USN-6281-1: Velocity Engine vulnerability ›
10 August 2023
Velocity Engine could be made to run arbitrary code if it opened a specially crafted file.
Developers issue an Ubuntu Security Notice when a security issue is fixed in an official Ubuntu package.
To report a security vulnerability in an Ubuntu package, please contact the Security Team.
The Security Team also produces OVAL files for each Ubuntu release. These are an industry-standard machine-readable format dataset that contain details of all known security vulnerabilities and fixes relevant to the Ubuntu release, and can be used to determine whether a particular patch is appropriate. OVAL files can also be used to audit a system to check whether the latest security fixes have been applied.
10 August 2023
Velocity Engine could be made to run arbitrary code if it opened a specially crafted file.
10 August 2023
PyPDF2 could be made to crash if it opened a specially crafted file.
9 August 2023
USN-6243-1 caused a minor regression in Graphite-Web.
9 August 2023
Several security issues were fixed in GNU binutils.
CVE-2017-9748 , CVE-2017-9747 , CVE-2017-9750 , and 3 others
9 August 2023
A hardening measure was added to OpenSSH.
8 August 2023
Several security issues were fixed in .NET.
8 August 2023
Several security issues were fixed in Dompdf.
CVE-2014-5011 , CVE-2014-5013 , CVE-2022-2400 , and 2 others
8 August 2023
USN-6267-1 caused some minor regressions in Firefox.
7 August 2023
unixODBC could be made to denial of service.
3 August 2023
XMLTooling could be made to allow for unintended server side actions if it received specially crafted input.