You are here
News
DSA-5985-1 ffmpeg - security update
Several vulnerabilities have been discovered in the FFmpeg multimedia
framework, which could result in denial of service or potentially the
execution of arbitrary code if malformed files/streams are processed.
Categories: Security
DSA-5984-1 thunderbird - security update
Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.
Categories: Security
DSA-5983-1 qemu - security update
This update removes the usage of the C (Credential) flag for the
binfmt_misc registration within the qemu-user package, as it allowed for
privilege escalation when running a suid/sgid binary under qemu-user.
This means suid/sgid foreign-architecture binaries are not running with
elevated privileges under qemu-user anymore. If you relied on this
behavior of qemu-user in the past (running suid/sgid foreign-arch
binaries), this will require changes to your deployment.
In Bookworm the affected packages are qemu-user-static (and qemu-user-binfmt) instead of qemu-user.
Additionally, two security issues were fixed the in SR-IOV support of QEMU system emulation.
Categories: Security
