Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
The system could be made to crash under certain conditions.
It was discovered that iwd, the iNet Wireless Daemon, does not properly handle messages in the 4-way handshake used when connecting to a protected WiFi network for the first time. An attacker can take advantage of this flaw to gain unauthorized access to a protected WiFi
An issue has been found in libjwt, a C library to handle JWT (JSON Web Token). Due to using strcmp(), which does not use constant time during execution, a timing side channel attack might be possible.
Update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy
Backport fix for CVE-2023-5841.
Update to 2.6.0, fixes CVE-2023-52425, CVE-2023-52426.
Update to python3.11.8, backport fix for CVE-2023-27043.
https://security-tracker.debian.org/tracker/DSA-5631-1
Coming in two waves, the campaign sought to demoralize Ukrainians and Ukrainian speakers abroad with disinformation messages about war-related subjects
Rebase to version 2.6.0
Update to qt-5.15.12.
Update to qt-5.15.12.
Update to qt-5.15.12.
Update to qt-5.15.12.
Update to qt-5.15.12.
* bsc#1210638 Cross-References: * CVE-2023-27043
Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.
Update to latest upstream. Fixes CVE-2023-50387 and CVE-2023-50868
New upstream release (123.0)
update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy
Update to latest upstream. Fixes CVE-2023-50387 and CVE-2023-50868
https://security-tracker.debian.org/tracker/DSA-5629-1
https://security-tracker.debian.org/tracker/DSA-5630-1
* bsc#1218564 Cross-References: * CVE-2023-52323
* bsc#1219267 * bsc#1219268 * bsc#1219438 Cross-References:
* bsc#1219267 * bsc#1219268 * bsc#1219438 Cross-References:
* bsc#1188609 * bsc#1212850 * bsc#1213210 * bsc#1213925 * bsc#1215311
Imagemagick a graphical software suite for displaying, creating and modifying images was vulnerable. CVE-2023-1289
Several security issues were fixed in Firefox.
https://security-tracker.debian.org/tracker/DSA-5628-1
Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: https://github.com/quic- go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf
Patch for CVE-2024-24258 and CVE-2024-24259
Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: https://github.com/quic- go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf
https://security-tracker.debian.org/tracker/DSA-5627-1
New libuv packages are available for Slackware 15.0 and -current to fix a security issue.
* bsc#1011205 * bsc#1093641 * bsc#1125882 * bsc#1167400 * bsc#1207973
* bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188
The updated packages fix security vulnerabilities: RTPS dissector memory leak. (CVE-2023-5371) SSH dissector invalid read of memory blocks. (CVE-2023-6174) NetScreen File Parsing Heap-based Buffer Overflow. (CVE-2023-6175) GVCP dissector crash via packet injection or crafted capture file.
Stack buffer overflow in virtio_net_flush_tx (CVE-2023-6693) (rhbz#2256436)
Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link
Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link
Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link
Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link
* bsc#1219059 Cross-References: * CVE-2024-22563
* bsc#1202903 * bsc#1219187 Cross-References: * CVE-2022-2132
* bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188
* bsc#1219059 Cross-References: * CVE-2024-22563
Multiple vulnerabilities have been discovered in Samba, the worst of which can lead to remote code execution.
A vulnerability has been discovered in Glade which can lead to a denial of service.
Multiple vulnerabilities have been discovered in QtNetwork, the worst of which could lead to execution of arbitrary code.
A vulnerability has been discovered in Thunar which may lead to arbitrary code execution
A vulnerability has been discovered in libcaca which can lead to arbitrary code execution.
Multiple vulnerabilities have been discovered in Exim, the worst of which can lead to remote code execution.
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can
Multiple vulnerabilities have been discovered in CUPS, the worst of which can lead to arbitrary code execution.
https://security-tracker.debian.org/tracker/DSA-5626-1
https://security-tracker.debian.org/tracker/DSA-5625-1
