Menu

Quote

Martin Kaesberger discovered a vulnerability which affects multiple OpenStack components (Nova, Glance and Cinder): Malformed QCOW2 disk images may result in the disclosure of arbitrary files.

https://security-tracker.debian.org/tracker/DSA-5754-1

https://security-tracker.debian.org/tracker/DSA-5755-1

https://security-tracker.debian.org/tracker/DSA-5756-1

https://security-tracker.debian.org/tracker/DSA-5752-1

https://security-tracker.debian.org/tracker/DSA-5753-1

Several security issues were fixed in Cacti.

* bsc#1213470 * bsc#1222979 * bsc#1222983 * bsc#1222986 * bsc#1222987

* bsc#1228046 * bsc#1228047 * bsc#1228048 * bsc#1228050 * bsc#1228051

* bsc#1228046 * bsc#1228047 * bsc#1228048 * bsc#1228050 * bsc#1228051

* bsc#1212968 * bsc#1215311 * bsc#1227322 Cross-References:

* bsc#1228143 Cross-References: * CVE-2024-1013

* bsc#1011205 * bsc#1093641 * bsc#1125882 * bsc#1167400 * bsc#1207973

* bsc#1223155 Cross-References: * CVE-2024-31744

* bsc#1192145 * bsc#1209657 * bsc#1218336 * bsc#1218447 * bsc#1218479

* bsc#1222835 * bsc#1222837 * jsc#SLE-23879 Cross-References:

* bsc#1184942 * bsc#1186060 * bsc#1192145 * bsc#1194516 * bsc#1208995

* bsc#1160688 * bsc#1223100 * jsc#PED-7677 * jsc#SLE-9298

https://security-tracker.debian.org/tracker/DSA-5751-1

https://security-tracker.debian.org/tracker/DSA-5750-1

* bsc#1082555 * bsc#1193454 * bsc#1193554 * bsc#1193787 * bsc#1194324

* bsc#1065729 * bsc#1179610 * bsc#1186463 * bsc#1216834 * bsc#1218820

* bsc#1228613 * bsc#1228693 * bsc#1228694 * bsc#1228695

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1229129 Cross-References: * CVE-2023-42667 * CVE-2023-49141

* bsc#1229069 Cross-References: * CVE-2023-31315

* bsc#1229069 Cross-References: * CVE-2023-31315

* bsc#1214327 * bsc#1218413 * bsc#1222120 * bsc#1227426 * bsc#1227513

* bsc#1065729 * bsc#1088701 * bsc#1149446 * bsc#1179610 * bsc#1186463

* bsc#1082555 * bsc#1156395 * bsc#1190336 * bsc#1191958 * bsc#1193454

https://security-tracker.debian.org/tracker/DSA-5749-1

* bsc#1156395 * bsc#1190336 * bsc#1191958 * bsc#1193454 * bsc#1193554

* bsc#1228535 Cross-References: * CVE-2024-7264

* bsc#1226463 * bsc#1227138 Cross-References: * CVE-2024-5535

* bsc#1225907 * bsc#1226463 * bsc#1227138 Cross-References:

* bsc#1227178 Cross-References: * CVE-2024-39134

* bsc#1227178 Cross-References: * CVE-2024-39134

https://security-tracker.debian.org/tracker/DSA-5743-2

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1065729 * bsc#1088701 * bsc#1149446 * bsc#1179610 * bsc#1186463

* bsc#1156395 * bsc#1190336 * bsc#1191958 * bsc#1193454 * bsc#1193554

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1228613 * bsc#1228693 * bsc#1228694 * bsc#1228695

https://security-tracker.debian.org/tracker/DSA-5748-1

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Multiple vulnerabilities have been discovered in protobuf-c, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in PHP, the worst of which can lead to a denial of service.

A vulnerability has been discovered in protobuf and protobuf-python, which can lead to a denial of service.

A vulnerability has been discovered in dpkg, which allows for directory traversal.

Multiple vulnerabilities have been discovered in MuPDF, the worst of which could lead to arbitrary code execution.

Update NSS to 3.103.0 Update to Firefox 129.0

https://security-tracker.debian.org/tracker/DSA-5747-1

Multiple vulnerabilities have been discovered in runc, the worst of which could lead to privilege escalation.

A vulnerability has been discovered in Ruby on Rails, which can lead to remote code execution via serialization of data.

New version 8.5.5

* bsc#1228256 * bsc#1228257 Cross-References: * CVE-2024-1737

* bsc#1220356 * bsc#1227525 Affected Products: * Basesystem Module 15-SP5

Multiple vulnerabilities have been discovered in GnuPG, the worst of which could lead to signature spoofing.

Multiple vulnerabilities have been discovered in Bundler, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in GPAC, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in libde265, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in ncurses, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in QEMU, the worst of which could lead to a denial of service.

A vulnerability has been discovered in Nautilus, which can lead to a denial of service.

Noah Misch discovered a race condition in the pg_dump tool included in PostgreSQL, which may result in privilege escalation. For the oldstable distribution (bullseye), this problem has been fixed

Noah Misch discovered a race condition in the pg_dump tool included in PostgreSQL, which may result in privilege escalation. For the stable distribution (bookworm), this problem has been fixed in

* bsc#1228549 * bsc#1228552 Cross-References: * CVE-2024-41671

https://security-tracker.debian.org/tracker/DSA-5745-1

https://security-tracker.debian.org/tracker/DSA-5746-1

A vulnerability was discovered in odoo, a suite of web based open source business apps. It could result in the execution of arbitrary code.

Multiple cross-site scripting vulnerabilities were discovered in RoundCube webmail. For the stable distribution (bookworm), these problems have been fixed in

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Kerberos could be made to crash if it received specially crafted input.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Update to upstream 2.1-43. 20240531 Addition of 06-aa-04/0xe6 (MTL-H/U C0) microcode at revision 0x1c; Addition of 06-ba-08/0xe0 microcode (in intel-ucode/06-ba-02) at revision 0x4121; Addition of 06-ba-08/0xe0 microcode (in intel-ucode/06-ba-03) at revision

https://security-tracker.debian.org/tracker/DSA-5742-1

https://security-tracker.debian.org/tracker/DSA-5743-1

https://security-tracker.debian.org/tracker/DSA-5744-1

https://security-tracker.debian.org/tracker/DSA-5741-1

https://security-tracker.debian.org/tracker/DSA-5739-1

https://security-tracker.debian.org/tracker/DSA-5738-1

A vulnerability has been discovered in Bitcoin, which can lead to a denial of service.

* bsc#1228872 Cross-References: * CVE-2024-7383

* bsc#1227296 Cross-References: * CVE-2024-32230

* bsc#1214855 * bsc#1219267 * bsc#1219268 * bsc#1219438 * bsc#1221916

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

Multiple vulnerabilities have been discovered in aiohttp, the worst of which could lead to service compromise.

https://security-tracker.debian.org/tracker/DSA-5740-1

* bsc#1220356 * bsc#1227525 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5

* bsc#1227052 Cross-References: * CVE-2024-6104

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1221302 * bsc#1223059

* bsc#1228549 * bsc#1228552 Cross-References: * CVE-2024-41671

* bsc#1227147 Cross-References: * CVE-2024-5535