Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The Bookworm backport of the security fix for CVE-2025-59032 introduced a regression in authenticating against managesieved. For the oldstable distribution (bookworm), this problem has been fixed in version 1:2.3.19.1+dfsg1-2.1+deb12u3. We recommend that you upgrade your dovecot packages.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6197-2
An integer overflow in Poco::UTF32Encoding() hase been fixed in the POCO C++ libraries for building network-based applications. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4024-1
The realtime computer music and graphics system puredata does now terminate when dropping setuid privileges failed. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3895-1
Cross-site scripting (XSS) vulnerabilities were discovered in Roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could allow a remote attacker to load arbitrary JavaScript code and might lead to privilege escalation or information disclosure. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3835-1
Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202402-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: QtWebEngine: Multiple Vulnerabilities Date: February 18, 2024 Bugs: #922189 ID: 202402-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to remote code execution. Background ========== QtWebEngine is a library for rendering dynamic web content in Qt5 and Qt6 C++ and QML applications. Affected packages ================= Package Vulnerable Unaffected ------------------ ------------------- -------------------- dev-qt/qtwebengine < 5.15.12_p20240122 > = 5.15.12_p20240122 Description =========== Multiple vulnerabilities have been discovered in QtWebEngine. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All QtWebEngine users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-qt/qtwebengine-5.15.12_p20240122" References ========== [ 1 ] CVE-2023-5997 https://nvd.nist.gov/vuln/detail/CVE-2023-5997 [ 2 ] CVE-2023-6112 https://nvd.nist.gov/vuln/detail/CVE-2023-6112 [ 3 ] CVE-2023-6345 https://nvd.nist.gov/vuln/detail/CVE-2023-6345 [ 4 ] CVE-2023-6346 https://nvd.nist.gov/vuln/detail/CVE-2023-6346 [ 5 ] CVE-2023-6347 https://nvd.nist.gov/vuln/detail/CVE-2023-6347 [ 6 ]CVE-2023-6348 https://nvd.nist.gov/vuln/detail/CVE-2023-6348 [ 7 ] CVE-2023-6350 https://nvd.nist.gov/vuln/detail/CVE-2023-6350 [ 8 ] CVE-2023-6351 https://nvd.nist.gov/vuln/detail/CVE-2023-6351 [ 9 ] CVE-2023-6508 https://nvd.nist.gov/vuln/detail/CVE-2023-6508 [ 10 ] CVE-2023-6509 https://nvd.nist.gov/vuln/detail/CVE-2023-6509 [ 11 ] CVE-2023-6510 https://nvd.nist.gov/vuln/detail/CVE-2023-6510 [ 12 ] CVE-2023-6511 https://nvd.nist.gov/vuln/detail/CVE-2023-6511 [ 13 ] CVE-2023-6512 https://nvd.nist.gov/vuln/detail/CVE-2023-6512 [ 14 ] CVE-2023-6702 https://nvd.nist.gov/vuln/detail/CVE-2023-6702 [ 15 ] CVE-2023-6703 https://nvd.nist.gov/vuln/detail/CVE-2023-6703 [ 16 ] CVE-2023-6704 https://nvd.nist.gov/vuln/detail/CVE-2023-6704 [ 17 ] CVE-2023-6705 https://nvd.nist.gov/vuln/detail/CVE-2023-6705 [ 18 ] CVE-2023-6706 https://nvd.nist.gov/vuln/detail/CVE-2023-6706 [ 19 ] CVE-2023-6707 https://nvd.nist.gov/vuln/detail/CVE-2023-6707 [ 20 ] CVE-2023-7024 https://nvd.nist.gov/vuln/detail/CVE-2023-7024 [ 21 ] CVE-2024-0222 https://nvd.nist.gov/vuln/detail/CVE-2024-0222 [ 22 ] CVE-2024-0223 https://nvd.nist.gov/vuln/detail/CVE-2024-0223 [ 23 ] CVE-2024-0224 https://nvd.nist.gov/vuln/detail/CVE-2024-0224 [ 24 ] CVE-2024-0225 https://nvd.nist.gov/vuln/detail/CVE-2024-0225 [ 25 ] CVE-2024-0333 https://nvd.nist.gov/vuln/detail/CVE-2024-0333 [ 26 ] CVE-2024-0517 https://nvd.nist.gov/vuln/detail/CVE-2024-0517 [ 27 ] CVE-2024-0518 https://nvd.nist.gov/vuln/detail/CVE-2024-0518 [ 28 ] CVE-2024-0519 https://nvd.nist.gov/vuln/detail/CVE-2024-0519 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202402-14 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concernsshould be addressed to
A vulnerability has been found in zlib that can lead to a heap-based buffer overflow.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202401-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: zlib: Buffer Overflow Date: January 15, 2024 Bugs: #916484 ID: 202401-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been found in zlib that can lead to a heap-based buffer overflow. Background ========== zlib is a widely used free and patent unencumbered data compression library. Affected packages ================= Package Vulnerable Unaffected ------------- ------------ ------------ sys-libs/zlib < 1.2.13-r2 > = 1.2.13-r2 Description =========== A vulnerability has been discovered in zlib. Please review the CVE identifier referenced below for details. Impact ====== MiniZip in zlib through 1.3 has an integer overflow and resultant heap- based buffer overflow in ZipOpenNewFileInZip4_64 via a long filename, comment, or extra field. Workaround ========== There is no known workaround at this time. Resolution ========== All zlib users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-libs/zlib-1.2.13-r2" References ========== [ 1 ] CVE-2023-45853 https://nvd.nist.gov/vuln/detail/CVE-2023-45853 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202401-18 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressedto
An issue has been found in cups, the Common UNIX Printing System. Due to a buffer overflow vulnerability in the function format_log_line() a remote attackers could cause a denial-of-service(DoS). The vulnerability . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3440-1
Denial of service (crash) via a crafted UDP message that leads to internal assert was fixed in sofia-sip, a SIP (Session Initiation Protocol) User-Agent library. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3334-1
Get the latest Linux and open source security news straight to your inbox.