Update NSS to 3.95 Update to Firefox 121.0
Archive for December, 2023
Update NSS to 3.95 Update to Firefox 121.0
Debian: DSA-5585-1: chromium security update
An important security issue was discovered in Chromium, which could result in the execution of arbitrary code. Google is aware that an exploit for CVE-2023-7024 exists in the wild.
Debian: DSA-5584-1: bluez security update
It was reported that the BlueZ’s HID profile implementation is not inline with the HID specification which mandates the use of Security Mode 4. The HID profile configuration option ClassicBondedOnly now defaults to “true” to make sure that input connections only come from
Debian: DSA-5583-1: gst-plugins-bad1.0 security update
A buffer overflow was discovered in the AV1 video plugin for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.
Debian: DSA-5582-1: thunderbird security update
Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or spoofing of signed PGP/MIME and SMIME emails.
The 6.6.7 stable kernel update contains a number of important fixes across the tree.
Debian: DSA-5581-1: firefox-esr security update
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or clickjacking.
Latest round of ansible/ansible-core minor releases. Mitigates CVE-2023-5764. https://forum.ansible.com/t/release-announcement-ansible-community- package-9-1-0/2764
Fedora 39: ansible-core 2023-3a0ce521ab
Latest round of ansible/ansible-core minor releases. Mitigates CVE-2023-5764. https://forum.ansible.com/t/release-announcement-ansible-community- package-9-1-0/2764
A security issue was fixed in libssh.
Ubuntu 6560-1: OpenSSH vulnerabilities
Several security issues were fixed in OpenSSH.
Fedora 38: rdiff-backup 2023-0fb94a1209
Rebuild for pyinstall CVE-2023-49797 BZ2253844
Fedora 39: rdiff-backup 2023-3909a0ab0e
Rebuild for pyinstall CVE-2023-49797 BZ2253844
Fedora 39: xorg-x11-server-Xwayland 2023-93940b58fd
xwayland 23.2.3, fixes CVE-2023-6377, CVE-2023-6478
Debian: DSA-5580-1: webkit2gtk security update
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2023-42883
Sleighing It: A Festive Feast of Features in 2023
Ho ho ho! Join us in revisiting 2023, explore all the improvements we added to Plesk, what you’d like to see in 2024, and more. Learn more!
The post Sleighing It: A Festive Feast of Features in 2023 appeared first on Plesk.
A Year in Focus: cPanel Added Value Solutions in 2023
With the year slowly coming to an end, we draw the curtains on yet another chapter in cPanel’s journey of offering added-value solutions that continue to lead the industry forward in web hosting management and security. We already introduced some valuable innovations and enhancements, such as the introduction of Manage Team to further collaboration and control, or the addition of Two-Factor Authentication for Webmail to further strengthen security, …
The post A Year in Focus: cPanel Added Value Solutions in 2023 first appeared on cPanel Blog.
Debian: DSA-5579-1: freeimage security update
Multiple vulnerabilities were discovered in FreeImage, a support library for graphics image formats, which could result in the execution of arbitrary code if malformed image files are processed.
Debian: DSA-5576-2: xorg-server security update
The initial fix for CVE-2023-6377 as applied in DSA 5576-1 did not fully fix the vulnerability. Updated packages correcting this issue including the upstream merged commit are now available.
The newest upstream commit Security fixes for CVE-2023-48706, CVE-2023-46246
Fedora 38: perl-Devel-Cover 2023-9ef8a60a05
Security fix for CVE-2023-47038
Update to 2.53.18
Security fix for CVE-2023-47038
Debian: DSA-5578-1: ghostscript security update
It was discovered that Ghostscript, the GPL PostScript/PDF interpreter, does not properly handle errors in the gdev_prn_open_printer_seekable() function, which could result in the execution of arbitrary commands if malformed document files are processed.
Update to 1.18 and security fix for CVE-2023-49297
This is the November 2023 update for .NET 6. It includes fixes for multiple CVEs. Release Notes: https://github.com/dotnet/core/blob/main/release- notes/6.0/6.0.25/6.0.25.md
– fix HSTS long file name clears contents (CVE-2023-46219) – fix cookie mixed case PSL bypass (CVE-2023-46218)
This is the November 2023 monthly update for .NET 7. It includes several security fixes. Release Notes: https://github.com/dotnet/core/blob/main/release-notes/7.0/7.0.14/7.0.14.md
Ubuntu 6488-2: strongSwan vulnerability
strongSwan could be made to crash or run programs if it received specially crafted network traffic.