An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for cairo ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:3502-1 Rating: low References: #1122321 Cross-References: CVE-2019-6462 CVSS scores: CVE-2019-6462 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2019-6462 (SUSE): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for cairo fixes the following issues: - CVE-2019-6462: Fixed a potentially infinite loop (bsc#1122321). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-3502=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-3502=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): cairo-debugsource-1.15.2-25.6.2 cairo-devel-1.15.2-25.6.2 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): cairo-debugsource-1.15.2-25.6.2 libcairo-gobject2-1.15.2-25.6.2 libcairo-gobject2-debuginfo-1.15.2-25.6.2 libcairo-script-interpreter2-1.15.2-25.6.2 libcairo-script-interpreter2-debuginfo-1.15.2-25.6.2 libcairo2-1.15.2-25.6.2 libcairo2-debuginfo-1.15.2-25.6.2 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): libcairo-gobject2-32bit-1.15.2-25.6.2 libcairo-gobject2-debuginfo-32bit-1.15.2-25.6.2 libcairo2-32bit-1.15.2-25.6.2 libcairo2-debuginfo-32bit-1.15.2-25.6.2 References: https://www.suse.com/security/cve/CVE-2019-6462.html https://bugzilla.suse.com/1122321 . A new patch has been released to address a minor vulnerability in cairo, improving both security and efficiency of the system.. Cairo Update, Linux Enterprise, Software Development Kit. . Severity: Low. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.