Debian 10135 Published by

The following security updates are available for Debian GNU/Linux:

Debian GNU/Linux 9 (Stretch) and 10 (Buster) Extended LTS:
ELA-1144-1 exim4 security update

Debian GNU/Linux 10 (Buster) Extended LTS:
ELA-1143-1 aom security update

Debian GNU/Linux 12 (Bookworm):
[SECURITY] [DSA 5735-1] chromium security update





[SECURITY] [DSA 5735-1] chromium security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-5735-1 security@debian.org
https://www.debian.org/security/ Andres Salomon
July 31, 2024 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : chromium
CVE ID : CVE-2024-6988 CVE-2024-6989 CVE-2024-6990 CVE-2024-6991
CVE-2024-6992 CVE-2024-6993 CVE-2024-6994 CVE-2024-6995
CVE-2024-6996 CVE-2024-6997 CVE-2024-6998 CVE-2024-6999
CVE-2024-7000 CVE-2024-7001 CVE-2024-7003 CVE-2024-7004
CVE-2024-7005 CVE-2024-7255 CVE-2024-7256

Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.

For the stable distribution (bookworm), these problems have been fixed in
version 127.0.6533.88-1~deb12u1.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


ELA-1144-1 exim4 security update

Package : exim4
Version : 4.89-2+deb9u13 (stretch), 4.92-8+deb10u10 (buster)

Related CVEs :
CVE-2024-39929

An issue has been found in exim4, the Mail Transport Agent.
Due to bad parsing of multiline RFC 2231 header filenames in mime ACL,
a remote attacker could bypass this protection mechanism and potentially
deliver executable attachements to mailboxes.

ELA-1144-1 exim4 security update


ELA-1143-1 aom security update

Package : aom
Version : 1.0.0-3+deb10u2 (buster)

Related CVEs :
CVE-2024-5171

Integer overflow have been fixed in aom, an AV1 Codec Library.

ELA-1143-1 aom security update