Update to latest version (#2404637) Fix CVE-2025-47910, CVE-2025-47906, CVE-2025-26625. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f8d1e1df04 2025-10-29 01:45:52.929013+00:00 -------------------------------------------------------------------------------- Name : git-lfs Product : Fedora 42 Version : 3.7.1 Release : 1.fc42 URL : https://git-lfs.com/ Summary : Git extension for versioning large files Description : Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. -------------------------------------------------------------------------------- Update Information: Update to latest version (#2404637) Fix CVE-2025-47910, CVE-2025-47906, CVE-2025-26625 -------------------------------------------------------------------------------- ChangeLog: * Mon Oct 20 2025 Elliott Sales de Andrade - 3.7.1-1 - Update to latest version (#2404637) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398691 - CVE-2025-47910 git-lfs: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398691 [ 2 ] Bug #2399372 - CVE-2025-47906 git-lfs: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399372 [ 3 ] Bug #2404637 - git-lfs-3.7.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2404637 [ 4 ] Bug #2404744 - CVE-2025-26625 git-lfs: Git LFS may write to arbitrary files via crafted symlinks [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2404744 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f8d1e1df04' atthe command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update plantuml to the latest version v1.2023.11. This update also includes fixes for CVE-2023-3431 and CVE-2023-3432.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-731133ab8e 2023-10-01 03:37:03.210259 -------------------------------------------------------------------------------- Name : plantuml Product : Fedora 39 Version : 1.2023.11 Release : 1.fc39 URL : https://plantuml.com/ Summary : Program to generate UML diagram from a text description Description : PlantUML is a program allowing to draw UML diagrams, using a simple and human readable text description. It is extremely useful for code documenting, sketching project architecture during team conversations and so on. PlantUML supports the following diagram types - sequence diagram - use case diagram - class diagram - activity diagram - component diagram - state diagram -------------------------------------------------------------------------------- Update Information: Update plantuml to the latest version v1.2023.11. This update also includes fixes for CVE-2023-3431 and CVE-2023-3432. -------------------------------------------------------------------------------- ChangeLog: * Sat Sep 23 2023 blinxen - 1:1.2023.11-1 - Update to version 1.2023.11 (rhbz#2232105) * Fri Sep 22 2023 blinxen - 1:1.2023.7-4 - Migrate license specification to SPDX -------------------------------------------------------------------------------- References: [ 1 ] Bug #2218063 - CVE-2023-3432 plantuml: URL Restriction Bypass in plantuml/plantuml https://bugzilla.redhat.com/show_bug.cgi?id=2218063 [ 2 ] Bug #2218066 - CVE-2023-3431 plantuml: Local file read through %load_json in plantuml/plantuml https://bugzilla.redhat.com/show_bug.cgi?id=2218066 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2023-731133ab8e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
It was found that wkhtmltopdf, a command line utility to render HTML files into PDF, allowed local filesystem access by default. This update disables local filesystem access, but it can be enabled if necessary with the --enable-local-file-access or the --allow options. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3158-1
n issue has been found in libxfont, an X11 font rasterisation library. By creating symlinks, a local attacker can open (but not read) local files as user root. This might create unwanted actions with special files like . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2901-1
Several security issues were fixed in Aptdaemon.. =========================================================================Ubuntu Security Notice USN-4664-1 December 08, 2020 aptdaemon vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Aptdaemon. Software Description: - aptdaemon: transaction based package management service Details: Kevin Backhouse discovered that Aptdaemon incorrectly handled certain properties. A local attacker could use this issue to test for the presence of local files. (CVE-2020-16128) Kevin Backhouse discovered that Aptdaemon incorrectly handled permission checks. A local attacker could possibly use this issue to cause a denial of service. (CVE-2020-27349) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: aptdaemon 1.1.1+bzr982-0ubuntu34.1 Ubuntu 20.04 LTS: aptdaemon 1.1.1+bzr982-0ubuntu32.3 Ubuntu 18.04 LTS: aptdaemon 1.1.1+bzr982-0ubuntu19.5 Ubuntu 16.04 LTS: aptdaemon 1.1.1+bzr982-0ubuntu14.5 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4664-1 CVE-2020-16128, CVE-2020-27349 Package Information: https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu34.1 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu32.3 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu19.5 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu14.5 . Ubuntu security bulletin concerning Aptdaemon vulnerabilities that may allow for local file exposure and possible denial ofservice scenarios.. Aptdaemon vulnerabilities, Ubuntu update, local file access issues. . Severity: Important. LinuxSecurity.com Team
