Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update that solves two vulnerabilities can now be installed.. # Security update for ucode-intel Announcement ID: SUSE-SU-2026:0668-1 Release Date: 2026-02-26T15:21:26Z Rating: important References: * bsc#1229129 * bsc#1258046 Cross-References: * CVE-2024-24853 * CVE-2025-31648 CVSS scores: * CVE-2024-24853 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2024-24853 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2025-31648 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31648 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N * CVE-2025-31648 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31648 ( NVD ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 *SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for ucode-intel fixes the following issues: * Intel CPU Microcode was updated to the 20260210 release (bsc#1258046) * CVE-2024-24853: Updated fix for incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privileged user to potentially enable escalation of privilege via local access. (bsc#1229129) * CVE-2025-31648: Improper handling of values in the microcode flow for some Intel Processor Family may allow an escalation of privilege. (bsc#1258046) ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-668=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-668=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-668=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-668=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-668=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-668=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-668=1 *SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-668=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-668=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-668=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-668=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-668=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-668=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-668=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-668=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-668=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-668=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-668=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-668=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (x86_64) * ucode-intel-20260210-150200.62.1 * openSUSE Leap 15.6 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux EnterpriseMicro 5.4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * ucode-intel-20260210-150200.62.1 * Basesystem Module 15-SP7 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * ucode-intel-20260210-150200.62.1 ## References: * https://www.suse.com/security/cve/CVE-2024-24853.html * https://www.suse.com/security/cve/CVE-2025-31648.html * https://bugzilla.suse.com/show_bug.cgi?id=1229129 * https://bugzilla.suse.com/show_bug.cgi?id=1258046 . Critical update for ucode-intel fixing important vulnerabilities, enhancing system security for SUSE systems. Install now!. SUSE update, ucode-intel, escalation of privilege, security advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities and has one fix can now be installed.. # Security update for go1.24 Announcement ID: SUSE-SU-2026:20429-1 Release Date: 2026-02-13T11:53:30Z Rating: critical References: * bsc#1236217 * bsc#1256818 * bsc#1256820 * bsc#1257692 Cross-References: * CVE-2025-61732 * CVE-2025-68119 * CVE-2025-68121 CVSS scores: * CVE-2025-61732 ( SUSE ): 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-61732 ( SUSE ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-61732 ( NVD ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-68119 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68119 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-68119 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68121 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-68121 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-68121 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-68121 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves three vulnerabilities and has one fix can now be installed. ## Description: This update for go1.24 fixes the following issues: Update to version 1.24.13. Security issues fixed: * CVE-2025-61732: cmd/go: discrepancy between Go and C/C++ comment parsing allows for C code smuggling (bsc#1257692). * CVE-2025-68121: crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain (bsc#1256818). * CVE-2025-68119: cmd/go: unexpected code execution when invoking toolchain (bsc1256820). Other updates and bugfixes: * version updateto 1.24.13: * go#77323 crypto/x509: single-label excluded DNS name constraints incorrectly match all wildcard SANs * go#77424 crypto/tls: CL 737700 broke session resumption on macOS ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-270=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-270=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.24-race-1.24.13-160000.1.1 * go1.24-1.24.13-160000.1.1 * go1.24-doc-1.24.13-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * go1.24-libstd-debuginfo-1.24.13-160000.1.1 * go1.24-libstd-1.24.13-160000.1.1 * go1.24-debuginfo-1.24.13-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * go1.24-race-1.24.13-160000.1.1 * go1.24-1.24.13-160000.1.1 * go1.24-doc-1.24.13-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (x86_64) * go1.24-libstd-debuginfo-1.24.13-160000.1.1 * go1.24-libstd-1.24.13-160000.1.1 * go1.24-debuginfo-1.24.13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-61732.html * https://www.suse.com/security/cve/CVE-2025-68119.html * https://www.suse.com/security/cve/CVE-2025-68121.html * https://bugzilla.suse.com/show_bug.cgi?id=1236217 * https://bugzilla.suse.com/show_bug.cgi?id=1256818 * https://bugzilla.suse.com/show_bug.cgi?id=1256820 * https://bugzilla.suse.com/show_bug.cgi?id=1257692 . Critical update for SUSE fixes three major issues in go1.24 ensuring better security and stability.. SUSE Linux, Security Update, Go Language, Critical Vulnerability, System Patch. . Severity: Critical. LinuxSecurity.com Team
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in execution of arbitrary code, erroneous parsing of invalid URLs or multipart form data, configuration setting bypass, or log pollution. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3920-1
* bsc#1228105 Cross-References: * CVE-2024-6345 . # Security update for python-setuptools Announcement ID: SUSE-SU-2024:2900-1 Rating: important References: * bsc#1228105 Cross-References: * CVE-2024-6345 CVSS scores: * CVE-2024-6345 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Containers Module 12 * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-setuptools fixes the following issues: * CVE-2024-6345: Fixed code execution via download functions in the package_index module (bsc#1228105) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 12 zypper in -t patch SUSE-SLE-Module-Containers-12-2024-2900=1 * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2024-2900=1 * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patchSUSE-SLE-SDK-12-SP5-2024-2900=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2900=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2900=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2900=1 ## Package List: * Containers Module 12 (noarch) * python-setuptools-40.6.2-4.24.1 * Public Cloud Module 12 (noarch) * python-setuptools-40.6.2-4.24.1 * python3-setuptools-40.6.2-4.24.