Actualizaciones de Seguridad

MGASA-2025-0325 - Updated webkit2 packages fix security vulnerabilities

Mageia Security - 9 Diciembre, 2025 - 20:12
Publication date: 09 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-13947 , CVE-2025-43421 , CVE-2025-43458 , CVE-2025-66287 Description A website may be able to exfiltrate sensitive system information. Description: The issue was addressed through improved state checks - CVE-2025-13947. Processing maliciously crafted web content may lead to an unexpected process crash. Description: Multiple issues were addressed by disabling array allocation sinking - CVE-2025-43421. Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management - CVE-2025-43458. Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling - CVE-2025-66287. References SRPMS 9/core
  • webkit2-2.50.3-1.mga9

MGASA-2025-0324 - Updated python3 packages fix security vulnerabilities

Mageia Security - 9 Diciembre, 2025 - 20:12
Publication date: 09 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-13836 , CVE-2025-13837 , CVE-2025-12084 Description Excessive read buffering DoS in http.client. (CVE-2025-13836) Out-of-memory when loading Plist. (CVE-2025-13837) Quadratic complexity in node ID cache clearing. (CVE-2025-12084) References SRPMS 9/core
  • python3-3.10.18-1.5.mga9

MGASA-2025-0323 - Updated libpng packages fix security vulnerability

Mageia Security - 8 Diciembre, 2025 - 19:36
Publication date: 08 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-66293 Description LIBPNG has an out-of-bounds read in png_image_read_composite. (CVE-2025-66293) References SRPMS 9/core
  • libpng-1.6.38-1.2.mga9

MGASA-2025-0322 - Updated apache packages fix security vulnerabilities

Mageia Security - 8 Diciembre, 2025 - 19:36
Publication date: 08 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-55753 , CVE-2025-58098 , CVE-2025-65082 , CVE-2025-66200 Description Apache HTTP Server: mod_md (ACME), unintended retry intervals. (CVE-2025-55753) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. (CVE-2025-58098) Apache HTTP Server: CGI environment variable override. (CVE-2025-65082) Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo. (CVE-2025-66200) References SRPMS 9/core
  • apache-2.4.66-1.mga9

MGASA-2025-0321 - Updated xkbcomp packages fix security vulnerabilities

Mageia Security - 5 Diciembre, 2025 - 00:29
Publication date: 04 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2018-15853 , CVE-2018-15859 , CVE-2018-15861 , CVE-2018-15863 Description Endless recursion in xkbcomp/expr.c resulting in a crash. (CVE-2018-15853) NULL pointer dereference when parsing invalid atoms in ExprResolveLhs resulting in a crash. (CVE-2018-15859) NULL pointer dereference in ExprResolveLhs resulting in a crash. (CVE-2018-15861) NULL pointer dereference in ResolveStateAndPredicate resulting in a crash. (CVE-2018-15863) References SRPMS 9/core
  • xkbcomp-1.4.6-1.1.mga9

MGASA-2025-0320 - Updated python-django packages fix security vulnerabilities

Mageia Security - 5 Diciembre, 2025 - 00:29
Publication date: 04 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-13372 , CVE-2025-64460 Description Potential SQL injection in FilteredRelation column aliases on PostgreSQL. (CVE-2025-13372) Potential denial-of-service vulnerability in XML serializer text extraction. (CVE-2025-64460) References SRPMS 9/core
  • python-django-4.1.13-1.9.mga9

MGASA-2025-0319 - Updated webkit2 packages fix security vulnerabilities

Mageia Security - 5 Diciembre, 2025 - 00:29

MGASA-2025-0318 - Updated unbound packages fix security vulnerabilities

Mageia Security - 5 Diciembre, 2025 - 00:29
Publication date: 04 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-11411 Description Possible domain hijacking via promiscuous records in the authority section. (CVE-2025-11411). Previous fixes for CVE-2025-11411 released with Unbound 1.24.1 were not complete. References SRPMS 9/core
  • unbound-1.24.2-1.mga9

MGASA-2025-0317 - Updated gnutls packages fix security vulnerability

Mageia Security - 5 Diciembre, 2025 - 00:29
Publication date: 04 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-9820 Description Stack write buffer overflow. (CVE-2025-9820) References SRPMS 9/core
  • gnutls-3.8.4-1.3.mga9

