Several vulnerabilities were discovered in modsecurity-apache, an Apache module to tighten the Web application security, which may result in denial of service (high memory consumption).
New libvpx packages are available for Slackware 15.0 and -current to fix security issues.
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data.
Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump. (CVE-2025-4598) References:
Security constraint bypass for CGI scripts. (CVE-2025-46701) References: – https://bugs.mageia.org/show_bug.cgi?id=34332 – https://openwall.com/lists/oss-security/2025/05/29/4
Update to version 4.21.6
Add patch for double free
Fix CVE-2025-23016
Update to Samba 4.22.2 – Security fix for CVE-2025-0620
Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink
This update includes mod_security version 2.9.9 which addresses CVE-2025-47947 and includes various bug fixes. See https://github.com/owasp- modsecurity/ModSecurity/releases/tag/v2.9.9 for more information on the changes in this release.
Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink
This update includes mod_security version 2.9.9 which addresses CVE-2025-47947 and includes various bug fixes. See https://github.com/owasp- modsecurity/ModSecurity/releases/tag/v2.9.9 for more information on the changes in this release.
ESET researchers analyzed a cyberespionage campaign conducted by BladedFeline, an Iran-aligned APT group with likely ties to OilRig
* bsc#1243268 Cross-References: * CVE-2025-47287
* bsc#1236826 * bsc#1239671 * bsc#1241012 Cross-References:
* bsc#1240392 Cross-References: * CVE-2025-2704
* bsc#1236974 Cross-References: * CVE-2024-12243
Several security issues were fixed in the Linux kernel.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-24223
https://security-tracker.debian.org/tracker/DSA-5937-1
https://security-tracker.debian.org/tracker/DSA-5938-1
https://security-tracker.debian.org/tracker/DSA-5939-1
Several security issues were fixed in Bootstrap.
Several security issues were fixed in the Linux kernel.
* bsc#1243332 * bsc#1243422 * bsc#1243423 Cross-References:
* bsc#1243313 Cross-References: * CVE-2025-47273
* bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5936-1
https://security-tracker.debian.org/tracker/DSA-5935-1
https://security-tracker.debian.org/tracker/DSA-5934-1
Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to “*.example.com”, a request to “[::1%25.example.com]:80` will incorrectly match and not be proxied – CVE-2025-22870.
Do you have online accounts you haven’t used in years? If so, a bit of digital spring cleaning might be in order.
Several security issues were fixed in the Linux kernel.
Open VM Tools could be made to overwrite files as the administrator.
Several security issues were fixed in MariaDB.
The month of June is a time for fun in the sun and a break from the school year, but did you know it’s also the perfect time to step up your family’s online security? June is Internet Safety Month, a yearly reminder to strengthen your defenses against online threats. In today’s hyper-connected world, we […]
Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Various other fixes
Two security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2025-47779
