Actualizaciones de Seguridad

MGASA-2025-0079 - Updated kernel, kmod-virtualbox & kmod-xtables-addons packages fix security vulnerabilities

Mageia Security - 26 Febrero, 2025 - 07:28

MGASA-2025-0077 - Updated iniparser packages fix security vulnerability

Mageia Security - 26 Febrero, 2025 - 07:28
Publication date: 26 Feb 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-0633 Description A heap-based buffer overflow vulnerability in iniparser_dumpsection_ini() in iniparser allows an attacker to read out-of-bounds memory. (CVE-2025-0633) References SRPMS 9/core
  • iniparser-4.1-4.1.mga9

MGASA-2025-0076 - Updated dcmtk packages fix security vulnerabilities

Mageia Security - 25 Febrero, 2025 - 22:40
Publication date: 25 Feb 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-25472 , CVE-2025-25474 , CVE-2025-25475 Description A buffer overflow in DCMTK allows attackers to cause a Denial of Service (DoS) via a crafted DCM file (CVE-2025-25472). DCMTK was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h (CVE-2025-25474). A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file (CVE-2025-25475). References SRPMS 9/core
  • dcmtk-3.6.7-4.4.mga9

MGAA-2025-0022 - Updated autohint-onoff, enki, pyzo & meteo-qt packages fix bug

Mageia Security - 25 Febrero, 2025 - 22:40
Publication date: 25 Feb 2025
Type: bugfix
Affected Mageia releases : 9
Description These packages have a bogus requirement on python3-sip; trying to install these packages will cause conflicts if you have applications that require python3-sip6. This update fixes the issue. References SRPMS 9/core
  • autohint-onoff-2.0-1.1.mga9
  • enki-22.08.0-1.1.mga9
  • pyzo-4.12.0-2.1.mga9
  • meteo-qt-3.3-2.1.mga9

MGASA-2025-0075 - Updated emacs packages fix a security vulnerability

Mageia Security - 25 Febrero, 2025 - 17:58
Publication date: 25 Feb 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-1244 Description A command injection flaw was found which could allow a remote, unauthenticated attacker to execute arbitrary shell commands by tricking users into visiting a specially crafted website or an HTTP URL with a redirect. References SRPMS 9/core
  • emacs-29.4-1.3.mga9

MGASA-2025-0074 - Updated vim packages fix security vulnerability

Mageia Security - 25 Febrero, 2025 - 17:58
Publication date: 25 Feb 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-26603 Description A heap use-after-free was found in str_to_reg() in Vim < 9.1.1115. (CVE-2025-26603) References SRPMS 9/core
  • vim-9.1.1122-1.mga9

MGASA-2025-0073 - Updated libxml2 packages fix security vulnerabilities

Mageia Security - 25 Febrero, 2025 - 17:58
Publication date: 25 Feb 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-56171 , CVE-2025-24928 , CVE-2025-27113 Description The updated packages fix security vulnerabilities: Use-after-free in xmlSchemaIDCFillNodeTables. (CVE-2024-56171) Stack-buffer-overflow in xmlSnprintfElements. (CVE-2025-24928) Null-deref in xmlPatMatch. (CVE-2025-27113) References SRPMS 9/core
  • libxml2-2.10.4-1.6.mga9

MGASA-2025-0072 - Updated krb5 packages fix security vulnerability

Mageia Security - 25 Febrero, 2025 - 17:58
Publication date: 25 Feb 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-24528 Description Overflow when calculating ulog block size. (CVE-2025-24528) References SRPMS 9/core
  • krb5-1.20.1-1.4.mga9

MGASA-2025-0071 - Updated gnutls packages fix security vulnerability

Mageia Security - 25 Febrero, 2025 - 17:58
Publication date: 25 Feb 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-12243 Description Gnutls impacted by inefficient DER decoding in libtasn1 leading to remote DoS. (CVE-2024-12243) References SRPMS 9/core
  • gnutls-3.8.4-1.1.mga9

MGAA-2025-0021 - Updated gtk+3.0 & lxpanel packages fix bug

Mageia Security - 25 Febrero, 2025 - 17:58
Publication date: 25 Feb 2025
Type: bugfix
Affected Mageia releases : 9
Description The updated packages fix a bug in GTK3 tooltips. References SRPMS 9/core
  • gtk+3.0-3.24.38-1.2.mga9
  • lxpanel-0.11.0-0.git20250215.1.mga9

