Explore top 10 tips to secure your open-source projects now. Read More
×
Matteo Memelli discovered a flaw in lldpd, an implementation of the IEEE 802.1ab protocol. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3578-1
An update that contains security fixes can now be installed. . openSUSE Security Update: Security update for xonotic ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0162-1 Rating: moderate References: #1212632 Affected Products: openSUSE Backports SLE-15-SP4 openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for xonotic fixes the following issues: Update to version 0.8.6 SECURITY ALERT: A bug was discovered in versions older than 0.8.6 that is believed to be exploitable by malicious server admins to crash clients or, if they defeat mitigations, execute arbitrary code. (boo#1212632) update to 0.8.5: * https://xonotic.org/posts/2022/xonotic-0-8-5-release/ Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-162=1 - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-162=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 ppc64le s390x x86_64): xonotic-0.8.6-bp155.2.3.1 xonotic-debuginfo-0.8.6-bp155.2.3.1 xonotic-debugsource-0.8.6-bp155.2.3.1 xonotic-server-0.8.6-bp155.2.3.1 xonotic-server-debuginfo-0.8.6-bp155.2.3.1 - openSUSE Backports SLE-15-SP5 (noarch): xonotic-data-0.8.6-bp155.2.3.1 - openSUSE Backports SLE-15-SP4 (aarch64 ppc64le s390x x86_64): xonotic-0.8.6-bp154.3.3.1 xonotic-server-0.8.6-bp154.3.3.1 - openSUSE Backports SLE-15-SP4 (noarch): xonotic-data-0.8.6-bp154.3.3.1 References: https://bugzilla.suse.com/1212632 . A security patch forxonotic resolves a vulnerability that could enable code execution by rogue server operators.. openSUSE,xonotic,security update,exploit fix,software patch. . LinuxSecurity.com Team
XBoard 4.2.6 and older contains a script which writes to a file in /tmp with a predictable filename. Malicious users could use this vulnerability to force XBoard users to overwrite any file writableby them. . ---------------------------------------------------------------------Fedora Update Notification FEDORA-2003-031 2003-12-04 ---------------------------------------------------------------------Name : xboard Version : 4.2.7 Release : 1 Summary : An X Window System graphical chessboard. Description : Xboard is an X Window System based graphical chessboard which can be used with the GNUchess and Crafty chess programs, with Internet Chess Servers (ICSs), with chess via email, or with your own saved games. Install the xboard package if you need a graphical chessboard. ---------------------------------------------------------------------Update Information: XBoard 4.2.6 and older contains a script which writes to a file in /tmp with a predictable filename. Malicious users could use this vulnerability to force XBoard users to overwrite any file writable by them. ---------------------------------------------------------------------* Thu Dec 04 2003 Karsten Hopp 4.2.7-1 - update to 4.2.7 ---------------------------------------------------------------------This update can be downloaded from: c9ee7f4bfdc30da49d4e4e968baf4512 SRPMS/xboard-4.2.7-1.src.rpm ed2216de0ce24bf9d18423e5eb94d734 i386/xboard-4.2.7-1.i386.rpm c22f3442cbd928378ace8d4aaaf4681f i386/debug/xboard-debuginfo-4.2.7-1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . XBoard versions 4.2.6 and prior possess a recognized vulnerability regarding file writing on Fedora platforms. To enhance your security, please update to version 4.2.7.. XBoard Exploit, Predictable File Write, Fedora Update, Exploit Fix. . LinuxSecurity.com Team
