Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
89

Fedora 40: 2024-d20163632f Moderate: Djvulibre Divide By Zero Security Fix

Security fix for CVE-2021-46310 and CVE-2021-46312.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-d20163632f 2024-05-16 01:50:39.118565 -------------------------------------------------------------------------------- Name : djvulibre Product : Fedora 40 Version : 3.5.28 Release : 9.fc40 URL : Summary : DjVu viewers, encoders, and utilities Description : DjVu is a web-centric format and software platform for distributing documents and images. DjVu can advantageously replace PDF, PS, TIFF, JPEG, and GIF for distributing scanned documents, digital documents, or high-resolution pictures. DjVu content downloads faster, displays and renders faster, looks nicer on a screen, and consume less client resources than competing formats. DjVu images display instantly and can be smoothly zoomed and panned with no lengthy re-rendering. DjVuLibre is a free (GPL'ed) implementation of DjVu, including viewers, decoders, simple encoders, and utilities. The browser plugin is in its own separate sub-package. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2021-46310 and CVE-2021-46312. -------------------------------------------------------------------------------- ChangeLog: * Tue May 7 2024 Marek Kasik - 3.5.28-9 - Check for zero-size image when allocating GBuffer - Resolves: #2234738 * Tue May 7 2024 Marek Kasik - 3.5.28-8 - Improve image size fix - Resolves: #2234741 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2234736 - CVE-2021-46312 djvulibre: divide by zero in IW44EncodeCodec.cpp https://bugzilla.redhat.com/show_bug.cgi?id=2234736 [ 2 ] Bug #2234739 - CVE-2021-46310 djvulibre: divide by zero in IW44Image.cpp https://bugzilla.redhat.com/show_bug.cgi?id=2234739 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-d20163632f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 40 release tackles vulnerabilities in libjpeg-turbo, fixing critical memory safety errors. Key details provided.. Fedora Updates,Djvu Security,Fedora 40 Advisory,Application Security Update. . LinuxSecurity.com Team

Calendar 2 May 16, 2024 Fedora
203

Mageia 9 MGASA-2024-0062 Critical: MPlayer Buffer Overflow Threat

The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function config () of llibmpcodecs/vf_scale.c. (CVE-2022-38850) Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record() of mplayer/libmpdemux/asfheader.c. . MGASA-2024-0062 - Updated mplayer packages fix security vulnerabilities Publication date: 15 Mar 2024 URL: https://advisories.mageia.org/MGASA-2024-0062.html Type: security Affected Mageia releases: 9 CVE: CVE-2022-38850, CVE-2022-38851, CVE-2022-38855, CVE-2022-38858, CVE-2022-38860, CVE-2022-38861, CVE-2022-38863, CVE-2022-38864, CVE-2022-38865, CVE-2022-38866 The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function config () of llibmpcodecs/vf_scale.c. (CVE-2022-38850) Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record() of mplayer/libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. (CVE-2022-38851) Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video () of mplayer/libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. (CVE-2022-38855) Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. (CVE-2022-38858) Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() of libmpdemux/demux_avi.c which affects mencoder. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. (CVE-2022-38860) The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c. (CVE-2022-38861) Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.cwhich affects mencoder and mplayer. This affects mecoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1. (CVE-2022-38863) Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1. (CVE-2022-38864) Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects mplyer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. (CVE-2022-38865) Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_avi_header() of libmpdemux/aviheader.c . This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. (CVE-2022-38866) References: - https://bugs.mageia.org/show_bug.cgi?id=31360 - https://www.cve.org/CVERecord?id=CVE-2022-38850 - https://www.cve.org/CVERecord?id=CVE-2022-38851 - https://www.cve.org/CVERecord?id=CVE-2022-38855 - https://www.cve.org/CVERecord?id=CVE-2022-38858 - https://www.cve.org/CVERecord?id=CVE-2022-38860 - https://www.cve.org/CVERecord?id=CVE-2022-38861 - https://www.cve.org/CVERecord?id=CVE-2022-38863 - https://www.cve.org/CVERecord?id=CVE-2022-38864 - https://www.cve.org/CVERecord?id=CVE-2022-38865 - https://www.cve.org/CVERecord?id=CVE-2022-38866 SRPMS: - 9/core/mplayer-1.5-12.1.mga9 - 9/tainted/mplayer-1.5-12.1.mga9.tainted . Recent updates to the mplayer software are essential to address multiple security issues within Mageia as of March 2024. Ensure your system is secure!. Mageia Security Update, MPlayer Patch, Software Vulnerability Fix, Out-of-Bounds Read, Buffer Overflow Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 15, 2024 Critical Mageia
202

