Explore top 10 tips to secure your open-source projects now. Read More
×
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7431 http://linux.oracle.com/errata/ELSA-2025-7431.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: php-8.0.30-3.el9_6.x86_64.rpm php-bcmath-8.0.30-3.el9_6.x86_64.rpm php-cli-8.0.30-3.el9_6.x86_64.rpm php-common-8.0.30-3.el9_6.x86_64.rpm php-dba-8.0.30-3.el9_6.x86_64.rpm php-dbg-8.0.30-3.el9_6.x86_64.rpm php-devel-8.0.30-3.el9_6.x86_64.rpm php-embedded-8.0.30-3.el9_6.x86_64.rpm php-enchant-8.0.30-3.el9_6.x86_64.rpm php-ffi-8.0.30-3.el9_6.x86_64.rpm php-fpm-8.0.30-3.el9_6.x86_64.rpm php-gd-8.0.30-3.el9_6.x86_64.rpm php-gmp-8.0.30-3.el9_6.x86_64.rpm php-intl-8.0.30-3.el9_6.x86_64.rpm php-ldap-8.0.30-3.el9_6.x86_64.rpm php-mbstring-8.0.30-3.el9_6.x86_64.rpm php-mysqlnd-8.0.30-3.el9_6.x86_64.rpm php-odbc-8.0.30-3.el9_6.x86_64.rpm php-opcache-8.0.30-3.el9_6.x86_64.rpm php-pdo-8.0.30-3.el9_6.x86_64.rpm php-pgsql-8.0.30-3.el9_6.x86_64.rpm php-process-8.0.30-3.el9_6.x86_64.rpm php-snmp-8.0.30-3.el9_6.x86_64.rpm php-soap-8.0.30-3.el9_6.x86_64.rpm php-xml-8.0.30-3.el9_6.x86_64.rpm aarch64: php-8.0.30-3.el9_6.aarch64.rpm php-bcmath-8.0.30-3.el9_6.aarch64.rpm php-cli-8.0.30-3.el9_6.aarch64.rpm php-common-8.0.30-3.el9_6.aarch64.rpm php-dba-8.0.30-3.el9_6.aarch64.rpm php-dbg-8.0.30-3.el9_6.aarch64.rpm php-devel-8.0.30-3.el9_6.aarch64.rpm php-embedded-8.0.30-3.el9_6.aarch64.rpm php-enchant-8.0.30-3.el9_6.aarch64.rpm php-ffi-8.0.30-3.el9_6.aarch64.rpm php-fpm-8.0.30-3.el9_6.aarch64.rpm php-gd-8.0.30-3.el9_6.aarch64.rpm php-gmp-8.0.30-3.el9_6.aarch64.rpm php-intl-8.0.30-3.el9_6.aarch64.rpm php-ldap-8.0.30-3.el9_6.aarch64.rpm php-mbstring-8.0.30-3.el9_6.aarch64.rpm php-mysqlnd-8.0.30-3.el9_6.aarch64.rpm php-odbc-8.0.30-3.el9_6.aarch64.rpm php-opcache-8.0.30-3.el9_6.aarch64.rpm php-pdo-8.0.30-3.el9_6.aarch64.rpm php-pgsql-8.0.30-3.el9_6.aarch64.rpm php-process-8.0.30-3.el9_6.aarch64.rpm php-snmp-8.0.30-3.el9_6.aarch64.rpm php-soap-8.0.30-3.el9_6.aarch64.rpm php-xml-8.0.30-3.el9_6.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//php-8.0.30-3.el9_6.src.rpm Related CVEs: CVE-2025-1217 CVE-2025-1219 CVE-2025-1734 CVE-2025-1736 CVE-2025-1861 Description of changes: [8.0.30-3] - Fix libxmlstreams use wrong content-type header when requesting a redirected resource CVE-2025-1219 - Fix Stream HTTP wrapper header check might omit basic auth header CVE-2025-1736 - Fix Stream HTTP wrapper truncate redirect location to 1024 bytes CVE-2025-1861 - Fix Streams HTTP wrapper does not fail for headers without colon CVE-2025-1734 - Fix Header parser of http stream wrapper does not handle folded headers CVE-2025-1217 _______________________________________________ El-errata mailing list
Unbundle libxml.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-af22a87e43 2025-03-13 01:47:29.556536+00:00 -------------------------------------------------------------------------------- Name : qt6-qtwebengine Product : Fedora 40 Version : 6.8.2 Release : 4.fc40 URL : http://www.qt.io Summary : Qt6 - QtWebEngine components Description : Qt6 - QtWebEngine components. -------------------------------------------------------------------------------- Update Information: Unbundle libxml. -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 4 2025 Jan Grulich - 6.8.2-4 - Unbundle libxml and libxslt * Mon Mar 3 2025 Jan Grulich - 6.8.2-3 - Rework OpenH264 support following Chromium package - Backport upstream change for ffmpeg codec selection issues. * Mon Feb 17 2025 Jan Grulich - 6.8.2-2 - Bump build for ppc64le enablement -------------------------------------------------------------------------------- References: [ 1 ] Bug #2280538 - CVE-2024-34459 qt6-qtwebengine: libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2280538 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-af22a87e43' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Libxml - GHSA-3qrf-m4j2-pcrr (Security issue with external entity loading in XML without enabling it). (CVE-2023-3823) Phar - GHSA-jqcx-ccgc-xwhv (Buffer mismanagement in phar_dir_read()) (CVE-2023-3824) . MGASA-2023-0248 - Updated php packages fix security vulnerability Publication date: 23 Aug 2023 URL: https://advisories.mageia.org/MGASA-2023-0248.