* bsc#1220145 * bsc#1223363 * bsc#1223681 * bsc#1223683 * bsc#1225211
* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059
* bsc#1210619 * bsc#1220537 * bsc#1223363 * bsc#1223683 * bsc#1225211
stunnel could allow unintended access to network services.
* bsc#1224122 Cross-References: * CVE-2024-3727
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
https://security-tracker.debian.org/tracker/DSA-5732-1
https://security-tracker.debian.org/tracker/DSA-5731-1
* bsc#1227399 Cross-References: * CVE-2024-34750
* bsc#1225771 Cross-References: * CVE-2024-5564
* bsc#1222665 * bsc#1227554 * bsc#1227560 Cross-References:
* bsc#1227554 * bsc#1227560 * bsc#1227561 * bsc#1227562 * bsc#1227563
This update fixes multiple CVEs and rebases to the latest upstream version: * Tue Jul 09 2024 Julien Rische – 1.21.3-1 – New upstream version (1.21.3) – CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c Resolves: rhbz#2266732
This update fixes CVE-2024-24791
https://security-tracker.debian.org/tracker/DSA-5730-1
Several security issues were fixed in the Linux kernel.
* bsc#1220145 * bsc#1223363 * bsc#1223681 * bsc#1223683
Several security issues were fixed in the Linux kernel.
An update that fixes three vulnerabilities is now available.
Several security issues were fixed in the Linux kernel.
* bsc#1215420 * bsc#1220833 * bsc#1221656 * bsc#1221659 * bsc#1222005
* bsc#1221530 Cross-References: * CVE-2024-21503
* bsc#1223363 * bsc#1223683 Cross-References: * CVE-2024-26828
* bsc#1224122 * bsc#1226136 Cross-References: * CVE-2024-24786
Vanilla upstream kernel version 6.6.37 fix bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33374
Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack. (CVE-2024-37894) References:
This vulnerability allows an attacker performing a meddler-in-the-middle attack between Palo Alto Networks PAN-OS firewall and a RADIUS server to bypass authentication and escalate privileges to Ā¢”superuserĀ¢” when RADIUS authentication is in use and either CHAP or PAP is selected in the RADIUS server profile.
* bsc#1216377 Cross-References: * CVE-2023-45803
* bsc#1189936 * bsc#1190531 * bsc#935380 Cross-References:
Upstream kernel version 6.6.37 fix bugs and vulnerabilities. The dwarves, kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.
This update fixes multiple CVEs and rebases to the latest upstream version: * Tue Jul 09 2024 Julien Rische – 1.21.3-1 – New upstream version (1.21.3) – CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c Resolves: rhbz#2266732
Backport fix for CVE-2024-4067.
Backport security fixes for CVE-2024-4216, CVE-2024-4068, CVE-2024-4067.
https://security-tracker.debian.org/tracker/DSA-5729-1
* bsc#1226448 Cross-References: * CVE-2024-4032
* bsc#1226495 * bsc#1227239 Cross-References: * CVE-2024-34703
Several security issues were fixed in the Linux kernel.
Backport fix for CVE-2024-4032.
Backport fix for CVE-2024-4032.
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-5728-1
https://security-tracker.debian.org/tracker/DSA-5727-1
* bsc#1223363 * bsc#1223683 Cross-References: * CVE-2024-26828
* bsc#1220145 * bsc#1223363 * bsc#1223683 * bsc#1225211
Updated to latest upstream (128.0)
Fix CVE-2024-39936.
Security fix for CVE-2024-5187
This is the May 2024 release for .NET 8. This is a security update for .NET 8. Release notes: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.5/8.0.5.md
* bsc#1224123 Cross-References: * CVE-2024-3727
* bsc#1220145 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1223059
* bsc#1119113 * bsc#1191958 * bsc#1195065 * bsc#1195254 * bsc#1195775
Several security issues were fixed in Firefox.
Multiple vulnerabilities have been discovered in Buildah, the worst of which could lead to privilege escalation.
Several security issues were fixed in dotnet6, dotnet8.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Multiple vulnerabilities have been discovered in LIVE555 Media Server, the worst of which could lead to a denial of service.
* bsc#1222045 Cross-References: * CVE-2024-29025
* bsc#1223965 Cross-References: * CVE-2024-33394
* bsc#1226469 Cross-References: * CVE-2024-37891
An update that fixes 7 vulnerabilities is now available.
Update to 2024.07.02
https://security-tracker.debian.org/tracker/DSA-5726-1
A vulnerability has been discovered in Stellarium, which can lead to arbitrary file writes.
Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which could arbitrary code execution.
Multiple vulnerabilities have been discovered in the X.Org X11 library, the worst of which could lead to a denial of service.
A vulnerability has been discovered in KDE Plasma Workspaces, which can lead to privilege escalation.
Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.
Two vulnerabilities were discovered in the GSS message token handling in krb5, the MIT implementation of Kerberos. An attacker can take advantage of these flaws to bypass integrity protections or cause a denial of service.
Multiple vulnerabilities have been discovered in BusyBox, the worst of which could lead to arbitrary code execution.
A vulnerability has been discovered in Coreutils, which can lead to a heap buffer overflow and possibly aribitrary code execution.
* bsc#1227186 * bsc#1227187 Cross-References: * CVE-2024-37370
Multiple vulnerabilities have been discovered in GraphicsMagick, the worst of which could lead to arbitrary code execution.
Multiple vulnerabilities have been discovered in TigerVNC, the worst of which could lead to remote code execution.
Multiple vulnerabilities have been discovered in WebKitGTK+, the worst of which could lead to arbitrary code execution
https://security-tracker.debian.org/tracker/DSA-5725-1
* bsc#1226642 Cross-References: * CVE-2024-6387
* bsc#1222050 * bsc#1222052 * bsc#1222053 * bsc#1226957
* bsc#1219217 * bsc#1220266 Cross-References: * CVE-2024-0914
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1225771 Cross-References: * CVE-2024-5564
* bsc#1227052 Cross-References: * CVE-2024-6104
* bsc#1213720 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5
* bsc#1224282 Cross-References: * CVE-2024-34459
Several security issues were fixed in Firefox.
* bsc#1224282 Cross-References: * CVE-2024-34459
USN-6851-1 caused systemctl enable to fail
USN-6844-1 caused the cupsd daemon to never start
* bsc#1226448 Cross-References: * CVE-2024-4032
* bsc#1224279 * bsc#1224309 Cross-References: * CVE-2024-3044
* bsc#1224279 * bsc#1224309 Cross-References: * CVE-2024-3044
OpenSSH could be made to bypass authentication and remotely access systems without proper credentials.
The Qualys Threat Research Unit (TRU) discovered that OpenSSH, an implementation of the SSH protocol suite, is prone to a signal handler race condition. If a client does not authenticate within LoginGraceTime seconds (120 by default), then sshd’s SIGALRM handler is called
* bsc#1223965 Cross-References: * CVE-2024-33394
