Mageia 2023-0200: thunderbird security update Click-jacking certificate exceptions through rendering lag (CVE-2023-34414) Memory safety bugs fixed in Thunderbird 102.12 (CVE-2023-34416) References: - https://bugs.mageia.org/show_bug.cgi?id=31996…
Mageia 2023-0199: firefox/nss security update Click-jacking certificate exceptions through rendering lag. (CVE-2023-34414) Memory safety bugs fixed in Firefox 114 and Firefox ESR 102.12. (CVE-2023-34416)…
Mageia 2023-0198: cups security update A heap buffer overflow vulnerability would allow a remote attacker to launch a denial of service (DoS) attack. A buffer overflow vulnerability in the function 'format_log_line' could allow remote attackers to cause a DoS on the affected system. Exploitation of…
Mageia 2023-0197: webkit2 security update Out-of-bounds read (CVE-2023-28204) Use-after-free issue (CVE-2023-32373) References: - https://bugs.mageia.org/show_bug.cgi?id=31986…
Mageia 2023-0196: httpie security update Cookie exposure to third parties (CVE-2022-24737) References: - https://bugs.mageia.org/show_bug.cgi?id=30188 - https://lists.fedoraproject.org/archives/list/[email protected]/thread/R5VYSYKEKVZEVEBIWAADGDXG4Y3EWCQ3/…
Mageia 2023-0195: openssl security update Possible DoS translating ASN.1 object identifiers. (CVE-2023-2650) References: - https://bugs.mageia.org/show_bug.cgi?id=31981 - https://www.openssl.org/news/secadv/20230530.txt…
Mageia 2023-0194: libreoffice security update Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed…
Mageia 2023-0193: python-flask security update Client 'session' cookie sent to other clients (CVE-2023-30861) References: - https://bugs.mageia.org/show_bug.cgi?id=31953 - https://lists.suse.com/pipermail/sle-security-updates/2023-May/014935.html…
Mageia 2023-0192: vim security update Use of Out-of-range Pointer Offset in GitHub repository vim/vim. (CVE-2023-2426) References: - https://bugs.mageia.org/show_bug.cgi?id=31954…
Mageia 2023-0191: tomcat security update The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters…
Mageia 2023-0190: qtbase5 security update Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match. (CVE-2023-32762) QTextLayout buffer overflow in SVG…
Mageia 2023-0189: cups-filters security update Possible command injection in the Backend Error Handler (CVE-2023-24805) References: - https://bugs.mageia.org/show_bug.cgi?id=31939 - https://www.openwall.com/lists/oss-security/2023/05/17/5…
Mageia 2023-0188: tcpreplay security update An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt_cleanup function at plugins/dlt_plugins.c. (CVE-2023-27783) An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a…
Mageia 2023-0187: postgresql security update CREATE SCHEMA ... schema_element defeats protective search_path changes. (CVE-2023-2454) Row security policies disregard user ID changes after inlining. (CVE-2023-2455)…
Mageia 2023-0186: python-reportlab security update Updates python3-reportlab includes a security fix and other minor bug fixes. See references for details. References: - https://bugs.mageia.org/show_bug.cgi?id=31927…
Mageia 2023-0185: mariadb security update It is possible for function spider_db_mbase::print_warnings to dereference a null pointer. (CVE-2022-47015) References: - https://bugs.mageia.org/show_bug.cgi?id=31920…
Mageia 2023-0184: libssh security update Potential NULL dereference during rekeying with algorithm guessing. (CVE-2023-1667) Authorization bypass in pki_verify_data_signature. (CVE-2023-2283 References:…
Mageia 2023-0183: python-sqlparse security update ReDoS (Regular Expression Denial of Service) (CVE-2023-30608) References: - https://bugs.mageia.org/show_bug.cgi?id=31913 - https://ubuntu.com/security/notices/USN-6064-1…
Mageia 2023-0182: freetype2 security update An integer overflow vulnerability was discovered in Freetype in tt_hvadvance_adjust() function in src/truetype/ttgxvar.c. (CVE-2023-2004) References: - https://bugs.mageia.org/show_bug.cgi?id=31887…
Mageia 2023-0181: cmark security update cmark incorrectly handled certain inputs. Fixes quadratic complexity in handle_close_bracket "![[]()" which may lead to a denial of service (CVE-2023-22486). Noting that this also fixes a quadratic parsing issue with repeated…