MGASA-2025-0316 - Updated libraw, digikam & darktable packages fix security vulnerabilities

Mageia Security - 5 Diciembre, 2025 - 00:29
Publication date: 04 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-43961 , CVE-2025-43962 , CVE-2025-43963 , CVE-2025-43964 Description In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser. (CVE-2025-43961) In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations. (CVE-2025-43962) In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing. (CVE-2025-43963) In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values. (CVE-2025-43964) References SRPMS 9/core
  • libraw-0.20.2-5.1.mga9
  • digikam-8.4.0-1.1.mga9
  • darktable-4.6.1-1.2.mga9

MGASA-2025-0315 - Updated cups packages fix security vulnerabilities

Mageia Security - 3 Diciembre, 2025 - 21:39
Publication date: 03 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-58436 , CVE-2025-61915 Description The updated packages fix security vulnerabilities and a regression with GTK+ apps caused by the fix for CVE-2025-58436: OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack. (CVE-2025-58436) OpenPrinting CUPS vulnerable to stack based out-of-bound write. (CVE-2025-61915) References SRPMS 9/core
  • cups-2.4.6-1.5.mga9

MGASA-2025-0314 - Updated libpng packages fix security vulnerabilities

Mageia Security - 1 Diciembre, 2025 - 23:01
Publication date: 01 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-64505 , CVE-2025-64506 , CVE-2025-64720 , CVE-2025-65018 Description LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index. (CVE-2025-64505) LIBPNG is vulnerable to a heap buffer over-read in `png_write_image_8bit` with grayscale+alpha or RGB/RGBA images. (CVE-2025-64506) LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication. (CVE-2025-64720) LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`. (CVE-2025-65018) References SRPMS 9/core
  • libpng-1.6.38-1.1.mga9

MGAA-2025-0103 - Updated guayadeque packages fix bug

Mageia Security - 1 Diciembre, 2025 - 23:01
Publication date: 01 Dec 2025
Type: bugfix
Affected Mageia releases : 9
Description This package corrects several minor bugs that appeared since version 0.7.0 (must of these bugs only appeared when using particular settings, not for default settings). References SRPMS 9/core
  • guayadeque-0.7.4-0.git20251129.mga9

MGAA-2025-0102 - Updated python-sslyze & python-nassl packages fix bug

Mageia Security - 1 Diciembre, 2025 - 23:01
Publication date: 01 Dec 2025
Type: bugfix
Affected Mageia releases : 9
Description The current version of python3-sslyze crash, these packages fixes the reported issue References SRPMS 9/core
  • python-sslyze-5.1.0-1.mga9
  • python-nassl-5.3.1-1.mga9

MGASA-2025-0313 - Updated webkit2 packages fix security vulnerabilities

Mageia Security - 25 Noviembre, 2025 - 20:41
Publication date: 25 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-23271 , CVE-2024-27808 , CVE-2024-27820 , CVE-2024-27833 , CVE-2024-40866 , CVE-2024-44187 , CVE-2024-44185 , CVE-2024-44244 , CVE-2024-44296 , CVE-2024-44308 , CVE-2024-54479 , CVE-2024-54502 , CVE-2024-54505 , CVE-2024-54534 , CVE-2024-27856 , CVE-2024-54543 , CVE-2025-24143 , CVE-2025-24150 , CVE-2025-24158 , CVE-2025-24162 , CVE-2024-44192 , CVE-2024-54467 , CVE-2025-24201 , CVE-2024-54551 , CVE-2025-24208 , CVE-2025-24209 , CVE-2025-24213 , CVE-2025-24216 , CVE-2025-24264 , CVE-2025-30427 , CVE-2025-24223 , CVE-2025-31204 , CVE-2025-31205 , CVE-2025-31206 , CVE-2025-31215 , CVE-2025-31257 , CVE-2025-24189 , CVE-2025-31273 , CVE-2025-31278 , CVE-2025-43211 , CVE-2025-43212 , CVE-2025-43216 , CVE-2025-43227 , CVE-2025-43228 , CVE-2025-43240 , CVE-2025-43265 , CVE-2025-6558 , CVE-2025-43272 , CVE-2025-43342 , CVE-2025-43356 , CVE-2025-43368 , CVE-2025-43343 Description We are updating webkit2 to version 2.50.1 that has many security fixes since our current version. Please see the links for additional information References SRPMS 9/core
  • webkit2-2.50.1-1.2.mga9

MGASA-2025-0312 - Updated cups-filters packages fix security vulnerability

Mageia Security - 24 Noviembre, 2025 - 20:08
Publication date: 24 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-64524 Description CUPS rastertopclx Filter Vulnerable to Heap Buffer Overflow Leading to Potential Arbitrary Code Execution. (CVE-2025-64524) References SRPMS 9/core
  • cups-filters-1.28.16-6.3.mga9

MGASA-2025-0311 - Updated ruby-rack packages fix security vulnerabilities

Mageia Security - 24 Noviembre, 2025 - 19:27
Publication date: 24 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-25184 , CVE-2025-27111 , CVE-2025-27610 Description Possible Log Injection in Rack::CommonLogger. (CVE-2025-25184) Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection. (CVE-2025-27111) Local File Inclusion in Rack::Static. (CVE-2025-27610) References SRPMS 9/core
  • ruby-rack-2.2.13-1.mga9

MGASA-2025-0310 - Updated kernel-linus packages fix security vulnerabilities

Mageia Security - 22 Noviembre, 2025 - 21:20
Publication date: 22 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-39869 , CVE-2025-39870 , CVE-2025-39871 , CVE-2025-39873 , CVE-2025-39876 , CVE-2025-39877 , CVE-2025-39880 , CVE-2025-39881 , CVE-2025-39882 , CVE-2025-39883 , CVE-2025-39885 , CVE-2025-39886 , CVE-2025-39907 , CVE-2025-39909 , CVE-2025-39911 , CVE-2025-39913 , CVE-2025-39914 , CVE-2025-39916 , CVE-2025-39923 , CVE-2025-39929 , CVE-2025-39931 , CVE-2025-39934 , CVE-2025-39937 , CVE-2025-39938 , CVE-2025-39942 , CVE-2025-39943 , CVE-2025-39944 , CVE-2025-39945 , CVE-2025-39946 , CVE-2025-39947 , CVE-2025-39949 , CVE-2025-39951 , CVE-2025-39952 , CVE-2025-39953 , CVE-2025-39955 , CVE-2025-39957 , CVE-2025-39961 , CVE-2025-39964 , CVE-2025-39965 , CVE-2025-39967 , CVE-2025-39968 , CVE-2025-39969 , CVE-2025-39970 , CVE-2025-39971 , CVE-2025-39972 , CVE-2025-39973 , CVE-2025-39975 , CVE-2025-39977 , CVE-2025-39978 , CVE-2025-39980 , CVE-2025-39982 , CVE-2025-39985 , CVE-2025-39986 , CVE-2025-39987 , CVE-2025-39988 , CVE-2025-39993 , CVE-2025-39994 , CVE-2025-39995 , CVE-2025-39996 , CVE-2025-39998 , CVE-2025-40006 , CVE-2025-40008 , CVE-2025-40010 , CVE-2025-40011 , CVE-2025-40013 , CVE-2025-40016 , CVE-2025-40018 , CVE-2025-40019 , CVE-2025-40020 , CVE-2025-40021 , CVE-2025-40022 , CVE-2025-40024 , CVE-2025-40026 , CVE-2025-40027 , CVE-2025-40029 , CVE-2025-40030 , CVE-2025-40032 , CVE-2025-40033 , CVE-2025-40035 , CVE-2025-40036 , CVE-2025-40038 , CVE-2025-40040 , CVE-2025-40042 , CVE-2025-40043 , CVE-2025-40044 , CVE-2025-40048 , CVE-2025-40049 , CVE-2025-40051 , CVE-2025-40052 , CVE-2025-40053 , CVE-2025-40055 , CVE-2025-40056 , CVE-2025-40060 , CVE-2025-40061 , CVE-2025-40062 , CVE-2025-40067 , CVE-2025-40068 , CVE-2025-40070 , CVE-2025-40071 , CVE-2025-40078 , CVE-2025-40080 , CVE-2025-40081 , CVE-2025-40084 , CVE-2025-40085 , CVE-2025-40087 , CVE-2025-40088 , CVE-2025-40092 , CVE-2025-40093 , CVE-2025-40094 , CVE-2025-40095 , CVE-2025-40096 , CVE-2025-40099 , CVE-2025-40100 , CVE-2025-40103 , CVE-2025-40104 , CVE-2025-40105 , CVE-2025-40106 , CVE-2025-40107 , CVE-2025-40300 Description Vanilla upstream kernel version 6.6.116 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References SRPMS 9/core
  • kernel-linus-6.6.116-1.mga9

