Menu

Quote

* bsc#1224044 Cross-References: * CVE-2024-34397

Several security issues were fixed in eSpeak NG.

Multiple vulnerabilities have been discovered in GNU Emacs and Org Mode, the worst of which could lead to arbitrary code execution.

https://security-tracker.debian.org/tracker/DSA-5724-1

Mojolicious is a Perl Web Application Framework built around the familiar Model-View-Controller philosophy. It supports a simple single file mode via Mojolicious::Lite, RESTful routes, plugins, Perl-ish templates, session management, signed cookies, a testing framework, internationalization, first

Backport fix for CVE-2024-6239.

Update to 1.26.19, fixes CVE-2024-0444.

Update to 1.26.19, fixes CVE-2024-0444.

A vulnerability was discovered in GNU Emacs, the extensible, customisable, self-documenting display editor. The org-link-expand-abbrev function expanded a %(…) link abbrev even

A vulnerability was discovered in Org-mode, a GNU Emacs major mode for keeping notes, authoring documents, and maintaining to-do lists. The org-link-expand-abbrev function expanded a %(…) link abbrev even

rebuild for rhbz#2292712

Fix CVE-2024-2698 and CVE-2024-3183

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Multiple vulnerabilities havebenn fixed in DCMTK, a collection of libraries and applications implementing large parts the DICOM standard for medical images.

* bsc#1216896 * bsc#1216897 * bsc#1216899 * bsc#1216900

It was discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. (CVE-2019-11471) Reza Mirzazade Farkhani discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash

Possible out-of-bounds read or write when reading malformed MED files. (r19389). [Null-pointer write (32bit platforms) or excessive memory allocation (64bit platforms) when reading close to 4GiB of data from unseekable files (r20336, r20338).

Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image. References:

Update to Emacs 29.4, fixing CVE-2024-39331.

The 6.9.6 stable kernel update contains a number of important fixes across the tree.

Several security issues were fixed in FontForge.

Wget could be made to connect to a different host than expected.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

OpenSSL could be made to consume resources and cause long delays if it processed certain input.

update to 126.0.6478.126 High CVE-2024-6290: Use after free in Dawn High CVE-2024-6291: Use after free in Swiftshader High CVE-2024-6292: Use after free in Dawn High CVE-2024-6293: Use after free in Dawn

https://security-tracker.debian.org/tracker/DSA-5723-1

https://security-tracker.debian.org/tracker/DSA-5720-1

https://security-tracker.debian.org/tracker/DSA-5719-1

https://security-tracker.debian.org/tracker/DSA-5718-1

Several security issues were fixed in the Linux kernel.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Multiple vulnerabilities were found in git, a fast, scalable and distributed revision control system. CVE-2019-1387

libheif could be made to crash if it opened a specially crafted file.

https://security-tracker.debian.org/tracker/DSA-5721-1

https://security-tracker.debian.org/tracker/DSA-5722-1

* bsc#1065729 * bsc#1141539 * bsc#1174585 * bsc#1181674 * bsc#1187716

* bsc#1224158 Cross-References: * CVE-2017-17507 * CVE-2018-11205

* bsc#1224458 * bsc#1225552 Cross-References: * CVE-2024-4741

* bsc#1225491 Cross-References: * CVE-2024-33871

* bsc#1225491 Cross-References: * CVE-2024-33871

* bsc#1216594 * bsc#1216598 * bsc#1226586 Cross-References:

Hibernate could be made to expose sensitive information.

* bsc#1226134 Cross-References: * CVE-2024-37535

* bsc#1226423 Cross-References: * CVE-2024-38394

* bsc#1226423 Cross-References: * CVE-2024-38394

* bsc#1225971 Cross-References: * CVE-2024-20696

* bsc#1089090 Cross-References: * CVE-2018-9918

https://security-tracker.debian.org/tracker/DSA-5715-2

Use-after-free in networking. (CVE-2024-5702) Use-after-free in JavaScript object transplant. (CVE-2024-5688) External protocol handlers leaked by timing attack. (CVE-2024-5690) Sandboxed iframes were able to bypass sandbox restrictions to open a new window. (CVE-2024-5691)

This update includes a rebase from 9.0.83 to 9.0.89. #2269611 CVE-2024-24549 tomcat: CVE-2024-24549: Apache Tomcat: HTTP/2 header handling DoS #2269612 CVE-2024-23672 tomcat: Apache Tomcat: WebSocket DoS with incomplete closing handshake

New emacs packages are available for Slackware 15.0 and -current to fix a security issue.

