Lector de Feeds
MGASA-2025-0299 - Updated apache-commons-beanutils packages fix security vulnerability
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-48734 Description Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default. (CVE-2025-48734) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-48734 Description Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default. (CVE-2025-48734) References
- https://bugs.mageia.org/show_bug.cgi?id=34330
- https://lists.opensuse.org/opensuse-updates/2019-09/msg00017.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48734
- apache-commons-beanutils-1.9.4-7.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2025-0298 - Updated stardict packages fix security vulnerability
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-55014 Description The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP. (CVE-2025-55014) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-55014 Description The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP. (CVE-2025-55014) References
- https://bugs.mageia.org/show_bug.cgi?id=34533
- https://seclists.org/oss-sec/2025/q3/75
- https://seclists.org/oss-sec/2025/q3/81
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55014
- stardict-3.0.6.3-2.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2025-0297 - Updated yelp & yelp-xsl packages fix security vulnerability
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-3155 Description The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. (CVE-2025-3155) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-3155 Description The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. (CVE-2025-3155) References
- https://bugs.mageia.org/show_bug.cgi?id=34173
- https://www.openwall.com/lists/oss-security/2025/04/04/1
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27Z5WA2SKQGJ4UVVHUNWY73Y4PNKT3AA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNBXVCRWOMV4OCPACFVW6R4I6T4PSAEM/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/T4HL3S3XNP5C4Q7YW3W22GDBDEEXQDW2/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-3155
- yelp-42.2-1.1.mga9
- yelp-xsl-42.1-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2025-0296 - Updated apache-commons-fileupload packages fix security vulnerability
Publication date: 15 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-48976 Description Apache Commons FileUpload: FileUpload DoS via part headers. (CVE-2025-48976) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-48976 Description Apache Commons FileUpload: FileUpload DoS via part headers. (CVE-2025-48976) References
- https://bugs.mageia.org/show_bug.cgi?id=34377
- https://www.openwall.com/lists/oss-security/2025/06/16/4
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/O4NTTRMGJEETFRWJKHNAERLI3E52LN2W/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48976
- apache-commons-fileupload-1.4-5.1.mga9
Categorías: Actualizaciones de Seguridad