Mozilla: Use-after-free during worker shutdown (CVE-2020-12387) * Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 (CVE-2020-12395) * usrsctp: Buffer overflow in AUTH chunk input validation (CVE-2020-6831) * Mozilla: Arbitrary local file access with 'Copy as cURL' (CVE-2020-12392) * Mozilla: Sender Email Address Spoofing using encoded Unicode characters (CVE-2020-12397) [More...]. Synopsis: Critical: thunderbird security update Advisory ID: SLSA-2020:2049-1 Issue Date: 2020-05-11 CVE Numbers: None -- Security Fix(es): * Mozilla: Use-after-free during worker shutdown (CVE-2020-12387) * Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 (CVE-2020-12395) * usrsctp: Buffer overflow in AUTH chunk input validation (CVE-2020-6831) * Mozilla: Arbitrary local file access with 'Copy as cURL' (CVE-2020-12392) * Mozilla: Sender Email Address Spoofing using encoded Unicode characters(CVE-2020-12397) -- SL6 x86_64 thunderbird-68.8.0-1.el6_10.x86_64.rpm thunderbird-debuginfo-68.8.0-1.el6_10.x86_64.rpm i386 thunderbird-68.8.0-1.el6_10.i686.rpm thunderbird-debuginfo-68.8.0-1.el6_10.i686.rpm - Scientific Linux Development Team . Important Thunderbird security patch addresses multiple vulnerabilities in Scientific Linux systems. Keep your data safe!. thunderbird security update, Scientific Linux advisory, buffer overflow fix, use-after-free vulnerability, local file access issue. . Severity: Critical. LinuxSecurity.com Team
Mozilla: Use-after-free during worker shutdown (CVE-2020-12387) * Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 (CVE-2020-12395) * Mozilla: Buffer overflow in SCTP chunk input validation (CVE-2020-6831) * Mozilla: Arbitrary local file access with 'Copy as cURL' (CVE-2020-12392) SL6 x86_64 firefox-68.8.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.8.0-1.el6_10. [More...]. Synopsis: Critical: firefox security update Advisory ID: SLSA-2020:2036-1 Issue Date: 2020-05-06 CVE Numbers: None -- Security Fix(es): * Mozilla: Use-after-free during worker shutdown (CVE-2020-12387) * Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 (CVE-2020-12395) * Mozilla: Buffer overflow in SCTP chunk input validation (CVE-2020-6831) * Mozilla: Arbitrary local file access with 'Copy as cURL' (CVE-2020-12392) -- SL6 x86_64 firefox-68.8.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.8.0-1.el6_10.x86_64.rpm firefox-68.8.0-1.el6_10.i686.rpm firefox-debuginfo-68.8.0-1.el6_10.i686.rpm i386 firefox-68.8.0-1.el6_10.i686.rpm firefox-debuginfo-68.8.0-1.el6_10.i686.rpm - Scientific Linux Development Team . Crucial Firefox patch addresses buffer overflow, memory safety, and unauthorized file access issues. firefox security update, buffer overflow, memory safety, local file access, SLSA advisory. . Severity: Critical. LinuxSecurity.com Team
An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2020:2031-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2031 Issue date: 2020-05-06 CVE Names: CVE-2020-6831 CVE-2020-12387 CVE-2020-12392 CVE-2020-12395 ==================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 68.8.0 ESR. Security Fix(es): * Mozilla: Use-after-free during worker shutdown (CVE-2020-12387) * Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 (CVE-2020-12395) * Mozilla: Buffer overflow in SCTP chunk input validation (CVE-2020-6831) * Mozilla: Arbitrary local file access with 'Copy as cURL' (CVE-2020-12392) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4.Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1831761 - CVE-2020-12387 Mozilla: Use-after-free during worker shutdown 1831763 - CVE-2020-6831 Mozilla: Buffer overflow in SCTP chunk input validation 1831764 - CVE-2020-12392 Mozilla: Arbitrary local file access with 'Copy as cURL' 1831765 - CVE-2020-12395 Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: firefox-68.8.0-1.el8_2.src.rpm aarch64: firefox-68.8.0-1.el8_2.aarch64.rpm firefox-debuginfo-68.8.0-1.el8_2.aarch64.rpm firefox-debugsource-68.8.0-1.el8_2.aarch64.rpm ppc64le: firefox-68.8.0-1.el8_2.ppc64le.rpm firefox-debuginfo-68.8.0-1.el8_2.ppc64le.rpm firefox-debugsource-68.8.0-1.el8_2.ppc64le.rpm s390x: firefox-68.8.0-1.el8_2.s390x.rpm firefox-debuginfo-68.8.0-1.el8_2.s390x.rpm firefox-debugsource-68.8.0-1.el8_2.s390x.rpm x86_64: firefox-68.8.0-1.el8_2.x86_64.rpm firefox-debuginfo-68.8.0-1.el8_2.x86_64.rpm firefox-debugsource-68.8.0-1.el8_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-6831 https://access.redhat.com/security/cve/CVE-2020-12387 https://access.redhat.com/security/cve/CVE-2020-12392 https://access.redhat.com/security/cve/CVE-2020-12395 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXrJ40tzjgjWX9erEAQhPEg/5AV9V68w1Pwr0fBV0sldXKFnPF+xJ2/2r eV9Bv46+Tb0gOlak7cLqmbL3FCNhNH2qV2b48UKrvfHZgWu/bIozLyq+JmCeExrk o0II7XaKja5hBdvKqlKX/4q5sm9PWR+Oay6kX6cR6PwZg91mbJ81QdRuCWBqvCXM 251NMmjzaFBnlLmfhBq/5cRxiNB36UMwn3RTB3Ai0z94WG3XYIEIVujBOjMlaxEq hn78HOUz34AuCu+kvaJwH3/L3Qtqu2FChlT56bk+TmYx+02mezS6ivhF7+gmal47 379sI7tKEY7CgqFWctrxAeGLzKI/zVR0ucoY9AFrJA1YaY36d6RTsdAQlrX76S6z 4SjhXXKNSnWlGqLkJtIu5oBFPXeGs6zUm8bvWLutQXPmQcUL1CwsCV72BTzzAHIm zxOE04EU0b3f2UWObI3VUYjbtOxj+YUEyBNdNRaN42JEJgq+S1XjHx+nsdBfXJqY HZ28fJ8ddzfDiGzkbczrYd8aKcIBIQ6qSbt0kT2ddg4Zm+TYHCk7f0nLGp00Fhwe k3RjH2q9f+8s/D/XcHjoOvgJaZ4gispSLdxRM6vZeHoS4whcH5mbaCDeU7IMUU+J s03BH0QOOz5ShDaIpuWzMYitQi5SwZCoxhvtKOSJio2ejhiIY8A+aBirfV0BfsIh NOHKwK5q/UY=XmB/ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.