The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:
* bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610
Several security issues were fixed in Thunderbird.
PAM could be made to stop responding if it opened a specially crafted file.
* bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610
* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5647-1
https://security-tracker.debian.org/tracker/DSA-5646-1
Stack-based buffer overflow has been fixed in gross, a server for greylisting emails. For Debian 10 buster, this problem has been fixed in version
QPDF could be made to crash or run programs if it opened a specially crafted file.
Net::CIDR::Lite could allow unintended access to network services.
It was discovered that there was a command-line injection issue in the FreeIPA identity, authentication and audit framework. A specially crafted HTTP request could have lead to a Denial of Service (DoS) attack and/or data exposure.
Several security issues were fixed in Firefox.
New upstream version (124.0.1)
https://security-tracker.debian.org/tracker/DSA-5645-1
Multiple security vulnerabilities have been discovered in Cacti, a web interface for graphing of monitoring systems, which could result in cross-site scripting, SQL injection, or command injection.
Buffer Overflow vulnerability in FreeImage_AllocateBitmap. (CVE-2023-47995) Infinite loop exits in Load in PluginTIFF.cpp. (CVE-2023-47997) References:
The updated package fixes security vulnerabilities: pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. (CVE-2023-30570) An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA
Patch CVE-2023-4256 and CVE-2023-43279
Updates google.golang.org/protobuf to v1.33.0 to resolve CVE-2024-24786. Kubernetes is now built with go 1.21.8.
Security fix for CVE-2024-22871 Update to upstream release 1.11.2
Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or leaks of encrypted email subjects.
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could […]
Update to version 2.13.1 Fix CVE-2024-28054
update to xen-4.18.1 rebase xen.gcc12.fixes.patch remove patches now included or superceded upstream x86: Register File Data Sampling [XSA-452, CVE-2023-28746] GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193]
Updated to 124.0 Updated to latest upstream (123.0.1)
Added upstream patch to fix out-of-bounds access due to multiple backspaces to address incomplete fix for CVE-2022-38223 (#2222775, #2222780, #2255207)
https://security-tracker.debian.org/tracker/DSA-5644-1
Graphviz could be made to crash if it opened a specially crafted config6a file.
* bsc#1221323 Cross-References: * CVE-2023-22655 * CVE-2023-28746
* bsc#1219357 * bsc#1219554 Cross-References: * CVE-2020-36773
* bsc#1219357 * bsc#1219554 Cross-References: * CVE-2020-36773
* bsc#1219465 Cross-References: * CVE-2023-3966
* bsc#1050549 * bsc#1186484 * bsc#1200599 * bsc#1212514 * bsc#1213456
A security flaw was found on rubygem-yard that documents generated by yard may be vulnerable to XSS attack. This issue is now assigned as CVE-2024-27285 . This new rpm is supposed to fix this issue.
Update to 4.14 for CVE-2024-2357, v6 SAN name and TFC padding fix for AEAD
Security fix for CVE-2024-1048
Update to 115.9.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-14/ https://www.thunderbird.net/en-US/thunderbird/115.9.0/releasenotes/
Update to 4.14 for CVE-2024-2357, v6 SAN name and TFC padding fix for AEAD
https://security-tracker.debian.org/tracker/DSA-5643-1
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-5641-1
A memory leak was found in imagemagick a popular software suite for displaying, creating, converting, modifying, and editing raster images. For Debian 10 buster, this problem has been fixed in version
Several security issues were fixed in Firefox.
The updated packages fix security vulnerabilities: Heap buffer overflow in sqlite. (CVE-2023-2137) A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler.
Updated to 124.0
Updated to 124.0
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
https://security-tracker.debian.org/tracker/DSA-5642-1
https://security-tracker.debian.org/tracker/DSA-5626-2
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.
Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.
Update to 2.6.1, backport fix for CVE-2024-28757.
Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.
Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.
* bsc#1219465 Cross-References: * CVE-2023-3966
* bsc#1213590 * bsc#1214686 * bsc#1214687 * bsc#1221187 * bsc#960589
Several security issues were fixed in OpenJDK 8.
Update to shim-15.8
Update to shim-15.8
Update to shim-15.8
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. (CVE-2020-36518) In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the
The updated packages fix security vulnerabilities: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. (CVE-2022-38398) Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML
curl was affected by a path traversal vulnerability. SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate
upstream security release 122.0.6261.128 High CVE-2024-2400: Use after free in Performance Manager
Security fix for CVE-2007-4559.
New upstream release with security fixes for CVE-2023-5992 and CVE-2024-1454
Path traversal in moment.locale. (CVE-2022-24785) Inefficient parsing algorithim resulting in DoS. (CVE-2022-31129) References: – https://bugs.mageia.org/show_bug.cgi?id=30664
Security fix for CVE-2007-4559.
Update to 3.2.2 It indirectly fix CVE-2023-3966 and CVE-2023-5366
* bsc#1219836 Cross-References: * CVE-2024-1062
It was discovered that composer, a dependency manager for the PHP language, processed files in the local working directory. This could lead to local privilege escalation or malicious code execution. Due to a technical issue this email was not sent on 2024-02-26 like it should
* jsc#PED-2362 * jsc#SLE-5514 Cross-References: * CVE-2023-20593
* jsc#PED-2362 * jsc#SLE-5514 Cross-References: * CVE-2023-20593
* bsc#1221134 * bsc#1221151 Cross-References: * CVE-2023-42465
* bsc#1221134 * bsc#1221151 Cross-References: * CVE-2023-42465
Expat could be made to crash if it received specially crafted input.
Several security issues were fixed in TeX Live.
Two vulnerabilities were discovered in Open vSwitch, a software-based Ethernet virtual switch, which could result in a bypass of OpenFlow rules or denial of service.
python-cryptography could be made to expose sensitive information over the network.
Update to 115.8.1 https://www.mozilla.org/en-US/security/advisories/mfsa2024-11/ read that if you have mails with encrypted email subjects https://www.thunderbird.net/en-US/thunderbird/115.8.1/releasenotes/
python-multipart 0.0.7 (2024-02-03) Refactor header option parser to use the standard library instead of a custom RegEx #75. Fixes a denial of service vulnerability, GHSA-qf9m-vfgh-m389, initially reported in FastAPI but applicable to other libraries and applications.
https://security-tracker.debian.org/tracker/DSA-5640-1
* bsc#1219775 Cross-References: * CVE-2024-22119
* bsc#1220404 * bsc#1220405 Cross-References: * CVE-2024-25081
* bsc#1220404 * bsc#1220405 Cross-References: * CVE-2024-25081
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Add implicit rejection in PKCS#1 v1.5 in OpenSSL.
https://security-tracker.debian.org/tracker/DSA-5639-1
