Menu

Quote

Command injection via RzBinInfo bclass due legacy code. (CVE-2022-1207) References: – https://bugs.mageia.org/show_bug.cgi?id=33895 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/YNDCM5TGWRLSMIJ74ZI6LMNSCCH5DBPL/

Various security, performance, accuracy, and stability issues have been fixed.

work around debugedit bug to fix aarch64 builds xen-hypervisor %post doesn’t load all needed grub2 modules update to xen-4.19.1 which includes Deadlock in x86 HVM standard VGA handling [XSA-463, CVE-2024-45818] libxl leaks data to PVH guests via ACPI tables [XSA-464, CVE-2024-45819]

https://security-tracker.debian.org/tracker/DSA-5841-1

The fix for CVE-2024-6923 in the python3.9 source package which was released as part of a suite of updates in DLA 3980-1 [0] introduced safer processing of input in the email module to order to increase the security around email header injection attacks.

Several vulnerabilities were discovered in OpenAFS, an implementation of the AFS distributed filesystem, which may result in theft of credentials in Unix client PAGs (CVE-2024-10394), fileserver crashes and information leak on StoreACL/FetchACL (CVE-2024-10396) or buffer overflows in XDR

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or privilege escalation.

Important: kernel-rt security update

Important: webkit2gtk3 security update

* jsc#PED-11136 Cross-References: * CVE-2024-12678 * CVE-2024-25131

* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:

* bsc#1234991 Cross-References: * CVE-2025-0237 * CVE-2025-0238

https://security-tracker.debian.org/tracker/DSA-5839-1

* bsc#1235029 Cross-References: * CVE-2024-56826

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

xfpt could be made to crash or run programs if it opened a specially crafted file.

Thunderbird could be made to bypass security restrictions.

Several security issues were fixed in Firefox.

Updated to latest upstream (134.0)

https://security-tracker.debian.org/tracker/DSA-5840-1

* bsc#1082555 * bsc#1176081 * bsc#1206344 * bsc#1213034 * bsc#1218562

* bsc#1082555 * bsc#1157160 * bsc#1218644 * bsc#1221977 * bsc#1222364

Tinyproxy could be made to crash or run programs if it received specially crafted input.

* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:

Several security issues were fixed in HTMLDOC.

* bsc#1234809 Cross-References: * CVE-2024-56326

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1234809 Cross-References: * CVE-2024-56326

* bsc#1234718 Cross-References: * CVE-2024-11614

* bsc#1202473 * bsc#1205224 * bsc#1211507 Cross-References:

tinyproxy could be made to expose sensitive information.

Vulnerabilities were found in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are prior to 7.0.22 and prior to 7.1.2. A difficult to exploit vulnerability allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise an Oracle

The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many ` `. (CVE-2024-39908)

Update to 2.46.5: Fix several crashes and rendering issues. CVE-2024-54479, CVE-2024-54502, CVE-2024-54508, CVE-2024-54505

* bsc#1217826 * bsc#1222815 * bsc#1230551 * bsc#1230552 * bsc#1231345

* bsc#1205224 * bsc#1211507 Cross-References: * CVE-2022-39377

iwd 3.3: Fix issue with handling External Authentication. iwd 3.2: Fix issue with GCC 15 and -std=c23 build errors. Add support for using PMKSA over SAE if available.

iwd 3.3: Fix issue with handling External Authentication. iwd 3.2: Fix issue with GCC 15 and -std=c23 build errors. Add support for using PMKSA over SAE if available.

Linux 6.1 has been packaged for Debian 11 as linux-6.1. This provides a supported upgrade path for systems that currently use kernel packages from the “bullseye-backports” suite.

* bsc#1226162 * bsc#1226468 * bsc#1234292 Cross-References:

* bsc#1234808 * bsc#1234809 Cross-References: * CVE-2024-56201

It was discovered that there was a potential Denial of Service (DoS) vulnerability, in Django, a popular Python-based web development framework.

Update to 2.12.9 Fixes CVE-2024-40896

Tornado is a scalable, non-blocking Python web framework and asynchronous networking library. CVE-2023-28370

* bsc#1234795 Cross-References: * CVE-2024-56378

debootstrap has been updated to avoid pulling in usr-is-merged in testing and unstable. This fixes creating testing/unstable chroots after src:usrmerge is removed from the archive.

Multiple vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

* bsc#1234795 Cross-References: * CVE-2024-56378

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.5 * openSUSE Leap 15.6

iwd 3.3: Fix issue with handling External Authentication. iwd 3.2: Fix issue with GCC 15 and -std=c23 build errors. Add support for using PMKSA over SAE if available.

iwd 3.3: Fix issue with handling External Authentication. iwd 3.2: Fix issue with GCC 15 and -std=c23 build errors. Add support for using PMKSA over SAE if available.

An update that contains security fixes can now be installed.

Multiple vulnerabilities were found in opensc, a set of libraries and utilities to access smart cards, which could lead to application crash, information leak, or PIN bypass.

https://security-tracker.debian.org/tracker/DSA-5838-1

* bsc#1228919 * bsc#1233821 Cross-References: * CVE-2024-11407

* bsc#1228919 * bsc#1233821 Cross-References: * CVE-2024-11407

Multiple CVE fixes

Update to 0^20241216git660795b dr_flac 0.12.43: Fix a possible buffer overflow during decoding. Improve detection of ARM64EC. dr_mp3 0.6.40: Improve detection of ARM64EC dr_wav 0.13.17: Fix a possible crash when reading from MS-ADPCM encoded files.

https://security-tracker.debian.org/tracker/DSA-5835-1

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74

https://security-tracker.debian.org/tracker/DSA-5836-1

https://security-tracker.debian.org/tracker/DSA-5837-1

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-54479

* bsc#1234795 Cross-References: * CVE-2024-56378

* bsc#1234795 Cross-References: * CVE-2024-56378

Automatic update for tomcat-9.0.98-1.fc41. Changelog for tomcat * Mon Dec 09 2024 Packit – 1:9.0.98-1 – Update to version 9.0.98 – Resolves: rhbz#2331168

Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74

Automatic update for tomcat-9.0.98-1.fc40. Changelog for tomcat * Mon Dec 09 2024 Packit – 1:9.0.98-1 – Update to version 9.0.98 – Resolves: rhbz#2331168

* bsc#1129772 * bsc#1152803 * bsc#1154838 * bsc#1181400 * bsc#1230961

In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte

Update to 3.12.8

Update to 3.12.8

* bsc#1220490 * jsc#PED-10258 * jsc#PED-10751 Cross-References: