Menu

Quote

Multiple vulnerabilities were found in libvirt, a C toolkit to interact with the virtualization capabilities of Linux, which could lead to denial of service or information disclosure.

* bsc#1041090 * bsc#1084627 * bsc#1133158 * bsc#1172267 * bsc#1191783

Update to 2.53.18.2

Update to 2.53.18.2

Update to 2.53.18.2

Two security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting or denial of service.

Skyler Ferrante discovered that the wall tool from util-linux does not properly handle escape sequences from command line arguments. A local attacker can take advantage of this flaw for information disclosure.

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23. (CVE-2024-30202) In Emacs before 29.3, Gnus treats inline MIME contents as trusted. (CVE-2024-30203)

Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access. (CVE-2023-22655) Information exposure through microarchitectural state after transient

Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `–with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a

These are bug fix and security releases including MODERATE, HIGH, and CRITICAL issues.

release v1.11.0 release v1.10.1 release v1.10.0

https://security-tracker.debian.org/tracker/DSA-5650-1

https://security-tracker.debian.org/tracker/DSA-5651-1

podman-tui release v1.0.0 Security fix for [CVE-2024-28180]

x86: Register File Data Sampling [XSA-452, CVE-2023-28746] GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193]

Automatic update for cockpit-314-1.fc39.

This update contains security fixes for CVE-2024-29131 and CVE-2024-29133. See https://github.com/apache/commons-configuration/blob/master/RELEASE- NOTES.txt for changes in versions 2.10.0 and 2.10.1.

Security fix for CVE-2023-35936 and CVE-2023-38745 pandoc: backport fixes for CVE-2023-35936 and CVE-2023-38745 pandoc-cli: new package for pandoc binary

Security fix for CVE-2023-35936 and CVE-2023-38745 pandoc: backport fixes for CVE-2023-35936 and CVE-2023-38745 pandoc-cli: new package for pandoc binary

https://security-tracker.debian.org/tracker/DSA-5648-1

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

podman-tui release v1.0.0

Version 6.7.4 (2024-03-21) Upgrade tcpdf tag encryption algorithm. Version 6.7.3 (2024-03-20) Fix regression issue #699. Version 6.7.2 (2024-03-18)

This update contains security fixes for CVE-2024-29131 and CVE-2024-29133. See https://github.com/apache/commons-configuration/blob/master/RELEASE- NOTES.txt for changes in versions 2.10.0 and 2.10.1.

CVE-2024-2004: Usage of disabled protocol If all protocols are disabled at run-time with none being added, curl/libcurl would still allow communication with the default set of allowed protocols, including some that are unencrypted. CVE-2024-2398: HTTP/2 push headers memory-leak

update to 123.0.6312.86 Critical CVE-2024-2883: Use after free in ANGLE High CVE-2024-2885: Use after free in Dawn High CVE-2024-2886: Use after free in WebCodecs High CVE-2024-2887: Type Confusion in WebAssembly

https://security-tracker.debian.org/tracker/DSA-5649-1

* bsc#1218610 Cross-References: * CVE-2023-51779

* bsc#1218487 * bsc#1218610 Cross-References: * CVE-2023-51779

* bsc#1218487 Cross-References: * CVE-2023-6531

* bsc#1208911 * bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610

* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:

* bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610

Several security issues were fixed in curl.

* bsc#1221237 * bsc#1221468 Cross-References: * CVE-2024-1441

* bsc#1220770 * bsc#1220771 Cross-References: * CVE-2024-26458

* bsc#1144060 * bsc#1176006 * bsc#1188307 * bsc#1203823 * bsc#1205502

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:

* bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610

Several security issues were fixed in Thunderbird.

PAM could be made to stop responding if it opened a specially crafted file.

* bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610

* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5647-1

https://security-tracker.debian.org/tracker/DSA-5646-1

Stack-based buffer overflow has been fixed in gross, a server for greylisting emails. For Debian 10 buster, this problem has been fixed in version

QPDF could be made to crash or run programs if it opened a specially crafted file.

Net::CIDR::Lite could allow unintended access to network services.

It was discovered that there was a command-line injection issue in the FreeIPA identity, authentication and audit framework. A specially crafted HTTP request could have lead to a Denial of Service (DoS) attack and/or data exposure.

Several security issues were fixed in Firefox.

New upstream version (124.0.1)

https://security-tracker.debian.org/tracker/DSA-5645-1

Multiple security vulnerabilities have been discovered in Cacti, a web interface for graphing of monitoring systems, which could result in cross-site scripting, SQL injection, or command injection.

Buffer Overflow vulnerability in FreeImage_AllocateBitmap. (CVE-2023-47995) Infinite loop exits in Load in PluginTIFF.cpp. (CVE-2023-47997) References:

The updated package fixes security vulnerabilities: pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. (CVE-2023-30570) An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA

Patch CVE-2023-4256 and CVE-2023-43279

Updates google.golang.org/protobuf to v1.33.0 to resolve CVE-2024-24786. Kubernetes is now built with go 1.21.8.

Security fix for CVE-2024-22871 Update to upstream release 1.11.2

Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or leaks of encrypted email subjects.

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could […]

Update to version 2.13.1 Fix CVE-2024-28054

update to xen-4.18.1 rebase xen.gcc12.fixes.patch remove patches now included or superceded upstream x86: Register File Data Sampling [XSA-452, CVE-2023-28746] GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193]

Updated to 124.0 Updated to latest upstream (123.0.1)

Added upstream patch to fix out-of-bounds access due to multiple backspaces to address incomplete fix for CVE-2022-38223 (#2222775, #2222780, #2255207)

https://security-tracker.debian.org/tracker/DSA-5644-1

Graphviz could be made to crash if it opened a specially crafted config6a file.

* bsc#1221323 Cross-References: * CVE-2023-22655 * CVE-2023-28746

* bsc#1219357 * bsc#1219554 Cross-References: * CVE-2020-36773

* bsc#1219357 * bsc#1219554 Cross-References: * CVE-2020-36773

* bsc#1219465 Cross-References: * CVE-2023-3966

* bsc#1050549 * bsc#1186484 * bsc#1200599 * bsc#1212514 * bsc#1213456

A security flaw was found on rubygem-yard that documents generated by yard may be vulnerable to XSS attack. This issue is now assigned as CVE-2024-27285 . This new rpm is supposed to fix this issue.

Update to 4.14 for CVE-2024-2357, v6 SAN name and TFC padding fix for AEAD

Security fix for CVE-2024-1048

Update to 115.9.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-14/ https://www.thunderbird.net/en-US/thunderbird/115.9.0/releasenotes/

Update to 4.14 for CVE-2024-2357, v6 SAN name and TFC padding fix for AEAD

https://security-tracker.debian.org/tracker/DSA-5643-1

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-5641-1

A memory leak was found in imagemagick a popular software suite for displaying, creating, converting, modifying, and editing raster images. For Debian 10 buster, this problem has been fixed in version

Several security issues were fixed in Firefox.

The updated packages fix security vulnerabilities: Heap buffer overflow in sqlite. (CVE-2023-2137) A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler.

Updated to 124.0

Updated to 124.0

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

https://security-tracker.debian.org/tracker/DSA-5642-1

https://security-tracker.debian.org/tracker/DSA-5626-2

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Update to 2.6.1, backport fix for CVE-2024-28757.

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

* bsc#1219465 Cross-References: * CVE-2023-3966

* bsc#1213590 * bsc#1214686 * bsc#1214687 * bsc#1221187 * bsc#960589

Several security issues were fixed in OpenJDK 8.

Update to shim-15.8