Menu

Quote

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of Java sandbox restrictions.

Several security issues were fixed in the Linux kernel.

Backport fix for CVE-2023-49528

https://security-tracker.debian.org/tracker/DSA-5736-1

https://security-tracker.debian.org/tracker/DSA-5737-1

update to 127.0.6533.88 Critical CVE-2024-6990: Uninitialized Use in Dawn High CVE-2024-7255: Out of bounds read in WebTransport High CVE-2024-7256: Insufficient data validation in Dawn

update to 127.0.6533.88 Critical CVE-2024-6990: Uninitialized Use in Dawn High CVE-2024-7255: Out of bounds read in WebTransport High CVE-2024-7256: Insufficient data validation in Dawn update to 127.0.6533.72

Update to upstream version 2.11.

Update to upstream version 2.11.

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

* bsc#1219296 * bsc#1220145 * bsc#1220211 * bsc#1220828 * bsc#1220832

* bsc#1214855 * bsc#1221916 * bsc#1228324 Cross-References:

Gross could be made to crash or to allow arbitrary code execution.

* bsc#1167721 Cross-References: * CVE-2019-20633

update to 127.0.6533.72 * CVE-2024-6988: Use after free in Downloads * CVE-2024-6989: Use after free in Loader * CVE-2024-6991: Use after free in Dawn * CVE-2024-6992: Out of bounds memory access in ANGLE

Several security issues were fixed in Tomcat.

https://security-tracker.debian.org/tracker/DSA-5735-1

Several security issues were fixed in Bind.

Several security issues were fixed in the Linux kernel.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1224788 Cross-References: * CVE-2024-35195

* bsc#1211674 Cross-References: * CVE-2023-32681

Several security issues were fixed in Python.

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 17.

Several security issues were fixed in OpenJDK 11.

Several security issues were fixed in OpenJDK 8.

Update to 1.3.3 https://github.com/hyprwm/xdg-desktop-portal-hyprland/releases/tag/v1.3.3

* bsc#1228184 Cross-References: * CVE-2024-40897

* bsc#916845 Cross-References: * CVE-2013-4235

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Affected Products: * openSUSE Leap 15.5

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in EDK II.

Several security issues were fixed in Lua.

https://security-tracker.debian.org/tracker/DSA-5734-2

The security update announced as DSA 5734-1 caused a regression on configurations using the Samba DLZ module. Updated packages are now available to correct this issue.

Update to 1.16 fixes rhbz#2259096

Update to 2.11.2

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Update to 1.16 fixes rhbz#2259096

Update to 2.11.2

https://security-tracker.debian.org/tracker/DSA-5734-1

* bsc#1222693 Cross-References: * CVE-2023-29483

* bsc#1198880 * bsc#1214678 Cross-References: * CVE-2022-28506

Update to 115.13.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-31/ https://www.thunderbird.net/en-US/thunderbird/115.13.0/releasenotes/

Backport upstream patch for CVE-2023-49606.

Update to v1.29.7 for FC40. Resolves CVE-2024-5321: Incorrect permissions on Windows containers logs. Additional bug and regression fixes from upstream.

Update to version 1.11.2 to fix CVE-2023-49606.

An update that fixes one vulnerability is now available.

Security fix for CVE-2024-5569 (rhbz#2297117)

New libxml2 packages are available for Slackware XXX 15.0 and -current to fix a security issue.

New htdig packages are available for Slackware 15.0 and -current to fix a security issue.

Update to 1.3.3 https://github.com/hyprwm/xdg-desktop-portal-hyprland/releases/tag/v1.3.3

Security fix for CVE-2024-5569 (rhbz#2297118)

Security fix for CVE-2024-33869 Security fixes for CVE-2024-29509, CVE-2024-29508, CVE-2024-29507, CVE-2024-29506

update xmedcon to 0.24.0 fixes: Bug 2283157 – xmedcon-0.24.0 is available Bug 2283100 – CVE-2024-29421 xmedcon: Heap overview when parsing DICOM medical files [fedora-all]

provd could be made to run programs as an administrator.

A vulnerability has been discovered in Freenet, which can lead to deanonymization due to path folding.

Multiple vulnerabilities have been discovered in ExifTool, the worst of which could lead to arbitrary code execution.

A vulnerability has been discovered in Dmidecode, which can lead to privilege escalation.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1227268 * bsc#1227269 * bsc#1227272 Cross-References:

* bsc#1219660 Cross-References: * CVE-2024-24577

* bsc#1219660 Cross-References: * CVE-2024-24577

* bsc#1214980 * bsc#1222804 * bsc#1222807 * bsc#1222811 * bsc#1222813

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

* bsc#1205628 Cross-References: * CVE-2022-4065

Several security issues were fixed in Thunderbird.

Update to 115.13.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-31/ https://www.thunderbird.net/en-US/thunderbird/115.13.0/releasenotes/

Memory corruption in WebGL API. (CVE-2024-6600) Race condition in permission assignment. (CVE-2024-6601) Memory corruption in thread creation. (CVE-2024-6603) Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13. (CVE-2024-6604)

Announcing v4.5.1 This release contains contributions from a record number of new contributors. This is greatly appreciated since I am a team of one, and do Tcpreplay maintenance in my spare time. There are many bug fixes and new features. Most notable features:

Backport fix for CVE-2023-49528 and backport fixes for compatibility with Mesa 24.0.6+ / 24.1.4+ for VA-API

update to 126.0.6478.182 High CVE-2024-6772: Inappropriate implementation in V8 High CVE-2024-6773: Type Confusion in V8 High CVE-2024-6774: Use after free in Screen Capture High CVE-2024-6775: Use after free in Media Stream

Announcing v4.5.1 This release contains contributions from a record number of new contributors. This is greatly appreciated since I am a team of one, and do Tcpreplay maintenance in my spare time. There are many bug fixes and new features. Most notable features:

An update that fixes 22 vulnerabilities is now available.

update to 126.0.6478.182 High CVE-2024-6772: Inappropriate implementation in V8 High CVE-2024-6773: Type Confusion in V8 High CVE-2024-6774: Use after free in Screen Capture High CVE-2024-6775: Use after free in Media Stream

Update to 3.0.4

New bugfix and security update

Rebase to v2.19.5

Update to 3.24.43

Update to 3.0.4

https://security-tracker.debian.org/tracker/DSA-5733-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

This is the July 2024 security update for .NET 6. Release Notes SDK: https://github.com/dotnet/core/blob/main/release- notes/6.0/6.0.32/6.0.132.md Runtime: https://github.com/dotnet/core/blob/main/release-

Fix for CVE-2024-38517.

Security fixes for https://nvd.nist.gov/vuln/detail/CVE-2024-38875 https://nvd.nist.gov/vuln/detail/CVE-2024-39329 https://nvd.nist.gov/vuln/detail/CVE-2024-3930 https://nvd.nist.gov/vuln/detail/CVE-2024-39614