Update to 1.25.2.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d3d959a176 2026-05-18 00:40:49.529053+00:00 -------------------------------------------------------------------------------- Name : pgbouncer Product : Fedora 44 Version : 1.25.2 Release : 1.fc44 URL : https://www.pgbouncer.org Summary : Lightweight connection pooler for PostgreSQL Description : pgbouncer is a lightweight connection pooler for PostgreSQL and uses libevent for low-level socket handling. -------------------------------------------------------------------------------- Update Information: Update to 1.25.2. -------------------------------------------------------------------------------- ChangeLog: * Sat May 9 2026 Simone Caronni - 1.25.2-1 - Update to 1.25.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2419513 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2419513 [ 2 ] Bug #2419514 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2419514 [ 3 ] Bug #2419515 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2419515 [ 4 ] Bug #2419516 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2419516 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d3d959a176' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An untrusted search path vulnerability was discovered in Node.js, which could result in unexpected searching or loading ICU data when running with elevated privileges. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5395-1
Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory. . - -------------------------------------------------------------------------Debian LTS Advisory DLA-3026-1
An untrusted search path vulnerability in python-updater might result in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201009-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: python-updater: Untrusted search path Date: September 21, 2010 Bugs: #288361 ID: 201009-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An untrusted search path vulnerability in python-updater might result in the execution of arbitrary code. Background ========= python-updater is a script used to remerge python packages when changing Python version. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-admin/python-updater < 0.7-r1 > = 0.7-r1 Description ========== Robert Buchholz of the Gentoo Security Team reported that python-updater includes the current working directory and subdirectories in the Python module search path (sys.path) before calling "import". Impact ===== A local attacker could entice the root user to run "python-updater" from a directory containing a specially crafted Python module, resulting in the execution of arbitrary code with root privileges. Workaround ========= Do not run "python-updater" from untrusted working directories. Resolution ========= All python-updater users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-admin/python-updater-0.7-r1" Availability =========== This GLSA and any updates to it are available for viewing at the GentooSecurity Website: https://security.gentoo.org/glsa/201009-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Dan Rosenberg discovered that in couchdb, a distributed, fault-tolerant and schema-free document-oriented database, an insecure library search path is used; a local attacker could execute arbitrary code by first dumping a maliciously crafted shared library in some . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - ------------------------------------------------------------------------ Debian Security Advisory DSA-2107-1
An untrusted search path vulnerability in the dstat might result in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200911-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: dstat: Untrusted search path Date: November 25, 2009 Bugs: #293497 ID: 200911-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An untrusted search path vulnerability in the dstat might result in the execution of arbitrary code. Background ========= dstat is a versatile system resource monitor written in Python. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/dstat < 0.6.9-r1 > = 0.6.9-r1 Description ========== Robert Buchholz of the Gentoo Security Team reported that dstat includes the current working directory and subdirectories in the Python module search path (sys.path) before calling "import". Impact ===== A local attacker could entice a user to run "dstat" from a directory containing a specially crafted Python module, resulting in the execution of arbitrary code with the privileges of the user running the application. Workaround ========= Do not run "dstat" from untrusted working directories. Resolution ========= All dstat users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-apps/dstat-0.6.9-r1" References ========= [ 1 ] CVE-2009-3894 https://www.cve.org/CVERecord?id=CVE-2009-3894 Availability =========== This GLSA and any updates to it areavailable for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200911-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
An untrusted search path vulnerability in the Eye of GNOME might result in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200904-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Eye of GNOME: Untrusted search path Date: April 06, 2009 Bugs: #257002 ID: 200904-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An untrusted search path vulnerability in the Eye of GNOME might result in the execution of arbitrary code. Background ========= The Eye of GNOME is the official image viewer for the GNOME Desktop environment. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/eog < 2.22.3-r3 > = 2.22.3-r3 Description ========== James Vega reported an untrusted search path vulnerability in the GObject Python interpreter wrapper in the Eye of GNOME, a vulnerabiliy related to CVE-2008-5983. Impact ===== A local attacker could entice a user to run the Eye of GNOME from a directory containing a specially crafted python module, resulting in the execution of arbitrary code with the privileges of the user running the application. Workaround ========= Do not run "eog" from untrusted working directories. Resolution ========= All Eye of GNOME users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/eog-2.22.3-r3" References ========= [ 1 ] CVE-2008-5983 https://www.cve.org/CVERecord?id=CVE-2008-5983 [ 2 ] CVE-2008-5987 https://www.cve.org/CVERecord?id=CVE-2008-5987 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200904-06 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
An untrusted search path vulnerability in Gnumeric might result in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200904-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Gnumeric: Untrusted search path Date: April 03, 2009 Bugs: #257012 ID: 200904-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An untrusted search path vulnerability in Gnumeric might result in the execution of arbitrary code. Background ========= The Gnumeric spreadsheet is a versatile application developed as part of the GNOME Office project. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-office/gnumeric < 1.8.4-r1 > = 1.8.4-r1 Description ========== James Vega reported an untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric. Impact ===== A local attacker could entice a user to run Gnumeric from a directory containing a specially crafted python module, resulting in the execution of arbitrary code with the privileges of the user running Gnumeric. Workaround ========= Do not run "gnumeric" from untrusted working directories. Resolution ========= All Gnumeric users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-office/gnumeric-1.8.4-r1" References ========= [ 1 ] CVE-2009-0318 https://www.cve.org/CVERecord?id=CVE-2009-0318 Availability =========== This GLSA and any updates to it are available for viewing at the GentooSecurity Website: https://security.gentoo.org/glsa/200904-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.