Lector de Feeds

MGASA-2025-0299 - Updated apache-commons-beanutils packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 20:52
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-48734 Description Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default. (CVE-2025-48734) References SRPMS 9/core
  • apache-commons-beanutils-1.9.4-7.1.mga9

Mageia 9 Errata

Wiki Mageia - 15 Noviembre, 2025 - 14:12

‎Various software: Wine update

← Older revision Revision as of 13:12, 15 November 2025 Line 336: Line 336:  {{Bug|28582}} - '''phppgadmin''' (umaintained upstream) did not work with php8 - that got FIXED by our patched update. But it still do not work with postgresql15 - '''WORKAROUND:''' downgrade to postgresql13. Both are in Mageia 9. {{Bug|28582}} - '''phppgadmin''' (umaintained upstream) did not work with php8 - that got FIXED by our patched update. But it still do not work with postgresql15 - '''WORKAROUND:''' downgrade to postgresql13. Both are in Mageia 9.    −{{Bug|28814}}, {{Bug|28840}}, {{Bug|31989}} - '''Wine''' missing a few dependencies, especially for 32 bit libs. (Thus also '''PlayOnLinux'''.) '''Manual fix''' and also other tips [[Ways_to_install_programs#Running_MSWindows_programs|'''here''']]. If launching a wine app gives warnings that suitable versions are missing, see {{Bug|16273}}.+'''FIXED BY UPDATE''' ''-mostly-'' '''Wine''' (Thus also '''PlayOnLinux.''') - If still problems see [[Ways_to_install_programs#Running_MSWindows_programs|'''here''']]. Bugs {{Bug|16273}}, {{Bug|28814}}, {{Bug|28840}}, {{Bug|31989}}.     {{Bug|30937}} - '''Thunderbird''' leaves temporary files on desktop if set to open pdf in external program. [https://bugzilla.mozilla.org/show_bug.cgi?id=1793932 Upstream.] Workaround is the default setting to open in TB, see linked bugs. {{Bug|30937}} - '''Thunderbird''' leaves temporary files on desktop if set to open pdf in external program. [https://bugzilla.mozilla.org/show_bug.cgi?id=1793932 Upstream.] Workaround is the default setting to open in TB, see linked bugs. Morgano
Categorías: Wiki de Mageia

Ways to install programs

Wiki Mageia - 15 Noviembre, 2025 - 14:12

‎Wine: #28814 fixed by update

← Older revision Revision as of 13:12, 15 November 2025 Line 232: Line 232:  For Wine integrated into Steam see [[#Proton|Proton]]. For Wine integrated into Steam see [[#Proton|Proton]].    −Sometimes Wine works, other times it doesn't work. There are several bug-reports still open, see there for workarounds.+Wine have a few quirks. Maybe see below for ideas, and ask in forum and upstreams.    −{{Bug|16273}} : If launching a wine app gives warnings that suitable versions are missing, see this bug.+{{Bug|16273}} If launching a wine app gives warnings that suitable versions are missing, see this bug. −   −{{bug|28814}} - Wine 32-bit install on 64-bit system doesn't pull mesa 32-bit drivers      {{bug|28840}} - wine32 should require libjpeg.so.8 {{bug|28840}} - wine32 should require libjpeg.so.8 Morgano
Categorías: Wiki de Mageia

MGASA-2025-0298 - Updated stardict packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-55014 Description The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP. (CVE-2025-55014) References SRPMS 9/core
  • stardict-3.0.6.3-2.1.mga9

MGASA-2025-0295 - Updated botan2 packages fix security vulnerabilitiy

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-50383 Description Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can be skipped if a carry is not set. This was observed for GCC 11.3.0 with -O2 on MIPS, and GCC on x86-i386 (only 32-bit processors can be affected). (CVE-2024-50383) References SRPMS 9/core
  • botan2-2.19.5-1.1.mga9

MGASA-2025-0294 - Updated spdlog packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-6140 Description Spdlog pattern_formatter-inl.h scoped_padder resource consumption. (CVE-2025-6140) References SRPMS 9/core
  • spdlog-1.11.0-4.1.mga9

MGASA-2025-0293 - Updated apache-commons-lang3 & apache-commons-lang packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-48924 Description Apache Commons Lang, Apache Commons Lang: ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs. (CVE-2025-48924) References SRPMS 9/core
  • apache-commons-lang3-3.12.0-3.1.mga9
  • apache-commons-lang-2.6-25.1.mga9

MGASA-2025-0292 - Updated python-django packages fix security vulnerability

Mageia Security - 15 Noviembre, 2025 - 08:11
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-64459 Description Potential SQL injection via ``_connector`` keyword argument in ``QuerySet`` and ``Q`` objects. (CVE-2025-64459) References SRPMS 9/core
  • python-django-4.1.13-1.8.mga9
Feed