Lector de Feeds

MGASA-2025-0200 - Updated libarchive packages fix security vulnerabilities

Mageia Security - 2 Julio, 2025 - 18:04
Publication date: 02 Jul 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-5914 , CVE-2025-5915 , CVE-2025-5916 , CVE-2025-5917 Description Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c. (CVE-2025-5914) Heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c. (CVE-2025-5915) Integer overflow while reading warc files at archive_read_support_format_warc.c. (CVE-2025-5916) Off by one error in build_ustar_entry_name() at archive_write_set_format_pax.c. (CVE-2025-5917) References SRPMS 9/core
  • libarchive-3.6.2-5.5.mga9

MGASA-2025-0199 - Updated x11-server, x11-server-xwayland & tigervnc packages fix security vulnerabilities

Mageia Security - 28 Junio, 2025 - 23:45
Publication date: 28 Jun 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-49175 , CVE-2025-49176 , CVE-2025-49177 , CVE-2025-49178 , CVE-2025-49179 , CVE-2025-49180 Description Out-of-bounds access in X Rendering extension (Animated cursors). (CVE-2025-49175) Integer overflow in Big Requests Extension. (CVE-2025-49176) Data leak in XFIXES Extension 6 (XFixesSetClientDisconnectMode). (CVE-2025-49177) Unprocessed client request via bytes to ignore. (CVE-2025-49178) Integer overflow in X Record extension. (CVE-2025-49179) Integer overflow in RandR extension (RRChangeProviderProperty). (CVE-2025-49180) References SRPMS 9/core
  • x11-server-21.1.8-7.8.mga9
  • x11-server-xwayland-22.1.9-1.8.mga9
  • tigervnc-1.13.1-2.8.mga9

MGAA-2025-0064 - Updated muse & qt5ct packages fix bug

Mageia Security - 28 Junio, 2025 - 23:45
Publication date: 28 Jun 2025
Type: bugfix
Affected Mageia releases : 9
Description In some desktops, Muse freezes when you set a custom color for a track. We fixed the issue requiring the qt5ct package and forcing QT_QPA_PLATFORMTHEME=qt5ct muse4 in the desktop file. But, to not introduce unwanted side effects in systems with mixed desktops (Plasma KDE with others), we split the profile.d files of qt5ct in the package qt5ct-profile; the package is not fetched as part of the update and if you want to keep the effects of qt5ct at desktop start you should install qt5ct-profile after the update. References SRPMS 9/core
  • muse-4.2.1-1.3.mga9
  • qt5ct-1.7-1.1.mga9
Feed