https://security-tracker.debian.org/tracker/DSA-5789-1
* bsc#1231298 Cross-References: * CVE-2024-47554
Several security issues were fixed in the Linux kernel.
The updated packages fix security vulnerabilities References: – https://bugs.mageia.org/show_bug.cgi?id=33614 – https://openssl-library.org/news/vulnerabilities-3.0/
Use-after-free when closing buffers in Vim
HTTP_REDIRECT_STATUS might be controlled via user request FPM log output might be modified by an attacker HTTP POST can be modified by an attacker For other bug fixes consult references
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
Several security issues were fixed in Go.
* bsc#1220826 * bsc#1226145 * bsc#1226666 * bsc#1227487 * bsc#1228466
* bsc#1027519 * bsc#1228574 * bsc#1228575 * bsc#1230366
Several security issues were fixed in the Linux kernel.
* bsc#1047218 * bsc#1202273 * bsc#1226975 * bsc#1229589 * jsc#PED-10362
* bsc#1047218 * bsc#1225597 * bsc#1226975 * bsc#1229589 * jsc#PED-10362
https://security-tracker.debian.org/tracker/DSA-5788-1
https://security-tracker.debian.org/tracker/DSA-5729-2
Patch the code to use https instead of http (CVE-2024-45321)
Fixes CVE-2024-45752: A vulnerability that allows users to remap keys arbitrarily. This allows all users on the system to remap a key unexpectedly to a potentially malicious sequence
Patch the code to use https instead of http (CVE-2024-45321)
Update to 0.3.13.3 and fix gresource generation
Patch the code to use https instead of http (CVE-2024-45321)
https://security-tracker.debian.org/tracker/DSA-5787-1
The fixes for CVE-2024-38474 and CVE-2024-39884 introduced two regressions in mod_rewrite and mod_proxy. For the stable distribution (bookworm), these problems have been fixed in
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
* bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References:
* bsc#1023072 * bsc#1023190 * bsc#1027776 * bsc#1027779 * bsc#1027785
Fix login QR code not shown in WhatsApp web. Disable PSON by default again in GTK 3 API versions. Disable DMABuf video sink by default to prevent file descriptor leaks. Fix several crashes and rendering issues. Use Skia instead of cairo for 2D rendering and enable GPU rendering by default.
Fix login QR code not shown in WhatsApp web. Disable PSON by default again in GTK 3 API versions. Disable DMABuf video sink by default to prevent file descriptor leaks. Fix several crashes and rendering issues. Use Skia instead of cairo for 2D rendering and enable GPU rendering by default.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
WEBrick could allow a HTTP request smuggling attack.
An update that fixes three vulnerabilities is now available.
* bsc#1231264 * bsc#1231265 * bsc#1231266 Cross-References:
cups-filters could be made to run programs if it received specially crafted network traffic.
CUPS could be made to crash or run programs if it received specially crafted network traffic.
Several security issues were fixed in Firefox.
https://security-tracker.debian.org/tracker/DSA-5786-1
Dom Walden discovered that the AbuseFilter extension in MediaWiki, a website engine for collaborative work, performed incomplete authorisation checks.
update to 129.0.6668.89 High CVE-2024-7025: Integer overflow in Layout High CVE-2024-9369: Insufficient data validation in Mojo High CVE-2024-9370: Inappropriate implementation in V8
Amongst other general bug fixes, this release addresses: CVE-2024-46951 CVE-2024-46952 CVE-2024-46953 CVE-2024-46954
The current versions have reached EOL and several security vulnerabilities were fixed by Mozilla. We are having some issues that are delaying the build for some architectures, so for the moment we are releasing this update just for x86_64
Integer overflows flaws were discovered in the Compound Document Binary File format parser of libgsf, the GNOME Project G Structured File Library, which could result in the execution of arbitrary code if a specially crafted file is processed.
