Two issues have been found in asterisk, an Open Source Private Branch Exchange.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
Update to 130.0.6723.58 * High CVE-2024-9954: Use after free in AI * Medium CVE-2024-9955: Use after free in Web Authentication * Medium CVE-2024-9956: Inappropriate implementation in Web Authentication * Medium CVE-2024-9957: Use after free in UI
Fixes possible denial of service attack on untrusted input
https://security-tracker.debian.org/tracker/DSA-5793-1
Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.
Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.
Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.
The average time it takes attackers to weaponize a vulnerability, either before or after a patch is released, shrank from 63 days in 2018-2019 to just five days last year
Update to 130.0.6723.58 * High CVE-2024-9954: Use after free in AI * Medium CVE-2024-9955: Use after free in Web Authentication * Medium CVE-2024-9956: Inappropriate implementation in Web Authentication * Medium CVE-2024-9957: Use after free in UI
Fix for CVE-2024-48957 Automatic update for libarchive-3.7.2-6.fc40.
Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.
Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.
Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.
Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
“Hey, wanna chat?” This innocent phrase can take on a sinister meaning when it comes from an adult to a child online – and even be the start of a predatory relationship
* bsc#1229910 Cross-References: * CVE-2024-42934
* bsc#1231689 Cross-References: * CVE-2024-47874
* bsc#1231651 Cross-References: * CVE-2024-8184
The fixes for CVE-2024-38474 and CVE-2024-39884 introduced two regressions in mod_rewrite and mod_proxy. For Debian 11 bullseye, these problems have been fixed in version
The more devices, digital apps and online accounts you use, the more efficient and convenient your life becomes. But all that ease of use comes with a price. Your devices are constantly collecting your personal data to fine-tune your user experience. At the same time, hackers, and other cyber criminals are working round the clock […]
* bsc#1228349 * bsc#1228786 Cross-References: * CVE-2024-40909
* bsc#1227651 * bsc#1228573 Cross-References: * CVE-2021-47291
* bsc#1225312 * bsc#1225739 * bsc#1226325 * bsc#1228573 * bsc#1228786
* bsc#1228573 * bsc#1228786 Cross-References: * CVE-2024-40954
* bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225099 * bsc#1225312
Prevent command injection by quoting template strings in activation scripts
* bsc#1231284 Cross-References: * CVE-2024-8508
* bsc#1231284 Cross-References: * CVE-2024-8508
* bsc#1095184 * bsc#1118897 * bsc#1118898 * bsc#1118899 * bsc#1121850
* bsc#1225312 * bsc#1226325 * bsc#1227651 * bsc#1228573
* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1223059 * bsc#1223363
* bsc#1210619 * bsc#1218487 * bsc#1220145 * bsc#1220537 * bsc#1221302
https://security-tracker.debian.org/tracker/DSA-5792-1
* bsc#1228123 Cross-References: * CVE-2024-41184
* bsc#1228123 Cross-References: * CVE-2024-41184
* bsc#1225312 * bsc#1225739 * bsc#1226325 * bsc#1228573 * bsc#1228786
* bsc#1219296 * bsc#1220145 * bsc#1220211 * bsc#1220828 * bsc#1220832
* bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225099 * bsc#1225312
* bsc#1223683 * bsc#1225099 * bsc#1225739 * bsc#1228349 * bsc#1228573
An update that fixes two vulnerabilities is now available.
Python could me made to bypass some restrictions if it received specially crafted input.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Update to 129.0.6668.100 * CVE-2024-9602: Type Confusion in V8 * CVE-2024-9603: Type Confusion in V
Automatic update for buildah-1.37.4-1.fc41, podman-5.2.4-1.fc41. Changelog for buildah * Mon Oct 07 2024 Packit – 2:1.37.4-1 – Update to 1.37.4 upstream release Changelog for podman
Automatic update for buildah-1.37.4-1.fc41, podman-5.2.4-1.fc41. Changelog for buildah * Mon Oct 07 2024 Packit – 2:1.37.4-1 – Update to 1.37.4 upstream release Changelog for podman
