Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or a bypass of sandbox restrictions.
Archive for April, 2025
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails.
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails.
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails.
WordPress 6.8.1 is now available! This minor release includes fixes for 15 bugs throughout Core and the Block Editor addressing issues affecting multiple areas of WordPress including the block editor, multisite, and REST API. For a full list of bug fixes, please refer to the release candidate announcement. WordPress 6.8.1 is a short-cycle maintenance release. […]
H2O could be made to crash if it received specially crafted network traffic.
PostgreSQL could be made to execute arbitrary code if it received specially crafted input.
Rebuild with pregenerated cbindgen
update internal Libraw to 2025/03/17 snapshot
Fix CVE-2024-56406
Update to LibRaw 0.21.4.
poppler could be made to treat documents with forged signatures as legitimately signed.
Several security issues were fixed in GNU binutils.
Node.js could be made to crash if it received specially crafted network traffic.
Several security issues were fixed in libxml2.
Several security issues were fixed in the Linux kernel.
Update to version 2.10.0. Aside from the new upstream features, this update also refreshes many bundled dependencies, fixing a few CVEs. https://github.com/caddyserver/caddy/releases/tag/v2.10.0
Juray Sarinay discovered that PDF documents signed with the adbe.pkcs7.sha1 standard were incompletely validated by LibreOffice, which could cause invalid signatures to be accepted as legitimate.
Several security issues were fixed in Mistral.
Apache Tomcat could be made to crash if it received specially crafted network traffic.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Update to 135.0.7049.114
April 2025 CPU
Update to pgadmin-9.2.
April 2025 CPU
April 2025 CPU
Several security issues were fixed in the Linux kernel.
Automatic update for ImageMagick-7.1.1.47-1.fc40. Changelog for ImageMagick * Sun Mar 30 2025 Packit
Update to 1.24.1, fixes CVE-2025-2291.
Backport fixes for CVE-2025-32910, CVE-2025-32911, CVE-2025-32913 Backport fixes for CVE-2025-32050 CVE-2025-32052 CVE-2025-32053 CVE-2025-32906 CVE-2025-32907 CVE-2025-32909