Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

* bsc#1211649 * bsc#1211888 * bsc#1216850 * bsc#1218482 * bsc#1219001

https://security-tracker.debian.org/tracker/DSA-5680-1

https://security-tracker.debian.org/tracker/DSA-5681-1

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to remote code execution.

Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to remote code execution.

A vulnerability has been discovered in borgmatic, which can lead to shell injection.

Multiple vulnerabilities have been discovered in Pillow, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in MIT krb5, the worst of which could lead to remote code execution.

A vulnerability has been discovered in Setuptools, which can lead to denial of service.

https://security-tracker.debian.org/tracker/DSA-5679-1

https://security-tracker.debian.org/tracker/DSA-5678-1

https://security-tracker.debian.org/tracker/DSA-5677-1

Multiple vulnerabilities have been found in MediaInfo and MediaInfoLib, the worst of which could allow user-assisted remote code execution.

Multiple vulnerabilities have been discovered in strongSwan, the worst of which could possibly lead to remote code execution.

Multiple vulnerabilities have been discovered in HTMLDOC, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in mujs, the worst of which could lead to remote code execution.

Multiple vulnerabilities have been discovered in MPlayer, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in systemd, the worst of which can lead to a denial of service.

Beyond the lingo: What does Red Hat Insights and FedRAMP mean for your workload?
Simplify hybrid cloud operations with Red Hat Enterprise Linux 9.4
Mitigating breaches on Red Hat OpenShift with the CrowdStrike Falcon Operator
Understanding Red Hat’s response to the XZ security incident

* bsc#1177529 * bsc#1192145 * bsc#1194869 * bsc#1200465 * bsc#1205316

update to 124.0.6367.118 * High CVE-2024-4331: Use after free in Picture In Picture * High CVE-2024-4368: Use after free in Dawn update to 124.0.6367.91 update to 124.0.6367.78

The 6.8.8 stable kernel update contains a number of important fixes across the tree.

Patch to fix CVE-2024-31031

Update matrix-synapse to v1.105.1 (CVE-2024-31208) Update to v1.105.0

Update matrix-synapse to v1.105.1 (CVE-2024-31208) Update to v1.105.0

Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

USN-6747-1 caused some minor regressions in Firefox.

Update to 6.2.8, fixing CVE-2022-48257 and CVE-2022-48258 Unbundle cpp-httlib, fixing CVE-2023-26130

tpm2-tss: Fixed CVE-2024-29040 tpm2-tools: Fixed CVE-2024-29038 Fixed CVE-2024-29039

tpm2-tss: Fixed CVE-2024-29040 tpm2-tools: Fixed CVE-2024-29038 Fixed CVE-2024-29039

Security update for CVE-2024-27306 https://github.com/aio-libs/aiohttp/releases/tag/v3.9.5 https://github.com/aio-libs/aiohttp/releases/tag/v3.9.4

https://security-tracker.debian.org/tracker/DSA-5676-1

Gerbv could be made to crash if it opened a specially crafted input file.

Several issues have been found in qtbase-opensource-src, a collection of several Qt modules/libraries. The issues are related to buffer overflows, infinite loops or application

A bug that could allow an attacker with access to the machine to potentially access data in a temporary directory created by the Guava. (CVE-2020-8908) Predictable temporary files and directories used in FileBackedOutputStream. (CVE-2023-2976)

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. (CVE-2024-26458) Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. (CVE-2024-26461)

This release is a security release and addresses multiple issues: [Low] OutOfBound Read in zgfx_decompress_segment. [Moderate] Integer overflow & OutOfBound Write in clear_decompress_residual_data. [Low] integer underflow in nsc_rle_decode.

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c. (CVE-2023-50471) cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. (CVE-2023-50472)

* bsc#1222518 Cross-References: * CVE-2024-31948

JSON5 could allow unintended access to network services or have other unspecified impact.

Multiple problems were discovered in Org-mode, a GNU Emacs major mode for keeping notes, authoring documents, and maintaining to-do lists. CVE-2024-30203 & CVE-2024-30204

Anope could be made to bypass authentication checks for suspended accounts.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Multiple problems were discovered in GNU Emacs, the extensible, customisable, self-documenting display editor. CVE-2024-30203 & CVE-2024-30204

Pillow could be made to crash or run programs as an administrator if it opened a specially crafted file.

