Fedora Security Advisories

perl-JSON-XS-4.04-1.fc41

1 week 1 day ago
FEDORA-2025-86573bd5d5 Packages in this update:
  • perl-JSON-XS-4.04-1.fc41
Update description:

This update updates perl-JSON-XS 4.04. This version fixes heap overflow causing crashes, possibly information disclosure or worse (CVE-2025-40928) and causes JSON::XS to accept invalid JSON texts as valid in some cases.

perl-JSON-XS-4.04-1.fc43

1 week 1 day ago
FEDORA-2025-8b24ea25bb Packages in this update:
  • perl-JSON-XS-4.04-1.fc43
Update description:

This update updates perl-JSON-XS 4.04. This version fixes heap overflow causing crashes, possibly information disclosure or worse (CVE-2025-40928) and causes JSON::XS to accept invalid JSON texts as valid in some cases.

perl-JSON-XS-4.04-1.fc42

1 week 1 day ago
FEDORA-2025-53273e282c Packages in this update:
  • perl-JSON-XS-4.04-1.fc42
Update description:

This update updates perl-JSON-XS 4.04. This version fixes heap overflow causing crashes, possibly information disclosure or worse (CVE-2025-40928) and causes JSON::XS to accept invalid JSON texts as valid in some cases.

perl-Plack-Middleware-Session-0.36-1.fc42

1 week 3 days ago
FEDORA-2025-ca07c36a0a Packages in this update:
  • perl-Plack-Middleware-Session-0.36-1.fc42
Update description:

This update upgrade the package to version 0.36. This version fixes CVE-2025-40923 by using Crypt::SysRandom to generate secure session IDs.

perl-Catalyst-Plugin-Session-0.44-1.fc42

1 week 3 days ago
FEDORA-2025-90d5989bee Packages in this update:
  • perl-Catalyst-Plugin-Session-0.44-1.fc42
Update description:

This update upgrade the package to version 0.44. This version fixes CVE-2025-40924 by using Crypt::SysRandom to generate properly random session IDs.

libopenmpt-0.8.3-1.el10_2

1 week 3 days ago
FEDORA-EPEL-2025-3f414a0955 Packages in this update:
  • libopenmpt-0.8.3-1.el10_2
Update description: libopenmpt 0.8.3 (2025-09-06)
  • [Bug] libopenmpt is now compatible with most non-standard builds of libmpg123 which do not by default output signed 16bit PCM.
  • [Bug] openmpt123: Pausing playback using the space key did not work since 0.8.0.
  • [Bug] Windows 10 binaries wrongly targeted Windows 11 22H2. They now target Windows 10 2004.
  • [Bug] in_openmpt: in_openmpt for Windows XP or later did not ever work in Winamp 2.x. We now provide a build specifically for Winamp 2.x in the Winamp2/ folder inside the retro.winxp package. The retro.win98 build was not affected.
  • [Change] in_openmpt: Modern and legacy builds of in_openmpt now officially only support Winamp 5.x.
  • IT: Even when the filter cutoff envelope is stopped before its first tick is applied, the filter should still be activated.
  • mpg123: Update to v1.33.2 (2025-08-05).
libopenmpt 0.8.2 (2025-07-19)
  • [Sec] Possible out-of-bounds sample data read in a specific combination of reverse sample playback + offset past sample loop.
  • [Bug] Fixed pre-C++20 undefined behaviour due to left-shifting negative integer values.
  • [New] Makefile now supports DragonFly BSD.
  • openmpt123: FLAC multithreaded encoding has been enabled for Windows builds.
  • Since libopenmpt 0.8.0, swapping between samples on the rear channels could introduce a click on the front channels.
  • IT: Volume column slides no longer propagate their effect memory to the regular effect column volume slides.
  • FC: Allow files with a sequence size of 0 to load (fixes a broken copy of cult.smod).
  • ogg: Update to v1.3.6 (2025-06-16).

libopenmpt-0.8.3-1.el10_0

1 week 3 days ago
FEDORA-EPEL-2025-dc43510de4 Packages in this update:
  • libopenmpt-0.8.3-1.el10_0
Update description: libopenmpt 0.8.3 (2025-09-06)
  • [Bug] libopenmpt is now compatible with most non-standard builds of libmpg123 which do not by default output signed 16bit PCM.
  • [Bug] openmpt123: Pausing playback using the space key did not work since 0.8.0.
  • [Bug] Windows 10 binaries wrongly targeted Windows 11 22H2. They now target Windows 10 2004.
  • [Bug] in_openmpt: in_openmpt for Windows XP or later did not ever work in Winamp 2.x. We now provide a build specifically for Winamp 2.x in the Winamp2/ folder inside the retro.winxp package. The retro.win98 build was not affected.
  • [Change] in_openmpt: Modern and legacy builds of in_openmpt now officially only support Winamp 5.x.
  • IT: Even when the filter cutoff envelope is stopped before its first tick is applied, the filter should still be activated.
  • mpg123: Update to v1.33.2 (2025-08-05).
libopenmpt 0.8.2 (2025-07-19)
  • [Sec] Possible out-of-bounds sample data read in a specific combination of reverse sample playback + offset past sample loop.
  • [Bug] Fixed pre-C++20 undefined behaviour due to left-shifting negative integer values.
  • [New] Makefile now supports DragonFly BSD.
  • openmpt123: FLAC multithreaded encoding has been enabled for Windows builds.
  • Since libopenmpt 0.8.0, swapping between samples on the rear channels could introduce a click on the front channels.
  • IT: Volume column slides no longer propagate their effect memory to the regular effect column volume slides.
  • FC: Allow files with a sequence size of 0 to load (fixes a broken copy of cult.smod).
  • ogg: Update to v1.3.6 (2025-06-16).