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (noarch) * python3-setuptools-40.6.2-4.24.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * python-setuptools-40.6.2-4.24.1 * python3-setuptools-40.6.2-4.24.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * python-setuptools-40.6.2-4.24.1 * python3-setuptools-40.6.2-4.24.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * python-setuptools-40.6.2-4.24.1 * python3-setuptools-40.6.2-4.24.1 ## References: * https://www.suse.com/security/cve/CVE-2024-6345.html * https://bugzilla.suse.com/show_bug.cgi?id=1228105 . Critical patch released for python-setuptools tackles potential code execution vulnerabilities in SUSE Linux versions 12 series.. python-setuptools security updates, SUSE Linux vulnerabilities, software security fixes. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202009-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Chromium, Google Chrome: Multiple vulnerabilities Date: September 10, 2020 Bugs: #741312 ID: 202009-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code. Background ========= Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. Google Chrome is one fast, simple, and secure browser for all your devices. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-client/chromium < 85.0.4183.102 > = 85.0.4183.102 2 www-client/google-chrome < 85.0.4183.102 > = 85.0.4183.102 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in Chromium and Google Chrome. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Chromium users should upgrade to the latest version: # emerge --sync #emerge --ask --oneshot -v "> =www-client/chromium-85.0.4183.102" All Google Chrome users should upgrade to the latest version: # emerge --sync # emerge -a --oneshot -v "> =www-client/google-chrome-85.0.4183.102" References ========= [ 1 ] CVE-2020-15959 https://nvd.nist.gov/vuln/detail/CVE-2020-15959 [ 2 ] CVE-2020-6573 https://nvd.nist.gov/vuln/detail/CVE-2020-6573 [ 3 ] CVE-2020-6575 https://nvd.nist.gov/vuln/detail/CVE-2020-6575 [ 4 ] CVE-2020-6576 https://nvd.nist.gov/vuln/detail/CVE-2020-6576 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202009-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in libmicrodns, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202005-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libmicrodns: Multiple vulnerabilities Date: May 14, 2020 Bugs: #714606 ID: 202005-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libmicrodns, the worst of which could result in the arbitrary execution of code. Background ========= libmicrodns is an mDNS library, focused on being simple and cross-platform. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/libmicrodns < 0.1.2 > = 0.1.2 Description ========== Multiple vulnerabilities have been discovered in libmicrodns. Please review the CVE identifiers and the upstream advisory referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All libmicrodns users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/libmicrodns-0.1.2" References ========= [ 1 ] CVE-2020-6071 https://nvd.nist.gov/vuln/detail/CVE-2020-6071 [ 2 ] CVE-2020-6072 https://nvd.nist.gov/vuln/detail/CVE-2020-6072 [ 3 ] CVE-2020-6073 https://nvd.nist.gov/vuln/detail/CVE-2020-6073 [ 4 ] CVE-2020-6077 https://nvd.nist.gov/vuln/detail/CVE-2020-6077 [ 5 ] CVE-2020-6078 https://nvd.nist.gov/vuln/detail/CVE-2020-6078 [ 6 ] CVE-2020-6079 https://nvd.nist.gov/vuln/detail/CVE-2020-6079 [ 7 ] CVE-2020-6080 https://nvd.nist.gov/vuln/detail/CVE-2020-6080 [ 8 ] VideoLAN-SB-VLC-309 https://www.videolan.org/security/sb-vlc309.html Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202005-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Devon Hubbard, Jesse Ruderman and Martijn Wargers discovered crashes in the layout engine, which might allow the execution of arbitrary code.