2267205 – CVE-2024-24246 qpdf – Heap Buffer Overflow vulnerability in qpdf [fedora-all]
Archive for March, 2024
Update to latest version Security fix for CVE-2023-39325
Over 1,300 attendees gathered at the Taipei International Convention Center in Taiwan for WordCamp Asia 2024. The three-day event emerged as a vibrant celebration showcasing the collaboration, diversity, and innovation that drive the world’s most popular web platform.
upstream security release 122.0.6261.111 – High CVE-2024-2173: Out of bounds memory access in V8 – High CVE-2024-2174: Inappropriate implementation in V8 – High CVE-2024-2176: Use after free in FedCM
Debian: DSA-5637-1: squid security update
Several security vulnerabilities have been discovered in Squid, a full featured web proxy cache. Due to programming errors in Squid’s HTTP request parsing, remote attackers may be able to execute a denial of service attack by sending large X-Forwarded-For header or trigger a stack buffer overflow while
iwd 2.15: Fix issue with notice events for connection timeouts. Fix issue with reason code and deauthenticate event. Fix issue with handling basename() functionality. libell 0.63:
upstream security release 122.0.6261.111 – High CVE-2024-2173: Out of bounds memory access in V8 – High CVE-2024-2174: Inappropriate implementation in V8 – High CVE-2024-2176: Use after free in FedCM
Update to 115.8.1 https://www.mozilla.org/en-US/security/advisories/mfsa2024-11/ read that if you have mails with encrypted email subjects https://www.thunderbird.net/en-US/thunderbird/115.8.1/releasenotes/
iwd 2.15: Fix issue with notice events for connection timeouts. Fix issue with reason code and deauthenticate event. Fix issue with handling basename() functionality. libell 0.63:
Ubuntu 6685-1: mqtt-client vulnerability
mqtt-client could be made to crash if it received specially crafted input.
ncurses could be made to crash if it received specially crafted input.
libhtmlcleaner-java could be made to crash if it received specially crafted input.
Several security issues were fixed in Puma.
In modern web development, deploying applications is crucial to bringing your software to life. The Go programming language, a statically typed and compiled language known for its efficiency and performance, has gained immense popularity among developers. You can build robust and high-performance web applications by leveraging the power of Go. However, deploying Go applications can be complex, requiring a solid grasp of server configurations, environment settings, and other technical nuances. This is where the Plesk control panel comes into play as a game-changer. Plesk, a powerful web hosting control panel, provides an intuitive and user-friendly interface for managing various web…
The post How to Host a Go App on Plesk appeared first on Plesk.
Fedora 38: golang-github-tdewolff-minify 2024-0d4d9925a2
Update to latest version Security fix for CVE-2023-39325
Fedora 38: golang-github-tdewolff-parse 2024-0d4d9925a2
Update to latest version Security fix for CVE-2023-39325
Ubuntu 6681-1: Linux kernel vulnerabilities
Several security issues were fixed in the Linux kernel.
Debian: DSA-5636-1: chromium security update
Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.
Administrators typically rely on a command-line interface (CLI) when managing a Linux remote system (such as a virtual private server). Numerous Linux distros feature a graphical user interface (GUI), which some users may find more helpful than a CLI. However, entering commands tends to be smoother and more flexible via a CLI. For instance, you can use one command to replace certain entries across several files with a CLI, but that takes longer when using a GUI. As Linux has lots of commands for different tasks, though, it can be difficult to utilize Bash (Bourne Again Shell) shell. That’s why…
The post Most Important Linux Commands appeared first on Plesk.
FRR could be made to crash if it received specially crafted network traffic.
February saw significant progress towards the upcoming WordPress 6.5 release and final preparations for WordCamp Asia. The results of the annual WordPress survey were released, and discussions began on the next steps for the Data Liberation project. Read on for the latest happenings in the WordPress space. Get ready for WordCamp Asia The stage is […]
USN-6649-1 caused some minor regressions in Firefox.
Several security issues were fixed in libgit2.
Several security issues were fixed in libde265.
Ubuntu 6675-1: ImageProcessing vulnerability
ImageProcessing could be made to crash or run programs as an administrator if it received specially crafted input.
WordPress 6.5 RC1 is ready for download and testing. Reaching this phase of the release cycle is an important milestone. Check out what’s coming in this release and how to get involved.
On Linux and other Unix systems, cron is a scheduler tool that enables you to set up automated tasks known as “cron jobs”. Tasks don’t need to be executed over and over again when you generate cron jobs, which can lead to better web development and improved management efficiency. Common examples of a cron job are automating file downloads (to back up important documents) and monitoring servers. But cron jobs go much deeper than this, and it can be a complex topic to explore, which is why we’ve written this guide. Read on as we cover cron job basics (from…
The post Cron Jobs: All You Need To Know appeared first on Plesk.
Ubuntu 6653-4: Linux kernel (GKE) vulnerabilities
Several security issues were fixed in the Linux kernel.
Aviv Keller discovered that the frames.html file generated by YARD, a documentation generation tool for the Ruby programming language, was vulnerable to cross-site scripting.
Django could be made to consume resources or crash if it received specially crafted network traffic.