* bsc#1233313 Cross-References: * CVE-2024-21820 * CVE-2024-21853
* bsc#1232590 Cross-References: * CVE-2024-50602
* bsc#1233282 Cross-References: * CVE-2024-52533
Several security issues were fixed in the Linux kernel.
Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code
Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code
Update to 2.46.3
Update to b3561
Backport fix for CVE-2024-50602.
CVE fix for CVE-2024-9632
Update to 2.46.3
giflib: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB Function. (CVE-2023-48161) Array indexing integer overflow. (CVE-2024-21210) HTTP client improper handling of maxHeaderSize. (CVE-2024-21208) Unbounded allocation leads to out-of-memory error. (CVE-2024-21217)
Update to 130.0.6723.116
Update to 1.16.2 Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or GHSA-f748-7hpg-88ch
Update to 130.0.6723.116
Update to 1.16.2 Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or GHSA-f748-7hpg-88ch
Several security issues were fixed in .NET.
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
https://security-tracker.debian.org/tracker/DSA-5811-1
https://security-tracker.debian.org/tracker/DSA-5810-1
* bsc#1186511 * bsc#1217826 * bsc#1222121 * bsc#1222815 * bsc#1230551
Fixes CVE-2024-9341, CVE-2024-9407, CVE-2024-9675 and CVE-2024-9676.
Fixes CVE-2024-9341, CVE-2024-9407, CVE-2024-9675 and CVE-2024-9676.
Multiple vulnerabilities have been fixed in libarchive, a multi-format archive and compression library. CVE-2021-36976
New wget packages are available for Slackware 15.0 and -current to fix a security issue.
An out-of-bounds write vulnerability when handling crafted streams was discovered in mpg123, a real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3, which could result in the execution of arbitrary code.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
* bsc#1216423 Cross-References: * CVE-2023-45802
* bsc#1216423 Cross-References: * CVE-2023-45802
https://security-tracker.debian.org/tracker/DSA-5809-1
https://security-tracker.debian.org/tracker/DSA-5808-1
https://security-tracker.debian.org/tracker/DSA-5807-1
https://security-tracker.debian.org/tracker/DSA-5805-1
A heap-based out-of-bounds write vulnerability was discovered in libarchive, a multi-format archive and compression library, which may result in the execution of arbitrary code if a specially crafted RAR archive is processed.
Invalid low-level GF(2^m) parameters can lead to an OOB memory access. (CVE-2024-9143) References: – https://bugs.mageia.org/show_bug.cgi?id=33736
HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. (CVE-2024-45508) HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. (CVE-2024-46478)
In Libheif, insufficient checks in ImageOverlay::parse() while decoding a HEIF file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. (CVE-2024-41311) References:
Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parsing `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A
Permission leak via embed or object elements. (CVE-2024-10458) Use-after-free in layout with accessibility. (CVE-2024-10459) Confusing display of origin for external protocol handler prompt. (CVE-2024-10460) XSS due to Content-Disposition being ignored in
https://security-tracker.debian.org/tracker/DSA-5806-1
https://security-tracker.debian.org/tracker/DSA-5804-1
