MGASA-2026-0060 - Updated graphicsmagick & imagemagick packages fix security vulnerabilities. MGASA-2026-0060 - Updated graphicsmagick & imagemagick packages fix security vulnerabilities Publication date: 19 Mar 2026 URL: https://advisories.mageia.org/MGASA-2026-0060.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-25799 Description: Division-by-Zero in YUV sampling factor validation leads to crash. (CVE-2026-25799) References: - https://bugs.mageia.org/show_bug.cgi?id=35199 - https://lists.opensuse.org/archives/list/
An update that solves one vulnerability can now be installed.. # Security update for GraphicsMagick Announcement ID: SUSE-SU-2026:0874-1 Release Date: 2026-03-11T17:07:37Z Rating: moderate References: * bsc#1258786 Cross-References: * CVE-2026-25799 CVSS scores: * CVE-2026-25799 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-25799 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-25799 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-25799 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for GraphicsMagick fixes the following issue: * CVE-2026-25799: Division-by-Zero in YUV sampling factor validation leads to crash (bsc#1258786). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-874=1 openSUSE-SLE-15.6-2026-874=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-874=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.10.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.10.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.10.1 * GraphicsMagick-debugsource-1.3.42-150600.3.10.1 * GraphicsMagick-devel-1.3.42-150600.3.10.1 * libGraphicsMagick++-devel-1.3.42-150600.3.10.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.10.1 *GraphicsMagick-1.3.42-150600.3.10.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.10.1 * libGraphicsMagick3-config-1.3.42-150600.3.10.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.10.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.10.1 * perl-GraphicsMagick-1.3.42-150600.3.10.1 * GraphicsMagick-debuginfo-1.3.42-150600.3.10.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.10.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.10.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.10.1 * GraphicsMagick-debugsource-1.3.42-150600.3.10.1 * GraphicsMagick-devel-1.3.42-150600.3.10.1 * libGraphicsMagick++-devel-1.3.42-150600.3.10.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.10.1 * GraphicsMagick-1.3.42-150600.3.10.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.10.1 * libGraphicsMagick3-config-1.3.42-150600.3.10.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.10.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.10.1 * perl-GraphicsMagick-1.3.42-150600.3.10.1 * GraphicsMagick-debuginfo-1.3.42-150600.3.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25799.html * https://bugzilla.suse.com/show_bug.cgi?id=1258786 . Upgrade GraphicsMagick for openSUSE to fix moderate issues leading to crashes from zero division errors.. GraphicsMagick Security Fix, openSUSE GraphicsMagick, GraphicsMagick Update, Security Patch GraphicsMagick. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for qt6-connectivity ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0033-1 Rating: moderate References: #1236237 Cross-References: CVE-2025-23050 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for qt6-connectivity fixes the following issues: - CVE-2025-23050: Fixed buffer over-read and division by zero (boo#1236237) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-33=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): libQt6Bluetooth6-6.6.3-bp156.2.3.1 libQt6Nfc6-6.6.3-bp156.2.3.1 qt6-connectivity-6.6.3-bp156.2.3.1 qt6-connectivity-devel-6.6.3-bp156.2.3.1 qt6-connectivity-docs-html-6.6.3-bp156.2.3.1 qt6-connectivity-docs-qch-6.6.3-bp156.2.3.1 qt6-connectivity-examples-6.6.3-bp156.2.3.1 qt6-connectivity-private-devel-6.6.3-bp156.2.3.1 References: https://www.suse.com/security/cve/CVE-2025-23050.html https://bugzilla.suse.com/1236237 . Essential security patch released for qt6-connectivity tackling buffer overflow issue in openSUSE.. qt6 update, openSUSE security, buffer over-read fix, division by zero, connectivity issue. