* bsc#1223356 Cross-References: * CVE-2024-0090 * CVE-2024-0091
* bsc#1219273 Cross-References: * CVE-2023-27534
* bsc#1065729 * bsc#1141539 * bsc#1174585 * bsc#1181674 * bsc#1187716
* bsc#1225365 Cross-References: * CVE-2024-35235
* bsc#1223179 * bsc#1225365 Cross-References: * CVE-2024-35235
https://security-tracker.debian.org/tracker/DSA-5709-1
Several security issues were fixed in the Linux kernel.
* bsc#1223375 Cross-References: * CVE-2024-4141
* bsc#1224262 Cross-References: * CVE-2024-26306
* bsc#1219823 * bsc#1219826 * bsc#1219851 * bsc#1219852 * bsc#1219854
* bsc#1065729 * bsc#1101816 * bsc#1141539 * bsc#1181674 * bsc#1185902
* bsc#1218501 Cross-References: * CVE-2023-50711
https://security-tracker.debian.org/tracker/DSA-5707-1
https://security-tracker.debian.org/tracker/DSA-5708-1
An update that fixes 16 vulnerabilities is now available.
* bsc#1225417 Cross-References: * CVE-2024-33427
* bsc#1222584 * bsc#1223849 Cross-References: * CVE-2024-4418
* bsc#1221401 * bsc#1222330 * bsc#1222332 Cross-References:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1218424 * bsc#1225973 * bsc#1225974 Cross-References:
* bsc#1212475 * bsc#1225973 * bsc#1225974 Cross-References:
* bsc#1224788 Cross-References: * CVE-2024-35195
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5706-1
USN-6567-1 introduced a regression in QEMU.
Update to upstream 1.3.2, including fix for CVE-2024-3727
Several security issues were fixed in OpenJDK 21.
Several security issues were fixed in OpenJDK 17.
Several security issues were fixed in OpenJDK 11.
Several security issues were fixed in OpenJDK 8.
* bsc#1225070 Cross-References: * CVE-2024-36039
Fix CVE-2024-36048
This is the May 2024 release for .NET 8. This is a security update for .NET 8. Release notes: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.5/8.0.5.md
Qt 5.15.14 bugfix update. Fix CVE-2024-36048
Qt 5.15.14 bugfix update. Fix CVE-2024-36048
Qt 5.15.14 bugfix update. Fix CVE-2024-36048
https://security-tracker.debian.org/tracker/DSA-5704-1
https://security-tracker.debian.org/tracker/DSA-5705-1
* bsc#1217405 Cross-References: * CVE-2023-22084
* bsc#1202031 * bsc#1202033 * bsc#1203643 * bsc#1219823 * bsc#1219826
An update that fixes one vulnerability is now available.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
* bsc#1225417 Cross-References: * CVE-2024-33427
* bsc#1212233 Cross-References: * CVE-2023-3164
* bsc#1224806 Cross-References: * CVE-2024-4453
* bsc#1219823 * bsc#1219826 * bsc#1219851 Cross-References:
* bsc#1221940 * bsc#1223423 * bsc#1223424 * bsc#1223425
fix CVE-2023-36308
CVE-2024-36041
update to 125.0.6422.141 High CVE-2024-5493: Heap buffer overflow in WebRTC High CVE-2024-5494: Use after free in Dawn High CVE-2024-5495: Use after free in Dawn High CVE-2024-5496: Use after free in Media Session
Security fix for CVE-2024-21501
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority
https://security-tracker.debian.org/tracker/DSA-5703-1
Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.
The updated packages fix security vulnerabilities: Excessive time spent checking DSA keys and parameters. (CVE-2024-4603) Use After Free with SSL_free_buffers. (CVE-2024-4741) References:
It was discovered that Jinja2 incorrectly handled certain HTML attributes that were accepted by the xmlattr filter. An attacker could use this issue to inject arbitrary HTML attribute keys and values to potentially execute a cross-site scripting (XSS) attack.
Several security issues were fixed in GNU C Library.
An integer overflow in the EXIF metadata parsing was discovered in the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed file is processed.
https://security-tracker.debian.org/tracker/DSA-5702-1
* bsc#1224806 Cross-References: * CVE-2024-4453
* bsc#1187446 * bsc#1224410 Cross-References: * CVE-2021-33813
* bsc#1224788 Cross-References: * CVE-2024-35195
* bsc#1224806 Cross-References: * CVE-2024-4453
New version 4.2.5. Includes fixes for CVE-2024-4853, CVE-2024-4854, CVE-2024-4855.
Release 1.6.7 Makefile: Use phpDocumentor v3.4 for the Framework docs (#9313) Fix bug where HTML entities in URLs were not decoded on HTML to plain text conversion (#9312) Fix bug in collapsing/expanding folders with some special characters in names
https://security-tracker.debian.org/tracker/DSA-5701-1
browserify-sign could allow unintended access if it opened a specially crafted file.
* bsc#1189495 * bsc#1191175 * bsc#1218686 Cross-References:
Update to 115.11.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-23/ https://www.thunderbird.net/en-US/thunderbird/115.11.0/releasenotes/ https://www.thunderbird.net/en-US/thunderbird/115.10.0/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-20/
Update to requests-2.32.0, fixes CVE-2024-35195.
update to 125.0.6422.112 High CVE-2024-5274: Type Confusion in V8
Update to requests-2.32.0, fixes CVE-2024-35195.
* bsc#1221465 * bsc#1222155 * bsc#1222277 * bsc#1222731 * jsc#MSQA-775
* bsc#1221465 * bsc#1222155 * bsc#1222277 * bsc#1222731 * jsc#MSQA-775
* bsc#1223858 * bsc#1224169 * bsc#1224340 Affected Products:
Jinja2 could allow cross-site scripting (XSS) attacks.
* bsc#1223110 Cross-References: * CVE-2024-32462
* bsc#1224168 * bsc#1224170 * bsc#1224171 * bsc#1224172 * bsc#1224173
https://security-tracker.debian.org/tracker/DSA-5700-1
Unbound could be made to take part in a denial of service attack.
amavisd-new could be made to bypass security measures.
