Mageia Security

Feed
Mageia Advisories
Updated: hace 9 horas 43 minutos

MGASA-2025-0179 - Updated php-adodb packages fix security vulnerability

8 Junio, 2025 - 07:22
Publication date: 08 Jun 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-46337 Description ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data. This issue has been patched in version 5.22.9 - CVE-2025-46337. References SRPMS 9/core
  • php-adodb-5.22.9-1.mga9

MGASA-2025-0178 - Updated systemd packages fix security vulnerability

8 Junio, 2025 - 07:22
Publication date: 08 Jun 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-4598 Description Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump. (CVE-2025-4598) References SRPMS 9/core
  • systemd-253.33-1.mga9

MGASA-2025-0177 - Updated tomcat packages fix security vulnerability

8 Junio, 2025 - 07:22
Publication date: 08 Jun 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-46701 Description Security constraint bypass for CGI scripts. (CVE-2025-46701) References SRPMS 9/core
  • tomcat-9.0.105-1.mga9

MGASA-2025-0176 - Updated cifs-utils packages fix security vulnerability

5 Junio, 2025 - 17:26
Publication date: 05 Jun 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-2312 Description cifs.upcall makes an upcall to the wrong namespace in containerized environments. (CVE-2025-2312) References SRPMS 9/core
  • cifs-utils-7.0-1.1.mga9

MGASA-2025-0175 - Updated golang packages fix security vulnerabilities

2 Junio, 2025 - 18:55
Publication date: 02 Jun 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-22870 , CVE-2025-22871 Description Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied - CVE-2025-22870. The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext - CVE-2025-22871. References SRPMS 9/core
  • golang-1.23.8-1.mga9

MGAA-2025-0056 - Updated mesa packages fix bug

2 Junio, 2025 - 18:55
Publication date: 02 Jun 2025
Type: bugfix
Affected Mageia releases : 9
Description mesa-25.0.5-1 introduced a bug that makes Extreme Tuxracer crash on some hardware. This update fixes the reported issue. References SRPMS 9/core
  • mesa-25.0.6-5.mga9
  • rust-cbindgen-0.26.0-0.1.mga9
9/tainted
  • mesa-25.0.6-5.mga9.tainted

MGASA-2025-0174 - Updated deluge packages fix security vulnerabilities & bug

31 Mayo, 2025 - 17:20
Publication date: 31 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-46561 , CVE-2025-46562 , CVE-2025-46563 , CVE-2025-46564 Description Limited unauthenticated file read in /flag. (CVE-2025-46561) New version check over unencrypted channel. (CVE-2025-46562) SSRF with information leak and limited unauthenticated file write. (CVE-2025-46563) Unauthenticated file read in /js may lead to RCE. (CVE-2025-46564) Mageia internal bug: deluge-daemon.service was not working; the update fixes this issue. References SRPMS 9/core
  • deluge-2.2.0-1.5.mga9

MGASA-2025-0173 - Updated glib2.0 packages fix security vulnerability

31 Mayo, 2025 - 04:36
Publication date: 31 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-4373 Description Buffer underflow on glib through glib/gstring.c via function g_string_insert_unichar. (CVE-2025-4373) References SRPMS 9/core
  • glib2.0-2.76.3-1.4.mga9

MGASA-2025-0172 - Updated coreutils packages fix security vulnerability

31 Mayo, 2025 - 04:36
Publication date: 31 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-5278 Description Heap buffer under-read in gnu coreutils sort via key specification. (CVE-2025-5278) References SRPMS 9/core
  • coreutils-9.1-1.1.mga9

MGASA-2025-0171 - Updated redis packages fix security vulnerabilitiy

31 Mayo, 2025 - 04:36
Publication date: 31 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-21605 Description Redis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated client. (CVE-2025-21605) References SRPMS 9/core
  • redis-7.0.14-1.3.mga9

