FEDORA-2025-67d2e84a2b
Packages in this update:
mingw-poppler-24.08.0-4.fc42
Update description:
Backport fixes for CVE-2025-32364 and CVE-2025-32365.
mingw-poppler-24.08.0-4.fc42
Backport fixes for CVE-2025-32364 and CVE-2025-32365.
mingw-poppler-24.02.0-5.fc40
Backport fixes for CVE-2025-32364 and CVE-2025-32365.
mingw-poppler-24.02.0-5.fc41
Backport fixes for CVE-2025-32364 and CVE-2025-32365.
It was discovered that QuickJS could be forced to reference uninitialized
memory in certain instances. An attacker could possibly use this issue to
cause QuickJS to crash, resulting in a denial of service, or execute
arbitrary code. (CVE-2023-48183)
It was discovered that QuickJS incorrectly managed memory in certain
circumstances. An attacker could possibly use this issue to exhaust
system resources, resulting in a denial of service. (CVE-2023-48184)
It was discovered that QuickJS could be forced to crash due to a
failing test. An attacker could possibly use this issue to cause a
denial of service. (CVE-2024-33263)
Igor Pavlov discovered that 7-Zip had several memory-related issues.
An attacker could possibly use these issues to cause 7-Zip to crash,
resulting in a denial of service, or execute arbitrary code.
(CVE-2023-52168, CVE-2023-52169)
mingw-libsoup-2.74.3-10.fc41
Backport fixes for CVE-2025-32050 CVE-2025-32052 CVE-2025-32053 CVE-2025-32906
CVE-2025-32907 CVE-2025-32909
mingw-libsoup-2.74.3-10.fc42
Backport fixes for CVE-2025-32050 CVE-2025-32052 CVE-2025-32053 CVE-2025-32906
CVE-2025-32907 CVE-2025-32909
mingw-libsoup-2.74.3-10.fc40
Backport fixes for CVE-2025-32050 CVE-2025-32052 CVE-2025-32053 CVE-2025-32906
CVE-2025-32907 CVE-2025-32909
giflib-5.2.2-6.fc40
Backport proposed fix for CVE-2025-31344 from OpenMandriva.
giflib-5.2.2-6.fc42
Backport proposed fix for CVE-2025-31344 from OpenMandriva.
Install gif_getarg.h header.