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for freerdp ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4292-1 Rating: moderate References: #1205563 #1205564 Cross-References: CVE-2022-39318 CVE-2022-39319 CVSS scores: CVE-2022-39318 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-39318 (SUSE): 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H CVE-2022-39319 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVE-2022-39319 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:H Affected Products: SUSE Enterprise Storage 7.1 SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Workstation Extension 15-SP3 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for freerdp fixes the following issues: - CVE-2022-39318: Fixed division by zero in urbdrc (bsc#1205563). - CVE-2022-39319: Fixed missing input buffer length check in urbdrc (bsc#1205564). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in-t patch openSUSE-SLE-15.3-2022-4292=1 - SUSE Linux Enterprise Workstation Extension 15-SP3: zypper in -t patch SUSE-SLE-Product-WE-15-SP3-2022-4292=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP3-2022-4292=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): freerdp-2.1.2-150200.15.24.1 freerdp-debuginfo-2.1.2-150200.15.24.1 freerdp-debugsource-2.1.2-150200.15.24.1 freerdp-devel-2.1.2-150200.15.24.1 freerdp-proxy-2.1.2-150200.15.24.1 freerdp-proxy-debuginfo-2.1.2-150200.15.24.1 freerdp-server-2.1.2-150200.15.24.1 freerdp-server-debuginfo-2.1.2-150200.15.24.1 freerdp-wayland-2.1.2-150200.15.24.1 freerdp-wayland-debuginfo-2.1.2-150200.15.24.1 libfreerdp2-2.1.2-150200.15.24.1 libfreerdp2-debuginfo-2.1.2-150200.15.24.1 libuwac0-0-2.1.2-150200.15.24.1 libuwac0-0-debuginfo-2.1.2-150200.15.24.1 libwinpr2-2.1.2-150200.15.24.1 libwinpr2-debuginfo-2.1.2-150200.15.24.1 uwac0-0-devel-2.1.2-150200.15.24.1 winpr2-devel-2.1.2-150200.15.24.1 - SUSE Linux Enterprise Workstation Extension 15-SP3 (x86_64): freerdp-2.1.2-150200.15.24.1 freerdp-debuginfo-2.1.2-150200.15.24.1 freerdp-debugsource-2.1.2-150200.15.24.1 freerdp-devel-2.1.2-150200.15.24.1 freerdp-proxy-2.1.2-150200.15.24.1 freerdp-proxy-debuginfo-2.1.2-150200.15.24.1 libfreerdp2-2.1.2-150200.15.24.1 libfreerdp2-debuginfo-2.1.2-150200.15.24.1 libwinpr2-2.1.2-150200.15.24.1 libwinpr2-debuginfo-2.1.2-150200.15.24.1 winpr2-devel-2.1.2-150200.15.24.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (aarch64 ppc64le s390x): freerdp-2.1.2-150200.15.24.1 freerdp-debuginfo-2.1.2-150200.15.24.1 freerdp-debugsource-2.1.2-150200.15.24.1 freerdp-devel-2.1.2-150200.15.24.1 freerdp-proxy-2.1.2-150200.15.24.1 freerdp-proxy-debuginfo-2.1.2-150200.15.24.1 libfreerdp2-2.1.2-150200.15.24.1 libfreerdp2-debuginfo-2.1.2-150200.15.24.1 libwinpr2-2.1.2-150200.15.24.1 libwinpr2-debuginfo-2.1.2-150200.15.24.1 winpr2-devel-2.1.2-150200.15.24.1 References: https://www.suse.com/security/cve/CVE-2022-39318.html https://www.suse.com/security/cve/CVE-2022-39319.html https://bugzilla.suse.com/1205563 https://bugzilla.suse.com/1205564 . SUSE Security Alert: freerdp has undergone an update to resolve moderate vulnerabilities. Ensure that you review your updates.. freerdp update, SUSE security, bug fix, Linux patch. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for freerdp ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4293-1 Rating: moderate References: #1205563 #1205564 Cross-References: CVE-2022-39318 CVE-2022-39319 CVSS scores: CVE-2022-39318 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-39318 (SUSE): 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H CVE-2022-39319 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVE-2022-39319 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:H Affected Products: SUSE Linux Enterprise Desktop 12-SP5 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Workstation Extension 12-SP5 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for freerdp fixes the following issues: - CVE-2022-39318: Fixed division by zero in urbdrc (bsc#1205563). - CVE-2022-39319: Fixed missing input buffer length check in urbdrc (bsc#1205564). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2022-4293=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-4293=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): freerdp-2.1.2-12.32.1 freerdp-debuginfo-2.1.2-12.32.1 freerdp-debugsource-2.1.2-12.32.1 freerdp-proxy-2.1.2-12.32.1 freerdp-server-2.1.2-12.32.1 libfreerdp2-2.1.2-12.32.1 libfreerdp2-debuginfo-2.1.2-12.32.1 libwinpr2-2.1.2-12.32.1 libwinpr2-debuginfo-2.1.2-12.32.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): freerdp-debuginfo-2.1.2-12.32.1 freerdp-debugsource-2.1.2-12.32.1 freerdp-devel-2.1.2-12.32.1 libfreerdp2-2.1.2-12.32.1 libfreerdp2-debuginfo-2.1.2-12.32.1 libwinpr2-2.1.2-12.32.1 libwinpr2-debuginfo-2.1.2-12.32.1 winpr2-devel-2.1.2-12.32.1 References: https://www.suse.com/security/cve/CVE-2022-39318.html https://www.suse.com/security/cve/CVE-2022-39319.html https://bugzilla.suse.com/1205563 https://bugzilla.suse.com/1205564 . SUSE Security Notice: Freerdp addresses critical flaws including zero division errors and input buffer size vulnerabilities. Urgent update needed.. SUSE Linux, Freerdp, Moderate Security Fix, Update Information. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for ImageMagick ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:3996-1 Rating: moderate References: #1181836 Cross-References: CVE-2021-20176 CVSS scores: CVE-2021-20176 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-20176 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for ImageMagick fixes the following issues: - CVE-2021-20176: Fixed division by zero caused by processing crafted file (bsc#1181836). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-3996=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): ImageMagick-7.0.7.34-10.18.1 ImageMagick-config-7-SUSE-7.0.7.34-10.18.1 ImageMagick-config-7-upstream-7.0.7.34-10.18.1 ImageMagick-debuginfo-7.0.7.34-10.18.1 ImageMagick-debugsource-7.0.7.34-10.18.1 ImageMagick-devel-7.0.7.34-10.18.1 ImageMagick-extra-7.0.7.34-10.18.1 ImageMagick-extra-debuginfo-7.0.7.34-10.18.1 libMagick++-7_Q16HDRI4-7.0.7.34-10.18.1 libMagick++-7_Q16HDRI4-debuginfo-7.0.7.34-10.18.1 libMagick++-devel-7.0.7.34-10.18.1 libMagickCore-7_Q16HDRI6-7.0.7.34-10.18.1 libMagickCore-7_Q16HDRI6-debuginfo-7.0.7.34-10.18.1 libMagickWand-7_Q16HDRI6-7.0.7.34-10.18.1 libMagickWand-7_Q16HDRI6-debuginfo-7.0.7.34-10.18.1 perl-PerlMagick-7.0.7.34-10.18.1 perl-PerlMagick-debuginfo-7.0.7.34-10.18.1 - openSUSE Leap 15.3 (x86_64): ImageMagick-devel-32bit-7.0.7.34-10.18.1 libMagick++-7_Q16HDRI4-32bit-7.0.7.34-10.18.1 libMagick++-7_Q16HDRI4-32bit-debuginfo-7.0.7.34-10.18.1 libMagick++-devel-32bit-7.0.7.34-10.18.1 libMagickCore-7_Q16HDRI6-32bit-7.0.7.34-10.18.1 libMagickCore-7_Q16HDRI6-32bit-debuginfo-7.0.7.34-10.18.1 libMagickWand-7_Q16HDRI6-32bit-7.0.7.34-10.18.1 libMagickWand-7_Q16HDRI6-32bit-debuginfo-7.0.7.34-10.18.1 - openSUSE Leap 15.3 (noarch): ImageMagick-doc-7.0.7.34-10.18.1 References: https://www.suse.com/security/cve/CVE-2021-20176.html https://bugzilla.suse.com/1181836 . A security patch for ImageMagick on openSUSE has been released, targeting a medium-level vulnerability and is advised for installation via standard update procedures.. ImageMagick Update, OpenSUSE Advice, Patch Installation. . LinuxSecurity.com Team
