PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation. (CVE-2025-1094) References: - https://bugs.mageia.org/show_bug.cgi?id=34018 . MGASA-2025-0064 - Updated postgresql15 & postgresql13 packages fix security vulnerability Publication date: 14 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0064.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-1094 PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation. (CVE-2025-1094) References: - https://bugs.mageia.org/show_bug.cgi?id=34018 - https://www.postgresql.org/about/news/postgresql-173-167-1511-1416-and-1319-released-3015/ - https://www.cve.org/CVERecord?id=CVE-2025-1094 SRPMS: - 9/core/postgresql15-15.11-1.mga9 - 9/core/postgresql13-13.19-1.mga9 . Improvements for PostgreSQL versions 15 and 13 have been implemented to resolve security vulnerabilities in Mageia release 9. Discover further details here.. PostgreSQL Security Updates,Mageia Security Advisory,Encoding Vulnerability Fix. . LinuxSecurity.com Team
The update of smarty3 released as DLA-2618-1 induced a regression due to a syntax error in sysplugins/smarty_security.php. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2618-2
Get the latest Linux and open source security news straight to your inbox.