An update that solves one vulnerability can now be installed.. # Security update for python-wheel Announcement ID: SUSE-SU-2026:0460-1 Release Date: 2026-02-11T23:30:24Z Rating: important References: * bsc#1257100 Cross-References: * CVE-2026-24049 CVSS scores: * CVE-2026-24049 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-24049 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2026-24049 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-wheel fixes the following issues: * CVE-2026-24049: Fixed absent path sanitization can cause arbitrary file permission modification (bsc#1257100). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-460=1 * SUSE LinuxEnterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-460=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-460=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-460=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-460=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-460=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-460=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-460=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-460=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-460=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-460=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python311-wheel-0.40.0-150400.13.10.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python311-wheel-0.40.0-150400.13.10.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python311-wheel-0.40.0-150400.13.10.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python311-wheel-0.40.0-150400.13.10.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python311-wheel-0.40.0-150400.13.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python311-wheel-0.40.0-150400.13.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python311-wheel-0.40.0-150400.13.10.1 * openSUSE Leap 15.4 (noarch) * python311-wheel-0.40.0-150400.13.10.1 * openSUSE Leap 15.6 (noarch) *python311-wheel-0.40.0-150400.13.10.1 * Public Cloud Module 15-SP4 (noarch) * python311-wheel-0.40.0-150400.13.10.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python311-wheel-0.40.0-150400.13.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-24049.html * https://bugzilla.suse.com/show_bug.cgi?id=1257100 . Update addressing a critical issue in python-wheel for openSUSE Leap to enhance security. Act promptly!. openSUSE python-wheel security update important patch. . Severity: Important. LinuxSecurity.com Team
New upstream release with a fix for [GNUTLS- SA-2023-10-23](https://www.gnutls.org/security-new.html#GNUTLS-SA-2023-10-23).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-e075ac32be 2023-11-30 03:29:42.580484 -------------------------------------------------------------------------------- Name : gnutls Product : Fedora 39 Version : 3.8.2 Release : 1.fc39 URL : http://www.gnutls.org/ Summary : A TLS protocol implementation Description : GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and other required structures. -------------------------------------------------------------------------------- Update Information: New upstream release with a fix for [GNUTLS- SA-2023-10-23](https://www.gnutls.org/security-new.html#GNUTLS-SA-2023-10-23). -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 27 2023 Daiki Ueno - 3.8.2-1 - [packit] 3.8.2 upstream release -------------------------------------------------------------------------------- References: [ 1 ] Bug #2249801 - gnutls-3.8.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2249801 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-e075ac32be' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] mozilla-thunderbird (SSA:2016-275-01) New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/mozilla-thunderbird-45.4.0-i586-1_slack14.2.txz: Upgraded. This release contains security fixes and improvements. For more information, see: https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/ (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.1 package: bbc7a109aed0f6258f563f152f3d95b3 mozilla-thunderbird-45.4.0-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 5aaf769ae54a1933f84833ad73808bb2 mozilla-thunderbird-45.4.0-x86_64-1_slack14.1.txz Slackware 14.2 package: 72106c3f885a6523422f22263c265a14 mozilla-thunderbird-45.4.0-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 241190d62a7eb1d87eb517cc176f463b mozilla-thunderbird-45.4.0-x86_64-1_slack14.2.txz Slackware -current package: f45be7939e94e14dc46f8571616580dd xap/mozilla-thunderbird-45.4.0-i586-1.txz Slackware x86_64 -current package: 458c7b0cf5519cb3284d4c22f07924e6 xap/mozilla-thunderbird-45.4.0-x86_64-1.txz Installation instructions: +------------------------+ Upgrade thepackage as root: # upgradepkg mozilla-thunderbird-45.4.0-i486-1_slack14.1.txz +-----+ . Security patches for Slackware enhance stability in mozilla-thunderbird, safeguarding user interactions. Ensure you're updated!. Mozilla-Thunderbird, Slackware Update, Software Security Patch, Package Upgrade. