Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LibreOffice could be made to run programs when clicking a graphic.

Several security issues were fixed in WebKitGTK.

What Can Linux Admins Learn from Microsoft’s Zero-Trust DNS Initiative?

Netatalk could allow arbitrary code execution if it receives a specially crafted input.

The chromium-browser-stable package has been updated to the 125.0.6422.112 release. It includes 1 security fix. * High CVE-2024-5274: Type Confusion in V8. Reported by Cl©ment Lecigne of Google’s Threat Analysis Group and Brendon Tiszka of Chrome Security on 2024-05-20

The CIA Triad in Open Source Security for Linux Environments: A Primer for Professionals

An update that fixes two vulnerabilities is now available.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

An update that fixes three vulnerabilities is now available.

Fossil was broken by fixes of CVE-2024-24795 for apache2 package, and needed an update. As part of the security fix, the Apache webserver

Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in HTTP response splitting, denial of service, or authorization bypass.

crosswords 0.3.13

crosswords 0.3.13

This is the May 2024 security update for .NET 7. This is the last upstream release of .NET 7. After this update, .NET 7 reaches its End of Life (EOL). Full release notes: https://github.com/dotnet/core/blob/main/release- notes/7.0/7.0.19/7.0.19.md

GNOME Remote Desktop would allow unintended access to sensitive information or remote desktop connections.

* bsc#1219386 Cross-References: * CVE-2023-5992

update to 125.0.6422.76 * High CVE-2024-5157: Use after free in Scheduling * High CVE-2024-5158: Type Confusion in V8 * High CVE-2024-5159: Heap buffer overflow in ANGLE * High CVE-2024-5160: Heap buffer overflow in Dawn

7.6.7.2

Update to 115.11.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-23/ https://www.thunderbird.net/en-US/thunderbird/115.11.0/releasenotes/

https://security-tracker.debian.org/tracker/DSA-5697-1

https://security-tracker.debian.org/tracker/DSA-5698-1

https://security-tracker.debian.org/tracker/DSA-5699-1

* bsc#1224277 Cross-References: * CVE-2023-45733 * CVE-2023-45745

Several security issues were fixed in klibc.

* bsc#1223603 Cross-References: * CVE-2024-4340

* bsc#1224038 * bsc#1224051 Cross-References: * CVE-2024-4317

Several security issues were fixed in the Linux kernel.

An update that fixes four vulnerabilities is now available.

Add implicit rejection in PKCS#1 v1.5 in OpenSSL.

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1222685

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1220211 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1223514

* bsc#1219296 * bsc#1220211 * bsc#1220828 * bsc#1220832 * bsc#1221302

* bsc#1221302 * bsc#1222882 * bsc#1223514 Cross-References:

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

Kentik for Ansible Automation Platform now certified with Red Hat

https://security-tracker.debian.org/tracker/DSA-5695-1

https://security-tracker.debian.org/tracker/DSA-5696-1

* bsc#1219296 * bsc#1220211 * bsc#1220828 * bsc#1220832 * bsc#1221302

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1222685

* bsc#1220211 * bsc#1220832 * bsc#1222685 * bsc#1223514

* bsc#1210619 * bsc#1218487 * bsc#1222685 * bsc#1223514

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1223514

Empowering Linux and Open-Source Security with AI: Strategies, Tools and Best Practices

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1224277 Cross-References: * CVE-2023-45733 * CVE-2023-45745

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1219296 * bsc#1220211 * bsc#1220828 * bsc#1220832 * bsc#1221302

* bsc#1221302 * bsc#1223514 Cross-References: * CVE-2022-48651

An update that fixes one vulnerability is now available.

This is a security and bug fix release.

Security fix for CVE-2024-3727 Automatic update for buildah-1.35.4-1.fc39. Changelog for buildah * Fri May 10 2024 Packit – 1.35.4-1 – Update to 1.35.4 upstream release

This is a security and bug fix release.

Backport fix for CVE-2024-34069.

update to 125.0.6422.60 * High CVE-2024-4947: Type Confusion in V8 * High CVE-2024-4948: Use after free in Dawn * Medium CVE-2024-4949: Use after free in V8 * Low CVE-2024-4950: Inappropriate implementation in Downloads

update to 125.0.6422.60 * High CVE-2024-4947: Type Confusion in V8 * High CVE-2024-4948: Use after free in Dawn * Medium CVE-2024-4949: Use after free in V8 * Low CVE-2024-4950: Inappropriate implementation in Downloads

new upstream update (126.0)

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1220211 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1222882

Two vulnerabilities were discovered in BIND, a DNS server implementation, which may result in denial of service. CVE-2023-50387

Automating fapolicyd with RHEL system roles

* bsc#1180833 * bsc#1183101 * bsc#1183102 * bsc#1183103 * bsc#1183105

* bsc#1222992 * bsc#1223423 * bsc#1223424 * bsc#1223425

new upstream update (126.0)

update to 125.0.6422.60 * High CVE-2024-4947: Type Confusion in V8 * High CVE-2024-4948: Use after free in Dawn * Medium CVE-2024-4949: Use after free in V8 * Low CVE-2024-4950: Inappropriate implementation in Downloads

Security fix for CVE-2024-3727

https://security-tracker.debian.org/tracker/DSA-5693-1

https://security-tracker.debian.org/tracker/DSA-5694-1

https://security-tracker.debian.org/tracker/DSA-5692-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in .NET.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1224038 * bsc#1224051 Cross-References: * CVE-2024-4317

* bsc#1224038 * bsc#1224051 Cross-References: * CVE-2024-4317

* bsc#1224038 * bsc#1224051 Cross-References: * CVE-2024-4317

* bsc#1219559 Cross-References: * CVE-2023-52425

* bsc#1190576 * bsc#1192145 * bsc#1204614 * bsc#1211592 * bsc#1218562

https://security-tracker.debian.org/tracker/DSA-5689-1

https://security-tracker.debian.org/tracker/DSA-5690-1

https://security-tracker.debian.org/tracker/DSA-5691-1

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

* bsc#1222548 Cross-References: * CVE-2024-2511

* bsc#1222548 Cross-References: * CVE-2024-2511

* bsc#1223690 Cross-References: * CVE-2024-29040