MGAA-2025-0020 - Updated postgresql15 & postgresql13 packages fix bug

Mageia Security - 24 Febrero, 2025 - 22:09
Publication date: 24 Feb 2025
Type: bugfix
Affected Mageia releases : 9
Description The updated packages fix a regression introduced by the fix for CVE-2025-1094 and a memory leak in pg_createsubscriber. References SRPMS 9/core
  • postgresql15-15.12-1.mga9
  • postgresql13-13.20-1.mga9

MGAA-2025-0019 - Updated guayadeque packages fix bugs

Mageia Security - 24 Febrero, 2025 - 22:09
Publication date: 24 Feb 2025
Type: bugfix
Affected Mageia releases : 9
Description - Crash when trying to create a tab for a Magnatune panel or a Jamendo panel - bug: playback was skipping after 20 or 30 minutes running - Remove the nonfunctional Jamendo feature (the Jamendo site has modified its access and is no longer reachable for any Music Player) References SRPMS 9/core
  • guayadeque-0.7.0-1.mga9

MGASA-2025-0070 - Updated neomutt packages fix security vulnerabilities

Mageia Security - 24 Febrero, 2025 - 19:29
Publication date: 24 Feb 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-49393 , CVE-2024-49394 Description The To and Cc email header fields are not protected by cryptographic signing. (CVE-2024-49393) The In-reply-to email header field is not protected by cryptographic signing. (CVE-2024-49394) References SRPMS 9/core
  • neomutt-20241002-1.mga9

MGAA-2025-0018 - Updated grisbi packages fix bug

Mageia Security - 24 Febrero, 2025 - 19:29
Publication date: 24 Feb 2025
Type: bugfix
Affected Mageia releases : 9
Description The current version can't handle files from newer versions. This update fixes the issue. Note the 1st time wizard can't select custom folder for backups, please select it later in Edit -> Preferences References SRPMS 9/core
  • grisbi-3.0.4-1.mga9

MGAA-2025-0017 - Updated get-telegram packages fix bug

Mageia Security - 22 Febrero, 2025 - 20:08
Publication date: 22 Feb 2025
Type: bugfix
Affected Mageia releases : 9
Description Instructions to uninstall the telegram application are not accurate. This update fixes the issue. References SRPMS 9/core
  • get-telegram-1.7.7-3.1.mga9

MGAA-2025-0016 - Updated claws-mail packages fix bug

Mageia Security - 20 Febrero, 2025 - 07:08
Publication date: 20 Feb 2025
Type: bugfix
Affected Mageia releases : 9
Description The updated packages fix some oauth2 problems. References SRPMS 9/core
  • claws-mail-4.3.0-1.mga9

MGASA-2025-0069 - Updated python-cryptography & openssl packages fix security vulnerabilities

Mageia Security - 17 Febrero, 2025 - 19:37
Publication date: 17 Feb 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-49083 , CVE-2023-50782 , CVE-2024-26130 Description Cryptography vulnerable to NULL-dereference when loading PKCS7 certificates. (CVE-2023-49083) Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659. (CVE-2023-50782) Cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override. (CVE-2024-26130) References SRPMS 9/core
  • openssl-3.0.15-1.3.mga9
  • python-cryptography-39.0.1-1.1.mga9

MGASA-2025-0068 - Updated microcode packages fix security vulnerabilities

Mageia Security - 17 Febrero, 2025 - 19:37
Publication date: 17 Feb 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-31068 , CVE-2024-36293 , CVE-2023-43758 , CVE-2024-39355 , CVE-2024-37020 Description Improper Finite State Machines (FSMs) in Hardware Logic for some Intel® Processors may allow privileged user to potentially enable denial of service via local access. (CVE-2024-31068) Improper access control in the EDECCSSA user leaf function for some Intel® Processors with Intel® SGX may allow an authenticated user to potentially enable denial of service via local access. (CVE-2024-36293) Improper input validation in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access. (CVE-2023-43758) Improper handling of physical or environmental conditions in some Intel® Processors may allow an authenticated user to enable denial of service via local access. (CVE-2024-39355) Sequence of processor instructions leads to unexpected behavior in the Intel® DSA V1.0 for some Intel® Xeon® Processors may allow an authenticated user to potentially enable denial of service via local access. (CVE-2024-37020) References SRPMS 9/nonfree
  • microcode-0.20250211-1.mga9.nonfree
Feed