MGASA-2025-0170 - Updated ghostscript packages fix security vulnerabilities

28 Mayo, 2025 - 20:45
Publication date: 28 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-48708 Description gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext. (CVE-2025-48708) References SRPMS 9/core
  • ghostscript-10.05.1-1.mga9

MGASA-2025-0169 - Updated cimg packages fix security vulnerability

28 Mayo, 2025 - 20:45
Publication date: 28 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-26540 Description A heap-based buffer overflow in Clmg before 3.3.3 can occur via a crafted file to cimg_library::CImg::_load_analyze. (CVE-2024-26540) References SRPMS 9/core
  • cimg-3.2.5-1.1.mga9

MGASA-2025-0168 - Updated thunderbird packages fix security vulnerabilities

27 Mayo, 2025 - 19:46
Publication date: 27 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-3875 , CVE-2025-3877 , CVE-2025-3909 , CVE-2025-3932 , CVE-2025-4918 , CVE-2025-4919 Description Sender Spoofing via Malformed From Header in Thunderbird. (CVE-2025-3875) Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links. (CVE-2025-3877) JavaScript Execution via Spoofed PDF Attachment and file:/// Link. (CVE-2025-3909) Tracking Links in Attachments Bypassed Remote Content Blocking. (CVE-2025-3932) Out-of-bounds access when resolving Promise objects. (CVE-2025-4918) Out-of-bounds access when optimizing linear sums. (CVE-2025-4919) References SRPMS 9/core
  • thunderbird-128.10.2-1.mga9
  • thunderbird-l10n-128.10.2-1.mga9

MGASA-2025-0167 - Updated sqlite3 packages fix security vulnerability

27 Mayo, 2025 - 19:46
Publication date: 27 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-29088 Description In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect. (CVE-2025-29088) References SRPMS 9/core
  • sqlite3-3.40.1-1.2.mga9

MGASA-2025-0166 - Updated open-vm-tools packages fix security vulnerability

27 Mayo, 2025 - 19:46
Publication date: 27 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-22247 Description VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM. (CVE-2025-22247) References SRPMS 9/core
  • open-vm-tools-12.3.5-2.1.mga9

MGASA-2025-0165 - Updated rootcerts, nss & firefox packages fix security vulnerabilities

27 Mayo, 2025 - 19:46
Publication date: 27 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-4918 , CVE-2025-4919 Description Out-of-bounds access when resolving Promise objects. (CVE-2025-4918) Out-of-bounds access when optimizing linear sums. (CVE-2025-4919) References SRPMS 9/core
  • rootcerts-20250424.00-1.mga9
  • nss-3.111.0-1.mga9
  • firefox-128.10.1-2.mga9
  • firefox-l10n-128.10.1-1.mga9

MGAA-2025-0055 - Updated aegisub packages fix bug

26 Mayo, 2025 - 18:52
Publication date: 26 May 2025
Type: bugfix
Affected Mageia releases : 9
Description aegisub crashes when run in a Wayland session. This update fixes the reported issue. References SRPMS 9/core
  • aegisub-3.4.2-1.mga9

MGASA-2025-0164 - Updated glibc packages fix security vulnerability

25 Mayo, 2025 - 00:25
Publication date: 24 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-4802 Description An untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library versions 2.27 to 2.38 allows attacker-controlled loading of dynamically shared libraries in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo). (CVE-2025-4802) References SRPMS 9/core
  • glibc-2.36-56.mga9

MGASA-2025-0163 - Updated iputils packages fix security vulnerability

25 Mayo, 2025 - 00:25
Publication date: 24 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-47268 Description ping in iputils through 20240905 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication. (CVE-2025-47268 References SRPMS 9/core
  • iputils-20221126-1.1.mga9

MGASA-2025-0162 - Updated zsync packages fix security vulnerabilities

25 Mayo, 2025 - 00:25
Publication date: 24 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-4638 Description Improper Pointer Arithmetic in pcl. (CVE-2025-4638) References SRPMS 9/core
  • zsync-0.6.2-11.1.mga9