Lector de Feeds

MGASA-2025-0299 - Updated apache-commons-beanutils packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 20:52
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-48734 Description Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default. (CVE-2025-48734) References SRPMS 9/core
  • apache-commons-beanutils-1.9.4-7.1.mga9

MGASA-2025-0298 - Updated stardict packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-55014 Description The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP. (CVE-2025-55014) References SRPMS 9/core
  • stardict-3.0.6.3-2.1.mga9

MGASA-2025-0295 - Updated botan2 packages fix security vulnerabilitiy

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-50383 Description Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can be skipped if a carry is not set. This was observed for GCC 11.3.0 with -O2 on MIPS, and GCC on x86-i386 (only 32-bit processors can be affected). (CVE-2024-50383) References SRPMS 9/core
  • botan2-2.19.5-1.1.mga9

MGASA-2025-0294 - Updated spdlog packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-6140 Description Spdlog pattern_formatter-inl.h scoped_padder resource consumption. (CVE-2025-6140) References SRPMS 9/core
  • spdlog-1.11.0-4.1.mga9

MGASA-2025-0293 - Updated apache-commons-lang3 & apache-commons-lang packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-48924 Description Apache Commons Lang, Apache Commons Lang: ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs. (CVE-2025-48924) References SRPMS 9/core
  • apache-commons-lang3-3.12.0-3.1.mga9
  • apache-commons-lang-2.6-25.1.mga9

MGASA-2025-0292 - Updated python-django packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-64459 Description Potential SQL injection via ``_connector`` keyword argument in ``QuerySet`` and ``Q`` objects. (CVE-2025-64459) References SRPMS 9/core
  • python-django-4.1.13-1.8.mga9
Feed