Collected every two hours from specialised publications — each link leads to the original article.
This is a backport of the upstream fix for CVE-2023-39975: https://github.com/krb5/krb5/pull/1312
Denial of service due to memory or disk exhaustion. (CVE-2022-1708) References: - https://bugs.mageia.org/show_bug.cgi?id=30526 - https://github.com/cri-o/cri-…
Multiple severe security issues were discovered in the GPAC multimedia framework, including a heap-based Buffer Overflow in the GitHub repository gpac/gpac bef…
Latest stable release. Full upstream changelog: https://github.com/WebAssembly/wabt/compare/1.0.32...1.0.33 . Fixes CVE-2023-27116, CVE-2023-30300 and CVE-2023…
Erik Krogh Kristensen and Rasmus Petersen from the GitHub Security Lab discovered a ReDoS (Regular Expression Denial of Service) vulnerability in python-mechan…
Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72
Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72
Alvaro Mu'±oz from the GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert, a tool and library used to con…
update to 2.40.1 (CVE-2023-25652, CVE-2023-25815, CVE-2023-29007) Refer to the release notes for 2.30.9 for details of each CVE as well as the following securi…
update to 2.40.1 (CVE-2023-25652, CVE-2023-25815, CVE-2023-29007) Refer to the release notes for 2.30.9 for details of each CVE as well as the following securi…
Backport a fix for [CVE-2022-48468](https://cve.mitre.org/cgi- bin/cvename.cgi?name=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c),…
Backport a fix for [CVE-2022-48468](https://cve.mitre.org/cgi- bin/cvename.cgi?name=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c),…
update to 2.40.1 (CVE-2023-25652, CVE-2023-25815, CVE-2023-29007) Refer to the release notes for 2.30.9 for details of each CVE as well as the following securi…
A heap overflow can occur with crafted JPEG image file. (CVE-2023-27781) References: - https://bugs.mageia.org/show_bug.cgi?id=31764 - https://github.com/tjko/…
## [3.1.48] - 2023-03-28 ### Security - Fixed Cross site scripting vulnerability in Javascript escaping. This addresses CVE-2023-28447. ### Fixed - Output buff…
"rvim" can execute a shell through :diffpatch. References: - https://bugs.mageia.org/show_bug.cgi?id=31766 - https://github.com/vim/vim/commit/23a971da506249fc…
Release of stargz snapshotter v0.14.2 https://github.com/containerd/stargz- snapshotter/releases/tag/v0.14.2 This release uses containerd v1.7.0-rc.1 which con…
High CVE-2023-1213: Use after free in Swiftshader. Reported by Jaehun Jeong(@n3sk) of Theori on 2023-01-30 High CVE-2023-1214: Type Confusion in V8. Reported b…
Release of stargz snapshotter v0.14.2 https://github.com/containerd/stargz- snapshotter/releases/tag/v0.14.2 This release uses containerd v1.7.0-rc.1 so this r…
Update to 2.39.2 (CVE-2023-22490, CVE-2023-23946) Refer to the [upstream release notes](https://github.com/git/git/raw/v2.39.2/Documentation/RelNotes/2.30.8.tx…
Update to 2.39.2 (CVE-2023-22490, CVE-2023-23946) Refer to the [upstream release notes](https://github.com/git/git/raw/v2.39.2/Documentation/RelNotes/2.30.8.tx…
Update to version 1.23.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.23.0 Additionally, this update was built with a version of gola…
Update to version 1.23.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.23.0 Additionally, this update was built with a version of gola…
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. (CVE-2023-0049) References: - https://bugs.mageia.org/show_bug.cgi?id=31422