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 4 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2011-1820 https://access.redhat.com/errata/RHSA-2011:1820.html The following updated rpms for Oracle Linux 4 have been uploaded to the Unbreakable Linux Network: i386: finch-2.6.6-10.el4.i386.rpm finch-devel-2.6.6-10.el4.i386.rpm libpurple-2.6.6-10.el4.i386.rpm libpurple-devel-2.6.6-10.el4.i386.rpm libpurple-perl-2.6.6-10.el4.i386.rpm libpurple-tcl-2.6.6-10.el4.i386.rpm pidgin-2.6.6-10.el4.i386.rpm pidgin-devel-2.6.6-10.el4.i386.rpm pidgin-perl-2.6.6-10.el4.i386.rpm x86_64: finch-2.6.6-10.el4.x86_64.rpm finch-devel-2.6.6-10.el4.x86_64.rpm libpurple-2.6.6-10.el4.x86_64.rpm libpurple-devel-2.6.6-10.el4.x86_64.rpm libpurple-perl-2.6.6-10.el4.x86_64.rpm libpurple-tcl-2.6.6-10.el4.x86_64.rpm pidgin-2.6.6-10.el4.x86_64.rpm pidgin-devel-2.6.6-10.el4.x86_64.rpm pidgin-perl-2.6.6-10.el4.x86_64.rpm ia64: finch-2.6.6-10.el4.ia64.rpm finch-devel-2.6.6-10.el4.ia64.rpm libpurple-2.6.6-10.el4.ia64.rpm libpurple-devel-2.6.6-10.el4.ia64.rpm libpurple-perl-2.6.6-10.el4.ia64.rpm libpurple-tcl-2.6.6-10.el4.ia64.rpm pidgin-2.6.6-10.el4.ia64.rpm pidgin-devel-2.6.6-10.el4.ia64.rpm pidgin-perl-2.6.6-10.el4.ia64.rpm SRPMS: https://oss.oracle.com:443/el4/SRPMS-updates/pidgin-2.6.6-10.el4.src.rpm Description of changes: [2.6.6-10.el4] - Add patch for CVE-2011-4603 (RH bug #766449). [2.6.6-9.el4] - Add patch for CVE-2011-4602 (RH bug #766449). [2.6.6-8.el4] - Add patch for CVE-2011-4601 (RH bug #766449). . As of October 2023, Oracle Linux 4 has updated Pidgin to address security issues from advisory ELSA-2011-1820, preventing potential exploits and enhancing system security. Oracle Linux Updates, Pidgin Security Fix, Moderate Severity Advisory. . LinuxSecurity.com Team
New gaim packages are available for Slackware 9.0, 9.1, 10.0, 10.1, and -current to fix some minor security issues. Sites that use GAIM should upgrade to the new version. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] gaim (SSA:2005-162-01) New gaim packages are available for Slackware 9.0, 9.1, 10.0, 10.1, and -current to fix some minor security issues. Sites that use GAIM should upgrade to the new version. Here are the details from the Slackware 10.1 ChangeLog: +--------------------------+ patches/packages/gaim-1.3.1-i486-1.tgz: Upgraded to gaim-1.3.1 and gaim-encryption-2.38. This fixes a couple of remote crash bugs, so users of the MSN and Yahoo! chat protocols should upgrade to gaim-1.3.1. (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Updated package for Slackware 9.0: Updated package for Slackware 9.1: Updated package for Slackware 10.0: Updated package for Slackware 10.1: Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 9.0 package: a75a60429363acd205166590ca17277f gaim-1.3.1-i386-1.tgz Slackware 9.1 package: 929de8fdd072554ae10e6bf8e75d232c gaim-1.3.1-i486-1.tgz Slackware 10.0 package: 4b0f13b8c99088536b7d72bb037cc5a2 gaim-1.3.1-i486-1.tgz Slackware 10.1 package: c0f249e8b5e862fa07f0c38e51e00844 gaim-1.3.1-i486-1.tgz Slackware -current package: f9b715b0d493fa91fc1d49cde13deefb gaim-1.3.1-i486-1.tgz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg gaim-1.3.1-i486-1.tgz +-----+ . Recent updates for Gaim on Slackware address several small security vulnerabilities. It's essential to upgrade to ensure your communication remains secure.. Slackware Security,Gaim Update,Remote Crash Fix. . LinuxSecurity.com Team
This update adds missing fix for CAN-2004-0081.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-078 2005-01-31 ---------------------------------------------------------------------Product : Fedora Core 3 Name : openssl096b Version : 0.9.6b Release : 21 Summary : The OpenSSL toolkit. Description : The OpenSSL toolkit provides support for secure communications between machines. OpenSSL includes a certificate management tool and shared libraries which provide various cryptographic algorithms and protocols. ---------------------------------------------------------------------Update Information: This update adds missing fix for CAN-2004-0081. ---------------------------------------------------------------------* Wed Oct 27 2004 Nalin Dahyabhai 0.9.6b-21 - rebuild * Wed Oct 27 2004 Nalin Dahyabhai 0.9.6b-20 - rebuild ---------------------------------------------------------------------This update can be downloaded from: 376588aa72cdac37281ae30e76e4092f SRPMS/openssl096b-0.9.6b-21.src.rpm def5ab22bd527f72611575e8f9edee0e x86_64/openssl096b-0.9.6b-21.x86_64.rpm 74ecfc4d2954604d2a54007d8dc54cb5 x86_64/debug/openssl096b-debuginfo-0.9.6b-21.x86_64.rpm 7154a102525adb6d7e6955783759559c x86_64/openssl096b-0.9.6b-21.i386.rpm 7154a102525adb6d7e6955783759559c i386/openssl096b-0.9.6b-21.i386.rpm fa8467ff5b3508b36f775ddd047625ea i386/debug/openssl096b-debuginfo-0.9.6b-21.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.