https://security-tracker.debian.org/tracker/DSA-5799-1
Learn how a rather clumsy cybercrime group wielding buggy malicious tools managed to compromise a number of SMBs in various parts of the world
https://security-tracker.debian.org/tracker/DSA-5798-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The updated package provides Firefox 128 for all mandatory arches of Mageia (x86_64, i586 and aarch64), fixing several bugs, including security vulnerabilities, for i586 and aarch64: Fullscreen notification dialog can be obscured by document content. (CVE-2024-7518)
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
* bsc#1220262 Cross-References: * CVE-2023-50782
pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink. (CVE-2024-47191)
fix CVE-2024-7006 (rhbz#2302997) fix CVE-2023-52356 (rhbz#2260112) fix CVE-2023-6228 (rhbz#2251863)
https://security-tracker.debian.org/tracker/DSA-5796-1
https://security-tracker.debian.org/tracker/DSA-5797-1
* bsc#1231294 Cross-References: * CVE-2024-47850
* bsc#1224038 * bsc#1224051 * bsc#1229013 Cross-References:
* bsc#1231039 Cross-References: * CVE-2024-23213 * CVE-2024-23271
* bsc#1231039 Cross-References: * CVE-2024-23206 * CVE-2024-23213
* bsc#1231698 Cross-References: * CVE-2024-9676
* bsc#1231698 Cross-References: * CVE-2024-9676
* bsc#1230683 Cross-References: * CVE-2024-45405
libheif could be made to crash or read sensitive data if it opened a specially crafted file
Several security issues were fixed in Go.
Various security, performance, accuracy, and stability issues have been fixed.
New version 4.2.8 Fix for CVE-2024-9781
It was discovered that there was a potential out-of-bounds read vulnerability in libheif, a decoder and encoder for the HEIF and AVIF image formats.
https://security-tracker.debian.org/tracker/DSA-5795-1
Unbound could be made to stop responding if it received specially crafted DNS traffic.
A heap-based pointer disclosure problem was found in Ghostscript, an interpreter for the PostScript language and for PDF. This could lead to information disclosure.
Firefox could be made to crash or run programs as your login
Multiple vulnerabilities were discovered in libsepol, a set of userspace utilities and libraries for manipulating SELinux policies. CVE-2021-36084, CVE-2021-36085, CVE-2021-36086
New openssl packages are available for Slackware 15.0 to fix a security issue.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
AMD processors may allow a privileged local attacker to further escalate their privileged and execute arbitrary code within the processor’s firmware layer.
https://security-tracker.debian.org/tracker/DSA-5794-1
