Lector de Feeds

MGASA-2025-0298 - Updated stardict packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-55014 Description The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP. (CVE-2025-55014) References SRPMS 9/core
  • stardict-3.0.6.3-2.1.mga9

MGASA-2025-0295 - Updated botan2 packages fix security vulnerabilitiy

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-50383 Description Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can be skipped if a carry is not set. This was observed for GCC 11.3.0 with -O2 on MIPS, and GCC on x86-i386 (only 32-bit processors can be affected). (CVE-2024-50383) References SRPMS 9/core
  • botan2-2.19.5-1.1.mga9

MGASA-2025-0294 - Updated spdlog packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-6140 Description Spdlog pattern_formatter-inl.h scoped_padder resource consumption. (CVE-2025-6140) References SRPMS 9/core
  • spdlog-1.11.0-4.1.mga9

MGASA-2025-0293 - Updated apache-commons-lang3 & apache-commons-lang packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-48924 Description Apache Commons Lang, Apache Commons Lang: ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs. (CVE-2025-48924) References SRPMS 9/core
  • apache-commons-lang3-3.12.0-3.1.mga9
  • apache-commons-lang-2.6-25.1.mga9

MGASA-2025-0292 - Updated python-django packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-64459 Description Potential SQL injection via ``_connector`` keyword argument in ``QuerySet`` and ``Q`` objects. (CVE-2025-64459) References SRPMS 9/core
  • python-django-4.1.13-1.8.mga9

MGAA-2025-0096 - Updated mariadb packages fix bugs

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: bugfix
Affected Mageia releases : 9
Description This release brings many fixes in storage engines InnoDB and Aria It also has many fixes in replication and optimizer. For more details, see the long list in release notes. References SRPMS 9/core
  • mariadb-11.4.9-1.mga9

MGASA-2025-0291 - Updated webkit2 packages fix security vulnerabilities

Mageia Security - 14 Noviembre, 2025 - 17:41
Publication date: 14 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-27838 , CVE-2024-27851 , CVE-2024-40776 , CVE-2024-40779 , CVE-2024-40780 , CVE-2024-40782 , CVE-2024-40789 , CVE-2024-4558 Description CVE-2024-27838 A maliciously crafted webpage may be able to fingerprint the user. Description: The issue was addressed by adding additional logic. CVE-2024-27851 Processing maliciously crafted web content may lead to arbitrary code execution. Description: The issue was addressed with improved bounds checks. CVE-2024-40776 Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management. CVE-2024-40779 / CVE-2024-40780 Processing maliciously crafted web content may lead to an unexpected process crash. Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2024-40782 Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management. CVE-2024-40789 Processing maliciously crafted web content may lead to an unexpected process crash. Description: An out-of-bounds access issue was addressed with improved bounds checking. CVE-2024-4558 Processing maliciously crafted web content may lead to an unexpected process crash. Description: Use after free in ANGLE allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. References SRPMS 9/core
  • webkit2-2.44.4-1.mga9

MGAA-2025-0095 - Updated wine packages fix bugs

Mageia Security - 14 Noviembre, 2025 - 17:41
Publication date: 14 Nov 2025
Type: bugfix
Affected Mageia releases : 9
Description When installed or upgraded, "Wine" does not load all of the libraries it depends on. This update upgrades "Wine" to the bug release version 8.0.2 and fixes loading libraries that "Wine" requires. References SRPMS 9/core
  • wine-8.0.2-1.1.mga9

MGASA-2025-0290 - Updated ruby packages fix security vulnerabilities

Mageia Security - 14 Noviembre, 2025 - 00:37
Publication date: 13 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-25186 , CVE-2025-27219 , CVE-2025-27220 , CVE-2025-27221 Description Net::IMAP vulnerable to possible DoS by memory exhaustion. (CVE-2025-25186) In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies. (CVE-2025-27219) In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method. (CVE-2025-27220) In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host. (CVE-2025-27221) References SRPMS 9/core
  • ruby-3.1.5-47.mga9
Feed