https://security-tracker.debian.org/tracker/DSA-5822-1
An update that fixes two vulnerabilities is now available.
Improve memory consumption and performance of Canvas getImageData. Fix preserve-3D intersection rendering. Fix video dimensions since GStreamer 1.24.9. Fix the HTTP-based remote Web Inspector not loading in Chromium. Fix content filters not working on about:blank iframes.
New version 4.4.2
Update to 5.0.2 fix rhbz#2326888
New version 4.2.9
Multiple vulnerabilities were discovered in Lemonldap::NG, an OpenID-Connect, CAS and SAML compatible Web-SSO system, which could lead to injection of arbitrary scripts or authorization bypass.
Two issues have been found in editorconfig-core, a coding style indenter for all editors. Both issues are related to buffer overflows in different locations.
Brief introduction CVE-2022-0934
An issue has been found in xfpt, a tool to generate XML from plain tex. The issue is about bad handling of input data, which may result in a stack-based buffer overflow and execution of arbitrary code, when
An issue has been found in tgt, Linux SCSI target user-space daemon and tools. The issue was related to using rand() without proper seed, resulting in identical sequences of challenges.
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because ‘’ characters at the end of header names are ignored, i.e., a “Transfer-Encoding: chunked” header is treated the same as a “Transfer-Encoding: chunked” header. (CVE-2024-52530) GNOME libsoup before 3.6.1 allows a buffer overflow in applications that
ProFTPD a popular FTP server was affected by multiple vulnerabilities. CVE-2023-48795
* bsc#1233447 Cross-References: * CVE-2024-52304
* bsc#1233323 * bsc#1233325 * bsc#1233326 * bsc#1233327
Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and
Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and
Deadlock in x86 HVM standard VGA handling [XSA-463, CVE-2024-45818] libxl leaks data to PVH guests via ACPI tables [XSA-464, CVE-2024-45819]
Update to 128.5.0 https://www.thunderbird.net/en-US/thunderbird/128.5.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-68/
https://security-tracker.debian.org/tracker/DSA-5821-1
https://security-tracker.debian.org/tracker/DSA-5820-1
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version
* bsc#1233695 Cross-References: * CVE-2024-11691 * CVE-2024-11692
* bsc#1225889 Cross-References: * CVE-2024-1298
* bsc#1209401 Affected Products: * Basesystem Module 15-SP6 * Desktop Applications Module 15-SP6
* jsc#PED-11092 Cross-References: * CVE-2023-31489 * CVE-2023-31490
1.37 – fix parsing of “use if …” Fixes errors in PAR::Packer test t/90-rt59710.t – add test for _parse_libs() 1.36
https://security-tracker.debian.org/tracker/DSA-5819-1
* bsc#1233695 Cross-References: * CVE-2024-11691 * CVE-2024-11692
* bsc#1233434 Cross-References: * CVE-2024-52316
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
* bsc#1230366 * bsc#1232542 * bsc#1232622 * bsc#1232624
Several security issues were fixed in libsoup.
* bsc#1219340 * bsc#1230423 * bsc#1233323 * bsc#1233325 * bsc#1233326
USN-7117-1 caused some regression in needrestart.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Multiple vulnerabilities have been fixed in pypy3, an alternative implementation of the Python 3.x language. CVE-2020-10735
* bsc#1233313 Cross-References: * CVE-2024-21820 * CVE-2024-21853
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
A microcode update has been released for Intel processors, addressing multiple vulnerabilties which potentially could cause information disclosue or local DoS.
Several security issues were fixed in OpenJDK 23.
