Rebuilt for CVE-2025-58185. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-cfdd59f20f 2025-12-30 00:38:13.645660+00:00 -------------------------------------------------------------------------------- Name : golang-github-alecthomas-chroma-2 Product : Fedora 43 Version : 2.14.0 Release : 6.fc43 URL : https://github.com/alecthomas/chroma Summary : A general purpose syntax highlighter in pure Go Description : A general purpose syntax highlighter in pure Go. -------------------------------------------------------------------------------- Update Information: Rebuilt for CVE-2025-58185 -------------------------------------------------------------------------------- ChangeLog: * Sun Dec 21 2025 W. Michael Petullo - 2.14.0-6 - Rebuilt for CVE-2025-58185 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2408184 - CVE-2025-58189 golang-github-alecthomas-chroma-2: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408184 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-cfdd59f20f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Security fix for [PUT CVEs HERE]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-33abbae37b 2021-02-07 01:38:28.260582 --------------------------------------------------------------------------------Name : python-pygments Product : Fedora 32 Version : 2.4.2 Release : 8.fc32 URL : https://pygments.org/ Summary : Syntax highlighting engine written in Python Description : Pygments is a generic syntax highlighter for general use in all kinds of software such as forum systems, wikis or other applications that need to prettify source code. Highlights are: * a wide range of common languages and markup formats is supported * special attention is paid to details that increase highlighting quality * support for new languages and formats are added easily; most languages use a simple regex-based lexing mechanism * a number of output formats is available, among them HTML, RTF, LaTeX and ANSI sequences * it is usable as a command-line tool and as a library * ... and it highlights even Brainf*ck! --------------------------------------------------------------------------------Update Information: Security fix for [PUT CVEs HERE] --------------------------------------------------------------------------------ChangeLog: * Fri Jan 29 2021 Tomas Hrnciar - 2.4.2-8 - Backport upstream patch to fix CVE (#1922137) --------------------------------------------------------------------------------References: [ 1 ] Bug #1922136 - python-pygments: infinite loop in SML lexer may lead to DoS https://bugzilla.redhat.com/show_bug.cgi?id=1922136 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-33abbae37b' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.