Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
xfpt could be made to crash or run programs if it opened a specially crafted file.
Thunderbird could be made to bypass security restrictions.
Several security issues were fixed in Firefox.
Updated to latest upstream (134.0)
https://security-tracker.debian.org/tracker/DSA-5840-1
* bsc#1082555 * bsc#1176081 * bsc#1206344 * bsc#1213034 * bsc#1218562
* bsc#1082555 * bsc#1157160 * bsc#1218644 * bsc#1221977 * bsc#1222364
Tinyproxy could be made to crash or run programs if it received specially crafted input.
* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:
Several security issues were fixed in HTMLDOC.
* bsc#1234809 Cross-References: * CVE-2024-56326
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
In today’s digital-first world, small and medium-sized businesses (SMBs) face cybersecurity challenges that grow more complex by the day. SMBs are prime targets for attackers hoping to gain a foothold inside any organization that doesn’t have extensive security measures. As threats increase, so does the need for comprehensive, reliable, and accessible protection. This is where […]
* bsc#1234809 Cross-References: * CVE-2024-56326
* bsc#1234718 Cross-References: * CVE-2024-11614
* bsc#1202473 * bsc#1205224 * bsc#1211507 Cross-References:
tinyproxy could be made to expose sensitive information.
Vulnerabilities were found in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are prior to 7.0.22 and prior to 7.1.2. A difficult to exploit vulnerability allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise an Oracle
The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many ` `. (CVE-2024-39908)
Update to 2.46.5: Fix several crashes and rendering issues. CVE-2024-54479, CVE-2024-54502, CVE-2024-54508, CVE-2024-54505
* bsc#1217826 * bsc#1222815 * bsc#1230551 * bsc#1230552 * bsc#1231345
* bsc#1205224 * bsc#1211507 Cross-References: * CVE-2022-39377
iwd 3.3: Fix issue with handling External Authentication. iwd 3.2: Fix issue with GCC 15 and -std=c23 build errors. Add support for using PMKSA over SAE if available.
iwd 3.3: Fix issue with handling External Authentication. iwd 3.2: Fix issue with GCC 15 and -std=c23 build errors. Add support for using PMKSA over SAE if available.
Linux 6.1 has been packaged for Debian 11 as linux-6.1. This provides a supported upgrade path for systems that currently use kernel packages from the “bullseye-backports” suite.
* bsc#1226162 * bsc#1226468 * bsc#1234292 Cross-References:
* bsc#1234808 * bsc#1234809 Cross-References: * CVE-2024-56201
It was discovered that there was a potential Denial of Service (DoS) vulnerability, in Django, a popular Python-based web development framework.
Update to 2.12.9 Fixes CVE-2024-40896
