UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2024-26146 Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a p ruby-rack ruby-rack
CVE CVE-2024-26141 Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Respo ruby-rack ruby-rack
CVE CVE-2023-3966 A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invali openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch
CVE CVE-2012-6655 An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted p accountsservice accountsservice accountsservice accountsservice
CVE CVE-2024-27913 ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a ma frr frr frr frr frr frr frr frr
CVE CVE-2024-25629 c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc c-ares c-ares c-ares c-ares c-ares c-ares
CVE CVE-2023-27103 Libde265 v1.0.11 was discovered to contain a heap buffer overflow via the function derive_collocated_motion_vectors at motion.cc. libde265 libde265 libde265 libde265
CVE CVE-2023-27102 Libde265 v1.0.11 was discovered to contain a segmentation violation via the function decoder_context::process_slice_segment_header at decctx.cc. libde265 libde265 libde265 libde265
CVE CVE-2023-22742 libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not per libgit2 libgit2 libgit2 libgit2
CVE CVE-2023-49468 Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc. libde265 libde265 libde265 libde265 libde265 libde265
CVE CVE-2023-49467 Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at mo libde265 libde265 libde265 libde265 libde265 libde265
CVE CVE-2023-49465 Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc. libde265 libde265 libde265 libde265 libde265 libde265
CVE CVE-2023-47471 Buffer Overflow vulnerability in strukturag libde265 v1.10.12 allows a local attacker to cause a denial of service via the slice_segment_header funct libde265 libde265 libde265 libde265 libde265 libde265
CVE CVE-2023-43887 Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_paramet libde265 libde265 libde265 libde265 libde265 libde265
CVE CVE-2024-24577 libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 libgit2 libgit2
CVE CVE-2024-24575 libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i libgit2 libgit2 libgit2 libgit2
CVE CVE-2024-0607 A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a linux linux linux-bluefield linux-bluefield linux-xilinx-zynqmp linux-xilinx-zynqmp linux-bluefield linux-bluefield linux-xilinx-zynqmp linux-xilinx-zynqmp
CVE CVE-2023-23004 In the Linux kernel before 5.19, drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expects it to be NULL in the error linux linux linux linux-bluefield linux linux-bluefield linux-xilinx-zynqmp linux-xilinx-zynqmp linux-bluefield linux-bluefield linux-xilinx-zynqmp linux-xilinx-zynqmp
CVE CVE-2023-39198 A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_o linux
Launchpad 2051655 Focal update: v5.4.266 upstream stable release linux linux linux-bluefield linux-bluefield linux-xilinx-zynqmp linux-xilinx-zynqmp linux-bluefield linux-bluefield linux-xilinx-zynqmp linux-xilinx-zynqmp



About   -   Send Feedback to @ubuntu_updates