You are here
Security
DSA-5752-1 dovecot - security update
Two vulnerabilities have been discovered in the IMAP implementation of
the Dovecot mail server: Excessive numbers of address headers or very
large headers can result in high CPU usage, leading to denial of
service.
Categories: Security
DSA-5751-1 squid - security update
Joshua Rogers that incorrect parsing of ESI variables in the Squid proxy
caching server could result in memory corruption.
Categories: Security
DSA-5750-1 python-asyncssh - security update
Support for the "strict kex" SSH extension has been backported to
AsyncSSH (a Python implementation of the SSHv2 protocol) as hardening
against the Terrapin attack.
Categories: Security
DSA-5749-1 flatpak - security update
Chris Williams discovered a flaw in the handling of mounts for
persistent directories in Flatpak, an application deployment framework
for desktop apps. A malicious or compromised Flatpak app using
persistent directories could take advantage of this flaw to access files
outside of the sandbox.
Details can be found in the upstream advisory at https://github.com/flatpak/flatpak/security/advisories/GHSA-7hgv-f2j8-xw87
Categories: Security
DSA-5748-1 ffmpeg - security update
Several vulnerabilities have been discovered in the FFmpeg multimedia
framework, which could result in denial of service or potentially the
execution of arbitrary code if malformed files/streams are processed.
Categories: Security
DSA-5743-2 roundcube - security update
Multiple cross-site scripting vulnerabilities were discovered in
RoundCube webmail.
Categories: Security
DSA-5747-1 linux - security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
Categories: Security
DSA-5746-1 postgresql-13 - security update
Noah Misch discovered a race condition in the pg_dump tool included in
PostgreSQL, which may result in privilege escalation.
Categories: Security
DSA-5745-1 postgresql-15 - security update
Noah Misch discovered a race condition in the pg_dump tool included in
PostgreSQL, which may result in privilege escalation.
Categories: Security
DSA-5744-1 thunderbird - security update
Multiple security issues were discovered in Thunderbird, which could
result in denial of service or the execution of arbitrary code.
Categories: Security
DSA-5742-1 odoo - security update
A vulnerability was discovered in odoo, a suite of web based open
source business apps. It could result in the execution of arbitrary
code.
Categories: Security
DSA-5743-1 roundcube - security update
Multiple cross-site scripting vulnerabilities were discovered in
RoundCube webmail.
Categories: Security
DSA-5741-1 chromium - security update
Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Categories: Security
DSA-5740-1 firefox-esr - security update
Multiple security issues have been found in the Mozilla Firefox web
browser, which could potentially result in the execution of arbitrary
code, the bypass of sandbox restrictions or an information leak.
Categories: Security
DSA-5739-1 wpa - security update
Rory McNamara reported a local privilege escalation in wpasupplicant: A
user able to escalate to the netdev group can load arbitrary shared
object files in the context of the wpa_supplicant process running as
root.
Categories: Security
DSA-5738-1 openjdk-17 - security update
Several vulnerabilities have been discovered in the OpenJDK Java runtime,
which may result in denial of service, information disclosure or bypass
of Java sandbox restrictions.
Categories: Security
DSA-5737-1 libreoffice - security update
If LibreOffice failed to validate a signed macro, it displayed a warning
but still allowed execution of the script after printing a warning.
Going forward in high macro security mode such macros are now disabled.
For additional information please refer to https://www.libreoffice.org/about-us/security/advisories/cve-2024-6472/
Categories: Security
DSA-5736-1 openjdk-11 - security update
Several vulnerabilities have been discovered in the OpenJDK Java runtime,
which may result in denial of service, information disclosure or bypass
of Java sandbox restrictions.
Categories: Security
DSA-5735-1 chromium - security update
Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Categories: Security
DSA-5734-2 bind9 - regression update
The security update announced as DSA 5734-1 caused a regression on
configurations using the Samba DLZ module. Updated packages are now
available to correct this issue.
Categories: Security