Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

A vulnerability has been discovered in dpkg, which allows for directory traversal.

Multiple vulnerabilities have been discovered in MuPDF, the worst of which could lead to arbitrary code execution.

Update NSS to 3.103.0 Update to Firefox 129.0

https://security-tracker.debian.org/tracker/DSA-5747-1

Multiple vulnerabilities have been discovered in runc, the worst of which could lead to privilege escalation.

A vulnerability has been discovered in Ruby on Rails, which can lead to remote code execution via serialization of data.

New version 8.5.5

* bsc#1228256 * bsc#1228257 Cross-References: * CVE-2024-1737

* bsc#1220356 * bsc#1227525 Affected Products: * Basesystem Module 15-SP5

Multiple vulnerabilities have been discovered in GnuPG, the worst of which could lead to signature spoofing.

Multiple vulnerabilities have been discovered in Bundler, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in GPAC, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in libde265, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in ncurses, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in QEMU, the worst of which could lead to a denial of service.

A vulnerability has been discovered in Nautilus, which can lead to a denial of service.

Noah Misch discovered a race condition in the pg_dump tool included in PostgreSQL, which may result in privilege escalation. For the oldstable distribution (bullseye), this problem has been fixed

Noah Misch discovered a race condition in the pg_dump tool included in PostgreSQL, which may result in privilege escalation. For the stable distribution (bookworm), this problem has been fixed in

* bsc#1228549 * bsc#1228552 Cross-References: * CVE-2024-41671

https://security-tracker.debian.org/tracker/DSA-5745-1

https://security-tracker.debian.org/tracker/DSA-5746-1

A vulnerability was discovered in odoo, a suite of web based open source business apps. It could result in the execution of arbitrary code.

Multiple cross-site scripting vulnerabilities were discovered in RoundCube webmail. For the stable distribution (bookworm), these problems have been fixed in

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Kerberos could be made to crash if it received specially crafted input.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Update to upstream 2.1-43. 20240531 Addition of 06-aa-04/0xe6 (MTL-H/U C0) microcode at revision 0x1c; Addition of 06-ba-08/0xe0 microcode (in intel-ucode/06-ba-02) at revision 0x4121; Addition of 06-ba-08/0xe0 microcode (in intel-ucode/06-ba-03) at revision

https://security-tracker.debian.org/tracker/DSA-5741-1

https://security-tracker.debian.org/tracker/DSA-5742-1

https://security-tracker.debian.org/tracker/DSA-5743-1

https://security-tracker.debian.org/tracker/DSA-5744-1

https://security-tracker.debian.org/tracker/DSA-5739-1

https://security-tracker.debian.org/tracker/DSA-5738-1

How AI and Machine Learning Are Transforming Cybersecurity Quality Assurance

A vulnerability has been discovered in Bitcoin, which can lead to a denial of service.

* bsc#1228872 Cross-References: * CVE-2024-7383

* bsc#1227296 Cross-References: * CVE-2024-32230

* bsc#1214855 * bsc#1219267 * bsc#1219268 * bsc#1219438 * bsc#1221916

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

Multiple vulnerabilities have been discovered in aiohttp, the worst of which could lead to service compromise.

https://security-tracker.debian.org/tracker/DSA-5740-1

* bsc#1220356 * bsc#1227525 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5

* bsc#1227052 Cross-References: * CVE-2024-6104

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1221302 * bsc#1223059

Extending Red Hat Unified Kernel Images More Securely By Using Addons

* bsc#1228549 * bsc#1228552 Cross-References: * CVE-2024-41671

* bsc#1227147 Cross-References: * CVE-2024-5535

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of Java sandbox restrictions.

Several security issues were fixed in the Linux kernel.

Backport fix for CVE-2023-49528

https://security-tracker.debian.org/tracker/DSA-5736-1

https://security-tracker.debian.org/tracker/DSA-5737-1

update to 127.0.6533.88 Critical CVE-2024-6990: Uninitialized Use in Dawn High CVE-2024-7255: Out of bounds read in WebTransport High CVE-2024-7256: Insufficient data validation in Dawn

update to 127.0.6533.88 Critical CVE-2024-6990: Uninitialized Use in Dawn High CVE-2024-7255: Out of bounds read in WebTransport High CVE-2024-7256: Insufficient data validation in Dawn update to 127.0.6533.72

Update to upstream version 2.11.

Update to upstream version 2.11.

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

* bsc#1219296 * bsc#1220145 * bsc#1220211 * bsc#1220828 * bsc#1220832

* bsc#1214855 * bsc#1221916 * bsc#1228324 Cross-References:

Gross could be made to crash or to allow arbitrary code execution.

* bsc#1167721 Cross-References: * CVE-2019-20633

update to 127.0.6533.72 * CVE-2024-6988: Use after free in Downloads * CVE-2024-6989: Use after free in Loader * CVE-2024-6991: Use after free in Dawn * CVE-2024-6992: Out of bounds memory access in ANGLE

Several security issues were fixed in Tomcat.

https://security-tracker.debian.org/tracker/DSA-5735-1

Several security issues were fixed in Bind.

Several security issues were fixed in the Linux kernel.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1224788 Cross-References: * CVE-2024-35195

* bsc#1211674 Cross-References: * CVE-2023-32681

Several security issues were fixed in Python.

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 17.

Several security issues were fixed in OpenJDK 11.

Several security issues were fixed in OpenJDK 8.

Update to 1.3.3 https://github.com/hyprwm/xdg-desktop-portal-hyprland/releases/tag/v1.3.3

* bsc#1228184 Cross-References: * CVE-2024-40897

* bsc#916845 Cross-References: * CVE-2013-4235

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Affected Products: * openSUSE Leap 15.5

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in EDK II.

Several security issues were fixed in Lua.

https://security-tracker.debian.org/tracker/DSA-5734-2

The security update announced as DSA 5734-1 caused a regression on configurations using the Samba DLZ module. Updated packages are now available to correct this issue.

Update to 1.16 fixes rhbz#2259096

Update to 2.11.2

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Update to 1.16 fixes rhbz#2259096

Update to 2.11.2

https://security-tracker.debian.org/tracker/DSA-5734-1

* bsc#1222693 Cross-References: * CVE-2023-29483