2 weeks 1 day ago
FEDORA-2025-381c988800
Packages in this update:
Update description:
31.0.2 release RHBZ#2345769 RHBZ#2345775 RHBZ#2350414
2 weeks 1 day ago
FEDORA-2025-ebd5b65ce8
Packages in this update:
Update description:
Automatic update for nextcloud-31.0.2-1.fc43.
Changelog
* Tue Mar 25 2025 Andrew Bauer <
zonexpertconsulting@outlook.com> - 31.0.2-1
- 31.0.2 release RHBZ#2345769 RHBZ#2345775 RHBZ#2350414
2 weeks 1 day ago
FEDORA-2025-b7f0c55e00
Packages in this update:
Update description:
Security: This update includes fix for VSV00015 aka CVE-2025-30346. Upstream considers this a low risk problem. For details, refer to https://varnish-cache.org/security/VSV00015.html.
2 weeks 1 day ago
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRDP to crash,
resulting in a denial of service. (CVE-2024-32458)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. A remote attacker could possibly use this issue to cause
FreeRDP clients and servers to crash, resulting in a denial of service.
(CVE-2024-32459)
It was discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRDP to crash,
resulting in a denial of service. (CVE-2024-32659, CVE-2024-32660)
2 weeks 2 days ago
Version:next-20250325 (linux-next)
Released:2025-03-25
2 weeks 2 days ago
2 weeks 2 days ago
It was discovered that SmartDNS did not correctly align certain objects in
memory, leading to undefined behaviour. An attacker could possibly use this
issue to cause a denial of service or execute arbitrary code. This issue
only affected Ubuntu 22.04 LTS. (CVE-2024-24198, CVE-2024-24199)
It was discovered that SmartDNS did not correctly handle certain inputs,
which could lead to an integer overflow. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2024-42643)
2 weeks 2 days ago
FEDORA-2025-12f2e3e40b
Packages in this update:
- dokuwiki-20240206b-1.fc42
- php-kissifrot-php-ixr-1.8.4-1.fc42
- php-phpseclib3-3.0.43-1.fc42
Update description:
Update DokuWiki to release 2024-02-06b "Kaos", update dependencies accordingly
2 weeks 2 days ago
FEDORA-2025-0ec100da82
Packages in this update:
- dokuwiki-20240206b-1.fc43
- php-kissifrot-php-ixr-1.8.4-1.fc43
- php-phpseclib3-3.0.43-1.fc43
Update description:
Update DokuWiki to release 2024-02-06b "Kaos", update dependencies accordingly
2 weeks 2 days ago
FEDORA-2025-d75bc3d211
Packages in this update:
Update description:
This is new version fixing possible remote SQL injection and FTBFS with gcc-15.
2 weeks 2 days ago
It was discovered that readelf from elfutils could be made to read out of
bounds. If a user or automated system were tricked into running readelf
on a specially crafted file, an attacker could cause readelf to crash,
resulting in a denial of service. This issue only affected Ubuntu 24.04
LTS. (CVE-2024-25260)
It was discovered that readelf from elfutils could be made to write out of
bounds. If a user or automated system were tricked into running readelf
on a specially crafted file, an attacker could cause readelf to crash,
resulting in a denial of service, or possibly execute arbitrary code.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2025-1365)
It was discovered that readelf from elfutils could be made to dereference
invalid memory. If a user or automated system were tricked into running
readelf on a specially crafted file, an attacker could cause readelf to
crash, resulting in a denial of service. This issue only affected Ubuntu
24.04 LTS and Ubuntu 24.10. (CVE-2025-1371)
It was discovered that readelf from elfutils could be made to dereference
invalid memory. If a user or automated system were tricked into running
readelf on a specially crafted file, an attacker could cause readelf to
crash, resulting in a denial of service. (CVE-2025-1372)
It was discovered that strip from elfutils could be made to dereference
invalid memory. If a user or automated system were tricked into running
strip on a specially crafted file, an attacker could cause strip to
crash, resulting in a denial of service. (CVE-2025-1377)
2 weeks 2 days ago
USN-7348-1 fixed vulnerabilities in Python. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Python ipaddress module contained incorrect
information about which IP address ranges were considered “private” or
“globally reachable”. This could possibly result in applications applying
incorrect security policies. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2024-4032)
It was discovered that Python incorrectly handled quoting path names when
using the venv module. A local attacker able to control virtual
environments could possibly use this issue to execute arbitrary code when
the virtual environment is activated. (CVE-2024-9287)
It was discovered that Python incorrectly handled parsing bracketed hosts.
A remote attacker could possibly use this issue to perform a Server-Side
Request Forgery (SSRF) attack. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2024-11168)
It was discovered that Python incorrectly handled parsing domain names that
included square brackets. A remote attacker could possibly use this issue
to perform a Server-Side Request Forgery (SSRF) attack. (CVE-2025-0938)
2 weeks 2 days ago
Nhật Thái Đỗ discovered that Rack incorrectly handled certain usernames. A
remote attacker could possibly use this issue to perform CRLF injection.
(CVE-2025-25184)
Phạm Quang Minh discovered that Rack incorrectly handled certain headers. A
remote attacker could possibly use this issue to perform log injection.
(CVE-2025-27111)
Phạm Quang Minh discovered that Rack did not properly handle relative file
paths. A remote attacker could potentially exploit this to include local
files that should have been inaccessible. (CVE-2025-27610)
2 weeks 2 days ago
2 weeks 3 days ago
It was discovered that zvbi incorrectly handled memory when processing user
input. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code.
2 weeks 3 days ago
Version:next-20250324 (linux-next)
Released:2025-03-24
2 weeks 3 days ago
FEDORA-2025-31036092ea
Packages in this update:
- augeas-1.14.2-0.4.20250324git4dffa3d.fc40
Update description:
CVE-2025-2588
2 weeks 3 days ago
FEDORA-2025-117fe4c81f
Packages in this update:
- augeas-1.14.2-0.4.20250324git4dffa3d.fc41
Update description:
CVE-2025-2588
2 weeks 3 days ago
FEDORA-2025-6b5c54bd05
Packages in this update:
- augeas-1.14.2-0.4.20250324git4dffa3d.fc42
Update description:
CVE-2025-2588
2 weeks 3 days ago
It was discovered that NLTK contained a regex that is susceptible to
catastrophic backtracking. An attacker could possibly use this issue to
cause a denial of service. (CVE-2021-3842, CVE-2021-43854)