This update for rhino fixes the following issues:
Update to version 1.7.15.1.
Security issues fixed:
* CVE-2025-66453: high CPU consumption when processing specific numbers via
the `toFixed()` function (bsc#1254481).
Other changes and issues fixed:
* Version 1.7.15:
* Basic support for "rest parameters".
* Improvements in Unicode support.
* "Symbol.species" implemented in many places.
* More correct property ordering in many places.
* Miscellaneous improvements and bug fixes.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-4390=1
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-4390=1
* Basesystem Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-4390=1
* Basesystem Module 15-SP7 (noarch)
* rhino-1.7.15.1-150200.12.7.1
* openSUSE Leap 15.6 (noarch)
* rhino-runtime-1.7.15.1-150200.12.7.1
* rhino-demo-1.7.15.1-150200.12.7.1
* rhino-1.7.15.1-150200.12.7.1
* rhino-javadoc-1.7.15.1-150200.12.7.1
* rhino-engine-1.7.15.1-150200.12.7.1
* Basesystem Module 15-SP6 (noarch)
* rhino-1.7.15.1-150200.12.7.1
* bsc#1254481
## References:
* https://www.suse.com/security/cve/CVE-2025-66453.html
* https://bugzilla.suse.com/show_bug.cgi?id=1254481
Get the latest Linux and open source security news straight to your inbox.