VYPR

rpm package

suse/brotli&distro=SUSE Linux Enterprise Module for Basesystem 15 SP7

pkg:rpm/suse/brotli&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Vulnerabilities (2)

  • CVE-2025-9086HigSep 12, 2025
    affected < 1.0.7-150200.3.5.1fixed 1.0.7-150200.3.5.1

    1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path

  • CVE-2025-10148MedSep 12, 2025
    affected < 1.0.7-150200.3.5.1fixed 1.0.7-150200.3.5.1

    curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traf