This update includes the changes in tzdata 2024a for the Perl bindings. For the list of changes, see DLA-3789-1. For Debian 10 buster, this problem has been fixed in version
This update includes the changes in tzdata 2024a. Notable changes are: – – Kazakhstan unifies on UTC+5 beginning 2024-03-01.
sosreport: Fix command injection with crafted report names [CVE-2024-2947]
Fix for CVE-2024-31497
https://security-tracker.debian.org/tracker/DSA-5655-2
* bsc#1200599 * bsc#1209635 * bsc#1212514 * bsc#1213456 * bsc#1217987
* bsc#1194869 * bsc#1200465 * bsc#1205316 * bsc#1207948 * bsc#1209635
New upstream release (125.0)
The 6.8.6 stable kernel update contains a number of important fixes across the tree.
Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791; Security fix for CVE-2024-25713
New version 4.2.4. Includes a fix for CVE-2024-2955
https://security-tracker.debian.org/tracker/DSA-5661-1
https://security-tracker.debian.org/tracker/DSA-5660-1
* bsc#1216992 Cross-References: * CVE-2023-4218
* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982
* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982
* bsc#1220053 * bsc#1222244 * bsc#1222384 * bsc#1222530 * bsc#1222603
* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982
* bsc#1220053 * bsc#1222244 * bsc#1222384 * bsc#1222530 * bsc#1222603
https://security-tracker.debian.org/tracker/DSA-5662-1
Bartek Nowotarski discovered that Apache Traffic Server, a reverse and forward proxy server, was susceptible to denial of service via HTTP2 continuation frames.
Multiple vulnerabilities have been fixed in the Xorg X server. CVE-2024-31080
* bsc#1219296 Cross-References: * CVE-2023-52340
update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn
New less packages are available for Slackware 15.0 and -current to fix a security issue.
Core: – Corrupted memory in destructor with weak references – GC does not scale well with a lot of objects created in destructor DOM: – Add some missing ZPP checks.
update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn
The 6.8.5 stable kernel update contains a number of important fixes across the tree.
Bring all current releases from either version 0.7.3 or 0.6.12 to version 0.7.6 for more bug-fixes and also as to resolve potential security issues: https://lib.openmpt.org/libopenmpt/news/
Bring all current releases from either version 0.7.3 or 0.6.12 to version 0.7.6 for more bug-fixes and also as to resolve potential security issues: https://lib.openmpt.org/libopenmpt/news/
https://security-tracker.debian.org/tracker/DSA-5659-1
https://security-tracker.debian.org/tracker/DSA-5657-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
The 6.8.5 stable kernel update contains a number of important fixes across the tree.
The 6.8.5 stable kernel update contains a number of important fixes across the tree.
Update to version 0.3.26. Addresses RUSTSEC-2024-0332.
Update to version 0.3.26. Addresses RUSTSEC-2024-0332.
https://security-tracker.debian.org/tracker/DSA-5658-1
Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with “collapsed_forwarding on” are vulnerable. Configurations with “collapsed_forwarding off” or without a “collapsed_forwarding” directive
* bsc#1221564 Cross-References: * CVE-2021-47154
* bsc#1218613 * bsc#1219078 * bsc#1219296 * bsc#1219432
Security fix for CVE-2024-24576 (Windows command injection)
Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)
Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)
4.2.3
These new packages fix bugs in SSL certificate validation; these bugs could allow for the compromising of encrypted SSL sessions.
* bsc#1028271 Cross-References: * CVE-2016-10243
* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672
* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672
This is the March 2024 update for .NET 7. Release Notes: https://github.com/dotnet/core/blob/main/release- notes/7.0/7.0.17/7.0.17.md
https://security-tracker.debian.org/tracker/DSA-5656-1
An update that fixes two vulnerabilities is now available.
util-linux could be made to expose sensitive information.
* bsc#1167896 * bsc#1206261 * bsc#1215301 Cross-References:
