ChangeLog for: 2025-07-23 19:37:01
a/bash-5.3.003-x86_64-1.txz: Upgraded.
l/enchant-2.8.11-x86_64-1.txz: Upgraded.
l/pipewire-1.4.7-x86_64-1.txz: Upgraded.
l/python-sane-2.9.2-x86_64-1.txz: Upgraded.
n/httpd-2.4.65-x86_64-1.txz: Upgraded.
This release fixes bugs and the following security issues:
HTTP/2 DoS by Memory Increase.
mod_ssl TLS upgrade attack.
mod_proxy_http2 denial of service.
mod_ssl access control bypass with session resumption.
mod_ssl error log variable escaping.
SSRF on Windows due to UNC paths (Linux is not affected).
SSRF with mod_headers setting Content-Type header.
HTTP response splitting.
For more information, see:
https://downloads.apache.org/httpd/CHANGES_2.4.65
https://www.cve.org/CVERecord?id=CVE-2025-53020
https://www.cve.org/CVERecord?id=CVE-2025-49812
https://www.cve.org/CVERecord?id=CVE-2025-49630
https://www.cve.org/CVERecord?id=CVE-2025-23048
https://www.cve.org/CVERecord?id=CVE-2024-47252
https://www.cve.org/CVERecord?id=CVE-2024-43394
https://www.cve.org/CVERecord?id=CVE-2024-43204
https://www.cve.org/CVERecord?id=CVE-2024-42516
(* Security fix *)
testing/packages/mesa-25.2.0_rc2-x86_64-1.txz: Upgraded.