Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Several security issues were fixed in the Linux kernel.

Aviv Keller discovered that the frames.html file generated by YARD, a documentation generation tool for the Ruby programming language, was vulnerable to cross-site scripting.

Several security issues were fixed in Node.js.

* bsc#1218351 Cross-References: * CVE-2023-51765

* bsc#1218351 Cross-References: * CVE-2023-51765

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.

Several security issues were fixed in Thunderbird.

Insights helps to provide Threat Intelligence

Multiple vulnerabilities have been discovered in UltraJSON, the worst of which could lead to key confusion and value overwriting.

Multiple vulnerabilities have been discovered in Blender, the worst of which could lead to arbitrary code execution.

A vulnerability has been discovered in Tox which may lead to remote code execution.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

An update that fixes one vulnerability is now available.

This is the February 2024 update for .NET 8. Release Notes: – Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.2/8.0.2.md – SDK: https://github.com/dotnet/core/blob/main/release-

fix CVE-2024-24814: prevent DoS when OIDCSessionType client-cookie is set and a crafted Cookie header is supplied

This is the February 2024 update for .NET 8. Release Notes: – Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.2/8.0.2.md – SDK: https://github.com/dotnet/core/blob/main/release-

* bsc#1219465 Cross-References: * CVE-2023-3966

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5634-1

* bsc#1220068 * bsc#1220070 Cross-References: * CVE-2024-25710

* bsc#1215300 * bsc#1217116 * bsc#1218733 Cross-References:

* bsc#1218733 Cross-References: * CVE-2023-51780

* bsc#1215300 * bsc#1217116 * bsc#1218733 Cross-References:

* bsc#1215300 * bsc#1218733 Cross-References: * CVE-2023-4921

* bsc#1210619 Cross-References: * CVE-2023-1829

https://security-tracker.debian.org/tracker/DSA-5633-1

* bsc#1219152 * bsc#1219724 * bsc#1219992 * bsc#1219993 * bsc#1219994

* bsc#1219724 * bsc#1219992 * bsc#1219993 * bsc#1219997 * bsc#1220014

* bsc#1219049 Cross-References: * CVE-2024-22211

* bsc#1219049 Cross-References: * CVE-2024-22211

The 6.7.6 stable kernel update contains a number of important fixes across the tree.

Update to 115.8.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-07/ https://www.thunderbird.net/en-US/thunderbird/115.8.0/releasenotes/

Cross-References: * CVE-2023-44487 CVSS scores:

* bsc#1185232 * bsc#1185261 * bsc#1185441 * bsc#1185621 * bsc#1187071

* bsc#1166486 * bsc#1185861 * bsc#1185863 * bsc#1186449 * bsc#1191256

* bsc#1177083 * bsc#1181995 * jsc#ECO-3329 * jsc#PM-2475 * jsc#PM-2730

* bsc#1071995 * bsc#1084842 * bsc#1114592 * bsc#1124644 * bsc#1128794

* bsc#1214052 Cross-References: * CVE-2023-4039

A vulnerability has been discovered in btrbk which can lead to remote code execution.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The system could be made to crash under certain conditions.

Unlock the Power of Cybersecurity Education for a Secure Future: A Comprehensive Guide for Linux Admins & Infosec Pros

It was discovered that iwd, the iNet Wireless Daemon, does not properly handle messages in the 4-way handshake used when connecting to a protected WiFi network for the first time. An attacker can take advantage of this flaw to gain unauthorized access to a protected WiFi

An issue has been found in libjwt, a C library to handle JWT (JSON Web Token). Due to using strcmp(), which does not use constant time during execution, a timing side channel attack might be possible.

Update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy

Backport fix for CVE-2023-5841.

Update to 2.6.0, fixes CVE-2023-52425, CVE-2023-52426.

Update to python3.11.8, backport fix for CVE-2023-27043.

https://security-tracker.debian.org/tracker/DSA-5631-1

Delivering a better view of system vulnerabilities with Red Hat Insights
Bridging innovation and standards compliance: Red Hat’s drive towards the next-generation of government computing standards
Environment-as-a-Service, part 4: External resources and dynamic credentials

Rebase to version 2.6.0

Update to qt-5.15.12.

Update to qt-5.15.12.

Update to qt-5.15.12.

Update to qt-5.15.12.

Update to qt-5.15.12.

* bsc#1210638 Cross-References: * CVE-2023-27043

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Update to latest upstream. Fixes CVE-2023-50387 and CVE-2023-50868

New upstream release (123.0)

update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy

Update to latest upstream. Fixes CVE-2023-50387 and CVE-2023-50868

https://security-tracker.debian.org/tracker/DSA-5629-1

https://security-tracker.debian.org/tracker/DSA-5630-1

* bsc#1218564 Cross-References: * CVE-2023-52323

* bsc#1219267 * bsc#1219268 * bsc#1219438 Cross-References:

* bsc#1219267 * bsc#1219268 * bsc#1219438 Cross-References:

* bsc#1188609 * bsc#1212850 * bsc#1213210 * bsc#1213925 * bsc#1215311

Imagemagick a graphical software suite for displaying, creating and modifying images was vulnerable. CVE-2023-1289

Several security issues were fixed in Firefox.

https://security-tracker.debian.org/tracker/DSA-5628-1

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: https://github.com/quic- go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf

Patch for CVE-2024-24258 and CVE-2024-24259

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: https://github.com/quic- go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf

https://security-tracker.debian.org/tracker/DSA-5627-1

New libuv packages are available for Slackware 15.0 and -current to fix a security issue.

* bsc#1011205 * bsc#1093641 * bsc#1125882 * bsc#1167400 * bsc#1207973

* bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188

The updated packages fix security vulnerabilities: RTPS dissector memory leak. (CVE-2023-5371) SSH dissector invalid read of memory blocks. (CVE-2023-6174) NetScreen File Parsing Heap-based Buffer Overflow. (CVE-2023-6175) GVCP dissector crash via packet injection or crafted capture file.

Stack buffer overflow in virtio_net_flush_tx (CVE-2023-6693) (rhbz#2256436)

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

* bsc#1219059 Cross-References: * CVE-2024-22563

* bsc#1202903 * bsc#1219187 Cross-References: * CVE-2022-2132

* bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188

* bsc#1219059 Cross-References: * CVE-2024-22563

Multiple vulnerabilities have been discovered in Samba, the worst of which can lead to remote code execution.

A vulnerability has been discovered in Glade which can lead to a denial of service.