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1607-1
Multiple flaws were discovered in FreeType's Printer Font Binary (PFB) font-file format parser. If a user loaded a carefully crafted font-file with a program linked against FreeType, it could cause the application to crash, or possibly execute arbitrary code.. ==================================================================== Red Hat Security Advisory Synopsis: Important: freetype security update Advisory ID: RHSA-2008:0556-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2008:0556.html Issue date: 2008-06-20 CVE Names: CVE-2008-1806 CVE-2008-1807 CVE-2008-1808 ==================================================================== 1. Summary: Updated freetype packages that fix various security issues are now available for Red Hat Enterprise Linux 3, 4, and 5. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 3. Description: FreeType is a free, high-quality, portable font engine that can open and manage font files, as well as efficiently load, hint and render individual glyphs. Multiple flaws were discovered in FreeType's Printer Font Binary (PFB) font-file format parser. If a user loaded a carefully craftedfont-file with a program linked against FreeType, it could cause the application to crash, or possibly execute arbitrary code. (CVE-2008-1806, CVE-2008-1807, CVE-2008-1808) Note: the flaw in FreeType's TrueType Font (TTF) font-file format parser, covered by CVE-2008-1808, did not affect the freetype packages as shipped in Red Hat Enterprise Linux 3, 4, and 5, as they are not compiled with TTF Byte Code Interpreter (BCI) support. Users of freetype should upgrade to these updated packages, which contain backported patches to resolve these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 450768 - CVE-2008-1806 FreeType PFB integer overflow 450773 - CVE-2008-1807 FreeType invalid free() flaw 450774 - CVE-2008-1808 FreeType off-by-one flaws 6. Package List: Red Hat Enterprise Linux AS version3: Source: i386: freetype-2.1.4-8.el3.i386.rpm freetype-debuginfo-2.1.4-8.el3.i386.rpm freetype-devel-2.1.4-8.el3.i386.rpm ia64: freetype-2.1.4-8.el3.i386.rpm freetype-2.1.4-8.el3.ia64.rpm freetype-debuginfo-2.1.4-8.el3.i386.rpm freetype-debuginfo-2.1.4-8.el3.ia64.rpm freetype-devel-2.1.4-8.el3.ia64.rpm ppc: freetype-2.1.4-8.el3.ppc.rpm freetype-2.1.4-8.el3.ppc64.rpm freetype-debuginfo-2.1.4-8.el3.ppc.rpm freetype-debuginfo-2.1.4-8.el3.ppc64.rpm freetype-devel-2.1.4-8.el3.ppc.rpm s390: freetype-2.1.4-8.el3.s390.rpm freetype-debuginfo-2.1.4-8.el3.s390.rpm freetype-devel-2.1.4-8.el3.s390.rpm s390x: freetype-2.1.4-8.el3.s390.rpm freetype-2.1.4-8.el3.s390x.rpm freetype-debuginfo-2.1.4-8.el3.s390.rpm freetype-debuginfo-2.1.4-8.el3.s390x.rpm freetype-devel-2.1.4-8.el3.s390x.rpm x86_64: freetype-2.1.4-8.el3.i386.rpm freetype-2.1.4-8.el3.x86_64.rpm freetype-debuginfo-2.1.4-8.el3.i386.rpm freetype-debuginfo-2.1.4-8.el3.x86_64.rpm freetype-devel-2.1.4-8.el3.x86_64.rpm Red Hat Desktop version 3: Source: i386: freetype-2.1.4-8.el3.i386.rpm freetype-debuginfo-2.1.4-8.el3.i386.rpm freetype-devel-2.1.4-8.el3.i386.rpm x86_64: