Expat could be made to crash if it received specially crafted input.
Several security issues were fixed in TeX Live.
Two vulnerabilities were discovered in Open vSwitch, a software-based Ethernet virtual switch, which could result in a bypass of OpenFlow rules or denial of service.
python-cryptography could be made to expose sensitive information over the network.
Update to 115.8.1 https://www.mozilla.org/en-US/security/advisories/mfsa2024-11/ read that if you have mails with encrypted email subjects https://www.thunderbird.net/en-US/thunderbird/115.8.1/releasenotes/
python-multipart 0.0.7 (2024-02-03) Refactor header option parser to use the standard library instead of a custom RegEx #75. Fixes a denial of service vulnerability, GHSA-qf9m-vfgh-m389, initially reported in FastAPI but applicable to other libraries and applications.
https://security-tracker.debian.org/tracker/DSA-5640-1
* bsc#1219775 Cross-References: * CVE-2024-22119
* bsc#1220404 * bsc#1220405 Cross-References: * CVE-2024-25081
* bsc#1220404 * bsc#1220405 Cross-References: * CVE-2024-25081
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Add implicit rejection in PKCS#1 v1.5 in OpenSSL.
https://security-tracker.debian.org/tracker/DSA-5639-1
Rack could be made do denial of service if it received a specially crafted header.
* bsc#1219243 Cross-References: * CVE-2024-0727
* bsc#1219243 Cross-References: * CVE-2024-0727
* bsc#1219243 Cross-References: * CVE-2024-0727
Several security issues were fixed in Open vSwitch.
An update that fixes one vulnerability is now available.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Two vulnerabilities were discovered in tiff, Tag Image File Format library. CVE-2023-3576
* bsc#1027519 * bsc#1218851 * bsc#1219080 * bsc#1219885
* bsc#1219243 Cross-References: * CVE-2024-0727
* bsc#1219243 Cross-References: * CVE-2024-0727
Evasive Panda has been spotted targeting Tibetans in several countries and territories with payloads that included a previously undocumented backdoor ESET has named Nightdoor
It was discovered that the uv_getaddrinfo() function in libuv, an asynchronous event notification library, incorrectly truncated certain hostnames, which may result in bypass of security measures on internal APIs or SSRF attacks.
2267205 – CVE-2024-24246 qpdf – Heap Buffer Overflow vulnerability in qpdf [fedora-all]
backport fix for PEAP client (CVE-2023-52160)
2267205 – CVE-2024-24246 qpdf – Heap Buffer Overflow vulnerability in qpdf [fedora-all]
Update to latest version Security fix for CVE-2023-39325
https://security-tracker.debian.org/tracker/DSA-5638-1
Incorrect handling of extension attributes in PAX archives has been fixed in the GNU tar archiving utility. For Debian 10 buster, this problem has been fixed in version
Several security vulnerabilities have been discovered in Squid, a full featured web proxy cache. Due to programming errors in Squid’s HTTP request parsing, remote attackers may be able to execute a denial of service attack by sending large X-Forwarded-For header or trigger a stack buffer overflow while
upstream security release 122.0.6261.111 – High CVE-2024-2173: Out of bounds memory access in V8 – High CVE-2024-2174: Inappropriate implementation in V8 – High CVE-2024-2176: Use after free in FedCM
* bsc#1218571 * bsc#1219238 Cross-References: * CVE-2023-7207
* bsc#1218571 * bsc#1219238 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5
The internet can be a wonderful place. But it’s also awash with fraudsters targeting people who are susceptible to fraud.
* bsc#1219243 Cross-References: * CVE-2024-0727
* bsc#1219243 Cross-References: * CVE-2024-0727
* bsc#1219243 Cross-References: * CVE-2024-0727
* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465
* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465
* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465
https://security-tracker.debian.org/tracker/DSA-5637-1
* bsc#1217213 Cross-References: * CVE-2023-44446
* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465
* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465
* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465
* bsc#1200528 Cross-References: * CVE-2022-1996
* bsc#1212475 * bsc#1219988 * bsc#1220999 * bsc#1221000 * bsc#1221001
Struggle to part ways with your tech? You’re not alone. Here’s why your devices are your vices.