High CVE-2023-1213: Use after free in Swiftshader. Reported by Jaehun Jeong(@n3sk) of Theori on 2023-01-30 High CVE-2023-1214: Type Confusion in V8. Reported by Man Yue Mo of GitHub Security Lab on 2023-02-03 . MGASA-2023-0090 - Updated chromium-browser-stable packages fix security vulnerability Publication date: 11 Mar 2023 URL: https://advisories.mageia.org/MGASA-2023-0090.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-1213, CVE-2023-1214, CVE-2023-1215, CVE-2023-1216, CVE-2023-1217, CVE-2023-1218, CVE-2023-1219, CVE-2023-1220, CVE-2023-1221, CVE-2023-1222, CVE-2023-1223, CVE-2023-1224, CVE-2023-1225, CVE-2023-1226, CVE-2023-1227, CVE-2023-1228, CVE-2023-1229, CVE-2023-1230, CVE-2023-1231, CVE-2023-1232, CVE-2023-1233, CVE-2023-1234, CVE-2023-1235, CVE-2023-1236 High CVE-2023-1213: Use after free in Swiftshader. Reported by Jaehun Jeong(@n3sk) of Theori on 2023-01-30 High CVE-2023-1214: Type Confusion in V8. Reported by Man Yue Mo of GitHub Security Lab on 2023-02-03 High CVE-2023-1215: Type Confusion in CSS. Reported by Anonymous on 2023-02-17 High CVE-2023-1216: Use after free in DevTools. Reported by Ganjiang Zhou(@refrain_areu) of ChaMd5-H1 team on 2023-02-21 High CVE-2023-1217: Stack buffer overflow in Crash reporting. Reported by sunburst of Ant Group Tianqiong Security Lab on 2023-02-03 High CVE-2023-1218: Use after free in WebRTC. Reported by Anonymous on 2023-02-07 High CVE-2023-1219: Heap buffer overflow in Metrics. Reported by Sergei Glazunov of Google Project Zero on 2023-02-13 High CVE-2023-1220: Heap buffer overflow in UMA. Reported by Sergei Glazunov of Google Project Zero on 2023-02-17 Medium CVE-2023-1221: Insufficient policy enforcement in Extensions API. Reported by Ahmed ElMasry on 2022-11-16 Medium CVE-2023-1222: Heap buffer overflow in Web Audio API. Reported by Cassidy Kim(@cassidy6564) on 2022-12-24 Medium CVE-2023-1223: Insufficient policyenforcement in Autofill. Reported by Ahmed ElMasry on 2022-12-07 Medium CVE-2023-1224: Insufficient policy enforcement in Web Payments API. Reported by Thomas Orlita on 2022-12-25 Medium CVE-2023-1225: Insufficient policy enforcement in Navigation. Reported by Roberto Ffrench-Davis @Lihaft on 2023-01-20 Medium CVE-2023-1226: Insufficient policy enforcement in Web Payments API. Reported by Anonymous on 2019-10-10 Medium CVE-2023-1227: Use after free in Core. Reported by @ginggilBesel on 2022-07-31 Medium CVE-2023-1228: Insufficient policy enforcement in Intents. Reported by Axel Chong on 2022-09-18 Medium CVE-2023-1229: Inappropriate implementation in Permission prompts. Reported by Thomas Orlita on 2020-12-20 Medium CVE-2023-1230: Inappropriate implementation in WebApp Installs. Reported by Axel Chong on 2022-12-30 Medium CVE-2023-1231: Inappropriate implementation in Autofill. Reported by Yan Zhu, Brave on 2021-11-30 Low CVE-2023-1232: Insufficient policy enforcement in Resource Timing. Reported by Sohom Datta on 2022-07-24 Low CVE-2023-1233: Insufficient policy enforcement in Resource Timing. Reported by Soroush Karami on 2020-01-25 Low CVE-2023-1234: Inappropriate implementation in Intents. Reported by Axel Chong on 2023-01-03 Low CVE-2023-1235: Type Confusion in DevTools. Reported by raven at KunLun lab on 2023-01-03 Low CVE-2023-1236: Inappropriate implementation in Internals. Reported by Alesandro Ortiz on 2022-10-14 References: - https://bugs.mageia.org/show_bug.cgi?id=31645 - https://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop.html - - https://www.cve.org/CVERecord?id=CVE-2023-1213 - https://www.cve.org/CVERecord?id=CVE-2023-1214 - https://www.cve.org/CVERecord?id=CVE-2023-1215 - https://www.cve.org/CVERecord?id=CVE-2023-1216 - https://www.cve.org/CVERecord?id=CVE-2023-1217 - https://www.cve.org/CVERecord?id=CVE-2023-1218 - https://www.cve.org/CVERecord?id=CVE-2023-1219 - https://www.cve.org/CVERecord?id=CVE-2023-1220 -https://www.cve.org/CVERecord?id=CVE-2023-1221 - https://www.cve.org/CVERecord?id=CVE-2023-1222 - https://www.cve.org/CVERecord?id=CVE-2023-1223 - https://www.cve.org/CVERecord?id=CVE-2023-1224 - https://www.cve.org/CVERecord?id=CVE-2023-1225 - https://www.cve.org/CVERecord?id=CVE-2023-1226 - https://www.cve.org/CVERecord?id=CVE-2023-1227 - https://www.cve.org/CVERecord?id=CVE-2023-1228 - https://www.cve.org/CVERecord?id=CVE-2023-1229 - https://www.cve.org/CVERecord?id=CVE-2023-1230 - https://www.cve.org/CVERecord?id=CVE-2023-1231 - https://www.cve.org/CVERecord?id=CVE-2023-1232 - https://www.cve.org/CVERecord?id=CVE-2023-1233 - https://www.cve.org/CVERecord?id=CVE-2023-1234 - https://www.cve.org/CVERecord?id=CVE-2023-1235 - https://www.cve.org/CVERecord?id=CVE-2023-1236 SRPMS: - 8/core/chromium-browser-stable-111.0.5563.64-1.mga8 . Important modifications issued for chromium-browser-stable correcting various concerns such as memory leaks and type misalignment.. Chromium Browser Security, Mageia 8 Updates, Browser Exploit Fixes. . Severity: Critical. LinuxSecurity.com Team
