Aggregator

USN-7886-1: Python vulnerabilities

2 weeks 6 days ago
It was discovered that Python inefficiently handled expanding system environment variables. An attacker could possibly use this issue to cause Python to consume excessive resources, leading to a denial of service. (CVE-2025-6075) Caleb Brown discovered that Python incorrectly handled the ZIP64 End of Central Directory (EOCD) Locator record offset value. An attacker could possibly use this issue to obfuscate malicious content. (CVE-2025-8291)

USN-7878-2: cups-filters vulnerabilities

2 weeks 6 days ago
USN-7878-1 fixed vulnerabilities in cups-filters, This update provides the corresponding update for CVE-2025-64524 for Ubuntu 25.04. Original advisory details: It was discovered that cups-filters incorrectly handled certain malformed TIFF image files. A remote attacker could use this issue to cause cups-filters to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2025-57812) It was discovered that cups-filters incorrectly handled certain malformed PDF document files. A remote attacker could use this issue to cause cups-filters to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2025-64503) It was discovered that cups-filters incorrectly handled certain malformed CUPS Raster files. A remote attacker could use this issue to cause cups-filters to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-64524)

USN-7885-1: OpenJDK 21 vulnerabilities

2 weeks 6 days ago
Jinfeng Guo discovered that the Security component of OpenJDK 21 did not correctly handle certain representations of encoded strings. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (CVE-2025-53057) Darius Bohni discovered that the JAXP component of OpenJDK 21 was vulnerable to a XML External Entity (XEE) attack. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (CVE-2025-53066) Yakov Shafranovich discovered that the Libraries component of OpenJDK 21 contained an issue where certain Strings built with StringBuilder returned an incorrect result for String.equals() checks. An unauthenticated remote attacker could possibly use this issue to update, insert, or delete accessible data. (CVE-2025-61748) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2025-10-21

USN-7884-1: OpenJDK 25 vulnerabilities

2 weeks 6 days ago
Jinfeng Guo discovered that the Security component of OpenJDK 25 did not correctly handle certain representations of encoded strings. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (CVE-2025-53057) Darius Bohni discovered that the JAXP component of OpenJDK 25 was vulnerable to a XML External Entity (XEE) attack. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (CVE-2025-53066) Yakov Shafranovich discovered that the Libraries component of OpenJDK 21 contained an issue where certain Strings built with StringBuilder returned an incorrect result for String.equals() checks. An unauthenticated remote attacker could possibly use this issue to update, insert, or delete accessible data. (CVE-2025-61748) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2025-10-21

USN-7851-2: runC regression

2 weeks 6 days ago
USN-7851-1 fixed vulnerabilities in runC. The introduction of a new upstream release has caused regressions in runc-app and runc-stable. This update fixes the problem. Original advisory details: Lei Wang and Li Fubang discovered that runC incorrectly handled masked paths. An attacker could possibly replace a container's /dev/null with a symlink to some other procfs file and possibly escape a container. (CVE-2025-31133) Lei Wang and Li Fubang discovered that runC incorrectly handled the /dev/console bind-mounts. An attacker could potentially exploit this issue to build-mount a symlink and escape a container. (CVE-2025-52565) Li Fubang and Tõnis Tiigi discovered that the fix for CVE-2019-16884 was incomplete. An attacker could possibly use this issue to cause a denial of service or escape the container. (CVE-2025-52881)

tigervnc-1.15.0-10.fc43

2 weeks 6 days ago
FEDORA-2025-e0c935675d Packages in this update:
  • tigervnc-1.15.0-10.fc43
Update description:

Fix recent xorg-x11-server CVEs: Fixes: CVE-2025-62229 CVE-2025-62230 CVE-2025-62231

tigervnc-1.15.0-10.fc42

2 weeks 6 days ago
FEDORA-2025-f59b250c31 Packages in this update:
  • tigervnc-1.15.0-10.fc42
Update description:

Fix recent xorg-x11-server CVEs: Fixes: CVE-2025-62229 CVE-2025-62230 CVE-2025-62231