* bsc#1228919 * bsc#1233821 Cross-References: * CVE-2024-11407
* bsc#1228919 * bsc#1233821 Cross-References: * CVE-2024-11407
Multiple CVE fixes
Update to 0^20241216git660795b dr_flac 0.12.43: Fix a possible buffer overflow during decoding. Improve detection of ARM64EC. dr_mp3 0.6.40: Improve detection of ARM64EC dr_wav 0.13.17: Fix a possible crash when reading from MS-ADPCM encoded files.
https://security-tracker.debian.org/tracker/DSA-5835-1
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74
https://security-tracker.debian.org/tracker/DSA-5836-1
https://security-tracker.debian.org/tracker/DSA-5837-1
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-54479
* bsc#1234795 Cross-References: * CVE-2024-56378
* bsc#1234795 Cross-References: * CVE-2024-56378
Automatic update for tomcat-9.0.98-1.fc41. Changelog for tomcat * Mon Dec 09 2024 Packit – 1:9.0.98-1 – Update to version 9.0.98 – Resolves: rhbz#2331168
Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74
Automatic update for tomcat-9.0.98-1.fc40. Changelog for tomcat * Mon Dec 09 2024 Packit – 1:9.0.98-1 – Update to version 9.0.98 – Resolves: rhbz#2331168
* bsc#1129772 * bsc#1152803 * bsc#1154838 * bsc#1181400 * bsc#1230961
In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte
Update to 3.12.8
Update to 3.12.8
* bsc#1220490 * jsc#PED-10258 * jsc#PED-10751 Cross-References:
* bsc#1047218 * bsc#1233297 Cross-References: * CVE-2024-47535
* bsc#1220618 * bsc#1229238 * bsc#1231373 Cross-References:
release v1.14.0
release v1.14.0
Update to 131.0.6778.204 High CVE-2024-12692: Type Confusion in V8 High CVE-2024-12693: Out of bounds memory access in V8 High CVE-2024-12694: Use after free in Compositing High CVE-2024-12695: Out of bounds write in V8
Update to 1.24.10, fixes multiple CVEs.
Update to 1.24.10, fixes multiple CVEs.
Update to 1.24.10, fixes multiple CVEs.
Update to 1.24.10, fixes multiple CVEs.
Update to 1.24.10, fixes multiple CVEs.
* bsc#1223098 Cross-References: * CVE-2024-27306
Update to 2.46.5: Fix several crashes and rendering issues. CVE-2024-54479, CVE-2024-54502, CVE-2024-54508, CVE-2024-54505
Update to v2.14
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Update to 4.3.3 (rhbz#2331357)
* bsc#1234371 Cross-References: * CVE-2021-3156
* bsc#1233973 Cross-References: * CVE-2024-53008
* bsc#1233894 Cross-References: * CVE-2024-53920
https://security-tracker.debian.org/tracker/DSA-5834-1
* bsc#1234068 Cross-References: * CVE-2024-11053
* bsc#1233282 Cross-References: * CVE-2024-52533
* bsc#1232528 Cross-References: * CVE-2024-9681
nodejs:22 bug fix and enhancement update
Important: postgresql:15 security update
Important: ruby:3.1 security update
https://security-tracker.debian.org/tracker/DSA-5833-1
EditorConfig could be made to crash or run programs as your login if it received specially crafted input.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
A buffer overflow was discovered in the vhost code of DPDK, a set of libraries for fast packet processing, which could result in denial of service or the execution of arbitrary code by malicious guests/containers.
* bsc#1233285 * bsc#1233287 * bsc#1233292 Cross-References:
* bsc#1218644 * bsc#1220382 * bsc#1221309 * bsc#1222590 * bsc#1229345
* bsc#1218644 * bsc#1220382 * bsc#1221309 * bsc#1222590 * bsc#1229808
* bsc#1233813 Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3
* bsc#1225462 Cross-References: * CVE-2024-54661
* bsc#1233285 * bsc#1233287 * bsc#1233292 Cross-References:
Multiple vulnerabilities have been fixed in the PostgreSQL JDBC Driver. CVE-2022-31197
* bsc#1217070 * bsc#1228324 * bsc#1228553 * bsc#1229806 * bsc#1230294
Fix CVE-2024-45337
The 6.12.4 stable kernel rebase contains new features, additional hardware support and a number of important fixes across the tree.
Update to 128.5.2 https://www.thunderbird.net/en-US/thunderbird/128.5.2esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-69/
The 6.12.4 stable kernel rebase contains new features, additional hardware support and a number of important fixes across the tree.
https://security-tracker.debian.org/tracker/DSA-5832-1
Update to upstream 20241210 Update firmware file for Intel BlazarU core amdgpu: numerous firmware updates upstream amdnpu firmware QCA: Add Bluetooth nvm files for WCN785x
This release contains a fix for a security issue: CVE-2024-46901 See https://subversion.apache.org/security/CVE-2024-46901-advisory.txt for more information. Changes in this release are: Fix printf-format build warnings in swig-rb (r1921264)
Update to pytest 8.3.4
An update that fixes one vulnerability is now available.
Multiple multiple vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.
Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in privilege escalation.
Update to 131.0.6778.139 High CVE-2024-12381: Type Confusion in V8 High CVE-2024-12382: Use after free in Translate
Python 3.10.16 security release. Security content in this release gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to consistently use the mapped IPv4 address value for deciding properties. Properties which have their behavior fixed are is_multicast, is_reserved, is_link_local, is_global, and
Python 3.10.16 security release. Security content in this release gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to consistently use the mapped IPv4 address value for deciding properties. Properties which have their behavior fixed are is_multicast, is_reserved, is_link_local, is_global, and
https://security-tracker.debian.org/tracker/DSA-5831-1
USN-7157-1 introduced a regression in PHP.
Several security issues were fixed in PHP.
https://security-tracker.debian.org/tracker/DSA-5830-1
