https://security-tracker.debian.org/tracker/DSA-5671-1
https://security-tracker.debian.org/tracker/DSA-5672-1
Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.
update to 124.0.6367.60 High CVE-2024-3832: Object corruption in V8 High CVE-2024-3833: Object corruption in WebAssembly High CVE-2024-3914: Use after free in V8 High CVE-2024-3834: Use after free in Downloads
New upstream release (125.0)
Security fix for CVE-2023-5752
Update to 1.15.8 Fixes CVE-2024-32462
Security fix for CVE-2024-27316
https://security-tracker.debian.org/tracker/DSA-5667-1
Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.
Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.
Security fixes for CVE-2024-27351 Potential regular expression DOS in django.utils.text.Truncator.words() CVE-2024-24680 denial-of-service in intcomma template filter CVE-2023-43665 Denial-of-service possibility in django.utils.text.Truncator
fix CONTINUATION frames DoS (CVE-2024-28182)
This update includes several bug fixes from the upstream glibc release branch, including a fix for CVE-2024-2961.
Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.
https://security-tracker.debian.org/tracker/DSA-5668-1
* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982
* bsc#1220181 Cross-References: * CVE-2024-24476
* bsc#1222535 Cross-References: * CVE-2024-2609 * CVE-2024-3302
* bsc#1219491 Cross-References: * CVE-2023-46045
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or clickjacking.
WordPress 6.4.4 Security Release Security updates included in this release A cross-site scripting (XSS) vulnerability affecting the Avatar block type; reported by John Blackbourn of the WordPress security team. Many thanks to Mat Rollings for assisting with the research.
https://security-tracker.debian.org/tracker/DSA-5666-1
https://security-tracker.debian.org/tracker/DSA-5665-1
https://security-tracker.debian.org/tracker/DSA-5664-1
https://security-tracker.debian.org/tracker/DSA-5663-1
GNU C Library could be made to crash or run programs if it processed specially crafted data.
* bsc#1194869 * bsc#1200465 * bsc#1205316 * bsc#1207948 * bsc#1209635
This update includes the changes in tzdata 2024a for the Perl bindings. For the list of changes, see DLA-3789-1. For Debian 10 buster, this problem has been fixed in version
This update includes the changes in tzdata 2024a. Notable changes are: – – Kazakhstan unifies on UTC+5 beginning 2024-03-01.
sosreport: Fix command injection with crafted report names [CVE-2024-2947]
Fix for CVE-2024-31497
https://security-tracker.debian.org/tracker/DSA-5655-2
* bsc#1200599 * bsc#1209635 * bsc#1212514 * bsc#1213456 * bsc#1217987
* bsc#1194869 * bsc#1200465 * bsc#1205316 * bsc#1207948 * bsc#1209635
New upstream release (125.0)
The 6.8.6 stable kernel update contains a number of important fixes across the tree.
Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791; Security fix for CVE-2024-25713
New version 4.2.4. Includes a fix for CVE-2024-2955
https://security-tracker.debian.org/tracker/DSA-5661-1
https://security-tracker.debian.org/tracker/DSA-5660-1
* bsc#1216992 Cross-References: * CVE-2023-4218
* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982
* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982
* bsc#1220053 * bsc#1222244 * bsc#1222384 * bsc#1222530 * bsc#1222603
* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982
* bsc#1220053 * bsc#1222244 * bsc#1222384 * bsc#1222530 * bsc#1222603
https://security-tracker.debian.org/tracker/DSA-5662-1
Bartek Nowotarski discovered that Apache Traffic Server, a reverse and forward proxy server, was susceptible to denial of service via HTTP2 continuation frames.
Multiple vulnerabilities have been fixed in the Xorg X server. CVE-2024-31080
* bsc#1219296 Cross-References: * CVE-2023-52340
update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn
New less packages are available for Slackware 15.0 and -current to fix a security issue.
Core: – Corrupted memory in destructor with weak references – GC does not scale well with a lot of objects created in destructor DOM: – Add some missing ZPP checks.
update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn
The 6.8.5 stable kernel update contains a number of important fixes across the tree.
Bring all current releases from either version 0.7.3 or 0.6.12 to version 0.7.6 for more bug-fixes and also as to resolve potential security issues: https://lib.openmpt.org/libopenmpt/news/
Bring all current releases from either version 0.7.3 or 0.6.12 to version 0.7.6 for more bug-fixes and also as to resolve potential security issues: https://lib.openmpt.org/libopenmpt/news/
https://security-tracker.debian.org/tracker/DSA-5659-1
https://security-tracker.debian.org/tracker/DSA-5657-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
The 6.8.5 stable kernel update contains a number of important fixes across the tree.
The 6.8.5 stable kernel update contains a number of important fixes across the tree.
Update to version 0.3.26. Addresses RUSTSEC-2024-0332.
Update to version 0.3.26. Addresses RUSTSEC-2024-0332.
https://security-tracker.debian.org/tracker/DSA-5658-1
Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with “collapsed_forwarding on” are vulnerable. Configurations with “collapsed_forwarding off” or without a “collapsed_forwarding” directive
* bsc#1221564 Cross-References: * CVE-2021-47154
* bsc#1218613 * bsc#1219078 * bsc#1219296 * bsc#1219432
Security fix for CVE-2024-24576 (Windows command injection)
Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)
Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)
4.2.3
These new packages fix bugs in SSL certificate validation; these bugs could allow for the compromising of encrypted SSL sessions.
* bsc#1028271 Cross-References: * CVE-2016-10243
* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672
* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672
This is the March 2024 update for .NET 7. Release Notes: https://github.com/dotnet/core/blob/main/release- notes/7.0/7.0.17/7.0.17.md
https://security-tracker.debian.org/tracker/DSA-5656-1
An update that fixes two vulnerabilities is now available.
util-linux could be made to expose sensitive information.
* bsc#1167896 * bsc#1206261 * bsc#1215301 Cross-References:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
Bind could be made to crash if it received specially crafted input.
* bsc#1221926 Cross-References: * CVE-2024-30161
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
* bsc#1207987 * bsc#1220117 * bsc#1221831 Cross-References:
* bsc#1214223 * bsc#1216980 * bsc#1220512 * bsc#1221237 * bsc#1221468
