Lector de Feeds

MGASA-2025-0149 - Updated pam packages fix security vulnerability

Mageia Security - 5 Mayo, 2025 - 05:57
Publication date: 05 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-10041 Description libpam vulnerable to leaking hashed passwords. (CVE-2024-10041) References SRPMS 9/core
  • pam-1.5.2-5.2.mga9

MGASA-2025-0148 - Updated graphicsmagick packages fix security vulnerabilities

Mageia Security - 5 Mayo, 2025 - 05:57
Publication date: 05 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-32460 Description GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call. (CVE-2025-32460) References SRPMS 9/core
  • graphicsmagick-1.3.40-1.2.mga9
9/tainted
  • graphicsmagick-1.3.40-1.2.mga9.tainted

MGASA-2025-0146 - Updated kernel-linus packages fix security vulnerabilities

Mageia Security - 5 Mayo, 2025 - 05:57
Publication date: 05 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-53034 , CVE-2025-21955 , CVE-2025-21956 , CVE-2025-21957 , CVE-2025-21959 , CVE-2025-21960 , CVE-2025-21962 , CVE-2025-21963 , CVE-2025-21964 , CVE-2025-21966 , CVE-2025-21967 , CVE-2025-21968 , CVE-2025-21969 , CVE-2025-21970 , CVE-2025-21971 , CVE-2025-21975 , CVE-2025-21978 , CVE-2025-21979 , CVE-2025-21980 , CVE-2025-21981 , CVE-2025-21986 , CVE-2025-21991 , CVE-2025-21992 , CVE-2025-21993 , CVE-2025-21994 , CVE-2025-21995 , CVE-2025-21996 , CVE-2025-21997 , CVE-2025-21999 , CVE-2025-22001 , CVE-2025-22003 , CVE-2025-22004 , CVE-2025-22005 , CVE-2025-22007 , CVE-2025-22008 , CVE-2025-22009 , CVE-2025-22010 , CVE-2025-22013 , CVE-2025-22014 , CVE-2025-22015 , CVE-2025-22018 , CVE-2025-22020 , CVE-2025-22021 , CVE-2025-22025 , CVE-2025-22027 , CVE-2025-22029 , CVE-2025-22033 , CVE-2025-22035 , CVE-2025-22038 , CVE-2025-22040 , CVE-2025-22041 , CVE-2025-22042 , CVE-2025-22043 , CVE-2025-22044 , CVE-2025-22045 , CVE-2025-22047 , CVE-2025-22048 , CVE-2025-22049 , CVE-2025-22050 , CVE-2025-22053 , CVE-2025-22054 , CVE-2025-22055 , CVE-2025-22056 , CVE-2025-22057 , CVE-2025-22058 , CVE-2025-22060 , CVE-2025-22063 , CVE-2025-22064 , CVE-2025-22066 , CVE-2025-22071 , CVE-2025-22072 , CVE-2025-22073 , CVE-2025-22074 , CVE-2025-22075 , CVE-2025-22077 , CVE-2025-22079 , CVE-2025-22080 , CVE-2025-22081 , CVE-2025-22083 , CVE-2025-22086 , CVE-2025-22088 , CVE-2025-22089 , CVE-2025-22090 , CVE-2025-22093 , CVE-2025-22095 , CVE-2025-22097 , CVE-2025-22119 , CVE-2025-23136 , CVE-2025-23138 , CVE-2025-37785 , CVE-2025-37893 , CVE-2025-38152 , CVE-2025-38240 , CVE-2025-38575 , CVE-2025-38637 , CVE-2025-39728 , CVE-2025-39735 Description Vanilla upstream kernel version 6.6.88 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References SRPMS 9/core
  • kernel-linus-6.6.88-1.mga9

MGASA-2025-0145 - Updated tomcat packages fix security vulnerabilities

Mageia Security - 5 Mayo, 2025 - 05:57
Publication date: 05 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-31650 , CVE-2025-31651 Description DoS via malformed HTTP/2 PRIORITY_UPDATE frame. (CVE-2025-31650) Bypass of rules in Rewrite Valve. (CVE-2025-31651) References SRPMS 9/core
  • tomcat-9.0.104-1.mga9

MGASA-2025-0144 - Updated fcgi packages fix security vulnerability

Mageia Security - 5 Mayo, 2025 - 05:57
Publication date: 05 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-23016 Description FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c. (CVE-2025-23016) References SRPMS 9/core
  • fcgi-2.4.0-22.1.mga9

MGASA-2025-0143 - Updated poppler packages fix security vulnerabilitiy

Mageia Security - 5 Mayo, 2025 - 05:57
Publication date: 05 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-43903 Description NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries. (CVE-2025-43903) References SRPMS 9/core
  • poppler-23.02.0-1.6.mga9

MGAA-2025-0044 - Updated mariadb packages fix bug

Mageia Security - 5 Mayo, 2025 - 05:57
Publication date: 05 May 2025
Type: bugfix
Affected Mageia releases : 9
Description Due to an script error introduced in the previous update mariadb server was not able to start on a clean install. Updated installations were not affected. However, this update makes mariadb work on clean and updated installations. References SRPMS 9/core
  • mariadb-11.4.5-3.mga9
Feed