ALT-BU-2025-11915-1
Branch p11 update bulletin.
Closed vulnerabilities
Modified: 2025-09-02
CVE-2025-54080
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions 0.28.5 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. The bug is fixed in version 0.28.6.
Modified: 2025-09-02
CVE-2025-55304
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted jpg image file. The bug is fixed in version 0.28.6.
Closed vulnerabilities
BDU:2025-10882
Уязвимость библиотеки ANGLE браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
BDU:2025-11125
Уязвимость обработчика JavaScript-сценариев V8 браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2025-11126
Уязвимость компонента Extensions (Расширения) браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю обойти ограничения безопасности
BDU:2025-11127
Уязвимость компонента Downloads (Загрузки) браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю проводить спуфинг-атаки
BDU:2025-11128
Уязвимость панели инструментов браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю проводить спуфинг-атаки
Modified: 2025-09-02
CVE-2025-9478
Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Modified: 2025-09-04
CVE-2025-9864
Use after free in V8 in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Modified: 2025-09-04
CVE-2025-9865
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
Modified: 2025-09-04
CVE-2025-9866
Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
Modified: 2025-09-04
CVE-2025-9867
Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Closed bugs
Обновление пакета Calligra
Package pdf-compress updated to version 0.4-alt1 for branch p11 in task 394686.
Closed bugs
Отсутствует проверка вводимых данных в полях "Что будем сжимать?" и "Куда будем сохранять?".
Closed vulnerabilities
BDU:2025-09673
Уязвимость файлового архиватора 7-Zip, связанная с неверным определением символических ссылок перед доступом к файлу, позволяющая нарушителю обойти ограничения безопасности
Modified: 2025-10-10
CVE-2025-55188
7-Zip before 25.01 does not always properly handle symbolic links during extraction.
- https://github.com/ip7z/7zip/compare/25.00...25.01
- https://github.com/ip7z/7zip/releases/tag/25.01
- https://github.com/lunbun/CVE-2025-55188/
- https://lunbun.dev/blog/cve-2025-55188/
- https://sourceforge.net/p/sevenzip/discussion/45797/thread/da14cd780b/
- https://www.openwall.com/lists/oss-security/2025/08/09/1
- https://www.vicarius.io/vsociety/posts/cve-2025-55188-detect-7-zip-vulnerable-version
- https://www.vicarius.io/vsociety/posts/cve-2025-55188-mitigate-7-zip-vulnerability
- https://youtu.be/sWT6M1cfnwM