The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
Bind could be made to crash if it received specially crafted input.
* bsc#1221926 Cross-References: * CVE-2024-30161
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
* bsc#1207987 * bsc#1220117 * bsc#1221831 Cross-References:
* bsc#1214223 * bsc#1216980 * bsc#1220512 * bsc#1221237 * bsc#1221468
* bsc#1221749 * bsc#1221815 Cross-References: * CVE-2024-2494
* bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746
* bsc#1027519 * bsc#1219885 * bsc#1221332 * bsc#1221334
* bsc#1205316 * bsc#1209554 * bsc#1218484 * bsc#1220062 * bsc#1220065
* bsc#1220239 * bsc#1220242 * bsc#1220248 Cross-References:
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets.
Andreas Beck discovered that versions of pam_xauth supplied with Red Hat Linux since version 7.1 would forward authorization information from the root account to unprivileged users.
Two Cross-site scripting vulnerabilities have been found that affect SquirrelMail version 1.2.7 and earlier.
A security hole has been found that does not affect the default configuration of Red Hat Linux, but can affect some custom configurations of Red Hat Linux 7.1 only. The bug is specific to the Linux 2.4 kernel series.
CVE-2024-28085 Skyler Ferrante discovered that the wall(1) utility found in util-linux, a collection of system utilities for Linux, does not
Two issues have been found in libcaca, a colour ASCII art library. Both are related to heap buffer overflow, which might lead to memory corruption.
Two security vulnerabilities have been discovered in the Tomcat servlet and JSP engine. CVE-2024-24549
update to 123.0.6312.105 * High CVE-2024-3156: Inappropriate implementation in V8 * High CVE-2024-3158: Use after free in Bookmarks * High CVE-2024-3159: Out of bounds memory access in V8
4.2.3
Update to 1.22.2 Security fixes for CVE-2023-7158 and CVE-2023-7152
* bsc#1212475 * bsc#1221400 Cross-References: * CVE-2023-45288
New tigervnc packages are available for Slackware 15.0 and -current to fix security issues.
* bsc#1145903 * bsc#1184799 Cross-References: * CVE-2019-15052
* bsc#1216594 * bsc#1216598 Cross-References: * CVE-2023-38469
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5654-1
USN-6710-1 caused some minor regressions in Firefox.
Update to 1.22.2 Security fixes for CVE-2023-7158 and CVE-2023-7152
Update to 1.22.2 Security fixes for CVE-2023-7158 and CVE-2023-7152
https://security-tracker.debian.org/tracker/DSA-5655-1
New xorg-server packages are available for Slackware 15.0 and -current to fix security issues.
Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.
Claudio Bozzato discovered multiple security issues in gtkwave, a file waveform viewer for VCD (Value Change Dump) files, which may result in the execution of arbitrary code if malformed files are opened.
The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5653-1
* bsc#1218946 Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.3
* bsc#1222045 Cross-References: * CVE-2024-29025
* bsc#1221815 Cross-References: * CVE-2024-2494
The 6.7.11 stable kernel update contains a number of important fixes across the tree.
Upgrade to 2.44.0: Make the DOM accessibility tree reachable from UI process with GTK4. Removed the X11 and WPE renderers in favor of DMA-BUF. Improved vblank synchronization when rendering. Removed key event reinjection in GTK4 to make keyboard shortcuts work in web
The 6.7.11 stable kernel update contains a number of important fixes across the tree.
https://security-tracker.debian.org/tracker/DSA-5652-1
Multiple vulnerabilities were found in libvirt, a C toolkit to interact with the virtualization capabilities of Linux, which could lead to denial of service or information disclosure.
* bsc#1041090 * bsc#1084627 * bsc#1133158 * bsc#1172267 * bsc#1191783
Update to 2.53.18.2
Update to 2.53.18.2
Update to 2.53.18.2
Two security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting or denial of service.
Skyler Ferrante discovered that the wall tool from util-linux does not properly handle escape sequences from command line arguments. A local attacker can take advantage of this flaw for information disclosure.
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23. (CVE-2024-30202) In Emacs before 29.3, Gnus treats inline MIME contents as trusted. (CVE-2024-30203)
Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access. (CVE-2023-22655) Information exposure through microarchitectural state after transient
Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `–with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a
These are bug fix and security releases including MODERATE, HIGH, and CRITICAL issues.
release v1.11.0 release v1.10.1 release v1.10.0
https://security-tracker.debian.org/tracker/DSA-5650-1
https://security-tracker.debian.org/tracker/DSA-5651-1
podman-tui release v1.0.0 Security fix for [CVE-2024-28180]
x86: Register File Data Sampling [XSA-452, CVE-2023-28746] GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193]
Automatic update for cockpit-314-1.fc39.
This update contains security fixes for CVE-2024-29131 and CVE-2024-29133. See https://github.com/apache/commons-configuration/blob/master/RELEASE- NOTES.txt for changes in versions 2.10.0 and 2.10.1.
Security fix for CVE-2023-35936 and CVE-2023-38745 pandoc: backport fixes for CVE-2023-35936 and CVE-2023-38745 pandoc-cli: new package for pandoc binary
Security fix for CVE-2023-35936 and CVE-2023-38745 pandoc: backport fixes for CVE-2023-35936 and CVE-2023-38745 pandoc-cli: new package for pandoc binary
https://security-tracker.debian.org/tracker/DSA-5648-1
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
podman-tui release v1.0.0
Version 6.7.4 (2024-03-21) Upgrade tcpdf tag encryption algorithm. Version 6.7.3 (2024-03-20) Fix regression issue #699. Version 6.7.2 (2024-03-18)
This update contains security fixes for CVE-2024-29131 and CVE-2024-29133. See https://github.com/apache/commons-configuration/blob/master/RELEASE- NOTES.txt for changes in versions 2.10.0 and 2.10.1.
CVE-2024-2004: Usage of disabled protocol If all protocols are disabled at run-time with none being added, curl/libcurl would still allow communication with the default set of allowed protocols, including some that are unencrypted. CVE-2024-2398: HTTP/2 push headers memory-leak
update to 123.0.6312.86 Critical CVE-2024-2883: Use after free in ANGLE High CVE-2024-2885: Use after free in Dawn High CVE-2024-2886: Use after free in WebCodecs High CVE-2024-2887: Type Confusion in WebAssembly
https://security-tracker.debian.org/tracker/DSA-5649-1
* bsc#1218610 Cross-References: * CVE-2023-51779
* bsc#1218487 * bsc#1218610 Cross-References: * CVE-2023-51779
* bsc#1218487 Cross-References: * CVE-2023-6531
* bsc#1208911 * bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610
* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:
* bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610
Several security issues were fixed in curl.
* bsc#1221237 * bsc#1221468 Cross-References: * CVE-2024-1441
* bsc#1220770 * bsc#1220771 Cross-References: * CVE-2024-26458
* bsc#1144060 * bsc#1176006 * bsc#1188307 * bsc#1203823 * bsc#1205502
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:
