Menu

Quote

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in EDK II.

update to 1.26.2

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several vulnerabilities were discovered in BIND, a DNS server implementation, which may result in denial of service. For the oldstable distribution (bullseye), these problems have been fixed

Two vulnerabilities were discovered in unbound, a validating, recursive, caching DNS resolver. Specially crafted DNSSEC answers could lead unbound down a very CPU intensive and time costly DNSSEC (CVE-2023-50387) or NSEC3 hash (CVE-2023-50868) validation path,

UltraJSON could be made to crash if it received specially crafted input.

https://security-tracker.debian.org/tracker/DSA-5620-1

https://security-tracker.debian.org/tracker/DSA-5621-1

Several security issues were fixed in WebKitGTK.

Glance_store could be made to expose sensitive information.

Several security issues were fixed in OpenSSL.

* bsc#1217654 * bsc#1219131 Cross-References: * CVE-2023-50269

Update to 1.0.5

* bsc#1218174 Affected Products: * Containers Module 15-SP5 * openSUSE Leap 15.5

Update to the latest stable version: Features Implement a new plugin manager from scratch to replace Yapsy, which does not work on Python 3.12 due to Python 3.12 carelessly removing parts of the standard library (Issue #3719)

Update to 121.0.6167.160 High CVE-2024-1284: Use after free in Mojo High CVE-2024-1283: Heap buffer overflow in Skia

Apply fix for CVE-2023-28531

Update to the latest stable version: Features Implement a new plugin manager from scratch to replace Yapsy, which does not work on Python 3.12 due to Python 3.12 carelessly removing parts of the standard library (Issue #3719)

Fix webkit_web_context_allow_tls_certificate_for_host to handle IPv6 URIs produced by SoupURI. Ignore stops with offset zero before last one when rendering gradients with cairo. Write bwrapinfo.json to disk for xdg-desktop-portal.

New version 4.0.12. Includes fixes for CVE-2023-5371, CVE-2023-6174, CVE-2023-6175, CVE-2024-0208.

Security fix for CVE-2024-21626

The updated packages fix security vulnerabilities: Logic bug in text extractor led to invalid memory access. (CVE-2022-30524) Integer overflow in rasterizer. (CVE-2022-30775) PDF object loop in Catalog::countPageTree. (CVE-2022-33108)

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

https://security-tracker.debian.org/tracker/DSA-5618-1

* bsc#1219048 Cross-References: * CVE-2023-50447

Several security issues were fixed in the Linux kernel.

Multiple denial of service vulnerabilities have been found in libxml2.

* bsc#1210638 Cross-References: * CVE-2023-27043

Upstream version 6.6.14 with many bugfixes and at least the following security fixes: An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.

fix gcc14 build error and another epub crash use https://github.com/mate-desktop/atril/commit/479e927 use https://github.com/mate-desktop/atril/commit/d901a9d update to 1.26.2 fix security security advisory

https://security-tracker.debian.org/tracker/DSA-5619-1

* bsc#1218303 Cross-References: * CVE-2023-6704

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-5617-1

Several security issues were fixed in the Linux kernel.

* bsc#1216044 * bsc#1217522 * bsc#1218255 Cross-References:

New expat packages are available for Slackware 15.0 and -current to fix security issues.

* bsc#1217522 * bsc#1218255 Cross-References: * CVE-2023-6176

* bsc#1210619 Cross-References: * CVE-2023-1829

* bsc#1218255 Cross-References: * CVE-2023-6932

* bsc#1217522 * bsc#1218255 Cross-References: * CVE-2023-6176

* bsc#1210619 * bsc#1218255 Cross-References: * CVE-2023-1829

* bsc#1210619 Cross-References: * CVE-2023-1829

https://security-tracker.debian.org/tracker/DSA-5616-1

* bsc#1217522 * bsc#1218255 Cross-References: * CVE-2023-6176

The 6.7.3 stable kernel rebase contains new features, improved hardware support, and a number of important fixes across the tree.

The 6.7.3 stable kernel rebase contains new features, improved hardware support, and a number of important fixes across the tree.

QtWebEngine 5.15.16 bugfix update.

