The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Multiple vulnerabilities were found in git, a fast, scalable and distributed revision control system. CVE-2019-1387
libheif could be made to crash if it opened a specially crafted file.
https://security-tracker.debian.org/tracker/DSA-5721-1
https://security-tracker.debian.org/tracker/DSA-5722-1
* bsc#1065729 * bsc#1141539 * bsc#1174585 * bsc#1181674 * bsc#1187716
* bsc#1224158 Cross-References: * CVE-2017-17507 * CVE-2018-11205
* bsc#1224458 * bsc#1225552 Cross-References: * CVE-2024-4741
* bsc#1225491 Cross-References: * CVE-2024-33871
* bsc#1225491 Cross-References: * CVE-2024-33871
* bsc#1216594 * bsc#1216598 * bsc#1226586 Cross-References:
Hibernate could be made to expose sensitive information.
* bsc#1226134 Cross-References: * CVE-2024-37535
* bsc#1226423 Cross-References: * CVE-2024-38394
* bsc#1226423 Cross-References: * CVE-2024-38394
* bsc#1225971 Cross-References: * CVE-2024-20696
* bsc#1089090 Cross-References: * CVE-2018-9918
https://security-tracker.debian.org/tracker/DSA-5715-2
Use-after-free in networking. (CVE-2024-5702) Use-after-free in JavaScript object transplant. (CVE-2024-5688) External protocol handlers leaked by timing attack. (CVE-2024-5690) Sandboxed iframes were able to bypass sandbox restrictions to open a new window. (CVE-2024-5691)
This update includes a rebase from 9.0.83 to 9.0.89. #2269611 CVE-2024-24549 tomcat: CVE-2024-24549: Apache Tomcat: HTTP/2 header handling DoS #2269612 CVE-2024-23672 tomcat: Apache Tomcat: WebSocket DoS with incomplete closing handshake
New emacs packages are available for Slackware 15.0 and -current to fix a security issue.
Understanding and preparing for the potential long-tail costs of data breaches is crucial for businesses that aim to mitigate the impact of security incidents
Multiple vulnerabilities have been discovered in JHead, the worst of which may lead to arbitrary code execution.
A vulnerability has been discovered in LZ4, which can lead to memory corruption.
A vulnerability has been discovered in RDoc, which can lead to execution of arbitrary code.
A vulnerability has been discovered in Flatpak, which can lead to a sandbox escape.
A vulnerability has been discovered in GLib, which can lead to privilege escalation.
Update to 2.44.2: Make gamepads visible on axis movements, and not only on button presses. Disable the gst-libav AAC decoder. Make user scripts and style sheets visible in the Web Inspector. Use the geolocation portal where available, with the existing geoclue as
As health data continues to be a prized target for hackers, here’s how to minimize the fallout from a breach impacting your own health records
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
* bsc#1012628 * bsc#1065729 * bsc#1181674 * bsc#1187716 * bsc#1193599
* bsc#1127514 * bsc#1127855 * bsc#1131544 Cross-References:
* bsc#1220210 Cross-References: * CVE-2024-26130
* bsc#1203171 * bsc#1225997 * jsc#PED-7982 * jsc#PED-8018
Hacktivism is nothing new, but the increasingly fuzzy lines between traditional hacktivism and state-backed operations make it a more potent threat
* bsc#1133222 * bsc#1224158 Cross-References: * CVE-2017-17507
gdb could be made to crash if it opened a specially crafted file.
Version 2.7.7 2024-06-10 Security: Fixed command injection via malicious git branch name (GHSA-47f6-5gq3-vx9c / CVE-2024-35241) Security: Fixed multiple command injections via malicious git/hg branch names (GHSA-v9qv-c7wm-wgmf / CVE-2024-35242)
Fixing CVE-2023-51765 (smtp smuggling) requires to reject email that include NUL bytes, in some configuration. Previous security version of sendmail, by default, does not
A malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. References: – https://bugs.mageia.org/show_bug.cgi?id=33119
A sensitive data leakage vulnerability was identified in scikit-learn’s TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. The vulnerability arises from the unexpected storage of all tokens present in the training data within the `stop_words_` attribute, rather than only storing the subset
https://security-tracker.debian.org/tracker/DSA-5717-1
https://security-tracker.debian.org/tracker/DSA-5715-1
Huy Nguy¡»’n Ph¡º¡m Nh¡ºt, and Valentin T. and Lutz Wolf of CrowdStrike, discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not correctly process and sanitize requests. This would allow an attacker to perform Cross-Side Scripting (XSS) attacks.
* bsc#1226027 Cross-References: * CVE-2024-5688 * CVE-2024-5690
* bsc#1226007 Cross-References: * CVE-2023-52890
https://security-tracker.debian.org/tracker/DSA-5716-1
Git could be made to run programs as your login if it clones a crafted repository.