An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for ImageMagick ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1277-1 Rating: moderate References: #1184624 #1184626 #1184627 #1184628 Cross-References: CVE-2021-20309 CVE-2021-20311 CVE-2021-20312 CVE-2021-20313 CVSS scores: CVE-2021-20309 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2021-20311 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2021-20312 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2021-20313 (SUSE): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for ImageMagick fixes the following issues: - CVE-2021-20309: Division by zero in WaveImage() of MagickCore/visual-effects. (bsc#1184624) - CVE-2021-20311: Division by zero in sRGBTransformImage() in MagickCore/colorspace.c (bsc#1184626) - CVE-2021-20312: Integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c (bsc#1184627) - CVE-2021-20313: Cipher leak when the calculating signatures in TransformSignatureof MagickCore/signature.c (bsc#1184628) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2021-1277=1 - SUSE LinuxEnterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-1277=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-1277=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): ImageMagick-6.8.8.1-71.165.1 ImageMagick-debuginfo-6.8.8.1-71.165.1 ImageMagick-debugsource-6.8.8.1-71.165.1 libMagick++-6_Q16-3-6.8.8.1-71.165.1 libMagick++-6_Q16-3-debuginfo-6.8.8.1-71.165.1 libMagickCore-6_Q16-1-32bit-6.8.8.1-71.165.1 libMagickCore-6_Q16-1-debuginfo-32bit-6.8.8.1-71.165.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): ImageMagick-6.8.8.1-71.165.1 ImageMagick-config-6-SUSE-6.8.8.1-71.165.1 ImageMagick-config-6-upstream-6.8.8.1-71.165.1 ImageMagick-debuginfo-6.8.8.1-71.165.1 ImageMagick-debugsource-6.8.8.1-71.165.1 ImageMagick-devel-6.8.8.1-71.165.1 libMagick++-6_Q16-3-6.8.8.1-71.165.1 libMagick++-6_Q16-3-debuginfo-6.8.8.1-71.165.1 libMagick++-devel-6.8.8.1-71.165.1 perl-PerlMagick-6.8.8.1-71.165.1 perl-PerlMagick-debuginfo-6.8.8.1-71.165.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): ImageMagick-config-6-SUSE-6.8.8.1-71.165.1 ImageMagick-config-6-upstream-6.8.8.1-71.165.1 ImageMagick-debuginfo-6.8.8.1-71.165.1 ImageMagick-debugsource-6.8.8.1-71.165.1 libMagickCore-6_Q16-1-6.8.8.1-71.165.1 libMagickCore-6_Q16-1-debuginfo-6.8.8.1-71.165.1 libMagickWand-6_Q16-1-6.8.8.1-71.165.1 libMagickWand-6_Q16-1-debuginfo-6.8.8.1-71.165.1 References: https://www.suse.com/security/cve/CVE-2021-20309.html https://www.suse.com/security/cve/CVE-2021-20311.html https://www.suse.com/security/cve/CVE-2021-20312.html https://www.suse.com/security/cve/CVE-2021-20313.html https://bugzilla.suse.com/1184624 https://bugzilla.suse.com/1184626 https://bugzilla.suse.com/1184627 https://bugzilla.suse.com/1184628 . This Fedora update delivers crucial patches for GIMP, enhancing protection from various security flaws.. ImageMagick Update, SUSE Security Patch, Software Vulnerability Fixes. . LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available.. openSUSE Security Update: Security update for zziplib ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2394-1 Rating: moderate References: #1107424 #1129403 Cross-References: CVE-2018-16548 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for zziplib fixes the following issues: Security issue fixed: - CVE-2018-16548: Prevented memory leak from __zzip_parse_root_directory(). Free allocated structure if its address is not passed back. (bsc#1107424) Other issue addressed: - Prevented a division by zero (bsc#1129403). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-2394=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): libzzip-0-13-0.13.69-lp150.7.1 libzzip-0-13-debuginfo-0.13.69-lp150.7.1 zziplib-debugsource-0.13.69-lp150.7.1 zziplib-devel-0.13.69-lp150.7.1 zziplib-devel-debuginfo-0.13.69-lp150.7.1 - openSUSE Leap 15.0 (x86_64): libzzip-0-13-32bit-0.13.69-lp150.7.1 libzzip-0-13-32bit-debuginfo-0.13.69-lp150.7.1 zziplib-devel-32bit-0.13.69-lp150.7.1 zziplib-devel-32bit-debuginfo-0.13.69-lp150.7.1 References: https://www.suse.com/security/cve/CVE-2018-16548.html https://bugzilla.suse.com/1107424 https://bugzilla.suse.com/1129403 -- . A significant patch for zziplib addresses a memory overflow and bug within openSUSE, improvingoverall system performance.. openSUSE security update, zziplib patch, memory leak fix, division by zero, openSUSE Leap. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.