Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

The updated packages fix security vulnerabilities: Heap buffer overflow in sqlite. (CVE-2023-2137) A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler.

Updated to 124.0

Updated to 124.0

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

https://security-tracker.debian.org/tracker/DSA-5642-1

https://security-tracker.debian.org/tracker/DSA-5626-2

Red Hat Quay 3.11: Smarter permissions, lifecycle, and AWS integration

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Update to 2.6.1, backport fix for CVE-2024-28757.

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

* bsc#1219465 Cross-References: * CVE-2023-3966

* bsc#1213590 * bsc#1214686 * bsc#1214687 * bsc#1221187 * bsc#960589

Several security issues were fixed in OpenJDK 8.

Update to shim-15.8

Update to shim-15.8

Update to shim-15.8

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. (CVE-2020-36518) In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the

The updated packages fix security vulnerabilities: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. (CVE-2022-38398) Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML

Red Hat OpenShift Service on AWS obtains FedRAMP “Ready” designation
Zero Trust MLOps with OpenShift Platform Plus

curl was affected by a path traversal vulnerability. SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate

upstream security release 122.0.6261.128 High CVE-2024-2400: Use after free in Performance Manager

Security fix for CVE-2007-4559.

New upstream release with security fixes for CVE-2023-5992 and CVE-2024-1454

Path traversal in moment.locale. (CVE-2022-24785) Inefficient parsing algorithim resulting in DoS. (CVE-2022-31129) References: – https://bugs.mageia.org/show_bug.cgi?id=30664

Security fix for CVE-2007-4559.

Update to 3.2.2 It indirectly fix CVE-2023-3966 and CVE-2023-5366

* bsc#1219836 Cross-References: * CVE-2024-1062

It was discovered that composer, a dependency manager for the PHP language, processed files in the local working directory. This could lead to local privilege escalation or malicious code execution. Due to a technical issue this email was not sent on 2024-02-26 like it should

* jsc#PED-2362 * jsc#SLE-5514 Cross-References: * CVE-2023-20593

* jsc#PED-2362 * jsc#SLE-5514 Cross-References: * CVE-2023-20593

* bsc#1221134 * bsc#1221151 Cross-References: * CVE-2023-42465

* bsc#1221134 * bsc#1221151 Cross-References: * CVE-2023-42465

Expat could be made to crash if it received specially crafted input.

Several security issues were fixed in TeX Live.

Two vulnerabilities were discovered in Open vSwitch, a software-based Ethernet virtual switch, which could result in a bypass of OpenFlow rules or denial of service.

python-cryptography could be made to expose sensitive information over the network.

Update to 115.8.1 https://www.mozilla.org/en-US/security/advisories/mfsa2024-11/ read that if you have mails with encrypted email subjects https://www.thunderbird.net/en-US/thunderbird/115.8.1/releasenotes/

python-multipart 0.0.7 (2024-02-03) Refactor header option parser to use the standard library instead of a custom RegEx #75. Fixes a denial of service vulnerability, GHSA-qf9m-vfgh-m389, initially reported in FastAPI but applicable to other libraries and applications.

https://security-tracker.debian.org/tracker/DSA-5640-1

* bsc#1219775 Cross-References: * CVE-2024-22119

* bsc#1220404 * bsc#1220405 Cross-References: * CVE-2024-25081

* bsc#1220404 * bsc#1220405 Cross-References: * CVE-2024-25081

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Add implicit rejection in PKCS#1 v1.5 in OpenSSL.

https://security-tracker.debian.org/tracker/DSA-5639-1

Rack could be made do denial of service if it received a specially crafted header.

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

Several security issues were fixed in Open vSwitch.

An update that fixes one vulnerability is now available.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Two vulnerabilities were discovered in tiff, Tag Image File Format library. CVE-2023-3576

* bsc#1027519 * bsc#1218851 * bsc#1219080 * bsc#1219885

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

It was discovered that the uv_getaddrinfo() function in libuv, an asynchronous event notification library, incorrectly truncated certain hostnames, which may result in bypass of security measures on internal APIs or SSRF attacks.

2267205 – CVE-2024-24246 qpdf – Heap Buffer Overflow vulnerability in qpdf [fedora-all]

backport fix for PEAP client (CVE-2023-52160)

2267205 – CVE-2024-24246 qpdf – Heap Buffer Overflow vulnerability in qpdf [fedora-all]

Update to latest version Security fix for CVE-2023-39325

https://security-tracker.debian.org/tracker/DSA-5638-1

Incorrect handling of extension attributes in PAX archives has been fixed in the GNU tar archiving utility. For Debian 10 buster, this problem has been fixed in version

Several security vulnerabilities have been discovered in Squid, a full featured web proxy cache. Due to programming errors in Squid’s HTTP request parsing, remote attackers may be able to execute a denial of service attack by sending large X-Forwarded-For header or trigger a stack buffer overflow while

Confidential Containers for Financial Services on Public Cloud

upstream security release 122.0.6261.111 – High CVE-2024-2173: Out of bounds memory access in V8 – High CVE-2024-2174: Inappropriate implementation in V8 – High CVE-2024-2176: Use after free in FedCM

* bsc#1218571 * bsc#1219238 Cross-References: * CVE-2023-7207

* bsc#1218571 * bsc#1219238 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

https://security-tracker.debian.org/tracker/DSA-5637-1

* bsc#1217213 Cross-References: * CVE-2023-44446

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1200528 Cross-References: * CVE-2022-1996

* bsc#1212475 * bsc#1219988 * bsc#1220999 * bsc#1221000 * bsc#1221001

* bsc#1034675 * bsc#1172961 * bsc#1182748 * bsc#1203672 * bsc#1203673

USN-6649-1 caused some minor regressions in Firefox.

https://security-tracker.debian.org/tracker/DSA-5636-1

Improper Domain Lookup in uv_getaddrinfo() has been fixed in libuv, an asynchronous event notification library. For Debian 10 buster, this problem has been fixed in version

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix a security issue.

* bsc#1210638 Cross-References: * CVE-2023-27043

* bsc#1220644 Cross-References: * CVE-2024-1597

https://security-tracker.debian.org/tracker/DSA-5635-1

Enhancing Security in Linux Web Applications with Advanced Secure Coding Practices

* bsc#1219911 Cross-References: * CVE-2024-24814

* bsc#1219911 Cross-References: * CVE-2024-24814

* bsc#1018158 * bsc#1178386 * bsc#1179694 * bsc#1179721 * bsc#1181505

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: