https://security-tracker.debian.org/tracker/DSA-5714-1
An out-of-bounds read in the ‘bson’ module allowed deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
A symlink attack with emergency file saving has been fixed in the text editor nano. For Debian 10 buster, this problem has been fixed in version
* bsc#1219823 * bsc#1219826 * bsc#1219851 * bsc#1219852 * bsc#1219854
* bsc#1225551 Cross-References: * CVE-2024-4741
* bsc#1225551 Cross-References: * CVE-2024-4741
* bsc#1222857 * bsc#1222858 * bsc#1226073 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5712-1
Multiple security issues were discovered in Thunderbird, which could result inthe execution of arbitrary code. For the oldstable distribution (bullseye), these problems have been fixed
Security fix for CVE-2024-3049
https://security-tracker.debian.org/tracker/DSA-5713-1
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink. (CVE-2024-5742)
Use-after-free in networking. (CVE-2024-5702) Use-after-free in JavaScript object transplant. (CVE-2024-5688) External protocol handlers leaked by timing attack. (CVE-2024-5690) Sandboxed iframes were able to bypass sandbox restrictions to open a new window. (CVE-2024-5691)
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
The spyware, called AridSpy by ESET, is distributed through websites that pose as various messaging apps, a job search app, and a Palestinian Civil Registry app
The I-SOON data leak confirms that this contractor is involved in cyberespionage for China, while Iran-aligned groups step up aggressive tactics following the Hamas-led attack on Israel in 2023
sendmail allowed SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports
A vulnerability was discovered in Atril, a simple document viewer designed for the MATE desktop environment. CVE-2023-52076
https://security-tracker.debian.org/tracker/DSA-5711-1
Unauthorized local user access to the session manager has been fixed in the Plasma Workspace component of the KDE Plasma desktop environment. For Debian 10 buster, this problem has been fixed in version
ESET researchers discovered Arid Viper espionage campaigns spreading trojanized apps to Android users in Egypt and Palestine
* bsc#1224122 * bsc#1226136 Cross-References: * CVE-2024-24786
* bsc#1226020 Cross-References: * CVE-2024-5171
update to 126.0.6478.55 High CVE-2024-5830: Type Confusion in V8 High CVE-2024-5831: Use after free in Dawn High CVE-2024-5832: Use after free in Dawn High CVE-2024-5833: Type Confusion in V8
Security fix for CVE-2024-34055
update to 126.0.6478.55 High CVE-2024-5830: Type Confusion in V8 High CVE-2024-5831: Use after free in Dawn High CVE-2024-5832: Use after free in Dawn High CVE-2024-5833: Type Confusion in V8
Security fix for CVE-2024-34055
https://security-tracker.debian.org/tracker/DSA-5710-1
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
libndp could be made to crash or run programs if it received specially crafted network traffic.
* bsc#1223356 Cross-References: * CVE-2024-0090 * CVE-2024-0091
* bsc#1219273 Cross-References: * CVE-2023-27534
* bsc#1065729 * bsc#1141539 * bsc#1174585 * bsc#1181674 * bsc#1187716
* bsc#1225365 Cross-References: * CVE-2024-35235
* bsc#1223179 * bsc#1225365 Cross-References: * CVE-2024-35235
https://security-tracker.debian.org/tracker/DSA-5709-1
The award is an excellent opportunity for us to thank our readers and to recognize the depth of talent of ESET’s security researchers and writers
Several security issues were fixed in the Linux kernel.
* bsc#1223375 Cross-References: * CVE-2024-4141
* bsc#1224262 Cross-References: * CVE-2024-26306
* bsc#1219823 * bsc#1219826 * bsc#1219851 * bsc#1219852 * bsc#1219854
* bsc#1065729 * bsc#1101816 * bsc#1141539 * bsc#1181674 * bsc#1185902
* bsc#1218501 Cross-References: * CVE-2023-50711
https://security-tracker.debian.org/tracker/DSA-5707-1
https://security-tracker.debian.org/tracker/DSA-5708-1
An update that fixes 16 vulnerabilities is now available.
* bsc#1225417 Cross-References: * CVE-2024-33427
