424: A use-after-free in FontFaceSet resulted in a potentially exploitable crash. CVE-2025-6425: An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing
ESET Chief Security Evangelist Tony Anscombe reviews some of the report’s standout findings and their implications for organizations in 2025 and beyond
ESET experts discuss Sandworm’s new data wiper, UnsolicitedBooker’s relentless campaigns, attribution challenges amid tool-sharing, and other key findings from the latest APT Activity Report
* bsc#1230092 Cross-References: * CVE-2024-45310
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that an exploit for CVE-2025-6554 exists in the wild.
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-5955-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