Multiple vulnerabilities have been discovered in JHead, the worst of which may lead to arbitrary code execution.

A vulnerability has been discovered in LZ4, which can lead to memory corruption.

A vulnerability has been discovered in RDoc, which can lead to execution of arbitrary code.

A vulnerability has been discovered in Flatpak, which can lead to a sandbox escape.

A vulnerability has been discovered in GLib, which can lead to privilege escalation.

Update to 2.44.2: Make gamepads visible on axis movements, and not only on button presses. Disable the gst-libav AAC decoder. Make user scripts and style sheets visible in the Web Inspector. Use the geolocation portal where available, with the existing geoclue as

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1012628 * bsc#1065729 * bsc#1181674 * bsc#1187716 * bsc#1193599

* bsc#1127514 * bsc#1127855 * bsc#1131544 Cross-References:

* bsc#1220210 Cross-References: * CVE-2024-26130

* bsc#1203171 * bsc#1225997 * jsc#PED-7982 * jsc#PED-8018

* bsc#1133222 * bsc#1224158 Cross-References: * CVE-2017-17507

gdb could be made to crash if it opened a specially crafted file.

Version 2.7.7 2024-06-10 Security: Fixed command injection via malicious git branch name (GHSA-47f6-5gq3-vx9c / CVE-2024-35241) Security: Fixed multiple command injections via malicious git/hg branch names (GHSA-v9qv-c7wm-wgmf / CVE-2024-35242)

Fixing CVE-2023-51765 (smtp smuggling) requires to reject email that include NUL bytes, in some configuration. Previous security version of sendmail, by default, does not

A malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. References: – https://bugs.mageia.org/show_bug.cgi?id=33119

A sensitive data leakage vulnerability was identified in scikit-learn’s TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. The vulnerability arises from the unexpected storage of all tokens present in the training data within the `stop_words_` attribute, rather than only storing the subset

https://security-tracker.debian.org/tracker/DSA-5717-1

https://security-tracker.debian.org/tracker/DSA-5715-1

Huy Nguy¡»’n Ph¡º¡m Nh¡º­t, and Valentin T. and Lutz Wolf of CrowdStrike, discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not correctly process and sanitize requests. This would allow an attacker to perform Cross-Side Scripting (XSS) attacks.

* bsc#1226027 Cross-References: * CVE-2024-5688 * CVE-2024-5690

* bsc#1226007 Cross-References: * CVE-2023-52890

https://security-tracker.debian.org/tracker/DSA-5716-1

Git could be made to run programs as your login if it clones a crafted repository.

* bsc#1223252 Cross-References: * CVE-2024-30171

* bsc#1223852 Cross-References: * CVE-2023-52722

* bsc#1223979 Cross-References: * CVE-2024-34069

* bsc#1226020 Cross-References: * CVE-2024-5171

* bsc#1225551 Cross-References: * CVE-2024-4741

* bsc#1222849 Cross-References: * CVE-2024-32487

https://security-tracker.debian.org/tracker/DSA-5714-1

An out-of-bounds read in the ‘bson’ module allowed deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.

A symlink attack with emergency file saving has been fixed in the text editor nano. For Debian 10 buster, this problem has been fixed in version

* bsc#1219823 * bsc#1219826 * bsc#1219851 * bsc#1219852 * bsc#1219854

* bsc#1225551 Cross-References: * CVE-2024-4741

* bsc#1225551 Cross-References: * CVE-2024-4741

* bsc#1222857 * bsc#1222858 * bsc#1226073 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5712-1

Multiple security issues were discovered in Thunderbird, which could result inthe execution of arbitrary code. For the oldstable distribution (bullseye), these problems have been fixed

Security fix for CVE-2024-3049

https://security-tracker.debian.org/tracker/DSA-5713-1

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink. (CVE-2024-5742)

Use-after-free in networking. (CVE-2024-5702) Use-after-free in JavaScript object transplant. (CVE-2024-5688) External protocol handlers leaked by timing attack. (CVE-2024-5690) Sandboxed iframes were able to bypass sandbox restrictions to open a new window. (CVE-2024-5691)

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.