openSUSE 15:3520-1 Low: Divide By Zero Vulnerability in djvulibre

This update for djvulibre fixes the following issues: CVE-2021-46310: Fixed divide by zero in IW44Image.cpp (bsc#1214670). CVE-2021-46312: Fixed divide by zero in IW44EncodeCodec.cpp (bsc#1214672).. # Security update for djvulibre Announcement ID: SUSE-SU-2023:3520-1 Rating: low References: * #1214670 * #1214672 Cross-References: * CVE-2021-46310 * CVE-2021-46312 CVSS scores: * CVE-2021-46310 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2021-46310 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2021-46312 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2021-46312 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Desktop Applications Module 15-SP4 * Desktop Applications Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 * SUSE Package Hub 15 15-SP4 * SUSE Package Hub 15 15-SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for djvulibre fixes the following issues: * CVE-2021-46310: Fixed divide by zero in IW44Image.cpp (bsc#1214670). * CVE-2021-46312: Fixed divide by zero in IW44EncodeCodec.cpp (bsc#1214672). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or"zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3520=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3520=1 * Desktop Applications Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2023-3520=1 * Desktop Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2023-3520=1 * SUSE Package Hub 15 15-SP4 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2023-3520=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-3520=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.14.1 * libdjvulibre-devel-3.5.27-150200.11.14.1 * libdjvulibre21-3.5.27-150200.11.14.1 * djvulibre-3.5.27-150200.11.14.1 * djvulibre-debugsource-3.5.27-150200.11.14.1 * libdjvulibre21-debuginfo-3.5.27-150200.11.14.1 * openSUSE Leap 15.4 (noarch) * djvulibre-doc-3.5.27-150200.11.14.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.14.1 * libdjvulibre-devel-3.5.27-150200.11.14.1 * libdjvulibre21-3.5.27-150200.11.14.1 * djvulibre-3.5.27-150200.11.14.1 * djvulibre-debugsource-3.5.27-150200.11.14.1 * libdjvulibre21-debuginfo-3.5.27-150200.11.14.1 * openSUSE Leap 15.5 (noarch) * djvulibre-doc-3.5.27-150200.11.14.1 * Desktop Applications Module 15-SP4 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.14.1 * libdjvulibre21-3.5.27-150200.11.14.1 * libdjvulibre-devel-3.5.27-150200.11.14.1 * djvulibre-debugsource-3.5.27-150200.11.14.1 * libdjvulibre21-debuginfo-3.5.27-150200.11.14.1 * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.14.1 * libdjvulibre21-3.5.27-150200.11.14.1 *libdjvulibre-devel-3.5.27-150200.11.14.1 * djvulibre-debugsource-3.5.27-150200.11.14.1 * libdjvulibre21-debuginfo-3.5.27-150200.11.14.1 * SUSE Package Hub 15 15-SP4 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.14.1 * djvulibre-debugsource-3.5.27-150200.11.14.1 * djvulibre-3.5.27-150200.11.14.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.14.1 * djvulibre-debugsource-3.5.27-150200.11.14.1 * djvulibre-3.5.27-150200.11.14.1 ## References: * https://www.suse.com/security/cve/CVE-2021-46310.html * https://www.suse.com/security/cve/CVE-2021-46312.html * https://bugzilla.suse.com/show_bug.cgi?id=1214670 * https://bugzilla.suse.com/show_bug.cgi?id=1214672 . Update for djvulibre addresses minor divide by zero vulnerabilities discovered in IW44Image and IW44EncodeCodec modules.. djvulibre Update, openSUSE Security, Security Advisory. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Sep 05, 2023 Low OpenSUSE
197

Debian 10 Buster DLA-3527-1 Critical: SoX Denial Of Service Issue

SoX is a command line utility that can convert various formats of computer audio files in to other formats. It can also apply various effects to these sound files during the conversion. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3527-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès August 13, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : sox Version : 14.4.2+git20190427-1+deb10u3 CVE ID : CVE-2023-32627 Debian Bug : 1041112 SoX is a command line utility that can convert various formats of computer audio files in to other formats. It can also apply various effects to these sound files during the conversion. Sox was vulnerable to divide by zero vulnerability by reading an specialy crafted Creative Voice File (.voc) file, in the read_samples function. This flaw can lead to a denial of service. For Debian 10 buster, this problem has been fixed in version 14.4.2+git20190427-1+deb10u3. We recommend that you upgrade your sox packages. For the detailed security status of sox please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sox Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-5102-1 tackles a severe buffer overflow vulnerability in GIMP impacting image processing capabilities.. Debian LTS, SoX Denial Of Service, Critical Update, Audio File Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 13, 2023 Critical Debian LTS
89

