Simone Margaritelli reported that cups, the Common UNIX Printing System, does not properly sanitize IPP attributes when creating PPD files, which may result in the execution of arbitrary code.
Two vulnerabilities were discovered in unbound, a validating, recursive, caching DNS resolver. Specially crafted input could cause a heap-buffer-overflow leading to memory corruption and potentially causing the application to crash or allowing arbitrary code execution
Update to new upstream version (closes rhbz#2237124)
https://security-tracker.debian.org/tracker/DSA-5779-1
https://security-tracker.debian.org/tracker/DSA-5778-1
Multiple vulnerabilities have been fixed in ruby-rails-html-sanitizer, a Ruby library for sanitizing HTML fragments in Rails applications. CVE-2022-23517
Multiple vulnerabilities have been fixed in ruby-loofah, a Ruby library for manipulating and transforming HTML/XML documents and fragments. CVE-2022-23514
ESET research examines the group’s malicious wares as used to spy on targets in Ukraine in the past two years
multipart/form-data request tampering has been fixed in ruby-httparty, a Ruby library for using Web-based APIs and related services. For Debian 11 bullseye, this problem has been fixed in version
Multiple vulnerabilities have been discovered in nginx, the worst of which could result in denial of service.
Multiple vulnerabilities have been found in Apache HTTPD, the worst of which could result in denial of service.
Multiple vulnerabilities have been found in yt-dlp, the worst of which could result in arbitrary code execution.
Multiple vulnerabilities have been discovered in Docker, the worst of which could result in denial of service.
Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service.
Keep your cool, arm yourself with the right knowledge, and other tips for staying unshaken by fraudsters’ scare tactics
An update that fixes four vulnerabilities is now available.
* bsc#1202346 * bsc#1227985 * bsc#1228002 * bsc#1228938 * bsc#1228959
* bsc#1225099 * bsc#1228349 Cross-References: * CVE-2023-52846
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
In today’s world, both small businesses and everyday consumers face a growing number of cyber threats. From ransomware attacks to phishing scams, hackers are becoming more sophisticated. OpenText’s 2024 Threat Hunter Perspective sheds light on what’s coming next and how to protect yourself. Whether you’re running a small business or managing personal data at home, […]
https://security-tracker.debian.org/tracker/DSA-5777-1
https://security-tracker.debian.org/tracker/DSA-5776-1
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
The CA certificates in the ca-certificates package were updated.
Several security issues were fixed in the Linux kernel.
OpenJPEG could be made to crash if it opened a specially crafted file.
The system could be made to expose sensitive information.
https://security-tracker.debian.org/tracker/DSA-5775-1
* bsc#1230366 Cross-References: * CVE-2024-45817
* bsc#1202023 * bsc#1229438 * bsc#1230866 Cross-References:
Several security issues were fixed in the Linux kernel.
Multiple vulnerabilities have been found in Xpdf, the worst of which could result in denial of service.
Several security issues were fixed in Intel Microcode.
* bsc#1069468 * bsc#1079798 * bsc#1079799 * bsc#1079800 * bsc#1079801
An update that fixes 6 vulnerabilities is now available.
An update that fixes 6 vulnerabilities is now available.
* bsc#1193629 * bsc#1194111 * bsc#1194765 * bsc#1194869 * bsc#1196261
* bsc#1229596 * bsc#1229704 * bsc#1230227 Cross-References:
py7zr could be made to create arbitrary files when extracting the contents of a specially crafted 7z archive.
Multiple vulnerabilities have been found in Tor, the worst of which could result in denial of service.
* bsc#1012628 * bsc#1193454 * bsc#1194869 * bsc#1205462 * bsc#1208783
* bsc#1229596 * bsc#1230227 Cross-References: * CVE-2024-6232
