* bsc#1223096 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757
Django could be made to log injection if received specially crafted input.
Update to 128.11.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/
Fixes CVE-2025-32873: Denial-of-service possibility in strip_tags() Fixes CVE-2025-48432: Potential log injection via unescaped request path
Rebuild for CVE-2024-12224, CVE-2025-4574
Rebuild against idna 1.0+ for CVE-2024-12224
* bsc#1215935 * bsc#1215936 * bsc#1233606 * bsc#1233608 * bsc#1233609
* bsc#1242015 Cross-References: * CVE-2025-3891
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in ModSecurity.
A stack-based buffer overflow has been fixed in ICU, a C++ and C library for Unicode and Globalization support. For Debian 11 bullseye, this problem has been fixed in version
Two vulnerabilities have been fixed in cJSON, a C library for parsing JSON. CVE-2023-26819
An input sanitization flaw in Konsole might allow remote attackers to execute commands via a malicious URL
An integer overflow vulnerability has been found in sysstat which could result in arbitrary code execution.
Fix CVE-2025-49112 Fix CVE-2025-49112
Security update
New version 4.4.7 Ignoring potential error when using udevadm in %post scriptlet
Update to 137.0.7151.103 CVE-2025-5958: Use after free in Media CVE-2025-5959: Type Confusion in V8
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574
Update to 3.12.11. gh-135034: [CVE 2024-12718] [CVE 2025-4138] [CVE 2025-4330] [CVE 2025-4435] [CVE 2025-4517] Fixes multiple issues that allowed tarfile extraction filters (filter=”data” and filter=”tar”) to be bypassed using crafted symlinks and hard links.
Fix CVE-2025-49466 (fedora#2370375)
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5942-1
* bsc#1240750 * bsc#1240752 * bsc#1240754 * bsc#1240756 * bsc#1240757
* bsc#1244035 Cross-References: * CVE-2025-22868 * CVE-2025-22869
* bsc#1237147 * bsc#1241938 * bsc#1243106 Cross-References:
* bsc#1242300 Cross-References: * CVE-2025-47268
* bsc#1232900 * bsc#1236701 * bsc#1239077 * bsc#1239096
* bsc#1236701 * bsc#1239077 * bsc#1239096 Cross-References:
