PDF signature forgery with adbe.pkcs7.sha1 SubFilter. (CVE-2025-2866) References: – https://bugs.mageia.org/show_bug.cgi?id=34234 – https://lists.debian.org/debian-security-announce/2025/msg00070.html
An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on
Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function. (CVE-2025-31162) Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function.
https://deluge.readthedocs.io/en/deluge-2.2.0/changelog.html 2.2.0 (2025-04-28) Breaking changes Removed Python 3.6 support (Python >= 3.7) Core
5.22.9
Update to version 22.15.0
Update to 47.7 notably fixing CVE-2025-3839
xz 5.8.1
xz 5.8.1
xz 5.8.1
xz 5.8.1
Fixes CVE-2025-47256 .
https://security-tracker.debian.org/tracker/DSA-5917-1
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
* bsc#1224259 Cross-References: * CVE-2024-4853
* bsc#1242210 Cross-References: * CVE-2025-32873
* bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References:
A vulnerability has been fixed in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality.
Django could be made to crash if it received specially crafted network traffic.
New mariadb packages are available for Slackware 15.0 and -current to fix security issues.
nodejs:18 enhancement update
nodejs:20 enhancement update
Moderate: libXpm security update
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-5916-1
An update that fixes four vulnerabilities is now available.
Several security issues were fixed in OpenJDK 24.
Several security issues were fixed in OpenJDK 21.
Several security issues were fixed in OpenJDK 17.
Several security issues were fixed in OpenJDK 11.
Several security issues were fixed in OpenJDK 8.
* bsc#1223272 * bsc#1234028 * bsc#1235091 * bsc#1235092 * bsc#1236007
* bsc#1202828 * bsc#1217770 * bsc#1224413 * jsc#PED-11066 * jsc#PED-1174
* bsc#1202828 * bsc#1217770 * bsc#1224413 * jsc#PED-11066 * jsc#PED-1174
ansible 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 introduced a regression in the win_template module. This caused win_template tasks to fail with an error. For Debian 11 bullseye, this problem has been fixed in version
Update to 136.0.7103.59 CVE-2025-4096: Heap buffer overflow in HTML CVE-2025-4050: Out of bounds memory access in DevTools CVE-2025-4051: Insufficient data validation in DevTools CVE-2025-4052: Inappropriate implementation in DevTools
April 2025 CPU
A heap-based buffer overflow vulnerability was discovered in vips, an fast image processing library designed with efficiency in mind, which may result in denial of service (application crash) if a specially crafted TIFF image file is processed.
Update to 136.0.7103.59 * CVE-2025-4096: Heap buffer overflow in HTML * CVE-2025-4050: Out of bounds memory access in DevTools * CVE-2025-4051: Insufficient data validation in DevTools * CVE-2025-4052: Inappropriate implementation in DevTools
Update to 128.10.0 https://www.thunderbird.net/en-US/thunderbird/128.10.0esr/releasenotes/
Update to version 0.24.4. Also contains fixes for RUSTSEC-2025-0006.
Update to version 1.5.0 (for now, without PPS feature enabled due to potential correctness issues in the code). Release notes: https://github.com/pendulum-project/ntpd-rs/releases/tag/v1.5.0 Also contains the fix for GHSA-v83q-83hj-rw38.
Update pnpm to version 10.9.0 to fix CVE-2024-47829 and nodejs-bash-language- server to version 5.6.0
https://security-tracker.debian.org/tracker/DSA-5915-1
https://security-tracker.debian.org/tracker/DSA-5914-1
https://security-tracker.debian.org/tracker/DSA-5913-1
Update to 1.17.4 Fixes CVE-2025-23359 or GHSA-4hmh-pm5p-9j7j
Update to 128.10.0 https://www.thunderbird.net/en-US/thunderbird/128.10.0esr/releasenotes/
Update to latest upstream (138.0)
Update to 1.17.4 Fixes CVE-2025-23359 or GHSA-4hmh-pm5p-9j7j
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
Update to 1.17.4 Fixes CVE-2025-23359 or GHSA-4hmh-pm5p-9j7j
https://security-tracker.debian.org/tracker/DSA-5911-1
https://security-tracker.debian.org/tracker/DSA-5910-1
https://security-tracker.debian.org/tracker/DSA-5909-1
Several security issues were fixed in micropython.
The following vulnerability has been discovered in the gorilla/csrf package for Go: Prior to 1.7.3, gorilla/csrf did not validate the Origin header against an allowlist. It executed its validation of the Referer header for
In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used. (CVE-2025-43965) In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order). (CVE-2025-46393)
Multiple vulnerabilties were discovered in u-boot, a boot loader for embedded systems.
Multiple vulnerabilities were discovered in nagvis, a visualization addon for Nagios or Icinga. CVE-2021-33178
Backport proposed fix for CVE-2025-31344 from OpenMandriva.
https://security-tracker.debian.org/tracker/DSA-5912-1
H2O could be made to crash if it received specially crafted network traffic.
PostgreSQL could be made to execute arbitrary code if it received specially crafted input.
* bsc#1233294 * bsc#1235431 Cross-References: * CVE-2024-50205
* bsc#1239909 Cross-References: * CVE-2025-2588
https://security-tracker.debian.org/tracker/DSA-5908-1
Several security issues were fixed in Mistral.
Several security issues were fixed in Mistral.
Apache Tomcat could be made to crash if it received specially crafted network traffic.
Apache Tomcat could be made to crash if it received specially crafted network traffic.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Update to version 2.10.0. Aside from the new upstream features, this update also refreshes many bundled dependencies, fixing a few CVEs. https://github.com/caddyserver/caddy/releases/tag/v2.10.0
Update to version 2.10.0. Aside from the new upstream features, this update also refreshes many bundled dependencies, fixing a few CVEs. https://github.com/caddyserver/caddy/releases/tag/v2.10.0
Heap buffer overflow in Codecs. (CVE-2025-3619) Use after free in USB. (CVE-2025-3620) References: – https://bugs.mageia.org/show_bug.cgi?id=34208
Heap buffer overflow in Codecs. (CVE-2025-3619) Use after free in USB. (CVE-2025-3620) References: – https://bugs.mageia.org/show_bug.cgi?id=34208
Juray Sarinay discovered that PDF documents signed with the adbe.pkcs7.sha1 standard were incompletely validated by LibreOffice, which could cause invalid signatures to be accepted as legitimate.
Juray Sarinay discovered that PDF documents signed with the adbe.pkcs7.sha1 standard were incompletely validated by LibreOffice, which could cause invalid signatures to be accepted as legitimate.
Several security vulnerabilities have been discovered in libsoup2.4, a http client/server library popularly used in GNOME, et.al. CVE-2025-2784
Multiple vulnerabilities have been fixed in the PDF rendering library poppler. CVE-2020-36023
* bsc#1241584 * bsc#1241585 Cross-References: * CVE-2015-3885