The 6.7.3 stable kernel rebase contains new features, improved hardware support, and a number of important fixes across the tree.

The 6.7.3 stable kernel rebase contains new features, improved hardware support, and a number of important fixes across the tree.

Fixes CVE-2023-52339. No API or ABI changes.

update to 121.0.6167.139 * High CVE-2024-1060: Use after free in Canvas * High CVE-2024-1059: Use after free in WebRTC * High CVE-2024-1077: Use after free in Network

Update to 2.15.1.

Combined update for several fixes as well as security fix for CVE-2023-4001 “` Mon Jan 15 2024 Nicolas Frayer – 2.06-114 grub- core/commands: add flag to only search root dev Resolves: #2223437 Resolves: #2224951 Resolves: #2258096 Resolves: CVE-2023-4001 Sat Jan 13 2024 Hector Martin – 2.06-113 Switch memdisk compression to lzop

Fixes CVE-2023-52339. No API or ABI changes.

Security update for CVE-2024-23334 and CVE-2024-23829 https://github.com/aio- libs/aiohttp/releases/tag/v3.9.2 https://github.com/aio- libs/aiohttp/releases/tag/v3.9.3

Multiple vulnerabilities have been found in NBD Tools, the worst of which could result in arbitary code execution.

Multiple out-of-bounds read vulnerabilities have been discovered in Wireshark.

Multiple vulnerabilities have been found in OpenSSL, the worst of which could result in denial of service.

Multiple vulnerabilities have been found in Xen, the worst of which can lead to arbitrary code execution.

The updated packages fix security vulnerabilities: A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program

Out of bounds write in ANGLE. (CVE-2024-0741) Failure to update user input timestamp. (CVE-2024-0742) Crash when listing printers on Linux. (CVE-2024-0746)

https://security-tracker.debian.org/tracker/DSA-5615-1

Sudo, a program designed to allow a sysadmin to give limited root privileges to users and log root activity, was vulnerable. CVE-2023-7090

Multiple vulnerabilities have been discovered in FreeType, the worst of which can lead to remote code execution.

Multiple vulnerabilities have been discovered in Microsoft Edge, the worst of which could lead to remote code execution.

A vulnerability has been discovered in GNAT Ada Suite which can lead to remote code execution.

Multiple vulnerabilities have been discovered in QtGui which can lead to remote code execution.

A vulnerability has been discovered in SDDM which can lead to privilege escalation.

https://security-tracker.debian.org/tracker/DSA-5614-1

https://security-tracker.debian.org/tracker/DSA-5613-1

* bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053

* bsc#1140772 * bsc#1157446 * bsc#1170452 * bsc#1171862 * bsc#1215669

* bsc#1068950 * bsc#1081527 * bsc#1211052 * jsc#PED-6584

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051

* bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051

* bsc#1217654 * bsc#1219131 Cross-References: * CVE-2023-50269

* bsc#1218894 Cross-References: * CVE-2024-21626

* bsc#1218894 Cross-References: * CVE-2024-21626

Security fix for CVE-2023-6246, CVE-2023-6779, and CVE-2023-6780. CVE-2023-6246: __vsyslog_internal did not handle a case where printing a SYSLOG_HEADER containing a long program name failed to update the required buffer size, leading to the allocation and overflow of a too-small buffer on the heap. CVE-2023-6779: __vsyslog_internal used the return value of

Update to 115.7.0 * https://www.mozilla.org/en- US/security/advisories/mfsa2024-04/ * https://www.thunderbird.net/en- US/thunderbird/115.7.0/releasenotes/

Security fix for CVE-2023-6246, CVE-2023-6779, and CVE-2023-6780. CVE-2023-6246: __vsyslog_internal did not handle a case where printing a SYSLOG_HEADER containing a long program name failed to update the required buffer size, leading to the allocation and overflow of a too-small buffer on the heap. CVE-2023-6779: __vsyslog_internal used the return value of

https://security-tracker.debian.org/tracker/DSA-5612-1

Multiple vulnerabilities have been found in containerd, the worst of which could result in privilege escalation.

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218049 * bsc#1218050

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051

* bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053

* bsc#1216207 * bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050

https://security-tracker.debian.org/tracker/DSA-5610-1