Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that fixes four vulnerabilities is now available.

* bsc#1202346 * bsc#1227985 * bsc#1228002 * bsc#1228938 * bsc#1228959

* bsc#1225099 * bsc#1228349 Cross-References: * CVE-2023-52846

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5776-1

https://security-tracker.debian.org/tracker/DSA-5777-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The CA certificates in the ca-certificates package were updated.

Several security issues were fixed in the Linux kernel.

OpenJPEG could be made to crash if it opened a specially crafted file.

The system could be made to expose sensitive information.

https://security-tracker.debian.org/tracker/DSA-5775-1

* bsc#1230366 Cross-References: * CVE-2024-45817

* bsc#1202023 * bsc#1229438 * bsc#1230866 Cross-References:

Several security issues were fixed in the Linux kernel.

Multiple vulnerabilities have been found in Xpdf, the worst of which could result in denial of service.

Several security issues were fixed in Intel Microcode.

* bsc#1069468 * bsc#1079798 * bsc#1079799 * bsc#1079800 * bsc#1079801

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

* bsc#1193629 * bsc#1194111 * bsc#1194765 * bsc#1194869 * bsc#1196261

* bsc#1229596 * bsc#1229704 * bsc#1230227 Cross-References:

py7zr could be made to create arbitrary files when extracting the contents of a specially crafted 7z archive.

Multiple vulnerabilities have been found in Tor, the worst of which could result in denial of service.

* bsc#1012628 * bsc#1193454 * bsc#1194869 * bsc#1205462 * bsc#1208783

* bsc#1229596 * bsc#1230227 Cross-References: * CVE-2024-6232

* bsc#1228349 Cross-References: * CVE-2024-40909

* bsc#1223521 * bsc#1225099 * bsc#1225313 Cross-References:

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

A vulnerability has been found in Emacs and org-mode which could result in arbitrary code execution.

Multiple vulnerabilities have been discovered in liblouis, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in VLC, the worst of which could result in arbitrary code execution.

Multiple vulnerabilities have been discovered in Slurm, the worst of which could result in privilege escalation or code execution.

Multiple vulnerabilities have been discovered in stb, the worst of which lead to a denial of service.

Multiple vulnerabilities have been discovered in gst-plugins-good, the worst of which could lead to denial of service or arbitrary code execution. [More…]

Google Chrome 129: Addressing Crucial Vulnerabilities and Enhancing Security
Fighting Back Against Hadooken Malware by Strengthening WebLogic Security

Rebase to version 2.6.3

Security fix for CVE-2024-8418

Fix CVE-2024-5535: SSL_select_next_proto buffer overread

Rebase to version 2.6.3

Security fix for CVE-2024-8418

https://security-tracker.debian.org/tracker/DSA-5773-1

How Static Residential Proxies Support Ethical Web Scraping Practices

It was discovered that ruby-saml, a SAML library implementing the client side of a SAML authorization, does not properly verify the signature of the SAML Response, which could result in bypass of authentication in an application using the ruby-saml library.

Cybersecurity Regulations and Compliance for Linux Users

* bsc#1227233 Cross-References: * CVE-2024-5642

* bsc#1227233 Cross-References: * CVE-2024-5642

* bsc#1223683 * bsc#1225099 * bsc#1228349 Cross-References:

update to 129.0.6668.58 * High CVE-2024-8904: Type Confusion in V8 * Medium CVE-2024-8905: Inappropriate implementation in V8 * Medium CVE-2024-8906: Incorrect security UI in Downloads * Medium CVE-2024-8907: Insufficient data validation in Omnibox

Fix for CVE-2024-44070

libell 0.69: Add support for getting remaining microseconds left on a timer. Add support for setting link MTU on a network interface. iwd 2.21: Fix issue with pending scan requests after regdom update.

https://security-tracker.debian.org/tracker/DSA-5774-1

* bsc#1230400 Cross-References: * CVE-2024-23984 * CVE-2024-24968

* bsc#1229907 Cross-References: * CVE-2024-8250

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5772-1

https://security-tracker.debian.org/tracker/DSA-5771-1

https://security-tracker.debian.org/tracker/DSA-5770-1

* bsc#1230353 Cross-References: * CVE-2023-29483

* bsc#1230353 Cross-References: * CVE-2023-29483

Several security issues were fixed in the Linux kernel.

A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. An attacker could generate a malicious dump file which could execute shell commands from the MariaDB client.

* bsc#1227378 * bsc#1227999 * bsc#1228780 * bsc#1229596

* bsc#1228780 Cross-References: * CVE-2024-6923

An update that solves four vulnerabilities and has one errata is now available.

A new stable version was released for galera-4, a synchronous multimaster replication engine for MySQL and MariaDB. This fixes several issues detailed at:

Several security issues were fixed in libxmltok.

How Red Hat is integrating post-quantum cryptography into our products

Several security issues were fixed in ClamAV.

Several security issues were fixed in DCMTK.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

An update that fixes four vulnerabilities is now available.

* bsc#1176447 * bsc#1195668 * bsc#1195928 * bsc#1195957 * bsc#1196018

* bsc#1229907 * bsc#1230372 Cross-References: * CVE-2024-8250

* bsc#1082555 * bsc#1190317 * bsc#1196516 * bsc#1205462 * bsc#1210629

* bsc#1082555 * bsc#1190317 * bsc#1196516 * bsc#1205462 * bsc#1210629

OpenSSH could be made to crash or run programs as your login if it received a specially crafted input.

Update to 1.0.7 CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files. CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser

flatpak 1.15.10 and bubblewrap 0.10.0 updates, which together fix CVE-2024-42472 in Flatpak.

flatpak 1.15.10 and bubblewrap 0.10.0 updates, which together fix CVE-2024-42472 in Flatpak.

Update to 1.15.10 (CVE-2024-42472)

https://security-tracker.debian.org/tracker/DSA-5769-1

Node.js a JavaScript runtime environment that executes JavaScript code outside a web browser (server side) was vulnerable. CVE-2023-30589

New libarchive packages are available for Slackware 15.0 and -current to fix security issues.

update to 128.0.6613.137 * High CVE-2024-8636: Heap buffer overflow in Skia * High CVE-2024-8637: Use after free in Media Router * High CVE-2024-8638: Type Confusion in V8 * High CVE-2024-8639: Use after free in Autofill

Update to expat-2.6.3.

Update to 1.0.7 CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files. CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser

Update to 115.15.0 https://www.thunderbird.net/en-US/thunderbird/115.15.0esr/releasenotes/

Update to expat-2.6.3.

Update to 3.6.1 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-3.6.1 Update to 3.6.0

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.