Multiple vulnerabilities were fixed in tiff, a library and tools providing support for the Tag Image File Format (TIFF). CVE-2024-13978
31.0.9 release RHBZ#2388493 RHBZ#2389830 RHBZ#2389831 RHBZ#2389842 RHBZ#2389843 RHBZ#2389814 RHBZ#2389815
31.0.9 release RHBZ#2388493 RHBZ#2389830 RHBZ#2389831 RHBZ#2389842 RHBZ#2389843 RHBZ#2389814 RHBZ#2389815
31.0.9 release RHBZ#2388493 RHBZ#2389830 RHBZ#2389831 RHBZ#2389842 RHBZ#2389843 RHBZ#2389814 RHBZ#2389815
A vulnerability has been discovered in python-internetarchive, a Python library and command-line interface for searching, downloading and uploading content to the Internet Archive.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
USN-7280-2 introduced a regression in Python 2.7
USN-7015-4 introduced a regression in Python 2.7
* bsc#1247674 Cross-References: * CVE-2025-54571
An update that solves one vulnerability can now be installed.
* bsc#1247674 Cross-References: * CVE-2025-54571
* bsc#1236658 * bsc#1236746 * bsc#1237208 * bsc#1237308 * bsc#1237585
An update that solves 2 vulnerabilities can now be installed.
An update that solves 18 vulnerabilities can now be installed.
An update that solves 7 vulnerabilities can now be installed.
Three security issues were discovered in the Squid proxy caching server, which could result in the execution of arbitrary code, information disclosure or denial of service.
It was discovered that the symlink validation in node-tar-fs, a Node.js module that provides filesystem-like access to tar files, could be bypassed.
Firefox 140.3.1 has been released, which fixes connection errors with some sites; if HTTP/3 connections failed, the fallback is now handled more gracefully.
https://security-tracker.debian.org/tracker/DSA-6014-1
https://security-tracker.debian.org/tracker/DSA-6013-1
https://security-tracker.debian.org/tracker/DSA-6003-2
https://security-tracker.debian.org/tracker/DSA-6012-1
Update to 140.0.7339.207 * CVE-2025-10890: Side-channel information leakage in V8 * CVE-2025-10891: Integer overflow in V8 * CVE-2025-10892: Integer overflow in V8
4.0.6.3221
Update to 140.0.7339.207 * CVE-2025-10890: Side-channel information leakage in V8 * CVE-2025-10891: Integer overflow in V8 * CVE-2025-10892: Integer overflow in V8
Eugene Medvedev discovered that nncp, a package facilitating secure store-and-forward file and mail exchange, was susceptible to path traversal with the freq and file commands.
An update that fixes one vulnerability is now available.
* bsc#1234896 * bsc#1244824 * bsc#1245970 * bsc#1246473 * bsc#1246911
* bsc#1247901 * bsc#1247902 * bsc#1247904 Cross-References:
* bsc#1246974 * bsc#1249375 Cross-References: * CVE-2025-8114
An update that solves two vulnerabilities can now be installed.
* bsc#1246974 * bsc#1249375 Cross-References: * CVE-2025-8114
An update that solves three vulnerabilities can now be installed.
* bsc#1246001 * bsc#1246356 * bsc#1247499 Cross-References:
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Two vulnerabilities were found in libxslt, an XSLT 1.0 processing library, which could lead to to denial of service or information disclosure.