This kernel-linus update is based on upstream 5.15.88 and fixes atleast the following security issues: A use-after-free flaw was found in the Linux kernelâs SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, . MGASA-2023-0008 - Updated kernel-linus packages fix security vulnerabilities Publication date: 22 Jan 2023 URL: https://advisories.mageia.org/MGASA-2023-0008.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-3424, CVE-2022-3534, CVE-2022-3545, CVE-2022-3643, CVE-2022-36280, CVE-2022-41218, CVE-2022-45934, CVE-2022-47929, CVE-2023-0210, CVE-2023-0266, CVE-2023-23454, CVE-2023-23455 This kernel-linus update is based on upstream 5.15.88 and fixes atleast the following security issues: A use-after-free flaw was found in the Linux kernelâs SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_assignment function. This flaw allows a local user to crash or potentially escalate their privileges on the system (CVE-2022-3424). A vulnerability in the function btf_dump_name_dups of the file tools/lib/bpf/ btf_dump.c of the component libbpf. This flaw allows a manipulation that may lea to a use-after-free issue (CVE-2022-3534). A vulnerability was found in area_cache_get in drivers/net/ethernet/ netronome/nfp/nfpcore/nfp_cppcore.c in the Netronome Flow Processor (NFP) driver in the Linux kernel. This flaw allows a manipulation that may lead to a use-after-free issue (CVE-2022-3545). Guests can trigger NIC interface reset/abort/crash via netback. It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appearsto be an (unwritten?) assumption in the rest of the Linux network stack that packet protocol headers are all contained within the linear section of the SKB and some NICs behave badly if this is not the case. Thishas been reported to occur with Cisco (enic) and Broadcom NetXtrem II BCM5780 (bnx2x) though it may be an issue with other NICs/drivers as well. In case the frontend is sending requests with split headers, netback will forward those violating above mentioned assumption to the networking core, resulting in said misbehavior (CVE-2022-3643, XSA-423). An out-of-bounds memory write vulnerability was found in the Linux kernel vmwgfx driver in vmw_kms_cursor_snoop due to a missing check of a memcpy length. This flaw allows a local, unprivileged attacker with access to either the /dev/dri/card0 or /dev/dri/rendererD128 and able to issue an ioctl() on the resulting file descriptor, to crash the system, causing a denial of service (CVE-2022-36280). A use-after-free flaw was found in the Linux kernelâs dvb-core subsystem (DVB API used by Digital TV devices) in how a user physically removed a USB device (such as a DVB demultiplexer device) while running malicious code. This flaw allows a local user to crash or potentially escalate their privileges on the system (CVE-2022-41218). An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets (CVE-2022-45934). In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc qdisc" and "tc class" commands. This affects qdisc_graft in net/sched/sch_api.c (CVE-2022-47929). A vulnerability in the kernel ksmbd allows a remote attacker to perform a denial of service (DoS) attack. The vulnerability exists due to a boundary error within the ksmbd_decode_ntlmssp_auth_blob() function in ksmbd when handling NTLMv2 authentication. A remote attacker can send specially crafted data to ksmbd, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack (CVE-2023-0210). ALSA: pcm: Move rwsemlock inside snd_ctl_elem_read to prevent UAF (CVE-2023-0266). cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results) (CVE-2023-23454). atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results) (CVE-2023-23455). For other upstream fixes in this update, see the referenced changelogs. References: - https://bugs.mageia.org/show_bug.cgi?id=31406 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.83 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.84 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.85 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.86 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.87 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.88 - https://xenbits.xenproject.org/xsa/advisory-423.txt - https://www.cve.org/CVERecord?id=CVE-2022-3424 - https://www.cve.org/CVERecord?id=CVE-2022-3534 - https://www.cve.org/CVERecord?id=CVE-2022-3545 - https://www.cve.org/CVERecord?id=CVE-2022-3643 - https://www.cve.org/CVERecord?id=CVE-2022-36280 - https://www.cve.org/CVERecord?id=CVE-2022-41218 - https://www.cve.org/CVERecord?id=CVE-2022-45934 - https://www.cve.org/CVERecord?id=CVE-2022-47929 - https://www.cve.org/CVERecord?id=CVE-2023-0210 - https://www.cve.org/CVERecord?id=CVE-2023-0266 - https://www.cve.org/CVERecord?id=CVE-2023-23454 - https://www.cve.org/CVERecord?id=CVE-2023-23455 SRPMS: - 8/core/kernel-linus-5.15.88-1.mga8 . Mageia 2023-0009 rectifies significant gcc vulnerabilities, bolstering operational integrity through a series of patches.. Kernel-Linus Update, Security Patches, System Exploits, CriticalVulnerabilities. . Severity: Critical. LinuxSecurity.com Team
This update provides the upstream 6.1.36 maintenance release that fixes at least the following security vulnerabilities: A vulnerability in the Oracle VM VirtualBox prior to 6.1.36 contains an easily exploitable vulnerability that allows a high privileged attacker . MGASA-2022-0265 - Updated virtualbox packages fix security vulnerabilities Publication date: 25 Jul 2022 URL: https://advisories.mageia.org/MGASA-2022-0265.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-21554, CVE-2022-21571 This update provides the upstream 6.1.36 maintenance release that fixes at least the following security vulnerabilities: A vulnerability in the Oracle VM VirtualBox prior to 6.1.36 contains an easily exploitable vulnerability that allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox (CVE-2022-21554). A vulnerability in the Oracle VM VirtualBox prior to 6.1.36 contains an easily exploitable vulnerability that allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox (CVE-2022-21571). For other fixes in this update, see the referenced changeelog References: - https://bugs.mageia.org/show_bug.cgi?id=30657 - https://www.oracle.com/security-alerts/cpujul2022.html#AppendixOVIR - - https://www.cve.org/CVERecord?id=CVE-2022-21554 - https://www.cve.org/CVERecord?id=CVE-2022-21571 SRPMS: - 8/core/virtualbox-6.1.36-1.mga8 - 8/core/kmod-virtualbox-6.1.36-1.mga8 . The recent update for Oracle VM VirtualBox addresses securityvulnerabilities identified as CVE-2022-21554 and CVE-2022-21571, enhancing protection for users.. Oracle VirtualBox Update, Mageia Security Patch, VirtualBox Exploit Fixes. . Severity: Critical. LinuxSecurity.com Team
An update that fixes 10 vulnerabilities is now available. . SUSE Security Update: Security update for MozillaThunderbird ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2320-1 Rating: important References: #1200793 Cross-References: CVE-2022-2200 CVE-2022-2226 CVE-2022-31744 CVE-2022-34468 CVE-2022-34470 CVE-2022-34472 CVE-2022-34478 CVE-2022-34479 CVE-2022-34481 CVE-2022-34484 Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Storage 7.1 SUSE Linux Enterprise Workstation Extension 15-SP3 SUSE Linux Enterprise Workstation Extension 15-SP4 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.2 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.2 SUSE Manager Server 4.3 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes 10 vulnerabilities is now available. Description: This update for MozillaThunderbird fixes the following issues: -CVE-2022-2200: Undesired attributes could be set as part of prototype pollution (bmo#1771381) - CVE-2022-2226: An email with a mismatching OpenPGP signature date was accepted as valid (bmo#1775441) - CVE-2022-31744: CSP bypass enabling stylesheet injection (bmo#1757604) - CVE-2022-34468: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI (bmo#1768537) - CVE-2022-34470: Use-after-free in nsSHistory (bmo#1765951) - CVE-2022-34472: Unavailable PAC file resulted in OCSP requests being blocked (bmo#1770123) - CVE-2022-34478: Microsoft protocols can be attacked if a user accepts a prompt (bmo#1773717) - CVE-2022-34479: A popup window could be resized in a way to overlay the address bar with web content (bmo#1745595) - CVE-2022-34481: Potential integer overflow in ReplaceElementsAt (bmo#1497246) - CVE-2022-34484: Memory safety bugs fixed in Thunderbird 91.11 and Thunderbird 102 (bmo#1763634, bmo#1772651) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-2320=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-2320=1 - SUSE Linux Enterprise Workstation Extension 15-SP4: zypper in -t patch SUSE-SLE-Product-WE-15-SP4-2022-2320=1 - SUSE Linux Enterprise Workstation Extension 15-SP3: zypper in -t patch SUSE-SLE-Product-WE-15-SP3-2022-2320=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2022-2320=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP3-2022-2320=1 Package List: - openSUSE Leap 15.4 (aarch64ppc64le s390x x86_64): MozillaThunderbird-91.11.0-150200.8.76.1 MozillaThunderbird-debuginfo-91.11.0-150200.8.76.1 MozillaThunderbird-debugsource-91.11.0-150200.8.76.1 MozillaThunderbird-translations-common-91.11.0-150200.8.76.1 MozillaThunderbird-translations-other-91.11.0-150200.8.76.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): MozillaThunderbird-91.11.0-150200.8.76.1 MozillaThunderbird-debuginfo-91.11.0-150200.8.76.1 MozillaThunderbird-debugsource-91.11.0-150200.8.76.1 MozillaThunderbird-translations-common-91.11.0-150200.8.76.1 MozillaThunderbird-translations-other-91.11.0-150200.8.76.1 - SUSE Linux Enterprise Workstation Extension 15-SP4 (x86_64): MozillaThunderbird-91.11.0-150200.8.76.1 MozillaThunderbird-debuginfo-91.11.0-150200.8.76.1 MozillaThunderbird-debugsource-91.11.0-150200.8.76.1 MozillaThunderbird-translations-common-91.11.0-150200.8.76.1 MozillaThunderbird-translations-other-91.11.0-150200.8.76.1 - SUSE Linux Enterprise Workstation Extension 15-SP3 (x86_64): MozillaThunderbird-91.11.0-150200.8.76.1 MozillaThunderbird-debuginfo-91.11.0-150200.8.76.1 MozillaThunderbird-debugsource-91.11.0-150200.8.76.1 MozillaThunderbird-translations-common-91.11.0-150200.8.76.1 MozillaThunderbird-translations-other-91.11.0-150200.8.76.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (aarch64 ppc64le s390x): MozillaThunderbird-91.11.0-150200.8.76.1 MozillaThunderbird-debuginfo-91.11.0-150200.8.76.1 MozillaThunderbird-debugsource-91.11.0-150200.8.76.1 MozillaThunderbird-translations-common-91.11.0-150200.8.76.1 MozillaThunderbird-translations-other-91.11.0-150200.8.76.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (aarch64 ppc64le s390x): MozillaThunderbird-91.11.0-150200.8.76.1 MozillaThunderbird-debuginfo-91.11.0-150200.8.76.1 MozillaThunderbird-debugsource-91.11.0-150200.8.76.1 MozillaThunderbird-translations-common-91.11.0-150200.8.76.1 MozillaThunderbird-translations-other-91.11.0-150200.8.76.1 References: https://www.suse.com/security/cve/CVE-2022-2200.html https://www.suse.com/security/cve/CVE-2022-2226.html https://www.suse.com/security/cve/CVE-2022-31744.html https://www.suse.com/security/cve/CVE-2022-34468.html https://www.suse.com/security/cve/CVE-2022-34470.html https://www.suse.com/security/cve/CVE-2022-34472.html https://www.suse.com/security/cve/CVE-2022-34478.html https://www.suse.com/security/cve/CVE-2022-34479.html https://www.suse.com/security/cve/CVE-2022-34481.html https://www.suse.com/security/cve/CVE-2022-34484.html https://bugzilla.suse.com/1200793 . Crucial SUSE Security Enhancement for MozillaThunderbird addresses 10 vulnerabilities, along with a suggested patch acquisition tutorial.. MozillaThunderbird Security, SUSE Patch Update, Software Exploit Fix. . Severity: Important. LinuxSecurity.com Team
Unsafe use of strncpy. (rhbz#1932066) References: - https://bugs.mageia.org/show_bug.cgi?id=29493 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.