Описание
Security update for neonmodem
This update for neonmodem fixes the following issues:
Changes in neonmodem:
-
Update golang.org/x/net dependency to v0.55.0 due to bsc#1267193
-
Update golang.org/x/image dependency to v0.38.0 due to bsc#1260727
-
Update golang.org/x/term dependency to v0.42.0 due to bsc#1260727
-
Update to version 1.0.7+git0.346d1d3:
- Update dependencies, remove debug output
- Update GitHub actions
- discourse: APi fixes
- Bump golang.org/x/net from 0.36.0 to 0.38.0
- Bump golang.org/x/net from 0.34.0 to 0.36.0
- Update dependencies
- Change chat button
-
Add build option for position-independent executables
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1260727
- SUSE Bug 1267193
- SUSE CVE CVE-2026-25680 page
- SUSE CVE CVE-2026-25681 page
- SUSE CVE CVE-2026-27136 page
- SUSE CVE CVE-2026-33809 page
- SUSE CVE CVE-2026-42502 page
- SUSE CVE CVE-2026-42506 page
Описание
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
Затронутые продукты
Ссылки
- CVE-2026-25680
- SUSE Bug 1267044
Описание
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
Затронутые продукты
Ссылки
- CVE-2026-25681
- SUSE Bug 1267044
Описание
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
Затронутые продукты
Ссылки
- CVE-2026-27136
- SUSE Bug 1267044
Описание
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
Затронутые продукты
Ссылки
- CVE-2026-33809
- SUSE Bug 1260692
Описание
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
Затронутые продукты
Ссылки
- CVE-2026-42502
- SUSE Bug 1267044
Описание
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
Затронутые продукты
Ссылки
- CVE-2026-42506
- SUSE Bug 1267044