https://security-tracker.debian.org/tracker/DSA-5627-1
New libuv packages are available for Slackware 15.0 and -current to fix a security issue.
* bsc#1011205 * bsc#1093641 * bsc#1125882 * bsc#1167400 * bsc#1207973
* bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188
The updated packages fix security vulnerabilities: RTPS dissector memory leak. (CVE-2023-5371) SSH dissector invalid read of memory blocks. (CVE-2023-6174) NetScreen File Parsing Heap-based Buffer Overflow. (CVE-2023-6175) GVCP dissector crash via packet injection or crafted capture file.
Stack buffer overflow in virtio_net_flush_tx (CVE-2023-6693) (rhbz#2256436)
Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link
Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link
Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link
Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link
* bsc#1219059 Cross-References: * CVE-2024-22563
* bsc#1202903 * bsc#1219187 Cross-References: * CVE-2022-2132
* bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188
* bsc#1219059 Cross-References: * CVE-2024-22563
Multiple vulnerabilities have been discovered in Samba, the worst of which can lead to remote code execution.
A vulnerability has been discovered in Glade which can lead to a denial of service.
Multiple vulnerabilities have been discovered in QtNetwork, the worst of which could lead to execution of arbitrary code.
A vulnerability has been discovered in Thunar which may lead to arbitrary code execution
A vulnerability has been discovered in libcaca which can lead to arbitrary code execution.
Multiple vulnerabilities have been discovered in Exim, the worst of which can lead to remote code execution.
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can
Multiple vulnerabilities have been discovered in CUPS, the worst of which can lead to arbitrary code execution.
https://security-tracker.debian.org/tracker/DSA-5626-1
https://security-tracker.debian.org/tracker/DSA-5625-1
Here’s how the results of vulnerability scans factor into decisions on cyber-insurance and how human intelligence comes into play in the assessment of such digital signals
Artificial intelligence is on everybody’s lips these days, but there are also many misconceptions about what AI actually is and isn’t. We unpack the basics and examine AI’s broader implications.
Update to 1.6.5 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575
Update to 2.11.5
Update to 1.6.5 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575
Update to 1.7.2 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575
Rebase to version 2.6.0
Update to 2.28.7 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.7 Security Advisories: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-
Several security issues were fixed in the Linux kernel.
* bsc#1218429 Cross-References: * CVE-2023-6879
* bsc#1218690 * bsc#1218810 * bsc#1219243 Cross-References:
* bsc#1219113 * bsc#1219604 Cross-References: * CVE-2014-1745
* bsc#1219679 Cross-References: * CVE-2024-0985
https://security-tracker.debian.org/tracker/DSA-5624-1
https://security-tracker.debian.org/tracker/DSA-5623-1
https://security-tracker.debian.org/tracker/DSA-5622-1
Did you know that more than nine million Americans have their identity stolen each year? Your data is stored across countless databases for various purposes, making it a prime target for criminals. With access to your personal information, bad actors can drain your bank account and damage your credit—or worse. But that doesn’t mean you […]
The updated packages fix security vulnerabilities: Parsing large DNS messages may cause excessive CPU load. (CVE-2023-4408) Querying RFC 1918 reverse zones may cause an assertion failure when “nxdomain-redirect” is enabled. (CVE-2023-5517) Enabling both DNS64 and serve-stale may cause an assertion failure
* bsc#1108281 * bsc#1193285 * bsc#1215275 * bsc#1216702 * bsc#1217987
Several security issues were fixed in UltraJSON.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in EDK II.
update to 1.26.2
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several vulnerabilities were discovered in BIND, a DNS server implementation, which may result in denial of service. For the oldstable distribution (bullseye), these problems have been fixed
Two vulnerabilities were discovered in unbound, a validating, recursive, caching DNS resolver. Specially crafted DNSSEC answers could lead unbound down a very CPU intensive and time costly DNSSEC (CVE-2023-50387) or NSEC3 hash (CVE-2023-50868) validation path,
UltraJSON could be made to crash if it received specially crafted input.
https://security-tracker.debian.org/tracker/DSA-5620-1
https://security-tracker.debian.org/tracker/DSA-5621-1
In the digital age, the quest for love has moved online, but so have the fraudsters, with romance scams reaching record highs. These scams don’t just harm individuals financially and emotionally; they can also pose significant risks to businesses. Let’s explore how these scams work, their impact, and how both businesses and consumers can protect […]
Several security issues were fixed in WebKitGTK.
Glance_store could be made to expose sensitive information.
