Update to uriparser-1.0.1.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-57515ed8b1 2026-05-05 00:53:44.303273+00:00 -------------------------------------------------------------------------------- Name : uriparser Product : Fedora 44 Version : 1.0.1 Release : 1.fc44 URL : https://uriparser.github.io/ Summary : URI parsing library - RFC 3986 Description : Uriparser is a strictly RFC 3986 compliant URI parsing library written in C. uriparser is cross-platform, fast, supports Unicode and is licensed under the New BSD license. -------------------------------------------------------------------------------- Update Information: Update to uriparser-1.0.1. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 30 2026 Sandro Mani - 1.0.1-1 - Update to 1.0.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2463210 - CVE-2026-42371 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2463210 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-57515ed8b1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # Security update for jetty-minimal Announcement ID: SUSE-SU-2026:1461-1 Release Date: 2026-04-20T05:47:00Z Rating: low References: * bsc#1259242 Cross-References: * CVE-2025-11143 CVSS scores: * CVE-2025-11143 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-11143 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-11143 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-11143 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for jetty-minimal fixes the following issues: * CVE-2025-11143: Fixed different parsing of invalid URIs (bsc#1259242). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-1461=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-1461=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1461=1 ## Package List: * openSUSE Leap 15.6 (noarch) * jetty-jsp-9.4.58-150200.3.37.1 * jetty-javax-websocket-client-impl-9.4.58-150200.3.37.1 * jetty-minimal-javadoc-9.4.58-150200.3.37.1 * jetty-start-9.4.58-150200.3.37.1 * jetty-security-9.4.58-150200.3.37.1 * jetty-webapp-9.4.58-150200.3.37.1 * jetty-websocket-common-9.4.58-150200.3.37.1 *jetty-deploy-9.4.58-150200.3.37.1 * jetty-server-9.4.58-150200.3.37.1 * jetty-plus-9.4.58-150200.3.37.1 * jetty-jmx-9.4.58-150200.3.37.1 * jetty-util-9.4.58-150200.3.37.1 * jetty-cdi-9.4.58-150200.3.37.1 * jetty-http-spi-9.4.58-150200.3.37.1 * jetty-project-9.4.58-150200.3.37.1 * jetty-websocket-servlet-9.4.58-150200.3.37.1 * jetty-annotations-9.4.58-150200.3.37.1 * jetty-io-9.4.58-150200.3.37.1 * jetty-continuation-9.4.58-150200.3.37.1 * jetty-javax-websocket-server-impl-9.4.58-150200.3.37.1 * jetty-jaas-9.4.58-150200.3.37.1 * jetty-jndi-9.4.58-150200.3.37.1 * jetty-websocket-server-9.4.58-150200.3.37.1 * jetty-servlet-9.4.58-150200.3.37.1 * jetty-proxy-9.4.58-150200.3.37.1 * jetty-websocket-client-9.4.58-150200.3.37.1 * jetty-xml-9.4.58-150200.3.37.1 * jetty-ant-9.4.58-150200.3.37.1 * jetty-rewrite-9.4.58-150200.3.37.1 * jetty-servlets-9.4.58-150200.3.37.1 * jetty-util-ajax-9.4.58-150200.3.37.1 * jetty-openid-9.4.58-150200.3.37.1 * jetty-http-9.4.58-150200.3.37.1 * jetty-websocket-api-9.4.58-150200.3.37.1 * jetty-websocket-javadoc-9.4.58-150200.3.37.1 * jetty-fcgi-9.4.58-150200.3.37.1 * jetty-quickstart-9.4.58-150200.3.37.1 * jetty-client-9.4.58-150200.3.37.1 * Development Tools Module 15-SP7 (noarch) * jetty-util-9.4.58-150200.3.37.1 * jetty-util-ajax-9.4.58-150200.3.37.1 * jetty-http-9.4.58-150200.3.37.1 * jetty-servlet-9.4.58-150200.3.37.1 * jetty-security-9.4.58-150200.3.37.1 * jetty-server-9.4.58-150200.3.37.1 * jetty-io-9.4.58-150200.3.37.1 * SUSE Package Hub 15 15-SP7 (noarch) * jetty-continuation-9.4.58-150200.3.37.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11143.html * https://bugzilla.suse.com/show_bug.cgi?id=1259242 . This advisory discusses the solution to a low-severity URI parsing issue in jetty-minimal for openSUSE.. openSUSE security patch, jetty-minimal update, CVE-2025-11143 fix. . Severity: Low.LinuxSecurity.com Team
Joergen Ibsen reported an issue with uriparser, a URI parsing library compliant with RFC 3986. . Package : uriparser Version : 0.8.0.1-2+deb8u2 CVE ID : CVE-2018-20721 Joergen Ibsen reported an issue with uriparser, a URI parsing library compliant with RFC 3986. An Out-of-bounds read for incomplete URIs with IPv6 addresses with embedded IPv4 address, e.g. "//[::44.1", were possible. For Debian 8 "Jessie", this problem has been fixed in version 0.8.0.1-2+deb8u2. We recommend that you upgrade your uriparser packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A security vulnerability was identified in the uriparser library by Joergen Ibsen, which has been addressed in Debian 8. Ensure that your packages are updated.. uriparser security update, Debian LTS advisory, out-of-bounds read issue. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.