* bsc#1230939 Cross-References: * CVE-2024-47176
update to 129.0.6668.89 High CVE-2024-7025: Integer overflow in Layout High CVE-2024-9369: Insufficient data validation in Mojo High CVE-2024-9370: Inappropriate implementation in V8
Update to new upstream version (closes rhbz#2237124)
Fix CVE-2024-39844 https://wiki.znc.in/ChangeLog/1.9.0
https://security-tracker.debian.org/tracker/DSA-5785-1
Fabian Vogt reported that the PAM module in oath-toolkit, a collection of components to build one-time password authentication systems, does not safely perform file operations in users’s home directories when using the usersfile feature (allowing to place the OTP state in the home
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
cJSON was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c. (CVE-2024-31755) References:
Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal. (CVE-2023-39327) References:
The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an “SSID Confusion” issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, […]
Use after free in Downloads. (CVE-2024-6988) Use after free in Loader. (CVE-2024-6989) Use after free in Dawn. (CVE-2024-6991) Heap buffer overflow in Layout. (CVE-2024-6994) Inappropriate implementation in Fullscreen. (CVE-2024-6995)
PHP version 8.2.24 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable
Fix CVE-2024-9014.
https://security-tracker.debian.org/tracker/DSA-5783-1
https://security-tracker.debian.org/tracker/DSA-5784-1
https://security-tracker.debian.org/tracker/DSA-5780-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
* bsc#1229930 * bsc#1229931 * bsc#1229932 Cross-References:
* bsc#1230020 * bsc#1230034 Cross-References: * CVE-2023-7256
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-5781-1
https://security-tracker.debian.org/tracker/DSA-5782-1
* bsc#1230986 Cross-References: * CVE-2024-38286
A protocol flaw was fixed in AsyncSSH.
PHP version 8.3.12 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable
Update to new upstream version (closes rhbz#2237124)
PHP version 8.3.12 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable
Several packages have been updated for Slackware 15.0 and -current to fix rpath security issues.
* bsc#1230698 Cross-References: * CVE-2024-41996
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Python could be made to bypass some restrictions if it received specially crafted input.
debian-security-support, the Debian security support coverage checker, has been updated in bullseye-security to mark the end of life of the following packages: * pdns-recursor: See https://bugs.debian.org/1070176
Two vulnerabilities have been fixed in the SQLite database. CVE-2021-36690
Flatpak could be made to read and write files in locations it would not normally have access to.
Simone Margaritelli reported that cups, the Common UNIX Printing System, does not properly sanitize IPP attributes when creating PPD files, which may result in the execution of arbitrary code.
An update that fixes four vulnerabilities is now available.
* bsc#1196018 * bsc#1196823 * bsc#1202346 * bsc#1209636 * bsc#1209799
Multiple vulnerabilities have been fixed in the network traffic analyzer Wireshark. CVE-2021-4181
Simone Margaritelli reported several vulnerabilities in cups-filters. Missing validation of IPP attributes returned from an IPP server and multiple bugs in the cups-browsed component can result in the execution
Simone Margaritelli reported that cups, the Common UNIX Printing System, does not properly sanitize IPP attributes when creating PPD files, which may result in the execution of arbitrary code.
Two vulnerabilities were discovered in unbound, a validating, recursive, caching DNS resolver. Specially crafted input could cause a heap-buffer-overflow leading to memory corruption and potentially causing the application to crash or allowing arbitrary code execution
Update to new upstream version (closes rhbz#2237124)
https://security-tracker.debian.org/tracker/DSA-5779-1
https://security-tracker.debian.org/tracker/DSA-5778-1
Multiple vulnerabilities have been fixed in ruby-rails-html-sanitizer, a Ruby library for sanitizing HTML fragments in Rails applications. CVE-2022-23517
Multiple vulnerabilities have been fixed in ruby-loofah, a Ruby library for manipulating and transforming HTML/XML documents and fragments. CVE-2022-23514
multipart/form-data request tampering has been fixed in ruby-httparty, a Ruby library for using Web-based APIs and related services. For Debian 11 bullseye, this problem has been fixed in version
Multiple vulnerabilities have been discovered in nginx, the worst of which could result in denial of service.
Multiple vulnerabilities have been found in Apache HTTPD, the worst of which could result in denial of service.
Multiple vulnerabilities have been found in yt-dlp, the worst of which could result in arbitrary code execution.
Multiple vulnerabilities have been discovered in Docker, the worst of which could result in denial of service.
Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service.
