Lector de Feeds

MGASA-2025-0134 - Updated poppler packages fix security vulnerabilities

Mageia Security - 12 Abril, 2025 - 05:23
Publication date: 12 Apr 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-32364 , CVE-2025-32365 Description A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN. (CVE-2025-32364) Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check. (CVE-2025-32365) References SRPMS 9/core
  • poppler-23.02.0-1.5.mga9

MGASA-2025-0133 - Updated gnupg2 packages fix security vulnerabilitiy

Mageia Security - 12 Abril, 2025 - 05:23
Publication date: 12 Apr 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-30258 Description In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS". (CVE-2025-30258) References SRPMS 9/core
  • gnupg2-2.3.8-1.3.mga9

MGASA-2025-0132 - Updated graphicsmagick packages fix security vulnerabilities

Mageia Security - 12 Abril, 2025 - 05:23
Publication date: 12 Apr 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-27795 Description ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. (CVE-2025-27795) References SRPMS 9/core
  • graphicsmagick-1.3.40-1.1.mga9
9/tainted
  • graphicsmagick-1.3.40-1.1.mga9.tainted

MGAA-2025-0037 - Updated libreoffice packages fix bug

Mageia Security - 12 Abril, 2025 - 05:23
Publication date: 12 Apr 2025
Type: bugfix
Affected Mageia releases : 9
Description Writer crashes in some circumstances when trying to edit or insert a TOC. This update fixes the issue. References SRPMS 9/core
  • libreoffice-24.2.7.2-1.2.mga9

MGASA-2025-0131 - Updated xz packages fix security vulnerability

Mageia Security - 10 Abril, 2025 - 01:22
Publication date: 10 Apr 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-31115 Description XZ has a heap-use-after-free bug in threaded .xz decoder. (CVE-2025-31115) References SRPMS 9/core
  • xz-5.4.3-1.1.mga9

MGASA-2025-0130 - Updated docker-containerd packages fix security vulnerability

Mageia Security - 10 Abril, 2025 - 01:22
Publication date: 10 Apr 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-40635 Description containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This could cause unexpected behavior for environments that require containers to run as a non-root user. This bug has been fixed in containerd 1.6.38, 1.7.27, and 2.04. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images. References SRPMS 9/core
  • docker-containerd-1.7.27-1.mga9

MGAA-2025-0036 - Updated qarte packages fix bug

Mageia Security - 10 Abril, 2025 - 01:22
Publication date: 10 Apr 2025
Type: bugfix
Affected Mageia releases : 9
Description arte.tv has changed the URL of the videos and qarte is unable to retrieve the lists and the videos. Version 5.9.0 fixes the issue. References SRPMS 9/core
  • qarte-5.9.0-1.mga9
Feed