Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

backport fix for PEAP client (CVE-2023-52160)

2267205 – CVE-2024-24246 qpdf – Heap Buffer Overflow vulnerability in qpdf [fedora-all]

Update to latest version Security fix for CVE-2023-39325

https://security-tracker.debian.org/tracker/DSA-5638-1

Incorrect handling of extension attributes in PAX archives has been fixed in the GNU tar archiving utility. For Debian 10 buster, this problem has been fixed in version

Several security vulnerabilities have been discovered in Squid, a full featured web proxy cache. Due to programming errors in Squid’s HTTP request parsing, remote attackers may be able to execute a denial of service attack by sending large X-Forwarded-For header or trigger a stack buffer overflow while

Confidential Containers for Financial Services on Public Cloud

upstream security release 122.0.6261.111 – High CVE-2024-2173: Out of bounds memory access in V8 – High CVE-2024-2174: Inappropriate implementation in V8 – High CVE-2024-2176: Use after free in FedCM

* bsc#1218571 * bsc#1219238 Cross-References: * CVE-2023-7207

* bsc#1218571 * bsc#1219238 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

https://security-tracker.debian.org/tracker/DSA-5637-1

* bsc#1217213 Cross-References: * CVE-2023-44446

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1200528 Cross-References: * CVE-2022-1996

* bsc#1212475 * bsc#1219988 * bsc#1220999 * bsc#1221000 * bsc#1221001

* bsc#1034675 * bsc#1172961 * bsc#1182748 * bsc#1203672 * bsc#1203673

USN-6649-1 caused some minor regressions in Firefox.

https://security-tracker.debian.org/tracker/DSA-5636-1

Improper Domain Lookup in uv_getaddrinfo() has been fixed in libuv, an asynchronous event notification library. For Debian 10 buster, this problem has been fixed in version

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix a security issue.

* bsc#1210638 Cross-References: * CVE-2023-27043

* bsc#1220644 Cross-References: * CVE-2024-1597

https://security-tracker.debian.org/tracker/DSA-5635-1

Enhancing Security in Linux Web Applications with Advanced Secure Coding Practices

* bsc#1219911 Cross-References: * CVE-2024-24814

* bsc#1219911 Cross-References: * CVE-2024-24814

* bsc#1018158 * bsc#1178386 * bsc#1179694 * bsc#1179721 * bsc#1181505

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in the Linux kernel.

Aviv Keller discovered that the frames.html file generated by YARD, a documentation generation tool for the Ruby programming language, was vulnerable to cross-site scripting.

Several security issues were fixed in Node.js.

* bsc#1218351 Cross-References: * CVE-2023-51765

* bsc#1218351 Cross-References: * CVE-2023-51765

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.

Several security issues were fixed in Thunderbird.

Insights helps to provide Threat Intelligence

Multiple vulnerabilities have been discovered in UltraJSON, the worst of which could lead to key confusion and value overwriting.

Multiple vulnerabilities have been discovered in Blender, the worst of which could lead to arbitrary code execution.

A vulnerability has been discovered in Tox which may lead to remote code execution.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

An update that fixes one vulnerability is now available.

This is the February 2024 update for .NET 8. Release Notes: – Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.2/8.0.2.md – SDK: https://github.com/dotnet/core/blob/main/release-

fix CVE-2024-24814: prevent DoS when OIDCSessionType client-cookie is set and a crafted Cookie header is supplied

This is the February 2024 update for .NET 8. Release Notes: – Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.2/8.0.2.md – SDK: https://github.com/dotnet/core/blob/main/release-

* bsc#1219465 Cross-References: * CVE-2023-3966

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5634-1

* bsc#1220068 * bsc#1220070 Cross-References: * CVE-2024-25710

* bsc#1215300 * bsc#1217116 * bsc#1218733 Cross-References:

* bsc#1218733 Cross-References: * CVE-2023-51780

* bsc#1215300 * bsc#1217116 * bsc#1218733 Cross-References:

* bsc#1215300 * bsc#1218733 Cross-References: * CVE-2023-4921

* bsc#1210619 Cross-References: * CVE-2023-1829

https://security-tracker.debian.org/tracker/DSA-5633-1

* bsc#1219152 * bsc#1219724 * bsc#1219992 * bsc#1219993 * bsc#1219994

* bsc#1219724 * bsc#1219992 * bsc#1219993 * bsc#1219997 * bsc#1220014

* bsc#1219049 Cross-References: * CVE-2024-22211

* bsc#1219049 Cross-References: * CVE-2024-22211

The 6.7.6 stable kernel update contains a number of important fixes across the tree.

Update to 115.8.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-07/ https://www.thunderbird.net/en-US/thunderbird/115.8.0/releasenotes/

Cross-References: * CVE-2023-44487 CVSS scores:

* bsc#1185232 * bsc#1185261 * bsc#1185441 * bsc#1185621 * bsc#1187071

* bsc#1166486 * bsc#1185861 * bsc#1185863 * bsc#1186449 * bsc#1191256

* bsc#1177083 * bsc#1181995 * jsc#ECO-3329 * jsc#PM-2475 * jsc#PM-2730

* bsc#1071995 * bsc#1084842 * bsc#1114592 * bsc#1124644 * bsc#1128794

* bsc#1214052 Cross-References: * CVE-2023-4039

A vulnerability has been discovered in btrbk which can lead to remote code execution.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The system could be made to crash under certain conditions.

Unlock the Power of Cybersecurity Education for a Secure Future: A Comprehensive Guide for Linux Admins & Infosec Pros

It was discovered that iwd, the iNet Wireless Daemon, does not properly handle messages in the 4-way handshake used when connecting to a protected WiFi network for the first time. An attacker can take advantage of this flaw to gain unauthorized access to a protected WiFi

An issue has been found in libjwt, a C library to handle JWT (JSON Web Token). Due to using strcmp(), which does not use constant time during execution, a timing side channel attack might be possible.

Update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy

Backport fix for CVE-2023-5841.

Update to 2.6.0, fixes CVE-2023-52425, CVE-2023-52426.

Update to python3.11.8, backport fix for CVE-2023-27043.

https://security-tracker.debian.org/tracker/DSA-5631-1

Delivering a better view of system vulnerabilities with Red Hat Insights
Bridging innovation and standards compliance: Red Hat’s drive towards the next-generation of government computing standards
Environment-as-a-Service, part 4: External resources and dynamic credentials

Rebase to version 2.6.0

Update to qt-5.15.12.

Update to qt-5.15.12.

Update to qt-5.15.12.