The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Contains fixes for regressions introduced during CVE bugfix update (3007.4).
5.22.9
5.22.9
An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute. (CVE-2024-56519) An issue was discovered in TCPDF …
Security fix for CVE-2023-52892, CVE-2024-27354
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
HTTP_REDIRECT_STATUS might be controlled via user request FPM log output might be modified by an attacker HTTP POST can be modified by an attacker For other bu…
A previously undocumented backdoor named Msupedge has been put to use against a cyber attack targeting an unnamed university in Taiwan."The most notable featur…
USN-6305-2 caused a regression in parsing XML.
* bsc#1226181 * bsc#1226182 Cross-References: * CVE-2024-35241
* bsc#1226181 * bsc#1226182 Cross-References: * CVE-2024-35241
https://www.mediawiki.org/wiki/Release_notes/1.41
Version 6.7.5 (2024-04-20) Update GitHub actions fix: CSV-2024-22640 (#712)
Core: - Corrupted memory in destructor with weak references - GC does not scale well with a lot of objects created in destructor DOM: - Add some missing ZPP ch…
Version 6.7.4 (2024-03-21) Upgrade tcpdf tag encryption algorithm. Version 6.7.3 (2024-03-20) Fix regression issue #699. Version 6.7.2 (2024-03-18)
* bsc#1219757 Cross-References: * CVE-2024-24821
Minor security note * The DSN support added in 6.8.0 reflects the DSN back to the user in an error message if it is invalid. If a DSN uses user-supplied input …
Libxml - GHSA-3qrf-m4j2-pcrr (Security issue with external entity loading in XML without enabling it). (CVE-2023-3823) Phar - GHSA-jqcx-ccgc-xwhv (Buffer misma…
Ubuntu security team noted after extensive testing that DLA-3495-1 was incomplete as one PoC for CVE-2022-2400 (particularly the chroot escape) was still worki…
Fixed SOAP bug GHSA-76gg-c692-v2mw (Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP). (CVE-2023-3247) References: - ht…
**Version 2.25.2** * This release provides a patch for **CVE-2023-29530** / GHSA-xv3h-4844-9h36 / LP2023-01.
Cross site scripting vulnerability in Javascript escaping. (CVE-2023-28447) Additional bug fixes included. See referenced release notes for details.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: