Use-after-free in XSLT. (CVE-2025-1009) Use-after-free in Custom Highlight. (CVE-2025-1010) A bug in WebAssembly code generation could result in a crash. (CVE-2025-1011) Use-after-free during concurrent delazification. (CVE-2025-1012) . MGASA-2025-0045 - Updated rootcerts, nss & firefox packages fix security vulnerabilities Publication date: 09 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0045.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-1009, CVE-2025-1010, CVE-2025-1011, CVE-2025-1012, CVE-2024-11704, CVE-2025-1013, CVE-2025-1014, CVE-2025-1016, CVE-2025-1017 Use-after-free in XSLT. (CVE-2025-1009) Use-after-free in Custom Highlight. (CVE-2025-1010) A bug in WebAssembly code generation could result in a crash. (CVE-2025-1011) Use-after-free during concurrent delazification. (CVE-2025-1012) Potential double-free vulnerability in PKCS#7 decryption handling. (CVE-2024-11704) Potential opening of private browsing tabs in normal browsing windows. (CVE-2025-1013) Certificate length was not properly checked. (CVE-2025-1014) Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7. (CVE-2025-1016) Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. (CVE-2025-1017) References: - https://bugs.mageia.org/show_bug.cgi?id=33983 - https://www.firefox.com/en-US/firefox/128.7.0/releasenotes/?redirect_source=mozilla-org - https://www.mozilla.org/en-US/security/advisories/mfsa2025-09/ - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_108.html#mozilla-projects-nss-nss-3-108-release-notes - https://www.cve.org/CVERecord?id=CVE-2025-1009 - https://www.cve.org/CVERecord?id=CVE-2025-1010 - https://www.cve.org/CVERecord?id=CVE-2025-1011 - https://www.cve.org/CVERecord?id=CVE-2025-1012 - https://www.cve.org/CVERecord?id=CVE-2024-11704 - https://www.cve.org/CVERecord?id=CVE-2025-1013 -https://www.cve.org/CVERecord?id=CVE-2025-1014 - https://www.cve.org/CVERecord?id=CVE-2025-1016 - https://www.cve.org/CVERecord?id=CVE-2025-1017 SRPMS: - 9/core/rootcerts-20250130.00-1.mga9 - 9/core/nss-3.108.0-1.mga9 - 9/core/firefox-128.7.0-1.mga9 - 9/core/firefox-l10n-128.7.0-1.mga9 . Mageia 2025-0046 resolves various vulnerabilities in libssl, gnutls, and chromium software to improve overall performance.. firefox updates, mageia security, rootcerts vulnerabilities, nss patches. . LinuxSecurity.com Team
Select list elements could be shown over another site. (CVE-2024-11692) CSP Bypass and XSS Exposure via Web Compatibility Shims. (CVE-2024-11694) URL Bar Spoofing via Manipulated Punycode and Whitespace Characters. (CVE-2024-11695) . MGASA-2024-0383 - Updated rootcerts, nss & firefox packages fix security vulnerabilities Publication date: 02 Dec 2024 URL: https://advisories.mageia.org/MGASA-2024-0383.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-11692, CVE-2024-11694, CVE-2024-11695, CVE-2024-11696, CVE-2024-11697, CVE-2024-11699 Select list elements could be shown over another site. (CVE-2024-11692) CSP Bypass and XSS Exposure via Web Compatibility Shims. (CVE-2024-11694) URL Bar Spoofing via Manipulated Punycode and Whitespace Characters. (CVE-2024-11695) Unhandled Exception in Add-on Signature Verification. (CVE-2024-11696) Improper Keypress Handling in Executable File Confirmation Dialog. (CVE-2024-11697) Memory safety bugs fixed in Firefox 133, Firefox ESR 128.5, and Thunderbird 128.5. (CVE-2024-11699) References: - https://bugs.mageia.org/show_bug.cgi?id=33804 - https://www.firefox.com/en-US/firefox/128.5.0/releasenotes/?redirect_source=mozilla-org - https://www.mozilla.org/en-US/security/advisories/mfsa2024-64/ - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_107.html#mozilla-projects-nss-nss-3-107-release-notes - https://www.cve.org/CVERecord?id=CVE-2024-11692 - https://www.cve.org/CVERecord?id=CVE-2024-11694 - https://www.cve.org/CVERecord?id=CVE-2024-11695 - https://www.cve.org/CVERecord?id=CVE-2024-11696 - https://www.cve.org/CVERecord?id=CVE-2024-11697 - https://www.cve.org/CVERecord?id=CVE-2024-11699 SRPMS: - 9/core/rootcerts-20241119.00-1.mga9 - 9/core/nss-3.107.0-1.mga9 - 9/core/firefox-128.5.0-1.mga9 - 9/core/firefox-l10n-128.5.0-1.mga9 . MGASA-2024-0451 addresses vulnerabilities in openssl and glibc for Mageia 9, strengthening system integrity and performance.. mageia updates, security fixes, firefox vulnerabilities, xssprotection, rootcerts update. . Severity: Critical. LinuxSecurity.com Team
Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates. r=KathleenWilson References: - https://bugs.mageia.org/show_bug.cgi?id=31232 . MGASA-2022-0462 - Updated rootcerts packages fix security vulnerability Publication date: 13 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0462.html Type: security Affected Mageia releases: 8 Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates. r=KathleenWilson References: - https://bugs.mageia.org/show_bug.cgi?id=31232 - https://phabricator.services.mozilla.com/D163527 - SRPMS: - 8/core/rootcerts-20221130.00-1.mga8 . MGASA-2022-0463 enhanced webserver packages addressing critical security issues, released on December 14, 2022.. Mageia Update, TrustCor Certificates, Security Fix, Root Certificates, Certificate Management. . LinuxSecurity.com Team
This update reverts the Symantec CA blacklist (which was originally #911289). The following root certificates were added back (+): + "GeoTrust Global CA" + "GeoTrust Primary Certification Authority" . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2593-1
An update that contains security fixes can now be An update that contains security fixes can now be An update that contains security fixes can now be installed. It includes one version update. installed. It includes one version update.. openSUSE Security Update: mozilla-nss: Update to 3.12.11 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2011:0935-1 Rating: important References: #712224 Affected Products: openSUSE 11.4 openSUSE 11.3 ______________________________________________________________________________ An update that contains security fixes can now be installed. It includes one version update. Description: The mozilla NSS libraries were updated to 3.12.11 to align with newer Mozilla seamonkey and Firefox releases. Interesting changes are: - blacklisting malicious root certificates - several bugfixes Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.4: zypper in -t patch libfreebl3-5023 - openSUSE 11.3: zypper in -t patch libfreebl3-5023 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.4 (i586 x86_64) [New Version: 3.12.11]: libfreebl3-3.12.11-1.3.1 libsoftokn3-3.12.11-1.3.1 mozilla-nss-3.12.11-1.3.1 mozilla-nss-certs-3.12.11-1.3.1 mozilla-nss-devel-3.12.11-1.3.1 mozilla-nss-sysinit-3.12.11-1.3.1 mozilla-nss-tools-3.12.11-1.3.1 - openSUSE 11.4 (x86_64) [New Version: 3.12.11]: libfreebl3-32bit-3.12.11-1.3.1 libsoftokn3-32bit-3.12.11-1.3.1 mozilla-nss-32bit-3.12.11-1.3.1 mozilla-nss-certs-32bit-3.12.11-1.3.1 mozilla-nss-sysinit-32bit-3.12.11-1.3.1 - openSUSE 11.3 (i586 x86_64) [New Version: 3.12.11]: libfreebl3-3.12.11-1.2.1 libsoftokn3-3.12.11-1.2.1 mozilla-nss-3.12.11-1.2.1 mozilla-nss-certs-3.12.11-1.2.1 mozilla-nss-devel-3.12.11-1.2.1 mozilla-nss-sysinit-3.12.11-1.2.1 mozilla-nss-tools-3.12.11-1.2.1 - openSUSE 11.3 (x86_64) [New Version: 3.12.11]: libfreebl3-32bit-3.12.11-1.2.1 libsoftokn3-32bit-3.12.11-1.2.1 mozilla-nss-32bit-3.12.11-1.2.1 mozilla-nss-certs-32bit-3.12.11-1.2.1 mozilla-nss-sysinit-32bit-3.12.11-1.2.1 References: . OpenSUSE has released a security patch to tackle vulnerabilities within Mozilla NSS, implementing measures to revoke problematic root certificates.. openSUSE Security, Mozilla NSS Update, Security Patches. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.