Fix CVE-2024-9014.
https://security-tracker.debian.org/tracker/DSA-5783-1
https://security-tracker.debian.org/tracker/DSA-5784-1
https://security-tracker.debian.org/tracker/DSA-5780-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
Generative AI has taken the world by storm, transforming how individuals and businesses interact with and trust this new technology. With tools like ChatGPT, Grok, DALL-E, and Microsoft Copilot, everyday users are finding new ways to enhance productivity, creativity, and efficiency. However, as the integration of AI into daily life accelerates, so do the concerns […]
* bsc#1229930 * bsc#1229931 * bsc#1229932 Cross-References:
* bsc#1230020 * bsc#1230034 Cross-References: * CVE-2023-7256
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-5781-1
https://security-tracker.debian.org/tracker/DSA-5782-1
Building efficient recovery options will drive ecosystem resilience
* bsc#1230986 Cross-References: * CVE-2024-38286
A protocol flaw was fixed in AsyncSSH.
PHP version 8.3.12 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable
Update to new upstream version (closes rhbz#2237124)
PHP version 8.3.12 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable
Several packages have been updated for Slackware 15.0 and -current to fix rpath security issues.
* bsc#1230698 Cross-References: * CVE-2024-41996
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
From the apps on our smartphones to chatbot assistant services, artificial intelligence (AI) is transforming our lives in both big and small ways. But as exciting as AI can be, it’s also important to understand its potential risks. October is Cybersecurity Awareness Month, making it the perfect time to become more cyber-savvy about AI. Let’s […]
As October rolls around, it’s time to focus on cybersecurity. After all, it’s Cybersecurity Awareness Month—a perfect reminder to check in on the safety of your identity. If you’ve ever had your identity stolen or know someone who has, you understand how serious the problem is. From text scams to stolen passwords, criminals are finding […]
October is the month for pumpkin spice and all things spooky. But protecting your personal information online doesn’t need to be scary. For more than 20 years now, October has also been recognized as Cybersecurity Awareness Month. In our digitally connected world, apps and online accounts can make our lives much more convenient. Sadly, they […]
Python could be made to bypass some restrictions if it received specially crafted input.
debian-security-support, the Debian security support coverage checker, has been updated in bullseye-security to mark the end of life of the following packages: * pdns-recursor: See https://bugs.debian.org/1070176
Two vulnerabilities have been fixed in the SQLite database. CVE-2021-36690
Flatpak could be made to read and write files in locations it would not normally have access to.
Simone Margaritelli reported that cups, the Common UNIX Printing System, does not properly sanitize IPP attributes when creating PPD files, which may result in the execution of arbitrary code.
An update that fixes four vulnerabilities is now available.
* bsc#1196018 * bsc#1196823 * bsc#1202346 * bsc#1209636 * bsc#1209799
Multiple vulnerabilities have been fixed in the network traffic analyzer Wireshark. CVE-2021-4181
Simone Margaritelli reported several vulnerabilities in cups-filters. Missing validation of IPP attributes returned from an IPP server and multiple bugs in the cups-browsed component can result in the execution
Simone Margaritelli reported that cups, the Common UNIX Printing System, does not properly sanitize IPP attributes when creating PPD files, which may result in the execution of arbitrary code.
Two vulnerabilities were discovered in unbound, a validating, recursive, caching DNS resolver. Specially crafted input could cause a heap-buffer-overflow leading to memory corruption and potentially causing the application to crash or allowing arbitrary code execution
Update to new upstream version (closes rhbz#2237124)
https://security-tracker.debian.org/tracker/DSA-5779-1
https://security-tracker.debian.org/tracker/DSA-5778-1
Multiple vulnerabilities have been fixed in ruby-rails-html-sanitizer, a Ruby library for sanitizing HTML fragments in Rails applications. CVE-2022-23517
Multiple vulnerabilities have been fixed in ruby-loofah, a Ruby library for manipulating and transforming HTML/XML documents and fragments. CVE-2022-23514
ESET research examines the group’s malicious wares as used to spy on targets in Ukraine in the past two years
multipart/form-data request tampering has been fixed in ruby-httparty, a Ruby library for using Web-based APIs and related services. For Debian 11 bullseye, this problem has been fixed in version
Multiple vulnerabilities have been discovered in nginx, the worst of which could result in denial of service.
Multiple vulnerabilities have been found in Apache HTTPD, the worst of which could result in denial of service.
Multiple vulnerabilities have been found in yt-dlp, the worst of which could result in arbitrary code execution.
Multiple vulnerabilities have been discovered in Docker, the worst of which could result in denial of service.
Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service.
