This release is a security release and addresses multiple issues: [Low] OutOfBound Read in zgfx_decompress_segment. [Moderate] Integer overflow & OutOfBound Write in clear_decompress_residual_data. [Low] integer underflow in nsc_rle_decode.
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c. (CVE-2023-50471) cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. (CVE-2023-50472)
* bsc#1222518 Cross-References: * CVE-2024-31948
JSON5 could allow unintended access to network services or have other unspecified impact.
Multiple problems were discovered in Org-mode, a GNU Emacs major mode for keeping notes, authoring documents, and maintaining to-do lists. CVE-2024-30203 & CVE-2024-30204
Anope could be made to bypass authentication checks for suspended accounts.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
Multiple problems were discovered in GNU Emacs, the extensible, customisable, self-documenting display editor. CVE-2024-30203 & CVE-2024-30204
Pillow could be made to crash or run programs as an administrator if it opened a specially crafted file.
Several security issues were fixed in libvirt.
Several security issues were fixed in GnuTLS.
Several security issues were fixed in curl.
Several security issues were fixed in Apache HTTP Server.
Security vulnerabilities were found in mediawiki, a website engine for collaborative work, that could lead to information disclosure, privilege escalation, or denial of service.
Several vulnerabilities have been found in frr, the FRRouting suite of internet protocols. An attacker could craft packages to trigger buffer overflows with the possibility to gain remote code execution, buffer overreads, crashes or trick the software to enter an infinite loop.
Release 4.2.0
update to 124.0.6367.78 * Critical CVE-2024-4058: Type Confusion in ANGLE * High CVE-2024-4059: Out of bounds read in V8 API * High CVE-2024-4060: Use after free in Dawn
Release 4.2.0
* bsc#1213470 * bsc#1222979 * bsc#1222983 * bsc#1222984 * bsc#1222986
* bsc#1213470 * bsc#1222979 * bsc#1222983 * bsc#1222984 * bsc#1222986
CVE-2024-3852: GetBoundName in the JIT returned the wrong object CVE-2024-3854: Out-of-bounds-read after mis-optimized switch statement CVE-2024-3857: Incorrect JITting of arguments led to use-after-free during garbage collection CVE-2024-2609: Permission prompt input delay could expire when not in
update to 124.0.6367.78 * Critical CVE-2024-4058: Type Confusion in ANGLE * High CVE-2024-4059: Out of bounds read in V8 API * High CVE-2024-4060: Use after free in Dawn
CVE-2024-3852: GetBoundName in the JIT returned the wrong object CVE-2024-3854: Out-of-bounds-read after mis-optimized switch statement CVE-2024-3857: Incorrect JITting of arguments led to use-after-free during garbage collection CVE-2024-2609: Permission prompt input delay could expire when not in
The chromium-browser-stable package has been updated to the 124.0.6367.60 release. It includes 23 security fixes. Please, do note, only x86_64 is supported from now on. i586 support for linux was stopped some years ago and the community is not able to provide patches anymore for the latest Chromium code.
https://security-tracker.debian.org/tracker/DSA-5674-1
* bsc#1219217 * jsc#PED-3360 * jsc#PED-3361 Cross-References:
* bsc#1213269 * bsc#1218889 * bsc#1222843 * bsc#1222845
* bsc#1222842 Cross-References: * CVE-2024-3651
* bsc#1222950 Cross-References: * CVE-2024-1135
* bsc#1222857 * bsc#1222858 Cross-References: * CVE-2024-2756
* bsc#1222857 * bsc#1222858 Cross-References: * CVE-2024-2756
https://security-tracker.debian.org/tracker/DSA-5675-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in Thunderbird.
Fix for CVE-2024-31497
Fix for CVE-2024-31497
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
* bsc#1217325 Cross-References: * CVE-2023-26364
* bsc#1217325 Cross-References: * CVE-2023-26364
* bsc#1118590 * bsc#874743 Cross-References: * CVE-2014-2913
* bsc#1219887 * bsc#1219912 * bsc#1220371 * jsc#MSQA-759 * jsc#PED-7893
Google Guest Agent and OS Config Agent could be made to crash if it open a specially crafted JSON.
