[oss-security] Perl 5.40 dir dup bug with threading: security consequences

2025-05-22 Thread Vincent Lefevre
Hi, In February, I reported the following bug in perl: https://github.com/Perl/perl5/issues/23010 The issue is that under some conditions, perl temporarily changes the current working directory at a thread creation, which affects the other threads as a consequence: file accesses related to the

[oss-security] CVE-2025-4575: OpenSSL: The x509 application adds trusted use instead of rejected use

2025-05-22 Thread Tomas Mraz
This issue was reported on 2nd May 2025 by Alexandr Sosedkin (Red Hat). The fix was developed by Tomáš Mráz. General Advisory Notes == URL for this Security Advisory: https://openssl-library.org/news/secadv/20250522.txt Note: the online version of the advisory may be updated