freetype-2.1.4-8.el3.i386.rpm freetype-2.1.4-8.el3.x86_64.rpm freetype-debuginfo-2.1.4-8.el3.i386.rpm freetype-debuginfo-2.1.4-8.el3.x86_64.rpm freetype-devel-2.1.4-8.el3.x86_64.rpm Red Hat Enterprise Linux ES version 3: Source: i386: freetype-2.1.4-8.el3.i386.rpm freetype-debuginfo-2.1.4-8.el3.i386.rpm freetype-devel-2.1.4-8.el3.i386.rpm ia64: freetype-2.1.4-8.el3.i386.rpm freetype-2.1.4-8.el3.ia64.rpm freetype-debuginfo-2.1.4-8.el3.i386.rpm freetype-debuginfo-2.1.4-8.el3.ia64.rpm freetype-devel-2.1.4-8.el3.ia64.rpm x86_64: freetype-2.1.4-8.el3.i386.rpm freetype-2.1.4-8.el3.x86_64.rpm freetype-debuginfo-2.1.4-8.el3.i386.rpm freetype-debuginfo-2.1.4-8.el3.x86_64.rpm freetype-devel-2.1.4-8.el3.x86_64.rpm Red Hat Enterprise Linux WS version3: Source: i386: freetype-2.1.4-8.el3.i386.rpm freetype-debuginfo-2.1.4-8.el3.i386.rpm freetype-devel-2.1.4-8.el3.i386.rpm ia64: freetype-2.1.4-8.el3.i386.rpm freetype-2.1.4-8.el3.ia64.rpm freetype-debuginfo-2.1.4-8.el3.i386.rpm freetype-debuginfo-2.1.4-8.el3.ia64.rpm freetype-devel-2.1.4-8.el3.ia64.rpm x86_64: freetype-2.1.4-8.el3.i386.rpm freetype-2.1.4-8.el3.x86_64.rpm freetype-debuginfo-2.1.4-8.el3.i386.rpm freetype-debuginfo-2.1.4-8.el3.x86_64.rpm freetype-devel-2.1.4-8.el3.x86_64.rpm Red Hat Enterprise Linux AS version4: Source: i386: freetype-2.1.9-7.el4.6.i386.rpm freetype-debuginfo-2.1.9-7.el4.6.i386.rpm freetype-demos-2.1.9-7.el4.6.i386.rpm freetype-devel-2.1.9-7.el4.6.i386.rpm freetype-utils-2.1.9-7.el4.6.i386.rpm ia64: freetype-2.1.9-7.el4.6.i386.rpm freetype-2.1.9-7.el4.6.ia64.rpm freetype-debuginfo-2.1.9-7.el4.6.i386.rpm freetype-debuginfo-2.1.9-7.el4.6.ia64.rpm freetype-demos-2.1.9-7.el4.6.ia64.rpm freetype-devel-2.1.9-7.el4.6.ia64.rpm freetype-utils-2.1.9-7.el4.6.ia64.rpm ppc: freetype-2.1.9-7.el4.6.ppc.rpm freetype-2.1.9-7.el4.6.ppc64.rpm freetype-debuginfo-2.1.9-7.el4.6.ppc.rpm freetype-debuginfo-2.1.9-7.el4.6.ppc64.rpm freetype-demos-2.1.9-7.el4.6.ppc.rpm freetype-devel-2.1.9-7.el4.6.ppc.rpm freetype-utils-2.1.9-7.el4.6.ppc.rpm s390: freetype-2.1.9-7.el4.6.s390.rpm freetype-debuginfo-2.1.9-7.el4.6.s390.rpm freetype-demos-2.1.9-7.el4.6.s390.rpm freetype-devel-2.1.9-7.el4.6.s390.rpm freetype-utils-2.1.9-7.el4.6.s390.rpm s390x: freetype-2.1.9-7.el4.6.s390.rpm freetype-2.1.9-7.el4.6.s390x.rpm freetype-debuginfo-2.1.9-7.el4.6.s390.rpm freetype-debuginfo-2.1.9-7.el4.6.s390x.rpm freetype-demos-2.1.9-7.el4.6.s390x.rpm freetype-devel-2.1.9-7.el4.6.s390x.rpm freetype-utils-2.1.9-7.el4.6.s390x.rpm x86_64: freetype-2.1.9-7.el4.6.i386.rpm freetype-2.1.9-7.el4.6.x86_64.rpm freetype-debuginfo-2.1.9-7.el4.6.i386.rpm freetype-debuginfo-2.1.9-7.el4.6.x86_64.rpm freetype-demos-2.1.9-7.el4.6.x86_64.rpm freetype-devel-2.1.9-7.el4.6.x86_64.rpm freetype-utils-2.1.9-7.el4.6.x86_64.rpm Red Hat Enterprise Linux Desktop version4: Source: i386: freetype-2.1.9-7.el4.6.i386.rpm freetype-debuginfo-2.1.9-7.el4.6.i386.rpm freetype-demos-2.1.9-7.el4.6.i386.rpm freetype-devel-2.1.9-7.el4.6.i386.rpm freetype-utils-2.1.9-7.el4.6.i386.rpm x86_64: freetype-2.1.9-7.el4.6.i386.rpm freetype-2.1.9-7.el4.6.x86_64.rpm freetype-debuginfo-2.1.9-7.el4.6.i386.rpm freetype-debuginfo-2.1.9-7.el4.6.x86_64.rpm freetype-demos-2.1.9-7.el4.6.x86_64.rpm freetype-devel-2.1.9-7.el4.6.x86_64.rpm freetype-utils-2.1.9-7.el4.6.