Debian 9902 Published by

Updated Util-Linux and Mediwiki packages has been released for Debian GNU/Linux 11 and 12:

[DSA 5650-1] util-linux security update
[DSA 5651-1] mediawiki security update




[DSA 5650-1] util-linux security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-5650-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
March 31, 2024 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : util-linux
CVE ID : CVE-2024-28085
Debian Bug : 1067849

Skyler Ferrante discovered that the wall tool from util-linux does not
properly handle escape sequences from command line arguments. A local
attacker can take advantage of this flaw for information disclosure.

With this update wall and write are not anymore installed with setgid
tty.

For the oldstable distribution (bullseye), this problem has been fixed
in version 2.36.1-8+deb11u2.

For the stable distribution (bookworm), this problem has been fixed in
version 2.38.1-5+deb12u1.

We recommend that you upgrade your util-linux packages.

For the detailed security status of util-linux please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/util-linux

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[DSA 5651-1] mediawiki security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-5651-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
March 31, 2024 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : mediawiki
CVE ID : not yet available

Two security issues were discovered in MediaWiki, a website engine for
collaborative work, which could result in cross-site scripting or denial
of service.

For the oldstable distribution (bullseye), this problem has been fixed
in version 1:1.35.13-1+deb11u2.

For the stable distribution (bookworm), this problem has been fixed in
version 1:1.39.7-1~deb12u1.

We recommend that you upgrade your mediawiki packages.

For the detailed security status of mediawiki please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/mediawiki

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/