FEDORA-EPEL-2025-141926b526
Packages in this update:
mujs-1.0.9-2.el8
Update description:
Backport upstream fix for CVE-2021-33796.
mujs-1.0.9-2.el8
Backport upstream fix for CVE-2021-33796.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
It was discovered that Protocol Buffers incorrectly handled memory when
receiving malicious input using the Java bindings. An attacker could
possibly use this issue to cause a denial of service.
golang-1.23.8-1.fc40
Includes security fixes to the net/http package, as well as bug fixes to the runtime and the go command. Full changelog.
golang-1.23.8-1.fc41
Includes security fixes to the net/http package, as well as bug fixes to the runtime and the go command. Full changelog.
It was discovered that Perl incorrectly handled transliterating non-ASCII
bytes. A remote attacker could use this issue to cause Perl to crash,
resulting in a denial of service, or possibly execute arbitrary code.
perl-5.40.2-517.fc42
perl-Devel-Cover-1.44-5.fc42
perl-PAR-Packer-1.063-6.fc42
Fix CVE-2024-56406
perl-5.40.2-515.fc41
perl-Devel-Cover-1.44-4.fc41
perl-PAR-Packer-1.063-5.fc41
Fix CVE-2024-56406
perl-5.38.4-508.fc40
perl-Devel-Cover-1.40-9.fc40
perl-PAR-Packer-1.063-3.fc40
Fix CVE-2024-56406
ruby-3.3.8-19.fc40
Upgrade to Ruby 3.3.8.
CVE-2025-25186: Fix Net::IMAP vulnerable to possible DoS by memory exhaustion
Resolves: rhbz#2345556
CVE-2025-27219: Denial of Service in CGI::Cookie.parse
Resolves: rhbz#2357516
CVE-2025-27221: userinfo leakage in URI#join, URI#merge and URI#+