Fedora 38: FEDORA-2023-2b3d47a920 Warning: Emacs Out Of Memory Exception

The newest upstream commit 2215591 - TRIAGE vim: Divide By Zero vulnerability in scroll_cursor_bot() in move.c. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-15c591bd6e 2023-06-30 01:34:31.054460 --------------------------------------------------------------------------------Name : vim Product : Fedora 37 Version : 9.0.1649 Release : 1.fc37 URL : https://www.vim.org/ Summary : The VIM editor Description : VIM (VIsual editor iMproved) is an updated and improved version of the vi editor. Vi was the first real screen-based editor for UNIX, and is still very popular. VIM improves on vi by adding new features: multiple windows, multi-level undo, block highlighting and more. --------------------------------------------------------------------------------Update Information: The newest upstream commit 2215591 - TRIAGE vim: Divide By Zero vulnerability in scroll_cursor_bot() in move.c --------------------------------------------------------------------------------ChangeLog: * Fri Jun 23 2023 Zdenek Dohnal - 2:9.0.1649-1 - patchlevel 1649 --------------------------------------------------------------------------------References: [ 1 ] Bug #2215590 - TRIAGE vim: Divide By Zero vulnerability in scroll_cursor_bot() in move.c https://bugzilla.redhat.com/show_bug.cgi?id=2215590 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-15c591bd6e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Tackling the Divide By Zero concern in vim via the current Fedora update alert. Remain updated and protected!. divide by zero,Fedora update,software vulnerability,vim editor,fix release. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 30, 2023 Important Fedora
89

Fedora 38 FEDORA-2023-6ad6467a06 Moderate: Vim Divide By Zero Issue

The newest upstream commit 2215591 - TRIAGE vim: Divide By Zero vulnerability in scroll_cursor_bot() in move.c. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-6ad6467a06 2023-06-25 00:49:42.634043 --------------------------------------------------------------------------------Name : vim Product : Fedora 38 Version : 9.0.1649 Release : 1.fc38 URL : https://www.vim.org/ Summary : The VIM editor Description : VIM (VIsual editor iMproved) is an updated and improved version of the vi editor. Vi was the first real screen-based editor for UNIX, and is still very popular. VIM improves on vi by adding new features: multiple windows, multi-level undo, block highlighting and more. --------------------------------------------------------------------------------Update Information: The newest upstream commit 2215591 - TRIAGE vim: Divide By Zero vulnerability in scroll_cursor_bot() in move.c --------------------------------------------------------------------------------ChangeLog: * Fri Jun 23 2023 Zdenek Dohnal - 2:9.0.1649-1 - patchlevel 1649 --------------------------------------------------------------------------------References: [ 1 ] Bug #2215590 - TRIAGE vim: Divide By Zero vulnerability in scroll_cursor_bot() in move.c https://bugzilla.redhat.com/show_bug.cgi?id=2215590 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6ad6467a06' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest Fedora 38 patch resolves the zero division error found in vim's cursor processing, improving overall performance and user experience.. Vim Updates,Fedora Security,Vulnerability Management. . LinuxSecurity.com Team

Calendar 2 Jun 25, 2023 Fedora
203

Mageia 8 MGASA-2022-0172 Moderate: Libcaca Divide By Zero Denial of Service

libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to cause a Denial of Service. (CVE-2022-0856) References: - https://bugs.mageia.org/show_bug.cgi?id=30364 . MGASA-2022-0172 - Updated libcaca packages fix security vulnerability Publication date: 12 May 2022 URL: https://advisories.mageia.org/MGASA-2022-0172.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-0856 libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to cause a Denial of Service. (CVE-2022-0856) References: - https://bugs.mageia.org/show_bug.cgi?id=30364 - - https://www.cve.org/CVERecord?id=CVE-2022-0856 SRPMS: - 8/core/libcaca-0.99-0.beta19.5.3.mga8 . A security patch for Libcaca in Mageia 8 fixes a Divide By Zero flaw that leads to Denial of Service. Find out more.. libcaca, security advisory, Denial of Service, Mageia updates. . LinuxSecurity.com Team