MGASA-2025-0309 - Updated kernel, kmod-xtables-addons & kmod-virtualbox packages fix security vulnerabilities

Mageia Security - 22 Noviembre, 2025 - 21:20
Publication date: 22 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-39869 , CVE-2025-39870 , CVE-2025-39871 , CVE-2025-39873 , CVE-2025-39876 , CVE-2025-39877 , CVE-2025-39880 , CVE-2025-39881 , CVE-2025-39882 , CVE-2025-39883 , CVE-2025-39885 , CVE-2025-39886 , CVE-2025-39907 , CVE-2025-39909 , CVE-2025-39911 , CVE-2025-39913 , CVE-2025-39914 , CVE-2025-39916 , CVE-2025-39923 , CVE-2025-39929 , CVE-2025-39931 , CVE-2025-39934 , CVE-2025-39937 , CVE-2025-39938 , CVE-2025-39942 , CVE-2025-39943 , CVE-2025-39944 , CVE-2025-39945 , CVE-2025-39946 , CVE-2025-39947 , CVE-2025-39949 , CVE-2025-39951 , CVE-2025-39952 , CVE-2025-39953 , CVE-2025-39955 , CVE-2025-39957 , CVE-2025-39961 , CVE-2025-39964 , CVE-2025-39965 , CVE-2025-39967 , CVE-2025-39968 , CVE-2025-39969 , CVE-2025-39970 , CVE-2025-39971 , CVE-2025-39972 , CVE-2025-39973 , CVE-2025-39975 , CVE-2025-39977 , CVE-2025-39978 , CVE-2025-39980 , CVE-2025-39982 , CVE-2025-39985 , CVE-2025-39986 , CVE-2025-39987 , CVE-2025-39988 , CVE-2025-39993 , CVE-2025-39994 , CVE-2025-39995 , CVE-2025-39996 , CVE-2025-39998 , CVE-2025-40006 , CVE-2025-40008 , CVE-2025-40010 , CVE-2025-40011 , CVE-2025-40013 , CVE-2025-40016 , CVE-2025-40018 , CVE-2025-40019 , CVE-2025-40020 , CVE-2025-40021 , CVE-2025-40022 , CVE-2025-40024 , CVE-2025-40026 , CVE-2025-40027 , CVE-2025-40029 , CVE-2025-40030 , CVE-2025-40032 , CVE-2025-40033 , CVE-2025-40035 , CVE-2025-40036 , CVE-2025-40038 , CVE-2025-40040 , CVE-2025-40042 , CVE-2025-40043 , CVE-2025-40044 , CVE-2025-40048 , CVE-2025-40049 , CVE-2025-40051 , CVE-2025-40052 , CVE-2025-40053 , CVE-2025-40055 , CVE-2025-40056 , CVE-2025-40060 , CVE-2025-40061 , CVE-2025-40062 , CVE-2025-40067 , CVE-2025-40068 , CVE-2025-40070 , CVE-2025-40071 , CVE-2025-40078 , CVE-2025-40080 , CVE-2025-40081 , CVE-2025-40084 , CVE-2025-40085 , CVE-2025-40087 , CVE-2025-40088 , CVE-2025-40092 , CVE-2025-40093 , CVE-2025-40094 , CVE-2025-40095 , CVE-2025-40096 , CVE-2025-40099 , CVE-2025-40100 , CVE-2025-40103 , CVE-2025-40104 , CVE-2025-40105 , CVE-2025-40106 , CVE-2025-40107 , CVE-2025-40300 Description Upstream kernel version 6.6.116 fixes bugs and vulnerabilities. The kmod-virtualbox & kmod-xtables-addons packages have been updated to work with this new kernel. References SRPMS 9/core
  • kernel-6.6.116-1.mga9
  • kmod-xtables-addons-3.24-87.mga9
  • kmod-virtualbox-7.1.14-13.mga9
Feed