Category Archives: Advisories

USN-7400-1: PHP vulnerabilities

Read Time:59 Second

It was discovered that PHP incorrectly handle certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2024-11235)

It was discovered that PHP incorrectly handle certain folded headers.
An attacker could possibly use this issue to cause a crash or
execute arbritrary code. (CVE-2025-1217)

It was discovered that PHP incorrectly handled certain headers.
An attacker could possibly use this issue to expose sensitive information
or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS
Ubuntu 24.10, and Ubuntu 24.04 LTS. (CVE-2025-1219)

It was discovered that PHP incorrectly handle certain headers with invalid
name and no colon. An attacker could possibly use this issue to confuse
applications into accepting invalid headers causing code injection.
(CVE-2025-1734)

It was discovered that PHP incorrectly handled certain headers.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.10, and Ubuntu 24.04
LTS. (CVE-2025-1736)

It was discovered that PHP incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive
information. (CVE-2025-1861)

Read More

USN-7398-1: libtar vulnerabilities

Read Time:27 Second

It was discovered that libtar may perform out-of-bounds reads when
processing specially crafted tar files. An attacker could possibly use
this issue to cause libtar to crash, resulting in a denial of service,
or execute arbitrary code. (CVE-2021-33643, CVE-2021-33644)

It was discovered that libtar contained a memory leak due to failing
to free a variable, causing performance degradation. An attacker
could possibly use this issue to cause libtar to crash, resulting in a
denial of service. (CVE-2021-33645, CVE-2021-33646)

Read More

USN-7397-1: AOM vulnerability

Read Time:11 Second

Xiantong Hou discovered that AOM did not properly handle certain malformed
media files. If an application using AOM opened a specially crafted file, a
remote attacker could cause a denial of service, or possibly execute
arbitrary code.

Read More

USN-7396-1: OVN vulnerability

Read Time:11 Second

Marius Berntsberg, Trygve Vea, Tore Anderson, Rodolfo Alonso, Jay Faulkner,
and Brian Haley discovered that OVN incorrectly handled certain crafted UDP
packets. A remote attacker could possibly use this issue to bypass egress
ACL rules.

Read More

USN-7395-1: WebKitGTK vulnerabilities

Read Time:15 Second

Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.

Read More

USN-7376-2: MariaDB vulnerability

Read Time:20 Second

USN-7376-1 fixed vulnerabilities in MariaDB. This update provides the
corresponding updates for Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.

Original advisory details:

A security issue was discovered in MariaDB and this update includes
a new upstream MariaDB version to fix the issue.

In addition to security fixes, the updated packages contain bug and
regression fixes, new features, and possibly incompatible changes.

Read More

USN-7394-1: Doorkeeper vulnerabilities

Read Time:18 Second

Jonathan Clem and Justin Bull discovered that Doorkeeper could allow
arbitrary token revocation and replay attacks. An attacker could possibly
use this issue to gain unauthorized access to a system. (CVE-2016-6582)

It was discovered that Doorkeeper incorrectly handled storing client names.
An attacker could possibly use this issue to execute a cross-site
scripting (XSS) attack. (CVE-2018-1000088)

Read More

perl-Data-Entropy-0.008-1.fc42

Read Time:14 Second

FEDORA-2025-76dbde76fe

Packages in this update:

perl-Data-Entropy-0.008-1.fc42

Update description:

Prior to version 0.008, the Perl module Data::Entropy relied on Perl’s builtin rand function to choose an entropy source. Version 0.008 does away with this need.

Read More

perl-Data-Entropy-0.008-1.fc40

Read Time:14 Second

FEDORA-2025-52d7857536

Packages in this update:

perl-Data-Entropy-0.008-1.fc40

Update description:

Prior to version 0.008, the Perl module Data::Entropy relied on Perl’s builtin rand function to choose an entropy source. Version 0.008 does away with this need.

Read More