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: freetype-2.1.9-7.el4.6.i386.rpm freetype-debuginfo-2.1.9-7.el4.6.i386.rpm freetype-demos-2.1.9-7.el4.6.i386.rpm freetype-devel-2.1.9-7.el4.6.i386.rpm freetype-utils-2.1.9-7.el4.6.i386.rpm ia64: freetype-2.1.9-7.el4.6.i386.rpm freetype-2.1.9-7.el4.6.ia64.rpm freetype-debuginfo-2.1.9-7.el4.6.i386.rpm freetype-debuginfo-2.1.9-7.el4.6.ia64.rpm freetype-demos-2.1.9-7.el4.6.ia64.rpm freetype-devel-2.1.9-7.el4.6.ia64.rpm freetype-utils-2.1.9-7.el4.6.ia64.rpm x86_64: freetype-2.1.9-7.el4.6.i386.rpm freetype-2.1.9-7.el4.6.x86_64.rpm freetype-debuginfo-2.1.9-7.el4.6.i386.rpm freetype-debuginfo-2.1.9-7.el4.6.x86_64.rpm freetype-demos-2.1.9-7.el4.6.x86_64.rpm freetype-devel-2.1.9-7.el4.6.x86_64.rpm freetype-utils-2.1.9-7.el4.6.x86_64.rpm Red Hat Enterprise Linux WS version4: Source: i386: freetype-2.1.9-7.el4.6.i386.rpm freetype-debuginfo-2.1.9-7.el4.6.i386.rpm freetype-demos-2.1.9-7.el4.6.i386.rpm freetype-devel-2.1.9-7.el4.6.i386.rpm freetype-utils-2.1.9-7.el4.6.i386.rpm ia64: freetype-2.1.9-7.el4.6.i386.rpm freetype-2.1.9-7.el4.6.ia64.rpm freetype-debuginfo-2.1.9-7.el4.6.i386.rpm freetype-debuginfo-2.1.9-7.el4.6.ia64.rpm freetype-demos-2.1.9-7.el4.6.ia64.rpm freetype-devel-2.1.9-7.el4.6.ia64.rpm freetype-utils-2.1.9-7.el4.6.ia64.rpm x86_64: freetype-2.1.9-7.el4.6.i386.rpm freetype-2.1.9-7.el4.6.x86_64.rpm freetype-debuginfo-2.1.9-7.el4.6.i386.rpm freetype-debuginfo-2.1.9-7.el4.6.x86_64.rpm freetype-demos-2.1.9-7.el4.6.x86_64.rpm freetype-devel-2.1.9-7.el4.6.x86_64.rpm freetype-utils-2.1.9-7.el4.6.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: freetype-2.2.1-20.el5_2.i386.rpm freetype-debuginfo-2.2.1-20.el5_2.i386.rpm x86_64: freetype-2.2.1-20.el5_2.i386.rpm freetype-2.2.1-20.el5_2.x86_64.rpm freetype-debuginfo-2.2.1-20.el5_2.i386.rpm freetype-debuginfo-2.2.1-20.el5_2.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: freetype-debuginfo-2.2.1-20.el5_2.i386.rpm freetype-demos-2.2.1-20.el5_2.i386.rpm freetype-devel-2.2.1-20.el5_2.i386.rpm x86_64: freetype-debuginfo-2.2.1-20.el5_2.i386.rpm freetype-debuginfo-2.2.1-20.el5_2.x86_64.rpm freetype-demos-2.2.1-20.el5_2.x86_64.rpm freetype-devel-2.2.1-20.el5_2.i386.rpm freetype-devel-2.2.1-20.el5_2.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: freetype-2.2.1-20.el5_2.i386.rpm freetype-debuginfo-2.2.1-20.el5_2.i386.rpm freetype-demos-2.2.1-20.el5_2.i386.rpm freetype-devel-2.2.1-20.el5_2.i386.rpm ia64: freetype-2.2.1-20.el5_2.i386.rpm freetype-2.2.1-20.el5_2.ia64.rpm freetype-debuginfo-2.2.1-20.el5_2.i386.rpm freetype-debuginfo-2.2.1-20.el5_2.ia64.rpm freetype-demos-2.2.1-20.el5_2.ia64.rpm freetype-devel-2.2.1-20.el5_2.ia64.rpm ppc: freetype-2.2.1-20.el5_2.ppc.rpm freetype-2.2.1-20.el5_2.ppc64.rpm freetype-debuginfo-2.2.1-20.el5_2.ppc.rpm freetype-debuginfo-2.2.1-20.el5_2.ppc64.rpm freetype-demos-2.2.1-20.el5_2.ppc.rpm freetype-devel-2.2.1-20.el5_2.ppc.rpm freetype-devel-2.2.1-20.el5_2.ppc64.rpm s390x: freetype-2.2.1-20.el5_2.s390.rpm freetype-2.2.1-20.el5_2.s390x.rpm freetype-debuginfo-2.2.1-20.el5_2.s390.rpm freetype-debuginfo-2.2.1-20.el5_2.s390x.rpm freetype-demos-2.2.1-20.el5_2.s390x.rpm freetype-devel-2.2.1-20.el5_2.s390.rpm freetype-devel-2.2.1-20.el5_2.s390x.rpm x86_64: freetype-2.2.1-20.el5_2.i386.rpm freetype-2.2.1-20.el5_2.x86_64.rpm freetype-debuginfo-2.2.1-20.el5_2.i386.rpm freetype-debuginfo-2.2.1-20.el5_2.x86_64.rpm freetype-demos-2.2.1-20.el5_2.x86_64.rpm freetype-devel-2.2.1-20.el5_2.i386.rpm freetype-devel-2.2.1-20.el5_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2008-1806 https://www.cve.org/CVERecord?id=CVE-2008-1807 https://www.cve.org/CVERecord?id=CVE-2008-1808 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2008 Red Hat, Inc. . Ubuntu has issued an urgent bulletin regarding OpenSSL, addressing significant vulnerabilities that could lead to system breaches and unauthorized access.. FreetypeUpdate, Red Hat Advisory, Important Security Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.