Rozšírené hľadanie
Streda 8. Január 2025 |
meniny má Severín
Mageia 2024-0069: jackson-databind security update

17.03.2024 05:30 jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the

Mageia 2024-0068: batik security update

17.03.2024 05:30 The updated packages fix security vulnerabilities: Server-Side Request Forgery vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. Server-Side Request Forgery vulnerability in Batik of Apache XML

Fedora 38: chromium 2024-ac1eb810c5

16.03.2024 09:15 upstream security release 122.0.6261.128 High CVE-2024-2400: Use after free in Performance Manager

Fedora 38: python3.6 2024-ebb3c95344

16.03.2024 09:15 Security fix for CVE-2007-4559.

Fedora 38: opensc 2024-b92d44f141

16.03.2024 09:15 New upstream release with security fixes for CVE-2023-5992 and CVE-2024-1454

Mageia 2024-0067: jupyter-notebook security update

16.03.2024 09:15 Path traversal in moment.locale. Inefficient parsing algorithim resulting in DoS. References: - https://bugs.mageia.org/show_bug.cgi?id=30664

Fedora 39: python3.6 2024-d1f1084584

16.03.2024 09:15 Security fix for CVE-2007-4559.

Fedora 39: openvswitch 2024-a4530e9bfe

16.03.2024 09:15 Update to 3.2.2 It indirectly fix CVE-2023-3966 and CVE-2023-5366

Debian LTS: DLA-3761-1: spip security update

15.03.2024 23:01 Hatim Chabik discovered a cross-site scripting vulnerability in spip, a content management system, which can lead to privilege escalation or information disclosure.

SUSE: 2024:0908-1 moderate: 389-ds

15.03.2024 23:01 * bsc#1219836 Cross-References: * CVE-2024-1062

Debian: DSA-5632-1: composer security update

15.03.2024 23:01 It was discovered that composer, a dependency manager for the PHP language, processed files in the local working directory. This could lead to local privilege escalation or malicious code execution. Due to a technical issue this email was not sent on 2024-02-26 like it should

SUSE: 2024:0884-1 moderate: spectre-meltdown-checker

15.03.2024 23:01 * jsc#PED-2362 * jsc#SLE-5514 Cross-References: * CVE-2023-20593

SUSE: 2024:0885-1 moderate: spectre-meltdown-checker

15.03.2024 23:01 * jsc#PED-2362 * jsc#SLE-5514 Cross-References: * CVE-2023-20593

SUSE: 2024:0889-1 important: sudo

15.03.2024 23:01 * bsc#1221134 * bsc#1221151 Cross-References: * CVE-2023-42465

Mageia 2024-0062: mplayer security update

15.03.2024 12:31 The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function config of llibmpcodecs/vf_scale.c. Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record of mplayer/libmpdemux/asfheader.c.