Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

https://security-tracker.debian.org/tracker/DSA-5813-1

https://security-tracker.debian.org/tracker/DSA-5812-1

Multiple security issues were discovered in PostgreSQL, which may result in the execution of arbitrary code, privilege escalation or log manipulation. For Debian 11 bullseye, these problems have been fixed in version

Update to upstream 2.1-47. 20241112 Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in intel-ucode/06-8f-05) from revision 0x2b0005c0 up to 0x2b000603; Update of 06-8f-05/0x87 (SPR-SP E2) microcode from revision 0x2b0005c0 up to 0x2b000603;

bartlett/php-compatinfo-db 6.12.0 – 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support

Update to version 3.0.1, which resolves CVE-2024-49768 and CVE-2024-49769.

CVE-2024-46951 ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space (fedora#2325237) 2325240 – CVE-2024-46952 CVE-2024-46953 CVE-2024-46954 CVE-2024-46955 CVE-2024-46956 ghostscript: various flaws

bartlett/php-compatinfo-db 6.12.0 – 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support

The Dual Edge of Open Source: Examining Key Benefits and Security Challenges

* bsc#1233313 Cross-References: * CVE-2024-21820 * CVE-2024-21853

* bsc#1232590 Cross-References: * CVE-2024-50602

* bsc#1233282 Cross-References: * CVE-2024-52533

AI meets security: POC to run workloads in confidential containers using NVIDIA accelerated computing

Several security issues were fixed in the Linux kernel.

Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code

Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code

OpenSSL in Red Hat Enterprise Linux 10: From engines to providers

Update to 2.46.3

Update to b3561

Backport fix for CVE-2024-50602.

CVE fix for CVE-2024-9632

Update to 2.46.3

giflib: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB Function. (CVE-2023-48161) Array indexing integer overflow. (CVE-2024-21210) HTTP client improper handling of maxHeaderSize. (CVE-2024-21208) Unbounded allocation leads to out-of-memory error. (CVE-2024-21217)

Update to 130.0.6723.116

Update to 1.16.2 Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or GHSA-f748-7hpg-88ch

Update to 130.0.6723.116

Update to 1.16.2 Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or GHSA-f748-7hpg-88ch

Several security issues were fixed in .NET.

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

https://security-tracker.debian.org/tracker/DSA-5811-1

https://security-tracker.debian.org/tracker/DSA-5810-1

* bsc#1186511 * bsc#1217826 * bsc#1222121 * bsc#1222815 * bsc#1230551

Fixes CVE-2024-9341, CVE-2024-9407, CVE-2024-9675 and CVE-2024-9676.

Fixes CVE-2024-9341, CVE-2024-9407, CVE-2024-9675 and CVE-2024-9676.

Multiple vulnerabilities have been fixed in libarchive, a multi-format archive and compression library. CVE-2021-36976

New wget packages are available for Slackware 15.0 and -current to fix a security issue.

An out-of-bounds write vulnerability when handling crafted streams was discovered in mpg123, a real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3, which could result in the execution of arbitrary code.

Containerizing WordPress: Best Practices for Robust Security and Management

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

* bsc#1216423 Cross-References: * CVE-2023-45802

* bsc#1216423 Cross-References: * CVE-2023-45802

https://security-tracker.debian.org/tracker/DSA-5808-1

https://security-tracker.debian.org/tracker/DSA-5809-1

https://security-tracker.debian.org/tracker/DSA-5807-1

https://security-tracker.debian.org/tracker/DSA-5805-1

A heap-based out-of-bounds write vulnerability was discovered in libarchive, a multi-format archive and compression library, which may result in the execution of arbitrary code if a specially crafted RAR archive is processed.

Invalid low-level GF(2^m) parameters can lead to an OOB memory access. (CVE-2024-9143) References: – https://bugs.mageia.org/show_bug.cgi?id=33736

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. (CVE-2024-45508) HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. (CVE-2024-46478)

In Libheif, insufficient checks in ImageOverlay::parse() while decoding a HEIF file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. (CVE-2024-41311) References:

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parsing `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A

Permission leak via embed or object elements. (CVE-2024-10458) Use-after-free in layout with accessibility. (CVE-2024-10459) Confusing display of origin for external protocol handler prompt. (CVE-2024-10460) XSS due to Content-Disposition being ignored in

https://security-tracker.debian.org/tracker/DSA-5806-1

https://security-tracker.debian.org/tracker/DSA-5804-1

Secure cloud bursting: Leveraging confidential computing for peace of mind
Recent improvements in Red Hat Enterprise Linux CoreOS security data
Strengthening security of the software supply chain for LLVM

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

New upstream build (132.0)

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Red Hat Insights expands its detection capabilities with CrowdStrike integration

Update to 128.4.0 https://www.thunderbird.net/en-US/thunderbird/128.4.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-58/

Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0

Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection fix for inline data images #646 Fix count svg #647

Update to 128.4.0 https://www.thunderbird.net/en-US/thunderbird/128.4.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-58/

Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0

Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection fix for inline data images #646 Fix count svg #647

https://security-tracker.debian.org/tracker/DSA-5803-1

https://security-tracker.debian.org/tracker/DSA-5802-1

Guide to Automating Third-Party Risk Management in Linux Environments
Red Hat Insights collaborated with Vulcan Cyber to provide a seamless integration for effective exposure management

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, spoofing or information disclosure.

* bsc#1227471 * bsc#1228349 * bsc#1228573 * bsc#1228786

* bsc#1223363 * bsc#1223683 * bsc#1225011 * bsc#1225012 * bsc#1225013

* bsc#1225011 * bsc#1225012 * bsc#1225309 * bsc#1225311 * bsc#1225819

Several security issues were fixed in the Linux kernel.

* bsc#1223363 * bsc#1223683 * bsc#1225011 * bsc#1225012 * bsc#1225013

Enhancing Cybersecurity with Breach and Attack Simulation in Linux Environments
Comprehensive Guide to Fixing and Securing MySQL InnoDB Table Corruption

https://security-tracker.debian.org/tracker/DSA-5801-1

https://security-tracker.debian.org/tracker/DSA-5800-1

https://security-tracker.debian.org/tracker/DSA-5799-1

FIPS 140-3 changes for PKCS #12

https://security-tracker.debian.org/tracker/DSA-5798-1

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: