* bsc#1220145 * bsc#1223363 * bsc#1223683 * bsc#1225211
Updated to latest upstream (128.0)
Fix CVE-2024-39936.
Security fix for CVE-2024-5187
This is the May 2024 release for .NET 8. This is a security update for .NET 8. Release notes: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.5/8.0.5.md
* bsc#1224123 Cross-References: * CVE-2024-3727
* bsc#1220145 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1223059
* bsc#1119113 * bsc#1191958 * bsc#1195065 * bsc#1195254 * bsc#1195775
Several security issues were fixed in Firefox.
Multiple vulnerabilities have been discovered in Buildah, the worst of which could lead to privilege escalation.
Several security issues were fixed in dotnet6, dotnet8.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Multiple vulnerabilities have been discovered in LIVE555 Media Server, the worst of which could lead to a denial of service.
* bsc#1222045 Cross-References: * CVE-2024-29025
* bsc#1223965 Cross-References: * CVE-2024-33394
* bsc#1226469 Cross-References: * CVE-2024-37891
An update that fixes 7 vulnerabilities is now available.
Update to 2024.07.02
https://security-tracker.debian.org/tracker/DSA-5726-1
A vulnerability has been discovered in Stellarium, which can lead to arbitrary file writes.
Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which could arbitrary code execution.
Multiple vulnerabilities have been discovered in the X.Org X11 library, the worst of which could lead to a denial of service.
A vulnerability has been discovered in KDE Plasma Workspaces, which can lead to privilege escalation.
Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.
Two vulnerabilities were discovered in the GSS message token handling in krb5, the MIT implementation of Kerberos. An attacker can take advantage of these flaws to bypass integrity protections or cause a denial of service.
Multiple vulnerabilities have been discovered in BusyBox, the worst of which could lead to arbitrary code execution.
A vulnerability has been discovered in Coreutils, which can lead to a heap buffer overflow and possibly aribitrary code execution.
* bsc#1227186 * bsc#1227187 Cross-References: * CVE-2024-37370
Multiple vulnerabilities have been discovered in GraphicsMagick, the worst of which could lead to arbitrary code execution.
Multiple vulnerabilities have been discovered in TigerVNC, the worst of which could lead to remote code execution.
Multiple vulnerabilities have been discovered in WebKitGTK+, the worst of which could lead to arbitrary code execution
https://security-tracker.debian.org/tracker/DSA-5725-1
* bsc#1226642 Cross-References: * CVE-2024-6387
* bsc#1222050 * bsc#1222052 * bsc#1222053 * bsc#1226957
* bsc#1219217 * bsc#1220266 Cross-References: * CVE-2024-0914
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1225771 Cross-References: * CVE-2024-5564
* bsc#1227052 Cross-References: * CVE-2024-6104
* bsc#1213720 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5
* bsc#1224282 Cross-References: * CVE-2024-34459
Several security issues were fixed in Firefox.
* bsc#1224282 Cross-References: * CVE-2024-34459
USN-6851-1 caused systemctl enable to fail
USN-6844-1 caused the cupsd daemon to never start
* bsc#1226448 Cross-References: * CVE-2024-4032
* bsc#1224279 * bsc#1224309 Cross-References: * CVE-2024-3044
* bsc#1224279 * bsc#1224309 Cross-References: * CVE-2024-3044
OpenSSH could be made to bypass authentication and remotely access systems without proper credentials.
The Qualys Threat Research Unit (TRU) discovered that OpenSSH, an implementation of the SSH protocol suite, is prone to a signal handler race condition. If a client does not authenticate within LoginGraceTime seconds (120 by default), then sshd’s SIGALRM handler is called
* bsc#1223965 Cross-References: * CVE-2024-33394
* bsc#1224044 Cross-References: * CVE-2024-34397
Several security issues were fixed in eSpeak NG.
Multiple vulnerabilities have been discovered in GNU Emacs and Org Mode, the worst of which could lead to arbitrary code execution.
https://security-tracker.debian.org/tracker/DSA-5724-1
Mojolicious is a Perl Web Application Framework built around the familiar Model-View-Controller philosophy. It supports a simple single file mode via Mojolicious::Lite, RESTful routes, plugins, Perl-ish templates, session management, signed cookies, a testing framework, internationalization, first
Backport fix for CVE-2024-6239.
Update to 1.26.19, fixes CVE-2024-0444.
Update to 1.26.19, fixes CVE-2024-0444.
A vulnerability was discovered in GNU Emacs, the extensible, customisable, self-documenting display editor. The org-link-expand-abbrev function expanded a %(…) link abbrev even
A vulnerability was discovered in Org-mode, a GNU Emacs major mode for keeping notes, authoring documents, and maintaining to-do lists. The org-link-expand-abbrev function expanded a %(…) link abbrev even
rebuild for rhbz#2292712
Fix CVE-2024-2698 and CVE-2024-3183
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Multiple vulnerabilities havebenn fixed in DCMTK, a collection of libraries and applications implementing large parts the DICOM standard for medical images.
* bsc#1216896 * bsc#1216897 * bsc#1216899 * bsc#1216900
It was discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. (CVE-2019-11471) Reza Mirzazade Farkhani discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash
Possible out-of-bounds read or write when reading malformed MED files. (r19389). [Null-pointer write (32bit platforms) or excessive memory allocation (64bit platforms) when reading close to 4GiB of data from unseekable files (r20336, r20338).
Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image. References:
Update to Emacs 29.4, fixing CVE-2024-39331.
The 6.9.6 stable kernel update contains a number of important fixes across the tree.
Several security issues were fixed in FontForge.
Wget could be made to connect to a different host than expected.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
OpenSSL could be made to consume resources and cause long delays if it processed certain input.
update to 126.0.6478.126 High CVE-2024-6290: Use after free in Dawn High CVE-2024-6291: Use after free in Swiftshader High CVE-2024-6292: Use after free in Dawn High CVE-2024-6293: Use after free in Dawn
https://security-tracker.debian.org/tracker/DSA-5723-1
https://security-tracker.debian.org/tracker/DSA-5720-1
https://security-tracker.debian.org/tracker/DSA-5719-1
https://security-tracker.debian.org/tracker/DSA-5718-1
Several security issues were fixed in the Linux kernel.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Multiple vulnerabilities were found in git, a fast, scalable and distributed revision control system. CVE-2019-1387
