Security researchers of JFrog Security and Ismail Aydemir discovered two remote
code execution vulnerabilities in the H2 Java SQL database engine which can be
exploited through various attack vectors, most notably through the H2 Console
and by loading custom classes from remote servers through JNDI. The H2 console
is a developer tool and not required by any reverse-dependency in Debian. It
has been disabled in (old)stable releases. Database developers are advised to
use at least version 2.1.210-1, currently available in Debian unstable.
More Stories
nextcloud-29.0.16-1.el9
FEDORA-EPEL-2025-9129f1f736 Packages in this update: nextcloud-29.0.16-1.el9 Update description: 29.0.16 release RHBZ#2345763 Read More
chromium-135.0.7049.95-1.fc42
FEDORA-2025-fb323a2b22 Packages in this update: chromium-135.0.7049.95-1.fc42 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.fc40
FEDORA-2025-7827e4feac Packages in this update: chromium-135.0.7049.95-1.fc40 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.el10_1
FEDORA-EPEL-2025-af0c337351 Packages in this update: chromium-135.0.7049.95-1.el10_1 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.el9
FEDORA-EPEL-2025-5104c5b9be Packages in this update: chromium-135.0.7049.95-1.el9 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.fc41
FEDORA-2025-9c1d536035 Packages in this update: chromium-135.0.7049.95-1.fc41 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...