< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Debian releases security updates and Debian 12.15 point release

Debian has released several security and bugfix advisories affecting its stable distributions, Trixie and Bookworm. Key updates include patches for python-httplib2 to resolve an unbounded decompression flaw that could lead to denial of service, and updates to unzip and zip utilities to prevent arbitrary code execution and command injection attacks.

Additionally, administrators are advised to upgrade util-linux to mitigate privilege escalation risks. For PostgreSQL-15 users, a configuration change is required to secure logical decoding output plugins following the patching of over two dozen CVEs related to unauthorized access and data leaks.

In a separate update, the Debian project announced the release of Debian 12.15, the final point release for the Bookworm oldstable distribution. This release focuses on security corrections and addressing serious issues. Notably, fwupd has been updated to version 2.0.20 to manage the expiration of the 2013 UEFI Secure Boot CA, which is critical for preventing boot failures on systems with Secure Boot enabled. Furthermore, the geoip-database has been reverted to a 2019 version to comply with Debian Free Software Guidelines.

Sources

Debian turns 33! [bits.debian.org]
about 1 month ago