Lector de Feeds
MGASA-2025-0325 - Updated webkit2 packages fix security vulnerabilities
Publication date: 09 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-13947 , CVE-2025-43421 , CVE-2025-43458 , CVE-2025-66287 Description A website may be able to exfiltrate sensitive system information. Description: The issue was addressed through improved state checks - CVE-2025-13947. Processing maliciously crafted web content may lead to an unexpected process crash. Description: Multiple issues were addressed by disabling array allocation sinking - CVE-2025-43421. Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management - CVE-2025-43458. Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling - CVE-2025-66287. References
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-13947 , CVE-2025-43421 , CVE-2025-43458 , CVE-2025-66287 Description A website may be able to exfiltrate sensitive system information. Description: The issue was addressed through improved state checks - CVE-2025-13947. Processing maliciously crafted web content may lead to an unexpected process crash. Description: Multiple issues were addressed by disabling array allocation sinking - CVE-2025-43421. Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management - CVE-2025-43458. Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling - CVE-2025-66287. References
- https://bugs.mageia.org/show_bug.cgi?id=34802
- https://webkitgtk.org/security/WSA-2025-0009.html
- https://webkitgtk.org/2025/12/04/webkitgtk2.50.3-released.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13947
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-43421
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-43458
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66287
- webkit2-2.50.3-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2025-0324 - Updated python3 packages fix security vulnerabilities
Publication date: 09 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-13836 , CVE-2025-13837 , CVE-2025-12084 Description Excessive read buffering DoS in http.client. (CVE-2025-13836) Out-of-memory when loading Plist. (CVE-2025-13837) Quadratic complexity in node ID cache clearing. (CVE-2025-12084) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-13836 , CVE-2025-13837 , CVE-2025-12084 Description Excessive read buffering DoS in http.client. (CVE-2025-13836) Out-of-memory when loading Plist. (CVE-2025-13837) Quadratic complexity in node ID cache clearing. (CVE-2025-12084) References
- https://bugs.mageia.org/show_bug.cgi?id=34808
- https://www.openwall.com/lists/oss-security/2025/12/05/5
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13836
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-12084
- python3-3.10.18-1.5.mga9
Categorías: Actualizaciones de Seguridad
QA ISO testers
For Qa team:
← Older revision Revision as of 13:20, 9 December 2025 Line 95: Line 95: * Aussie_matt - Xboxboy - xboxboy dot mageia at gmail dot com * Aussie_matt - Xboxboy - xboxboy dot mageia at gmail dot com −* papoteur - Yves Brungard - yves.brungard_mageia at gadz dotorg+* papoteur - Yves Brungard - yves.brungard+mageia at gadz dotorg * tonyb - Tony Blackwell - tablackwell at bigpond dot com * tonyb - Tony Blackwell - tablackwell at bigpond dot com Papoteur
Categorías: Wiki de Mageia
MediaWiki:Titlewhitelist
Adding nikos5446
← Older revision Revision as of 12:15, 9 December 2025 Line 121: Line 121: User:mvt7 User:mvt7 + +User:nikos5446 User:nmalykh User:nmalykh Marja
Categorías: Wiki de Mageia
MGASA-2025-0323 - Updated libpng packages fix security vulnerability
Publication date: 08 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-66293 Description LIBPNG has an out-of-bounds read in png_image_read_composite. (CVE-2025-66293) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-66293 Description LIBPNG has an out-of-bounds read in png_image_read_composite. (CVE-2025-66293) References
- https://bugs.mageia.org/show_bug.cgi?id=34799
- https://www.openwall.com/lists/oss-security/2025/12/03/5
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66293
- libpng-1.6.38-1.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2025-0322 - Updated apache packages fix security vulnerabilities
Publication date: 08 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-55753 , CVE-2025-58098 , CVE-2025-65082 , CVE-2025-66200 Description Apache HTTP Server: mod_md (ACME), unintended retry intervals. (CVE-2025-55753) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. (CVE-2025-58098) Apache HTTP Server: CGI environment variable override. (CVE-2025-65082) Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo. (CVE-2025-66200) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-55753 , CVE-2025-58098 , CVE-2025-65082 , CVE-2025-66200 Description Apache HTTP Server: mod_md (ACME), unintended retry intervals. (CVE-2025-55753) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. (CVE-2025-58098) Apache HTTP Server: CGI environment variable override. (CVE-2025-65082) Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo. (CVE-2025-66200) References
- https://bugs.mageia.org/show_bug.cgi?id=34803
- https://www.openwall.com/lists/oss-security/2025/12/04/4
- https://www.openwall.com/lists/oss-security/2025/12/04/5
- https://www.openwall.com/lists/oss-security/2025/12/04/7
- https://www.openwall.com/lists/oss-security/2025/12/04/8
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55753
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-58098
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-65082
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66200
- apache-2.4.66-1.mga9
Categorías: Actualizaciones de Seguridad
QA ISO testers
updated email address
← Older revision Revision as of 12:49, 8 December 2025 Line 79: Line 79: * schultz - Donald Stewart - watersnowrock at gmail dot com * schultz - Donald Stewart - watersnowrock at gmail dot com −* dtux - Daniel Tartavel - contact at librepc dot com+* dtux - Daniel Tartavel - dtux at free dot fr * neoser10 - Mauricio Andres Bustamante Viveros - neoser10 at hotmail dot com * neoser10 - Mauricio Andres Bustamante Viveros - neoser10 at hotmail dot com Dtux
Categorías: Wiki de Mageia