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-3823, CVE-2023-3824 Libxml - GHSA-3qrf-m4j2-pcrr (Security issue with external entity loading in XML without enabling it). (CVE-2023-3823) Phar - GHSA-jqcx-ccgc-xwhv (Buffer mismanagement in phar_dir_read()) (CVE-2023-3824) References: - https://bugs.mageia.org/show_bug.cgi?id=32158 - https://www.php.net/ChangeLog-8.php#8.0.30 - https://www.cve.org/CVERecord?id=CVE-2023-3823 - https://www.cve.org/CVERecord?id=CVE-2023-3824 SRPMS: - 8/core/php-8.0.30-1.mga8 . Ubuntu 2023-0385 resolves serious python vulnerabilities affecting earlier editions by rectifying memory handling flaws and injection threats.. Mageia Security, PHP Update, Buffer Management, Entity Loading Issue, Software Patch. . Severity: Critical. LinuxSecurity.com Team
XML::LibXML could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-2592-1 May 04, 2015 libxml-libxml-perl vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: XML::LibXML could be made to expose sensitive information. Software Description: - libxml-libxml-perl: Perl interface to the libxml2 library Details: Tilmann Haak discovered that XML::LibXML incorrectly handled the expand_entities parameter in certain situations. A remote attacker could possibly use this issue to access sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: libxml-libxml-perl 2.0116+dfsg-1ubuntu0.15.04.1 Ubuntu 14.10: libxml-libxml-perl 2.0116+dfsg-1ubuntu0.14.10.1 Ubuntu 14.04 LTS: libxml-libxml-perl 2.0108+dfsg-1ubuntu0.1 Ubuntu 12.04 LTS: libxml-libxml-perl 1.89+dfsg-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2592-1 CVE-2015-3451 Package Information: https://launchpad.net/ubuntu/+source/libxml-libxml-perl/2.0116+dfsg-1ubuntu0.15.04.1 https://launchpad.net/ubuntu/+source/libxml-libxml-perl/2.0116+dfsg-1ubuntu0.14.10.1 https://launchpad.net/ubuntu/+source/libxml-libxml-perl/2.0108+dfsg-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libxml-libxml-perl/1.89+dfsg-1ubuntu0.1 . A vulnerability found in the libxml-libxml-perl package of Ubuntu could potentially leak confidential information. Follow the provided steps for updates.. libxml, update instructions, exposure risk, ubuntu security. . Severity: Critical. LinuxSecurity.com Team
Tilmann Haak from xing.com discovered that XML::LibXML, a Perl interface to the libxml2 library, did not respect the expand_entities parameter to disable processing of external entities in some circumstances. This may allow attackers to gain read access to otherwise protected ressources, . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3243-1
Jueri Aedla discovered a buffer overflow in the libxml XML library, which could result in the execution of arbitrary code. For the stable distribution (squeeze), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2580-1
This update includes patches from RHEL-3 addressing a number of security vulnerabilities: - CVE-2004-0110 (arbitrary code execution via a long URL) - CVE-2004-0989 (arbitrary code execution via a long URL) - CVE-2009-2414 (stack consumption DoS vulnerabilities) - CVE-2009-2416 (use-after-free DoS vulnerabilities). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-8594 2009-08-15 07:20:42 -------------------------------------------------------------------------------- Name : libxml Product : Fedora 10 Version : 1.8.17 Release : 24.fc10 URL : http://veillard.com/XML/ Summary : Old XML library for Gnome-1 application compatibility Description : This library allows old Gnome-1 applications to manipulate XML files. -------------------------------------------------------------------------------- Update Information: This update includes patches from RHEL-3 addressing a number of security vulnerabilities: - CVE-2004-0110 (arbitrary code execution via a long URL) - CVE-2004-0989 (arbitrary code execution via a long URL) - CVE-2009-2414 (stack consumption DoS vulnerabilities) - CVE-2009-2416 (use-after-free DoS vulnerabilities) -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 12 2009 Paul Howarth 1:1.8.17-24 - renumber existing patches to free up low-numbered patches for EL-3 patches - add patch for CAN-2004-0110 and CAN-2004-0989 (#139090) - add patch for CVE-2009-2414 and CVE-2009-2416 (#515195, #515205) * Sat Jul 25 2009 Fedora Release Engineering 1:1.8.17-23 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Mon Apr 20 2009 Paul Howarth 1:1.8.17-22 - rebuild for %{_isa} provides/requires * Wed Feb 25 2009 Fedora Release Engineering 1:1.8.17-21 - rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #430644- CVE-2004-0110 libxml2 long URL causes SEGV https://bugzilla.redhat.com/show_bug.cgi?id=430644 [ 2 ] Bug #430645 - CVE-2004-0989 libxml2 various overflows https://bugzilla.redhat.com/show_bug.cgi?id=430645 [ 3 ] Bug #515195 - CVE-2009-2414 libxml, libxml2: Stack overflow by parsing root XML element DTD definition https://bugzilla.redhat.com/show_bug.cgi?id=515195 [ 4 ] Bug #515205 - CVE-2009-2416 libxml, libxml2: Pointer use-after-free flaws by parsing Notation and Enumeration attribute types https://bugzilla.redhat.com/show_bug.cgi?id=515205 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libxml' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
This update includes patches from RHEL-3 addressing a number of security vulnerabilities: - CVE-2004-0110 (arbitrary code execution via a long URL) - CVE-2004-0989 (arbitrary code execution via a long URL) - CVE-2009-2414 (stack consumption DoS vulnerabilities) - CVE-2009-2416 (use-after-free DoS vulnerabilities). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-8582 2009-08-15 07:17:49 -------------------------------------------------------------------------------- Name : libxml Product : Fedora 11 Version : 1.8.17 Release : 24.fc11 URL : http://veillard.com/XML/ Summary : Old XML library for Gnome-1 application compatibility Description : This library allows old Gnome-1 applications to manipulate XML files. -------------------------------------------------------------------------------- Update Information: This update includes patches from RHEL-3 addressing a number of security vulnerabilities: - CVE-2004-0110 (arbitrary code execution via a long URL) - CVE-2004-0989 (arbitrary code execution via a long URL) - CVE-2009-2414 (stack consumption DoS vulnerabilities) - CVE-2009-2416 (use-after-free DoS vulnerabilities) -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 12 2009 Paul Howarth 1:1.8.17-24 - renumber existing patches to free up low-numbered patches for EL-3 patches - add patch for CAN-2004-0110 and CAN-2004-0989 (#139090) - add patch for CVE-2009-2414 and CVE-2009-2416 (#515195, #515205) * Sat Jul 25 2009 Fedora Release Engineering 1:1.8.17-23 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Mon Apr 20 2009 Paul Howarth 1:1.8.17-22 - rebuild for %{_isa} provides/requires -------------------------------------------------------------------------------- References: [ 1 ] Bug #430644 - CVE-2004-0110 libxml2 long URL causes SEGV https://bugzilla.redhat.com/show_bug.cgi?id=430644 [ 2 ] Bug #430645 -CVE-2004-0989 libxml2 various overflows https://bugzilla.redhat.com/show_bug.cgi?id=430645 [ 3 ] Bug #515195 - CVE-2009-2414 libxml, libxml2: Stack overflow by parsing root XML element DTD definition https://bugzilla.redhat.com/show_bug.cgi?id=515195 [ 4 ] Bug #515205 - CVE-2009-2416 libxml, libxml2: Pointer use-after-free flaws by parsing Notation and Enumeration attribute types https://bugzilla.redhat.com/show_bug.cgi?id=515205 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libxml' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.