FEDORA-2025-aad560ca4b
Packages in this update:
java-latest-openjdk-24.0.1.0.9-1.rolling.fc41
Update description:
April 2025 CPU
java-latest-openjdk-24.0.1.0.9-1.rolling.fc41
April 2025 CPU
java-latest-openjdk-24.0.1.0.9-1.rolling.fc40
April 2025 CPU
thunderbird-128.9.2-1.fc40
Update to 128.9.2
https://www.thunderbird.net/en-US/thunderbird/128.9.1esr/releasenotes/
https://www.thunderbird.net/en-US/thunderbird/128.9.2esr/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2025-27/
thunderbird-128.9.2-1.fc41
Update to 128.9.2
https://www.thunderbird.net/en-US/thunderbird/128.9.1esr/releasenotes/
https://www.thunderbird.net/en-US/thunderbird/128.9.2esr/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2025-27/
Fabian Bäumer, Marcel Maehren, Marcus Brinkmann, and Jörg Schwenk
discovered that Erlang OTP’s SSH module incorrect handled authentication. A
remote attacker could use this issue to execute arbitrary commands without
authentication, possibly leading to a system compromise.
It was discovered that the Ruby CGI gem incorrectly handled parsing certain
cookies. A remote attacker could possibly use this issue to consume
resources, leading to a denial of service. (CVE-2025-27219)
It was discovered that the Ruby CGI gem incorrectly handled parsing certain
regular expressions. A remote attacker could possibly use this issue to
consume resources, leading to a denial of service. (CVE-2025-27220)
It was discovered that the Ruby URI gem incorrectly handled certain URI
handling methods. A remote attacker could possibly use this issue to leak
authentication credentials. (CVE-2025-27221)
It was discovered that the Ruby REXML gem incorrectly handled parsing XML
documents containing many digits in a hex numeric character reference. A
remote attacker could use this issue to consume resources, leading to a
denial of service. (CVE-2024-49761)
pgbouncer-1.24.1-1.el9
Update to 1.24.1, fixes CVE-2025-2291.
pgbouncer-1.24.1-2.el8
Update to 1.24.1, fixes CVE-2025-2291.
pgbouncer-1.24.1-2.fc40
Update to 1.24.1, fixes CVE-2025-2291.
pgbouncer-1.24.1-2.fc42
Update to 1.24.1, fixes CVE-2025-2291.