Automatic update for buildah-1.37.4-1.fc41, podman-5.2.4-1.fc41. Changelog for buildah * Mon Oct 07 2024 Packit – 2:1.37.4-1 – Update to 1.37.4 upstream release Changelog for podman
Automatic update for buildah-1.37.4-1.fc41, podman-5.2.4-1.fc41. Changelog for buildah * Mon Oct 07 2024 Packit – 2:1.37.4-1 – Update to 1.37.4 upstream release Changelog for podman
https://security-tracker.debian.org/tracker/DSA-5791-1
https://security-tracker.debian.org/tracker/DSA-5790-1
ESET research dives deep into a series of attacks that leveraged bespoke toolsets to compromise air-gapped systems belonging to governmental and diplomatic entities
Various file formats are based on the zip file format. In cases of corruption of the underlying zip’s central directory, LibreOffice offers a “repair mode” which will attempt to recover the zip file structure by scanning for secondary local
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in
Update to 2.0.19
Redis Community Edition 7.2.6 Released Wed 02 Oct 2024 20:17:04 IDT Upgrade urgency SECURITY: See security fixes below. Security fixes CVE-2024-31449 Lua library commands may lead to stack overflow and potential RCE.
Update rust-brotli-decompressor to 4.0.1, rust-brotli to 7.0.0, and rust-async- compression to 0.4.13. Patch dependent packages as needed to avoid compat packages. Rebuild with the latest Rust crate dependency versions; fix automatic provides on Python extension due to SONAME when built with Rust 1.81 or later.
https://security-tracker.debian.org/tracker/DSA-5789-1
* bsc#1231298 Cross-References: * CVE-2024-47554
Several security issues were fixed in the Linux kernel.
The updated packages fix security vulnerabilities References: – https://bugs.mageia.org/show_bug.cgi?id=33614 – https://openssl-library.org/news/vulnerabilities-3.0/
Use-after-free when closing buffers in Vim
HTTP_REDIRECT_STATUS might be controlled via user request FPM log output might be modified by an attacker HTTP POST can be modified by an attacker For other bug fixes consult references
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
Several security issues were fixed in Go.
* bsc#1220826 * bsc#1226145 * bsc#1226666 * bsc#1227487 * bsc#1228466
* bsc#1027519 * bsc#1228574 * bsc#1228575 * bsc#1230366
Several security issues were fixed in the Linux kernel.
* bsc#1047218 * bsc#1202273 * bsc#1226975 * bsc#1229589 * jsc#PED-10362
* bsc#1047218 * bsc#1225597 * bsc#1226975 * bsc#1229589 * jsc#PED-10362
https://security-tracker.debian.org/tracker/DSA-5788-1
https://security-tracker.debian.org/tracker/DSA-5729-2
Could human risk in cybersecurity be managed with a cyber-rating, much like credit scores help assess people’s financial responsibility?
Patch the code to use https instead of http (CVE-2024-45321)
Fixes CVE-2024-45752: A vulnerability that allows users to remap keys arbitrarily. This allows all users on the system to remap a key unexpectedly to a potentially malicious sequence
Patch the code to use https instead of http (CVE-2024-45321)
Update to 0.3.13.3 and fix gresource generation
Patch the code to use https instead of http (CVE-2024-45321)
https://security-tracker.debian.org/tracker/DSA-5787-1
The fixes for CVE-2024-38474 and CVE-2024-39884 introduced two regressions in mod_rewrite and mod_proxy. For the stable distribution (bookworm), these problems have been fixed in
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
* bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References:
* bsc#1023072 * bsc#1023190 * bsc#1027776 * bsc#1027779 * bsc#1027785
Fix login QR code not shown in WhatsApp web. Disable PSON by default again in GTK 3 API versions. Disable DMABuf video sink by default to prevent file descriptor leaks. Fix several crashes and rendering issues. Use Skia instead of cairo for 2D rendering and enable GPU rendering by default.
Fix login QR code not shown in WhatsApp web. Disable PSON by default again in GTK 3 API versions. Disable DMABuf video sink by default to prevent file descriptor leaks. Fix several crashes and rendering issues. Use Skia instead of cairo for 2D rendering and enable GPU rendering by default.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
WEBrick could allow a HTTP request smuggling attack.
An update that fixes three vulnerabilities is now available.
* bsc#1231264 * bsc#1231265 * bsc#1231266 Cross-References:
cups-filters could be made to run programs if it received specially crafted network traffic.
CUPS could be made to crash or run programs if it received specially crafted network traffic.