Multiple vulnerabilities have been fixed in the PostScript/PDF interpreter Ghostscript. CVE-2024-46951
Ansible is a command-line IT automation software application. It can configure systems, deploy software, and orchestrate advanced workflows to support application deployment, system updates, …
https://security-tracker.debian.org/tracker/DSA-5818-1
A buffer overflow with long SOCKS4a proxy hostname and username has been fixed in the GNOME Input/Output library (GIO). For Debian 11 bullseye, this problem has been fixed in version
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
PHP version 8.3.14 (21 Nov 2024) CLI: Fixed bug GH-16373 (Shebang is not skipped for router script in cli-server started through shebang). (ilutov) Fixed bug GHSA-4w77-75f9-2c8w (Heap-Use-After-Free in sapi_read_post_data
This is the .NET 9.0 GA release. It contains security fixes for CVE-2024-43498 and CVE-2024-43499 Announcement: https://devblogs.microsoft.com/dotnet/announcing-dotnet-9/ Release Notes: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.0/9.0.0.md
https://security-tracker.debian.org/tracker/DSA-5817-1
New php packages are available for Slackware 15.0 and -current to fix security issues.
https://security-tracker.debian.org/tracker/DSA-5812-2
An update that fixes 8 vulnerabilities is now available.
An update that fixes 8 vulnerabilities is now available.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-40866
Fix null pointer dereference in opendmarc_policy.c. (CVE-2024-25768) References: – https://bugs.mageia.org/show_bug.cgi?id=33756
Upstream kernel version 6.6.61 fixes bugs and vulnerabilities. The bluez, kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.
Vanilla upstream kernel version 6.6.61 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33776
An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function. (CVE-2024-48241) References: – https://bugs.mageia.org/show_bug.cgi?id=33755
In versions prior to 1.2.31 an authenticated user is able to perform a SQL injection, leading to a privilege escalation or loss of confidentiality. It appears that in some insert and update operations the code improperly uses the PicoDB library to update/insert new information.
Potential disclosure of plaintext in OpenPGP encrypted message. (CVE-2024-11159) References: – https://bugs.mageia.org/show_bug.cgi?id=33763
Remove ClamAV subdirectory because of viruses in input files: These were the findings: MultiSource/Applications/ClamAV/inputs/rtf-test/rtf1.rtf: Eicar-Signature MultiSource/Applications/ClamAV/inputs/clam.zip: Clamav.Test.File-6 MultiSource/Applications/ClamAV/inputs/rtf-test/docCLAMexe.rtf:
Remove ClamAV subdirectory because of viruses in input files: These were the findings: MultiSource/Applications/ClamAV/inputs/rtf-test/rtf1.rtf: Eicar-Signature MultiSource/Applications/ClamAV/inputs/clam.zip: Clamav.Test.File-6 MultiSource/Applications/ClamAV/inputs/rtf-test/docCLAMexe.rtf:
Update to 130.0.6723.116
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in Ruby.
A security issue was discovered in Thunderbird, which could result in the disclosure of OpenPGP encrypted messages. For Debian 11 bullseye, this problem has been fixed in version
The system could be made to crash under certain conditions.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by “Refresh my rights” [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid
Update to 2.6.4. Backport fix for CVE-2024-50602.
Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by “Refresh my rights” [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid
Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by “Refresh my rights” [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid
Update to 2.6.4. Backport fix for CVE-2024-50602.
https://security-tracker.debian.org/tracker/DSA-5815-1
https://security-tracker.debian.org/tracker/DSA-5816-1
GLib could be made to crash or other undefined behavior if it received a specially crafted input.
Several issues were fixed in AsyncSSH.
This is the .NET 9.0 GA release. It contains security fixes for CVE-2024-43498 and CVE-2024-43499 Announcement: https://devblogs.microsoft.com/dotnet/announcing-dotnet-9/ Release Notes: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.0/9.0.0.md
Several security issues were fixed in Tomcat.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Multiple vulnerabilties were discovered for smarty3, a widely-used PHP templating engine, which potentially allows an attacker to perform an XSS (e.g JavaScript or PHP code injection).
A vulnerability has been discovered in the Xorg Server and XWayland, the worst of which can result in privilege escalation.
A vulnerability has been discovered in Pillow, which may lead to arbitrary code execution.
CVE-2024-46951 ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space (fedora#2325238) 2325241 – CVE-2024-46952 CVE-2024-46953 CVE-2024-46954 CVE-2024-46955 CVE-2024-46956 ghostscript: various flaws [fedora-41]
DoS due to resource exhaustion has been fixed in waitress, a Python Web Server Gateway Interface. For Debian 11 bullseye, this problem has been fixed in version
https://security-tracker.debian.org/tracker/DSA-5814-1
