Lector de Feeds

MGASA-2025-0251 - Updated poppler packages fix security vulnerability

Mageia Security - 29 Octubre, 2025 - 05:28
Publication date: 29 Oct 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-52885 Description Use After Free (UAF) in Poppler. (CVE-2025-52885) References SRPMS 9/core
  • poppler-23.02.0-1.8.mga9

MGASA-2025-0250 - Updated tomcat packages fix security vulnerabilities

Mageia Security - 29 Octubre, 2025 - 05:28
Publication date: 29 Oct 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-55752 , CVE-2025-55754 , CVE-2025-61795 Description Directory traversal via rewrite with possible RCE if PUT is enabled. (CVE-2025-55752) Console manipulation via escape sequences in log messages. (CVE-2025-55754) Delayed cleaning of multi-part upload temporary files may lead to DoS. (CVE-2025-61795) References SRPMS 9/core
  • tomcat-9.0.111-1.mga9

MGASA-2025-0249 - Updated icu packages fix security vulnerability

Mageia Security - 27 Octubre, 2025 - 17:53
Publication date: 27 Oct 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-5222 Description A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution. References SRPMS 9/core
  • icu-73.2-1.2.mga9

MGASA-2025-0248 - Updated libtpms package fixes security vulnerability

Mageia Security - 27 Octubre, 2025 - 17:53
Publication date: 27 Oct 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-49133 Description It was discovered that libtpms had a potential out-of-bound access & abort due to HMAC signing issue (CVE-2025-49133). References SRPMS 9/core
  • libtpms-0.9.6-1.1.mga9
Feed