Two vulnerabilities were discovered in pgpool2, a connection pool server and replication proxy for PostgreSQL. CVE-2023-22332
CVE-2024-52805, CVE-2024-52815, CVE-2024-53863 Backport fixes from v1.120.1
Update to 131.0.6778.139 High CVE-2024-12381: Type Confusion in V8 High CVE-2024-12382: Use after free in Translate
Update to 128.5.2 https://www.thunderbird.net/en-US/thunderbird/128.5.2esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-69/
Update to upstream 20241210 Update firmware file for Intel BlazarU core amdgpu: numerous firmware updates upstream amdnpu firmware QCA: Add Bluetooth nvm files for WCN785x
Update to 1.4.8
https://security-tracker.debian.org/tracker/DSA-5828-1
https://security-tracker.debian.org/tracker/DSA-5829-1
https://security-tracker.debian.org/tracker/DSA-5827-1
https://security-tracker.debian.org/tracker/DSA-5826-1
Multiple vulnerabilities have been fixed in the graphics debugger RenderDoc. CVE-2023-33863
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in denial of service, authorization bypass, or information disclosure.
Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially among other effects allowing denial of service, information disclosure, use-after-free or remote code inclusion.
Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service.
Multiple vulnerabilities have been discovered in PostgreSQL, the worst of which could lead to arbitrary code execution.
Update to 131.0.6778.108 High CVE-2024-12053: Type Confusion in V8
Buffer overflow when calculating the quantile value has been fixed in the GNU Scientific Library (GSL). For Debian 11 bullseye, this problem has been fixed in version
A vulnerability has been discovered in OATH Toolkit, which could lead to local root privilege escalation.
Multiple vulnerabilities have been discovered in Dnsmasq, the worst of which could lead to a denial of service.
Multiple vulnerabilities have been discovered in Salt, the worst of which can lead to arbitrary code execution.
Multiple vulnerabilities have been discovered in Icinga2, the worst of which could lead to arbitrary code execution.
Multiple vulnerabilities have been discovered in OpenJDK, the worst of which could lead to remote code execution.
Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.
* bsc#1233420 Cross-References: * CVE-2024-52616
* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059
* bsc#1225429 * bsc#1225733 * bsc#1229273 * bsc#1229553
* bsc#1223683 * bsc#1225099 * bsc#1225429 * bsc#1225733 * bsc#1225739
* bsc#1225733 * bsc#1229553 Cross-References: * CVE-2024-36904
* bsc#1223683 * bsc#1225309 * bsc#1225310 * bsc#1225311 * bsc#1225312
https://security-tracker.debian.org/tracker/DSA-5824-1
https://security-tracker.debian.org/tracker/DSA-5825-1
* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168
* bsc#1234115 Cross-References: * CVE-2024-53981
* bsc#1225733 * bsc#1229553 Cross-References: * CVE-2024-36904
* bsc#1210619 * bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225202
Improve memory consumption and performance of Canvas getImageData. Fix preserve-3D intersection rendering. Fix video dimensions since GStreamer 1.24.9. Fix the HTTP-based remote Web Inspector not loading in Chromium. Fix content filters not working on about:blank iframes.
Update to 128.5.0 https://www.thunderbird.net/en-US/thunderbird/128.5.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-68/
* bsc#1227378 * bsc#1231795 * bsc#1233307 Cross-References:
* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168
* bsc#1232747 * bsc#1233631 * bsc#1233632 Cross-References:
* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168
* bsc#1027519 * bsc#1230366 * bsc#1232542 * bsc#1232622 * bsc#1232624
* bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553
https://security-tracker.debian.org/tracker/DSA-5815-2
https://security-tracker.debian.org/tracker/DSA-5823-1
* bsc#1233773 Cross-References: * CVE-2024-10524
* bsc#1233651 * bsc#1233702 * bsc#1233703 Cross-References:
* bsc#1233650 * bsc#1233695 Cross-References: * CVE-2024-11691
* bsc#1227378 * bsc#1231795 * bsc#1233307 Cross-References:
* bsc#1233815 Cross-References: * CVE-2024-53849
* bsc#1231795 * bsc#1232750 * bsc#1233307 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5822-1
An update that fixes two vulnerabilities is now available.