* bsc#1213269 * bsc#1218889 * bsc#1220134 * bsc#1222843 * bsc#1222845
* bsc#1190011 * bsc#1198038 * bsc#1207205 * bsc#1212850 * bsc#1213925
* bsc#1223155 Cross-References: * CVE-2024-31744
The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5673-1
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service or information disclosure. For Debian 10 buster, these problems have been fixed in version
Pillow could be made to crash or run programs as an administrator if it opened a specially crafted file.
percona-xtrabackup could be made to run programs as your login if it opened a specially crafted file.
* bsc#1221793 * bsc#1221797 Cross-References: * CVE-2024-29131
* bsc#1198101 * bsc#1205588 * bsc#1205855 * bsc#1210382 * bsc#1213945
* bsc#1219435 Cross-References: * CVE-2024-1086
https://security-tracker.debian.org/tracker/DSA-5669-1
https://security-tracker.debian.org/tracker/DSA-5670-1
https://security-tracker.debian.org/tracker/DSA-5671-1
https://security-tracker.debian.org/tracker/DSA-5672-1
Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.
update to 124.0.6367.60 High CVE-2024-3832: Object corruption in V8 High CVE-2024-3833: Object corruption in WebAssembly High CVE-2024-3914: Use after free in V8 High CVE-2024-3834: Use after free in Downloads
New upstream release (125.0)
Security fix for CVE-2023-5752
Update to 1.15.8 Fixes CVE-2024-32462
Security fix for CVE-2024-27316
https://security-tracker.debian.org/tracker/DSA-5667-1
Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.
Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.
Security fixes for CVE-2024-27351 Potential regular expression DOS in django.utils.text.Truncator.words() CVE-2024-24680 denial-of-service in intcomma template filter CVE-2023-43665 Denial-of-service possibility in django.utils.text.Truncator
fix CONTINUATION frames DoS (CVE-2024-28182)
This update includes several bug fixes from the upstream glibc release branch, including a fix for CVE-2024-2961.
Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.
https://security-tracker.debian.org/tracker/DSA-5668-1
* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982
* bsc#1220181 Cross-References: * CVE-2024-24476
* bsc#1222535 Cross-References: * CVE-2024-2609 * CVE-2024-3302
* bsc#1219491 Cross-References: * CVE-2023-46045
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or clickjacking.
WordPress 6.4.4 Security Release Security updates included in this release A cross-site scripting (XSS) vulnerability affecting the Avatar block type; reported by John Blackbourn of the WordPress security team. Many thanks to Mat Rollings for assisting with the research.
https://security-tracker.debian.org/tracker/DSA-5666-1
https://security-tracker.debian.org/tracker/DSA-5665-1
https://security-tracker.debian.org/tracker/DSA-5664-1
https://security-tracker.debian.org/tracker/DSA-5663-1
GNU C Library could be made to crash or run programs if it processed specially crafted data.
* bsc#1194869 * bsc#1200465 * bsc#1205316 * bsc#1207948 * bsc#1209635
This update includes the changes in tzdata 2024a for the Perl bindings. For the list of changes, see DLA-3789-1. For Debian 10 buster, this problem has been fixed in version
This update includes the changes in tzdata 2024a. Notable changes are: – – Kazakhstan unifies on UTC+5 beginning 2024-03-01.
sosreport: Fix command injection with crafted report names [CVE-2024-2947]
Fix for CVE-2024-31497
https://security-tracker.debian.org/tracker/DSA-5655-2
* bsc#1200599 * bsc#1209635 * bsc#1212514 * bsc#1213456 * bsc#1217987
* bsc#1194869 * bsc#1200465 * bsc#1205316 * bsc#1207948 * bsc#1209635
New upstream release (125.0)
