xz 5.8.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-051becf4f2 2025-05-10 01:58:21.497365+00:00 -------------------------------------------------------------------------------- Name : perl-Compress-Raw-Lzma Product : Fedora 41 Version : 2.212 Release : 6.fc41 URL : https://metacpan.org/dist/Compress-Raw-Lzma Summary : Low-level interface to lzma compression library Description : This module provides a Perl interface to the lzma compression library. It is used by IO::Compress::Lzma. -------------------------------------------------------------------------------- Update Information: xz 5.8.1 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 3 2025 Richard W.M. Jones - 2.212-6 - Rebuild against xz 5.8.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2357253 - CVE-2025-31115 xz: XZ has a heap-use-after-free bug in threaded .xz decoder [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2357253 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-051becf4f2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
xz 5.8.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4871b31998 2025-05-10 01:38:46.492145+00:00 -------------------------------------------------------------------------------- Name : perl-Compress-Raw-Lzma Product : Fedora 40 Version : 2.209 Release : 9.fc40 URL : https://metacpan.org/dist/Compress-Raw-Lzma Summary : Low-level interface to lzma compression library Description : This module provides a Perl interface to the lzma compression library. It is used by IO::Compress::Lzma. -------------------------------------------------------------------------------- Update Information: xz 5.8.1 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 3 2025 Richard W.M. Jones - 2.209-9 - Rebuild against xz 5.8.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2357251 - CVE-2025-31115 xz: XZ has a heap-use-after-free bug in threaded .xz decoder [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2357251 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4871b31998' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Tobias Stoeckmann discovered that the libXpm library contained two integer overflow flaws, leading to a heap out-of-bounds write, while parsing XPM extensions in a file. An attacker can provide a specially crafted XPM file that, when processed by an application using the libXpm . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3772-1
Get the latest Linux and open source security news straight to your inbox.