Improve memory consumption and performance of Canvas getImageData. Fix preserve-3D intersection rendering. Fix video dimensions since GStreamer 1.24.9. Fix the HTTP-based remote Web Inspector not loading in Chromium. Fix content filters not working on about:blank iframes.
New version 4.4.2
Update to 5.0.2 fix rhbz#2326888
New version 4.2.9
Multiple vulnerabilities were discovered in Lemonldap::NG, an OpenID-Connect, CAS and SAML compatible Web-SSO system, which could lead to injection of arbitrary scripts or authorization bypass.
Two issues have been found in editorconfig-core, a coding style indenter for all editors. Both issues are related to buffer overflows in different locations.
Brief introduction CVE-2022-0934
An issue has been found in xfpt, a tool to generate XML from plain tex. The issue is about bad handling of input data, which may result in a stack-based buffer overflow and execution of arbitrary code, when
An issue has been found in tgt, Linux SCSI target user-space daemon and tools. The issue was related to using rand() without proper seed, resulting in identical sequences of challenges.
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because ‘’ characters at the end of header names are ignored, i.e., a “Transfer-Encoding: chunked” header is treated the same as a “Transfer-Encoding: chunked” header. (CVE-2024-52530) GNOME libsoup before 3.6.1 allows a buffer overflow in applications that
ProFTPD a popular FTP server was affected by multiple vulnerabilities. CVE-2023-48795
* bsc#1233447 Cross-References: * CVE-2024-52304
* bsc#1233323 * bsc#1233325 * bsc#1233326 * bsc#1233327
Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and
Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and
Deadlock in x86 HVM standard VGA handling [XSA-463, CVE-2024-45818] libxl leaks data to PVH guests via ACPI tables [XSA-464, CVE-2024-45819]
Update to 128.5.0 https://www.thunderbird.net/en-US/thunderbird/128.5.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-68/
https://security-tracker.debian.org/tracker/DSA-5821-1
https://security-tracker.debian.org/tracker/DSA-5820-1
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version
* bsc#1233695 Cross-References: * CVE-2024-11691 * CVE-2024-11692
* bsc#1225889 Cross-References: * CVE-2024-1298
* bsc#1209401 Affected Products: * Basesystem Module 15-SP6 * Desktop Applications Module 15-SP6
* jsc#PED-11092 Cross-References: * CVE-2023-31489 * CVE-2023-31490
1.37 – fix parsing of “use if …” Fixes errors in PAR::Packer test t/90-rt59710.t – add test for _parse_libs() 1.36
https://security-tracker.debian.org/tracker/DSA-5819-1
* bsc#1233695 Cross-References: * CVE-2024-11691 * CVE-2024-11692
* bsc#1233434 Cross-References: * CVE-2024-52316
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
* bsc#1230366 * bsc#1232542 * bsc#1232622 * bsc#1232624
Several security issues were fixed in libsoup.
* bsc#1219340 * bsc#1230423 * bsc#1233323 * bsc#1233325 * bsc#1233326
USN-7117-1 caused some regression in needrestart.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Multiple vulnerabilities have been fixed in pypy3, an alternative implementation of the Python 3.x language. CVE-2020-10735
* bsc#1233313 Cross-References: * CVE-2024-21820 * CVE-2024-21853
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
A microcode update has been released for Intel processors, addressing multiple vulnerabilties which potentially could cause information disclosue or local DoS.
Several security issues were fixed in OpenJDK 23.
Multiple vulnerabilities have been fixed in the PostScript/PDF interpreter Ghostscript. CVE-2024-46951
