ALT-BU-2025-5751-1
Branch sisyphus_loongarch64 update bulletin.
Package chromium updated to version 135.0.7049.95-alt0.port for branch sisyphus_loongarch64.
Closed vulnerabilities
Modified: 2025-04-23
CVE-2025-3619
Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Modified: 2025-04-23
CVE-2025-3620
Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Package festival updated to version 2.5-alt0.6 for branch sisyphus_loongarch64.
Closed bugs
Словарь QStardict не озвучивает слова
Неполные зависимости
sh: mbrola: команда не найдена
Package systray-x updated to version 0.9.11-alt2 for branch sisyphus_loongarch64.
Closed bugs
SysTray-X несовместимо с Thunderbird 137.0.
Package thunderbird updated to version 137.0.2-alt1 for branch sisyphus_loongarch64.
Closed vulnerabilities
Modified: 2025-04-15
CVE-2025-2830
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
Modified: 2025-04-15
CVE-2025-3522
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
Modified: 2025-04-15
CVE-2025-3523
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
Closed bugs
Некорректный desktop файл
Package setup updated to version 2.2.22-alt1 for branch sisyphus_loongarch64.
Closed bugs
Добавить xonsh в /etc/shells
Package phosh updated to version 0.46.0-alt1.1 for branch sisyphus_loongarch64.
Closed bugs
phosh: Добавить зависимость на xdg-desktop-portal-phosh
Package python3-module-django updated to version 5.1.8-alt1 for branch sisyphus_loongarch64.
Closed vulnerabilities
Modified: 2025-04-03
CVE-2025-27556
An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.
Package baikal-openuds updated to version 0.0.3-alt2.2 for branch sisyphus_loongarch64.
Closed bugs
Файловые конфликты с пакетом baikal-openuds и xfreerdp3