VYPR

rpm package

suse/brotli&distro=SUSE Linux Enterprise Server 15 SP5-LTSS

pkg:rpm/suse/brotli&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Vulnerabilities (2)

  • CVE-2025-9086HigSep 12, 2025
    affected < 1.0.7-150200.3.5.1fixed 1.0.7-150200.3.5.1

    1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path

  • CVE-2025-10148MedSep 12, 2025
    affected < 1.0.7-150200.3.5.1fixed 1.0.7-150200.3.5.1

    curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traf