UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
Launchpad 2055530 Mutter (sometimes) fails to build with [fatal error: meta/meta-enum-types.h: No such file or directory] mutter mutter mutter mutter
Launchpad 2056732 [BPO] libreoffice 7.6.5 for jammy libreoffice libreoffice
CVE CVE-2024-21392 .NET and Visual Studio Denial of Service Vulnerability dotnet8 dotnet7 dotnet8 dotnet7 dotnet8 dotnet8
Launchpad 2039017 [SRU] 2.61.3 snapd snapd snapd snapd snapd snapd snapd snapd snapd snapd snapd snapd
CVE CVE-2022-25647 The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal clas libgoogle-gson-java libgoogle-gson-java
Launchpad 2056201 [BPO] rpki-client/9.0-1 from noble rpki-client
CVE CVE-2024-26146 Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a p ruby-rack ruby-rack
CVE CVE-2024-26141 Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Respo ruby-rack ruby-rack
CVE CVE-2023-3966 A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invali openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch openvswitch
CVE CVE-2012-6655 An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted p accountsservice accountsservice accountsservice accountsservice
CVE CVE-2024-27913 ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a ma frr frr frr frr frr frr frr frr
CVE CVE-2024-25629 c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc c-ares c-ares c-ares c-ares c-ares c-ares
CVE CVE-2023-27103 Libde265 v1.0.11 was discovered to contain a heap buffer overflow via the function derive_collocated_motion_vectors at motion.cc. libde265 libde265 libde265 libde265
CVE CVE-2023-27102 Libde265 v1.0.11 was discovered to contain a segmentation violation via the function decoder_context::process_slice_segment_header at decctx.cc. libde265 libde265 libde265 libde265
CVE CVE-2023-22742 libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not per libgit2 libgit2 libgit2 libgit2
CVE CVE-2023-49468 Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc. libde265 libde265 libde265 libde265 libde265 libde265
CVE CVE-2023-49467 Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at mo libde265 libde265 libde265 libde265 libde265 libde265
CVE CVE-2023-49465 Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc. libde265 libde265 libde265 libde265 libde265 libde265
CVE CVE-2023-47471 Buffer Overflow vulnerability in strukturag libde265 v1.10.12 allows a local attacker to cause a denial of service via the slice_segment_header funct libde265 libde265 libde265 libde265 libde265 libde265
CVE CVE-2023-43887 Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_paramet libde265 libde265 libde265 libde265 libde265 libde265



About   -   Send Feedback to @ubuntu_updates