* bsc#1251198 * bsc#1251199 Cross-References: * CVE-2025-61984
* bsc#1238879 Cross-References: * CVE-2025-27516
* bsc#1254132 Cross-References: * CVE-2025-9820
Insufficient validation of incoming notifies over TCP in PDNS Recursor, a resolving name server, could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 5.2.7-0+deb13u1. We recommend that you upgrade your pdns-recursor packages.
Several vulnerabilities were reported in the libpng PNG library, which could lead to information leaks, denial of service or potentially the execution of arbitrary code if a specially crafted image is processed. For the oldstable distribution (bookworm), these problems have been fixed in version 1.6.39-2+deb12u1.
* bsc#1244485 * bsc#1245878 * bsc#1254227 * bsc#1254430 * bsc#1254431
https://security-tracker.debian.org/tracker/DSA-6079-1
https://security-tracker.debian.org/tracker/DSA-6078-1
https://security-tracker.debian.org/tracker/DSA-6077-1
https://security-tracker.debian.org/tracker/DSA-6076-1
https://security-tracker.debian.org/tracker/DSA-6075-1
Several security issues were fixed in radare2.
* bsc#1241772 * bsc#1250683 * bsc#1253181 * bsc#1253185 * bsc#1253186
python-apt could be made to crash if it opened a specially crafted file.
* bsc#1254132 Cross-References: * CVE-2025-9820
An update that solves one vulnerability can now be installed.
* bsc#1250497 Cross-References: * CVE-2025-10922
https://security-tracker.debian.org/tracker/DSA-6074-1
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), this problem has been fixed in version 7:7.1.3-0+deb13u1.
Multiple vulnerabilties have been found in libpng, the official PNG reference library, allowing information disclosure via out-of-bounds read, denial of service via application crash, or heap corruption with potential for arbitrary code execution.
Update to 2.9.7
Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287
Update to 2.9.7
https://security-tracker.debian.org/tracker/DSA-6073-1
Loading a manipulated TGA file in krita, an image manipulation program, could result in a heap-based buffer overflow in KisTgaImport.
Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials
Fix CVE-2025-12744
Update to cef-142.0.17+g60aac24 & chromium 142.0.7444.175 (rhbz#2413981) High CVE-2025-13223: Type Confusion in V8 High CVE-2025-13224: Type Confusion in V8
Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials
Fix CVE-2025-12744
https://security-tracker.debian.org/tracker/DSA-6072-1
https://security-tracker.debian.org/tracker/DSA-6071-1
Identity is effectively the new network boundary. It must be protected at all costs.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Update to security release 4.3.5a
Rebuilt with latest patched stb_image: memory-safety fixes
https://security-tracker.debian.org/tracker/DSA-6069-1