Calendar 2 May 12, 2022 Mageia
100

SUSE: 2022:1476-1 Security Update: libcaca App Crash Issue Fixed

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libcaca ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1476-1 Rating: moderate References: #1197028 Cross-References: CVE-2022-0856 CVSS scores: CVE-2022-0856 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2022-0856 (SUSE): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Realtime Extension 15-SP2 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libcaca fixes the following issues: - CVE-2022-0856: Fixed a divide by zero issue which could be exploited to cause an application crash (bsc#1197028). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypperin -t patch openSUSE-SLE-15.4-2022-1476=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-1476=1 - SUSE Linux Enterprise Realtime Extension 15-SP2: zypper in -t patch SUSE-SLE-Product-RT-15-SP2-2022-1476=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-1476=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-1476=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): caca-utils-0.99.beta19.git20171003-150200.11.6.1 caca-utils-debuginfo-0.99.beta19.git20171003-150200.11.6.1 libcaca-debugsource-0.99.beta19.git20171003-150200.11.6.1 libcaca-devel-0.99.beta19.git20171003-150200.11.6.1 libcaca-ruby-0.99.beta19.git20171003-150200.11.6.1 libcaca-ruby-debuginfo-0.99.beta19.git20171003-150200.11.6.1 libcaca0-0.99.beta19.git20171003-150200.11.6.1 libcaca0-debuginfo-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-debuginfo-0.99.beta19.git20171003-150200.11.6.1 - openSUSE Leap 15.4 (x86_64): libcaca0-32bit-0.99.beta19.git20171003-150200.11.6.1 libcaca0-32bit-debuginfo-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-32bit-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-32bit-debuginfo-0.99.beta19.git20171003-150200.11.6.1 - openSUSE Leap 15.4 (noarch): python3-caca-0.99.beta19.git20171003-150200.11.6.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): caca-utils-0.99.beta19.git20171003-150200.11.6.1 caca-utils-debuginfo-0.99.beta19.git20171003-150200.11.6.1 libcaca-debugsource-0.99.beta19.git20171003-150200.11.6.1 libcaca-devel-0.99.beta19.git20171003-150200.11.6.1 libcaca-ruby-0.99.beta19.git20171003-150200.11.6.1 libcaca-ruby-debuginfo-0.99.beta19.git20171003-150200.11.6.1 libcaca0-0.99.beta19.git20171003-150200.11.6.1 libcaca0-debuginfo-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-debuginfo-0.99.beta19.git20171003-150200.11.6.1 - openSUSE Leap 15.3 (noarch): python3-caca-0.99.beta19.git20171003-150200.11.6.1 - openSUSE Leap 15.3 (x86_64): libcaca0-32bit-0.99.beta19.git20171003-150200.11.6.1 libcaca0-32bit-debuginfo-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-32bit-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-32bit-debuginfo-0.99.beta19.git20171003-150200.11.6.1 - SUSE Linux Enterprise Realtime Extension 15-SP2 (x86_64): libcaca-debugsource-0.99.beta19.git20171003-150200.11.6.1 libcaca-devel-0.99.beta19.git20171003-150200.11.6.1 libcaca0-0.99.beta19.git20171003-150200.11.6.1 libcaca0-debuginfo-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-debuginfo-0.99.beta19.git20171003-150200.11.6.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (aarch64 ppc64le s390x x86_64): libcaca-debugsource-0.99.beta19.git20171003-150200.11.6.1 libcaca-devel-0.99.beta19.git20171003-150200.11.6.1 libcaca0-0.99.beta19.git20171003-150200.11.6.1 libcaca0-debuginfo-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-debuginfo-0.99.beta19.git20171003-150200.11.6.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): libcaca-debugsource-0.99.beta19.git20171003-150200.11.6.1 libcaca-devel-0.99.beta19.git20171003-150200.11.6.1 libcaca0-0.99.beta19.git20171003-150200.11.6.1 libcaca0-debuginfo-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-0.99.beta19.git20171003-150200.11.6.1 libcaca0-plugins-debuginfo-0.99.beta19.git20171003-150200.11.6.1 References: https://www.suse.com/security/cve/CVE-2022-0856.html https://bugzilla.suse.com/1197028 . SUSE launches security patch for libcaca addressing a moderate concern related to division by zero flaw. Ensure your security!. libcaca security update, SUSE vulnerability patch, application crash fix. . LinuxSecurity.com Team

Calendar 2 Apr 29, 2022 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here