09.05.2024 22:45 GLib could be made to accept spoofed D-Bus signals.
09.05.2024 22:45 * bsc#1223100 Cross-References: * CVE-2023-3758
09.05.2024 22:45 * bsc#1223852 Cross-References: * CVE-2023-52722
09.05.2024 22:45 * bsc#1216853 Cross-References: * CVE-2023-38472
09.05.2024 22:45 * bsc#1222492 Cross-References: * CVE-2024-21506
09.05.2024 12:45 An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
09.05.2024 12:45 A flaw was found in the tpm2-tss package, where there was no check that the magic number in the attest is equal to the TPM2_GENERATED_VALUE. This flaw allows an attacker to generate arbitrary quote data, which may not be detected by Fapi_VerifyQuote.
09.05.2024 12:45 freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function. freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.
09.05.2024 12:45 The chromium-browser-stable package has been updated to the 124.0.6367.128 release. It includes 2 security fixes. Please, do note, only x86_64 is supported from now on. i586 support for linux was stopped some years ago and the community is not able to provide patches anymore for the latest Chromium code.
09.05.2024 12:45 Buffer overread vulnerability in StringIO. RCE vulnerability with .rdoc_options in RDoc. Arbitrary memory address read vulnerability with Regex search.
09.05.2024 12:45 Update to 2.11.7
09.05.2024 02:00 Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.
09.05.2024 02:00 Guido Vranken discovered an issue in python3-idna, a library to support the Internationalized Domain Names in Applications protocol. A specially crafted argument to the idna.encode function could consume significant resources, which may lead to Denial of Service.
09.05.2024 02:00 * bsc#1216644 * bsc#1219079 * bsc#1219435 * bsc#1220828
09.05.2024 02:00 * bsc#1219079 * bsc#1219435 * bsc#1220828 Cross-References: