Multiple out-of-bounds read vulnerabilities have been discovered in Wireshark.
Multiple vulnerabilities have been found in OpenSSL, the worst of which could result in denial of service.
Multiple vulnerabilities have been found in Xen, the worst of which can lead to arbitrary code execution.
The updated packages fix security vulnerabilities: A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program
Out of bounds write in ANGLE. (CVE-2024-0741) Failure to update user input timestamp. (CVE-2024-0742) Crash when listing printers on Linux. (CVE-2024-0746)
https://security-tracker.debian.org/tracker/DSA-5615-1
The banking trojan, which targeted mostly Brazil, Mexico and Spain, blocked the victim’s screen, logged keystrokes, simulated mouse and keyboard activity and displayed fake pop-up windows
Sudo, a program designed to allow a sysadmin to give limited root privileges to users and log root activity, was vulnerable. CVE-2023-7090
Multiple vulnerabilities have been discovered in FreeType, the worst of which can lead to remote code execution.
Multiple vulnerabilities have been discovered in Microsoft Edge, the worst of which could lead to remote code execution.
A vulnerability has been discovered in GNAT Ada Suite which can lead to remote code execution.
Multiple vulnerabilities have been discovered in QtGui which can lead to remote code execution.
A vulnerability has been discovered in SDDM which can lead to privilege escalation.
https://security-tracker.debian.org/tracker/DSA-5614-1
https://security-tracker.debian.org/tracker/DSA-5613-1
* bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053
* bsc#1140772 * bsc#1157446 * bsc#1170452 * bsc#1171862 * bsc#1215669
* bsc#1068950 * bsc#1081527 * bsc#1211052 * jsc#PED-6584
* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051
* bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053
* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051
An AI chatbot inadvertently kindles a cybercrime boom, ransomware bandits plunder organizations without deploying ransomware, and a new botnet enslaves Android TV boxes
ESET provided technical analysis, statistical information, known C&C servers and was able to get a glimpse of the victimology
* bsc#1217654 * bsc#1219131 Cross-References: * CVE-2023-50269
* bsc#1218894 Cross-References: * CVE-2024-21626
* bsc#1218894 Cross-References: * CVE-2024-21626
Security fix for CVE-2023-6246, CVE-2023-6779, and CVE-2023-6780. CVE-2023-6246: __vsyslog_internal did not handle a case where printing a SYSLOG_HEADER containing a long program name failed to update the required buffer size, leading to the allocation and overflow of a too-small buffer on the heap. CVE-2023-6779: __vsyslog_internal used the return value of
Update to 115.7.0 * https://www.mozilla.org/en- US/security/advisories/mfsa2024-04/ * https://www.thunderbird.net/en- US/thunderbird/115.7.0/releasenotes/
Security fix for CVE-2023-6246, CVE-2023-6779, and CVE-2023-6780. CVE-2023-6246: __vsyslog_internal did not handle a case where printing a SYSLOG_HEADER containing a long program name failed to update the required buffer size, leading to the allocation and overflow of a too-small buffer on the heap. CVE-2023-6779: __vsyslog_internal used the return value of
https://security-tracker.debian.org/tracker/DSA-5612-1
Multiple vulnerabilities have been found in containerd, the worst of which could result in privilege escalation.
* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051
* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218049 * bsc#1218050
* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051
* bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053
* bsc#1216207 * bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050
https://security-tracker.debian.org/tracker/DSA-5610-1
Postfix, a popular mail server, allowed SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking
TinyXML could be made to crash if it opened a specially crafted file.
The container bci/python was updated. The following patches have been included in this update:
The container bci/php-fpm was updated. The following patches have been included in this update:
The container bci/golang was updated. The following patches have been included in this update:
The container bci/golang was updated. The following patches have been included in this update:
https://security-tracker.debian.org/tracker/DSA-5611-1
Exim could be made to bypass an SPF protection mechanism if it received a specially crafted request.
The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update:
The container suse/rmt-mariadb was updated. The following patches have been included in this update:
The container suse/rmt-mariadb-client was updated. The following patches have been included in this update:
The container suse/nginx was updated. The following patches have been included in this update:
Security fix for CVE-2023-48795
https://security-tracker.debian.org/tracker/DSA-5608-1
Several vulnerabilities were discovered in the Slurm Workload Manager, a cluster resource management and job scheduling system, which may result in privilege escalation, denial of service, bypass of message hash checks or opening files with an incorrect set of extended groups.
The container bci/ruby was updated. The following patches have been included in this update:
The container bci/python was updated. The following patches have been included in this update:
The container suse/postgres was updated. The following patches have been included in this update:
The container suse/postgres was updated. The following patches have been included in this update:
The container bci/php was updated. The following patches have been included in this update:
https://security-tracker.debian.org/tracker/DSA-5609-1
The previously unknown threat actor used the implant to target Chinese and Japanese companies, as well as individuals in China, Japan, and the UK
Blindly trusting your partners and suppliers on their security posture is not sustainable – it’s time to take control through effective supplier risk management
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container suse/rmt-server was updated. The following patches have been included in this update:
The container bci/php-apache was updated. The following patches have been included in this update:
