Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

The 6.8.6 stable kernel update contains a number of important fixes across the tree.

Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791; Security fix for CVE-2024-25713

New version 4.2.4. Includes a fix for CVE-2024-2955

https://security-tracker.debian.org/tracker/DSA-5661-1

https://security-tracker.debian.org/tracker/DSA-5660-1

* bsc#1216992 Cross-References: * CVE-2023-4218

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1220053 * bsc#1222244 * bsc#1222384 * bsc#1222530 * bsc#1222603

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1220053 * bsc#1222244 * bsc#1222384 * bsc#1222530 * bsc#1222603

https://security-tracker.debian.org/tracker/DSA-5662-1

Protect Your Linux Web Apps and Meet Compliance Standards

Bartek Nowotarski discovered that Apache Traffic Server, a reverse and forward proxy server, was susceptible to denial of service via HTTP2 continuation frames.

Multiple vulnerabilities have been fixed in the Xorg X server. CVE-2024-31080

* bsc#1219296 Cross-References: * CVE-2023-52340

update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn

New less packages are available for Slackware 15.0 and -current to fix a security issue.

Core: – Corrupted memory in destructor with weak references – GC does not scale well with a lot of objects created in destructor DOM: – Add some missing ZPP checks.

Red Hat Enterprise Linux 7: End of compliance content on June 30, 2024

update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn

The 6.8.5 stable kernel update contains a number of important fixes across the tree.

Bring all current releases from either version 0.7.3 or 0.6.12 to version 0.7.6 for more bug-fixes and also as to resolve potential security issues: https://lib.openmpt.org/libopenmpt/news/

Bring all current releases from either version 0.7.3 or 0.6.12 to version 0.7.6 for more bug-fixes and also as to resolve potential security issues: https://lib.openmpt.org/libopenmpt/news/

https://security-tracker.debian.org/tracker/DSA-5659-1

https://security-tracker.debian.org/tracker/DSA-5657-1

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The 6.8.5 stable kernel update contains a number of important fixes across the tree.

The 6.8.5 stable kernel update contains a number of important fixes across the tree.

Update to version 0.3.26. Addresses RUSTSEC-2024-0332.

Update to version 0.3.26. Addresses RUSTSEC-2024-0332.

https://security-tracker.debian.org/tracker/DSA-5658-1

Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with “collapsed_forwarding on” are vulnerable. Configurations with “collapsed_forwarding off” or without a “collapsed_forwarding” directive

* bsc#1221564 Cross-References: * CVE-2021-47154

Understanding the Red Hat security impact scale

* bsc#1218613 * bsc#1219078 * bsc#1219296 * bsc#1219432

Security fix for CVE-2024-24576 (Windows command injection)

Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)

Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)

4.2.3

These new packages fix bugs in SSL certificate validation; these bugs could allow for the compromising of encrypted SSL sessions.

* bsc#1028271 Cross-References: * CVE-2016-10243

* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672

* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672

This is the March 2024 update for .NET 7. Release Notes: https://github.com/dotnet/core/blob/main/release- notes/7.0/7.0.17/7.0.17.md

https://security-tracker.debian.org/tracker/DSA-5656-1

An update that fixes two vulnerabilities is now available.

Strategies for Improving Linux Security Through Cross-Browser Compatibility Testing

util-linux could be made to expose sensitive information.

* bsc#1167896 * bsc#1206261 * bsc#1215301 Cross-References:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Bind could be made to crash if it received specially crafted input.

* bsc#1221926 Cross-References: * CVE-2024-30161

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1207987 * bsc#1220117 * bsc#1221831 Cross-References:

* bsc#1214223 * bsc#1216980 * bsc#1220512 * bsc#1221237 * bsc#1221468

* bsc#1221749 * bsc#1221815 Cross-References: * CVE-2024-2494

* bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746

* bsc#1027519 * bsc#1219885 * bsc#1221332 * bsc#1221334

* bsc#1205316 * bsc#1209554 * bsc#1218484 * bsc#1220062 * bsc#1220065

* bsc#1220239 * bsc#1220242 * bsc#1220248 Cross-References:

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets.

Andreas Beck discovered that versions of pam_xauth supplied with Red Hat Linux since version 7.1 would forward authorization information from the root account to unprivileged users.

Two Cross-site scripting vulnerabilities have been found that affect SquirrelMail version 1.2.7 and earlier.

A security hole has been found that does not affect the default configuration of Red Hat Linux, but can affect some custom configurations of Red Hat Linux 7.1 only. The bug is specific to the Linux 2.4 kernel series.

CVE-2024-28085 Skyler Ferrante discovered that the wall(1) utility found in util-linux, a collection of system utilities for Linux, does not

Two issues have been found in libcaca, a colour ASCII art library. Both are related to heap buffer overflow, which might lead to memory corruption.

Introducing Confidential Containers Trustee: Attestation Services Solution Overview and Use Cases

Two security vulnerabilities have been discovered in the Tomcat servlet and JSP engine. CVE-2024-24549

update to 123.0.6312.105 * High CVE-2024-3156: Inappropriate implementation in V8 * High CVE-2024-3158: Use after free in Bookmarks * High CVE-2024-3159: Out of bounds memory access in V8

4.2.3

Update to 1.22.2 Security fixes for CVE-2023-7158 and CVE-2023-7152

* bsc#1212475 * bsc#1221400 Cross-References: * CVE-2023-45288

New tigervnc packages are available for Slackware 15.0 and -current to fix security issues.

* bsc#1145903 * bsc#1184799 Cross-References: * CVE-2019-15052

* bsc#1216594 * bsc#1216598 Cross-References: * CVE-2023-38469

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5654-1

Security Risks of Open-Source Software & Mitigations to Overcome Them

USN-6710-1 caused some minor regressions in Firefox.

Update to 1.22.2 Security fixes for CVE-2023-7158 and CVE-2023-7152

Update to 1.22.2 Security fixes for CVE-2023-7158 and CVE-2023-7152

https://security-tracker.debian.org/tracker/DSA-5655-1

New xorg-server packages are available for Slackware 15.0 and -current to fix security issues.

Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Claudio Bozzato discovered multiple security issues in gtkwave, a file waveform viewer for VCD (Value Change Dump) files, which may result in the execution of arbitrary code if malformed files are opened.

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: