Debian LTS Essential and Critical Security Patch Updates - Page 11
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
Security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in information disclosure or incorrect validation of password hashes.
A bug in libkf5ksieve, an email filtering library for KDE, exposed the user password in plaintext server logs. For Debian 10 buster, this problem has been fixed in version
Intel has released microcode updates, addressing serveral vulnerabilties. CVE-2023-22655
Out-of-bounds write in the iconv ISO-2022-CN-EXT module has been fixed in the GNU C library. For Debian 10 buster, this problem has been fixed in version
This is a routine update of the distro-info-data database for Debian LTS users. It adds Ubuntu 24.10.
Several issues have been found in qtbase-opensource-src, a collection of several Qt modules/libraries. The issues are related to buffer overflows, infinite loops or application
Bartek Nowotarskis discovered that nghttp2, a set of programs implementing the HTTP/2, keeps reading CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream, which could lead to Denial of Service.
It was discovered that there was a potential remote code execution vulnerability in Astropy, a suite of tools, utilities and Python utilities for astrophysics.
Multiple problems were discovered in Org-mode, a GNU Emacs major mode for keeping notes, authoring documents, and maintaining to-do lists. CVE-2024-30203 & CVE-2024-30204
Multiple problems were discovered in GNU Emacs, the extensible, customisable, self-documenting display editor. CVE-2024-30203 & CVE-2024-30204
Multiple vulnerabilities were fixed in ruby-rack, an interface for developing web applications in Ruby. CVE-2024-25126
Potential DoS attacks have been fixed by rate limiting HTTP/2 CONTINUATION frames in Apache Traffic Server, an HTTP/1.1 and HTTP/2 compliant caching proxy server.
Improper form input field validation has been fixed in Zabbix, a network monitoring solution. For Debian 10 buster, this problem has been fixed in version
Several vulnerabilities have been found in frr, the FRRouting suite of internet protocols. An attacker could craft packages to trigger buffer overflows with the possibility to gain remote code execution, buffer overreads, crashes or trick the software to enter an infinite loop.
Security vulnerabilities were found in mediawiki, a website engine for collaborative work, that could lead to information disclosure, privilege escalation, or denial of service.
Several security vulnerabilities have been discovered in knot-resolver, a caching, DNSSEC-validating DNS resolver which may allow remote attackers to bypass DNSSEC validation or cause a denial-of-service.
Putty, a Telnet/SSH client for X, was vulnerable. CVE-2019-17069
Several vulnerabilities were discovered in Samba, SMB/CIFS file, print, and login server for Unix CVE-2020-14318
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service or information disclosure. For Debian 10 buster, these problems have been fixed in version
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version