Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens
0.9.30, rebuild due golang CVE-2025-22870
https://security-tracker.debian.org/tracker/DSA-5885-1
Ivan Fratric discovered two use-after-free vulnerabilities in libxslt, an XSLT processing runtime library, which may result in the execution of arbitrary code if a specially crafted files are processed.
Two use-after-free vulnerabilities have been fixed in the XSLT processing library libxslt. CVE-2024-55549
Several security issues were fixed in NLTK.
Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-44192
An update that fixes two vulnerabilities is now available.
Update to 4.3.6 (rhbz#2352545)
This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md
Update to 4.3.6 (rhbz#2352545)
This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md
Backported fix for CVE-2024-12361 .
This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md
https://security-tracker.debian.org/tracker/DSA-5884-1
A cross-site scripting vulnerability was discovered in hgweb, the integrated stand-alone web interface of the Mercurial version control system.
Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes
https://security-tracker.debian.org/tracker/DSA-5883-1
* bsc#1197331 * bsc#1203769 * bsc#1235441 * bsc#1237768 * bsc#1238271
* bsc#1239750 Cross-References: * CVE-2022-49737
https://security-tracker.debian.org/tracker/DSA-5882-1
go-gh could be made to expose sensitive information over the network.
* bsc#1239547 Cross-References: * CVE-2025-24201
* bsc#1239547 Cross-References: * CVE-2025-24201
* bsc#1237363 * bsc#1237370 * bsc#1237418 Cross-References:
Several security issues were fixed in Valkey.
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in HTTP request smuggling, validation bypass or denial of service.
Multiple vulnerabilities were discovered in modules shipped with cpython 3.9, the primary interpreter for the Python programming language.
fix CVE-2024-56737, CVE-2025-56737, CVE-2025-1864 Fix CVE-2025-1744 and CVE-2025-1864
fix CVE-2024-56737, CVE-2025-56737, CVE-2025-1864 Fix CVE-2025-1744 and CVE-2025-1864
Several security issues were fixed in Alpine.
* bsc#1229640 * bsc#1231196 * bsc#1231204 * bsc#1233679 * bsc#1235452
* bsc#1228755 * bsc#1231196 * bsc#1231204 * bsc#1233679 * bsc#1235452
* bsc#1231204 * bsc#1233679 Cross-References: * CVE-2024-46818
* bsc#1229640 * bsc#1231204 * bsc#1233679 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5881-1