Several security issues were fixed in libvirt.

Several security issues were fixed in GnuTLS.

Several security issues were fixed in curl.

Several security issues were fixed in Apache HTTP Server.

Security vulnerabilities were found in mediawiki, a website engine for collaborative work, that could lead to information disclosure, privilege escalation, or denial of service.

Several vulnerabilities have been found in frr, the FRRouting suite of internet protocols. An attacker could craft packages to trigger buffer overflows with the possibility to gain remote code execution, buffer overreads, crashes or trick the software to enter an infinite loop.

Release 4.2.0

update to 124.0.6367.78 * Critical CVE-2024-4058: Type Confusion in ANGLE * High CVE-2024-4059: Out of bounds read in V8 API * High CVE-2024-4060: Use after free in Dawn

Release 4.2.0

* bsc#1213470 * bsc#1222979 * bsc#1222983 * bsc#1222984 * bsc#1222986

* bsc#1213470 * bsc#1222979 * bsc#1222983 * bsc#1222984 * bsc#1222986

CVE-2024-3852: GetBoundName in the JIT returned the wrong object CVE-2024-3854: Out-of-bounds-read after mis-optimized switch statement CVE-2024-3857: Incorrect JITting of arguments led to use-after-free during garbage collection CVE-2024-2609: Permission prompt input delay could expire when not in

update to 124.0.6367.78 * Critical CVE-2024-4058: Type Confusion in ANGLE * High CVE-2024-4059: Out of bounds read in V8 API * High CVE-2024-4060: Use after free in Dawn

CVE-2024-3852: GetBoundName in the JIT returned the wrong object CVE-2024-3854: Out-of-bounds-read after mis-optimized switch statement CVE-2024-3857: Incorrect JITting of arguments led to use-after-free during garbage collection CVE-2024-2609: Permission prompt input delay could expire when not in

The chromium-browser-stable package has been updated to the 124.0.6367.60 release. It includes 23 security fixes. Please, do note, only x86_64 is supported from now on. i586 support for linux was stopped some years ago and the community is not able to provide patches anymore for the latest Chromium code.

https://security-tracker.debian.org/tracker/DSA-5674-1

* bsc#1219217 * jsc#PED-3360 * jsc#PED-3361 Cross-References:

* bsc#1213269 * bsc#1218889 * bsc#1222843 * bsc#1222845

* bsc#1222842 Cross-References: * CVE-2024-3651

* bsc#1222950 Cross-References: * CVE-2024-1135

* bsc#1222857 * bsc#1222858 Cross-References: * CVE-2024-2756

* bsc#1222857 * bsc#1222858 Cross-References: * CVE-2024-2756

https://security-tracker.debian.org/tracker/DSA-5675-1

Hacker’s Corner: Complete Guide to Keylogging in Linux – Part 1

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in Thunderbird.

Fix for CVE-2024-31497

Fix for CVE-2024-31497

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

* bsc#1217325 Cross-References: * CVE-2023-26364

* bsc#1217325 Cross-References: * CVE-2023-26364

* bsc#1118590 * bsc#874743 Cross-References: * CVE-2014-2913

* bsc#1219887 * bsc#1219912 * bsc#1220371 * jsc#MSQA-759 * jsc#PED-7893

Google Guest Agent and OS Config Agent could be made to crash if it open a specially crafted JSON.

* bsc#1213269 * bsc#1218889 * bsc#1220134 * bsc#1222843 * bsc#1222845

* bsc#1190011 * bsc#1198038 * bsc#1207205 * bsc#1212850 * bsc#1213925

* bsc#1223155 Cross-References: * CVE-2024-31744

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5673-1

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service or information disclosure. For Debian 10 buster, these problems have been fixed in version

Pillow could be made to crash or run programs as an administrator if it opened a specially crafted file.

percona-xtrabackup could be made to run programs as your login if it opened a specially crafted file.

* bsc#1221793 * bsc#1221797 Cross-References: * CVE-2024-29131

* bsc#1198101 * bsc#1205588 * bsc#1205855 * bsc#1210382 * bsc#1213945

* bsc#1219435 Cross-References: * CVE-2024-1086

https://security-tracker.debian.org/tracker/DSA-5669-1

https://security-tracker.debian.org/tracker/DSA-5670-1