libopenmpt-0.8.3-1.el8

1 week 3 days ago
FEDORA-EPEL-2025-8aaa96c683 Packages in this update:
  • libopenmpt-0.8.3-1.el8
Update description: libopenmpt 0.8.3 (2025-09-06)
  • [Bug] libopenmpt is now compatible with most non-standard builds of libmpg123 which do not by default output signed 16bit PCM.
  • [Bug] openmpt123: Pausing playback using the space key did not work since 0.8.0.
  • [Bug] Windows 10 binaries wrongly targeted Windows 11 22H2. They now target Windows 10 2004.
  • [Bug] in_openmpt: in_openmpt for Windows XP or later did not ever work in Winamp 2.x. We now provide a build specifically for Winamp 2.x in the Winamp2/ folder inside the retro.winxp package. The retro.win98 build was not affected.
  • [Change] in_openmpt: Modern and legacy builds of in_openmpt now officially only support Winamp 5.x.
  • IT: Even when the filter cutoff envelope is stopped before its first tick is applied, the filter should still be activated.
  • mpg123: Update to v1.33.2 (2025-08-05).
libopenmpt 0.8.2 (2025-07-19)
  • [Sec] Possible out-of-bounds sample data read in a specific combination of reverse sample playback + offset past sample loop.
  • [Bug] Fixed pre-C++20 undefined behaviour due to left-shifting negative integer values.
  • [New] Makefile now supports DragonFly BSD.
  • openmpt123: FLAC multithreaded encoding has been enabled for Windows builds.
  • Since libopenmpt 0.8.0, swapping between samples on the rear channels could introduce a click on the front channels.
  • IT: Volume column slides no longer propagate their effect memory to the regular effect column volume slides.
  • FC: Allow files with a sequence size of 0 to load (fixes a broken copy of cult.smod).
  • ogg: Update to v1.3.6 (2025-06-16).

libopenmpt-0.8.3-1.el10_1

1 week 3 days ago
FEDORA-EPEL-2025-3f99ee4dca Packages in this update:
  • libopenmpt-0.8.3-1.el10_1
Update description: libopenmpt 0.8.3 (2025-09-06)
  • [Bug] libopenmpt is now compatible with most non-standard builds of libmpg123 which do not by default output signed 16bit PCM.
  • [Bug] openmpt123: Pausing playback using the space key did not work since 0.8.0.
  • [Bug] Windows 10 binaries wrongly targeted Windows 11 22H2. They now target Windows 10 2004.
  • [Bug] in_openmpt: in_openmpt for Windows XP or later did not ever work in Winamp 2.x. We now provide a build specifically for Winamp 2.x in the Winamp2/ folder inside the retro.winxp package. The retro.win98 build was not affected.
  • [Change] in_openmpt: Modern and legacy builds of in_openmpt now officially only support Winamp 5.x.
  • IT: Even when the filter cutoff envelope is stopped before its first tick is applied, the filter should still be activated.
  • mpg123: Update to v1.33.2 (2025-08-05).
libopenmpt 0.8.2 (2025-07-19)
  • [Sec] Possible out-of-bounds sample data read in a specific combination of reverse sample playback + offset past sample loop.
  • [Bug] Fixed pre-C++20 undefined behaviour due to left-shifting negative integer values.
  • [New] Makefile now supports DragonFly BSD.
  • openmpt123: FLAC multithreaded encoding has been enabled for Windows builds.
  • Since libopenmpt 0.8.0, swapping between samples on the rear channels could introduce a click on the front channels.
  • IT: Volume column slides no longer propagate their effect memory to the regular effect column volume slides.
  • FC: Allow files with a sequence size of 0 to load (fixes a broken copy of cult.smod).
  • ogg: Update to v1.3.6 (2025-06-16).

libopenmpt-0.8.3-1.el9

1 week 3 days ago
FEDORA-EPEL-2025-305ac41026 Packages in this update:
  • libopenmpt-0.8.3-1.el9
Update description: libopenmpt 0.8.3 (2025-09-06)
  • [Bug] libopenmpt is now compatible with most non-standard builds of libmpg123 which do not by default output signed 16bit PCM.
  • [Bug] openmpt123: Pausing playback using the space key did not work since 0.8.0.
  • [Bug] Windows 10 binaries wrongly targeted Windows 11 22H2. They now target Windows 10 2004.
  • [Bug] in_openmpt: in_openmpt for Windows XP or later did not ever work in Winamp 2.x. We now provide a build specifically for Winamp 2.x in the Winamp2/ folder inside the retro.winxp package. The retro.win98 build was not affected.
  • [Change] in_openmpt: Modern and legacy builds of in_openmpt now officially only support Winamp 5.x.
  • IT: Even when the filter cutoff envelope is stopped before its first tick is applied, the filter should still be activated.
  • mpg123: Update to v1.33.2 (2025-08-05).
libopenmpt 0.8.2 (2025-07-19)
  • [Sec] Possible out-of-bounds sample data read in a specific combination of reverse sample playback + offset past sample loop.
  • [Bug] Fixed pre-C++20 undefined behaviour due to left-shifting negative integer values.
  • [New] Makefile now supports DragonFly BSD.
  • openmpt123: FLAC multithreaded encoding has been enabled for Windows builds.
  • Since libopenmpt 0.8.0, swapping between samples on the rear channels could introduce a click on the front channels.
  • IT: Volume column slides no longer propagate their effect memory to the regular effect column volume slides.
  • FC: Allow files with a sequence size of 0 to load (fixes a broken copy of cult.smod).
  • ogg: Update to v1.3.6 (2025-06-16).
Checked
45 minutes 30 seconds ago