Mageia 2023-0238: kernel-linus security update This kernel-linus update is based on upstream 5.15.120 and fixes atleast the following security issues: A flaw null pointer dereference in the Linux kernel DECnet networking protocol was found. A remote user could use this flaw to crash the…
Mageia 2023-0237: kernel security update This kernel update is based on upstream 5.15.120 and fixes atleast the following security issues: A flaw null pointer dereference in the Linux kernel DECnet networking protocol was found. A remote user could use this flaw to crash the…
Mageia 2023-0236: mingw-nsis security update Mishandles access control for an uninstaller directory. (CVE-2023-37378) References: - https://bugs.mageia.org/show_bug.cgi?id=32091 - https://www.debian.org/lts/security/2023/dla-3483…
Mageia 2023-0235: firefox/nss security update An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS (CVE-2023-37201). Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment…
Mageia 2023-0234: php security update Fixed SOAP bug GHSA-76gg-c692-v2mw (Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP). (CVE-2023-3247) References: - https://bugs.mageia.org/show_bug.cgi?id=32075…
Mageia 2023-0229: webkit2 security update Details not available at this time. (CVE-2022-48503) Memory corruption issue may lead to arbitrary code execution (CVE-2023-32435) Type confusion issue may lead to arbitrary code execution (CVE-2023-32439)…
Mageia 2023-0228: curaengine security update Denial of service due to integer overflow (CVE-2022-28041) References: - https://bugs.mageia.org/show_bug.cgi?id=32055 - https://lists.fedoraproject.org/archives/list/[email protected]/thread/SEQGDVH43YW7AG7TRU2CTU5TMIYP27WP/…
Mageia 2023-0227: golang security update Code injection via go command with cgo in cmd/go (CVE-2023-29402) Ignoring setuid/setgid bits. (CVE-2023-29403) Arbitrary code execution (CVE-2023-29404) Arbitrary code execution (CVE-2023-29405)…
Mageia 2023-0226: nodejs security update Current nodejs 14 branch in Mageia 8 is end of life and there are no more security updates. This release allows to move to the new nodejs 18 LTS branch and fixes the following CVEs…
Mageia 2023-0225: libreoffice security update Arbitrary File Write in hsqldb 1.8.0. (CVE-2023-1183) References: - https://bugs.mageia.org/show_bug.cgi?id=32042 - https://www.libreoffice.org/about-us/security/advisories/cve-2023-1183/…
Mageia 2023-0224: minidlna security update Out-of-bounds read/write due to buffer overflow (CVE-2023-33476) References: - https://bugs.mageia.org/show_bug.cgi?id=32041 - https://www.debian.org/security/2023/dsa-5434…
Mageia 2023-0212: xonotic security update A bug was discovered in versions older than 0.8.6 that is believed to be exploitable by malicious server admins to crash clients or, if they defeat mitigations, execute arbitrary code. No working exploit code is known to exist at this…
Mageia 2023-0211: python-tornado security update Remote unauthenticated attacker may redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL. (CVE-2023-28370) References:…
Mageia 2023-0210: python-requests security update Forwarding proxy credentials to the destination server unintentionally (CVE-2023-32681) References: - https://bugs.mageia.org/show_bug.cgi?id=32032…
Mageia 2023-0209: sofia-sip security update The OOB read and integer-overflow made by attacker may lead to crash, high consumption of memory or even other more serious consequences. (CVE-2023-32307) References:…
Mageia 2023-0208: sqlite security update os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working…
Mageia 2023-0207: docker-docker-registry security update Denail of service through excessive use of memory. (CVE-2023-2253) References: - https://bugs.mageia.org/show_bug.cgi?id=32017 - https://www.debian.org/security/2023/dsa-5414…
Mageia 2023-0203: sysstat security update Multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377. (CVE-2023-33204) References:…
Mageia 2023-0202: kernel-linus security update This kernel-linus update is based on upstream 5.15.117 and fixes atleast the following security issues: In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before replaying logs…
Mageia 2023-0201: kernel security update This kernel update is based on upstream 5.15.117 and fixes atleast the following security issues: In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before replaying logs…