A security issue was discovered in Thunderbird, which could result in the disclosure of OpenPGP encrypted messages. For Debian 11 bullseye, this problem has been fixed in version
The system could be made to crash under certain conditions.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by “Refresh my rights” [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid
Update to 2.6.4. Backport fix for CVE-2024-50602.
Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by “Refresh my rights” [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid
Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by “Refresh my rights” [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid
Update to 2.6.4. Backport fix for CVE-2024-50602.
https://security-tracker.debian.org/tracker/DSA-5816-1
https://security-tracker.debian.org/tracker/DSA-5815-1
GLib could be made to crash or other undefined behavior if it received a specially crafted input.
Several issues were fixed in AsyncSSH.
This is the .NET 9.0 GA release. It contains security fixes for CVE-2024-43498 and CVE-2024-43499 Announcement: https://devblogs.microsoft.com/dotnet/announcing-dotnet-9/ Release Notes: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.0/9.0.0.md
Several security issues were fixed in Tomcat.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Multiple vulnerabilties were discovered for smarty3, a widely-used PHP templating engine, which potentially allows an attacker to perform an XSS (e.g JavaScript or PHP code injection).
A vulnerability has been discovered in the Xorg Server and XWayland, the worst of which can result in privilege escalation.
A vulnerability has been discovered in Pillow, which may lead to arbitrary code execution.
CVE-2024-46951 ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space (fedora#2325238) 2325241 – CVE-2024-46952 CVE-2024-46953 CVE-2024-46954 CVE-2024-46955 CVE-2024-46956 ghostscript: various flaws [fedora-41]
DoS due to resource exhaustion has been fixed in waitress, a Python Web Server Gateway Interface. For Debian 11 bullseye, this problem has been fixed in version
https://security-tracker.debian.org/tracker/DSA-5814-1
https://security-tracker.debian.org/tracker/DSA-5813-1
https://security-tracker.debian.org/tracker/DSA-5812-1
Multiple security issues were discovered in PostgreSQL, which may result in the execution of arbitrary code, privilege escalation or log manipulation. For Debian 11 bullseye, these problems have been fixed in version
Update to upstream 2.1-47. 20241112 Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in intel-ucode/06-8f-05) from revision 0x2b0005c0 up to 0x2b000603; Update of 06-8f-05/0x87 (SPR-SP E2) microcode from revision 0x2b0005c0 up to 0x2b000603;
bartlett/php-compatinfo-db 6.12.0 – 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support
Update to version 3.0.1, which resolves CVE-2024-49768 and CVE-2024-49769.
CVE-2024-46951 ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space (fedora#2325237) 2325240 – CVE-2024-46952 CVE-2024-46953 CVE-2024-46954 CVE-2024-46955 CVE-2024-46956 ghostscript: various flaws
bartlett/php-compatinfo-db 6.12.0 – 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support
* bsc#1233313 Cross-References: * CVE-2024-21820 * CVE-2024-21853
* bsc#1232590 Cross-References: * CVE-2024-50602
* bsc#1233282 Cross-References: * CVE-2024-52533
Several security issues were fixed in the Linux kernel.
Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code
Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code
