Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 56 articles for you...
89

Fedora 43 DjVuLibre Important Out of Bounds Issue Fix 2026-bfa185dbb3

Update to 3.5.30.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bfa185dbb3 2026-05-30 01:07:34.273965+00:00 -------------------------------------------------------------------------------- Name : djvulibre Product : Fedora 43 Version : 3.5.30 Release : 1.fc43 URL : http://djvu.sourceforge.net/ Summary : DjVu viewers, encoders, and utilities Description : DjVu is a web-centric format and software platform for distributing documents and images. DjVu can advantageously replace PDF, PS, TIFF, JPEG, and GIF for distributing scanned documents, digital documents, or high-resolution pictures. DjVu content downloads faster, displays and renders faster, looks nicer on a screen, and consume less client resources than competing formats. DjVu images display instantly and can be smoothly zoomed and panned with no lengthy re-rendering. DjVuLibre is a free (GPL'ed) implementation of DjVu, including viewers, decoders, simple encoders, and utilities. The browser plugin is in its own separate sub-package. -------------------------------------------------------------------------------- Update Information: Update to 3.5.30. -------------------------------------------------------------------------------- ChangeLog: * Thu May 21 2026 Marek Kasik - 3.5.30-1 - Rebase to 3.5.30 - Resolves: #2376253 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2376253 - CVE-2025-53367 djvulibre: DjVuLibre out of bounds write [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2376253 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bfa185dbb3' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Djvulibre 3.5.30 for Fedora addresses critical security risks to enhance performance and document handling.. DjVu Document Handling,djvulibre Security Update,Fedora 43 Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 30, 2026 Important Fedora
89

Fedora 44 djvulibre Important Out of Bounds Write Advisory 2026-956f05a733

Update to 3.5.30.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-956f05a733 2026-05-30 00:54:46.011423+00:00 -------------------------------------------------------------------------------- Name : djvulibre Product : Fedora 44 Version : 3.5.30 Release : 1.fc44 URL : http://djvu.sourceforge.net/ Summary : DjVu viewers, encoders, and utilities Description : DjVu is a web-centric format and software platform for distributing documents and images. DjVu can advantageously replace PDF, PS, TIFF, JPEG, and GIF for distributing scanned documents, digital documents, or high-resolution pictures. DjVu content downloads faster, displays and renders faster, looks nicer on a screen, and consume less client resources than competing formats. DjVu images display instantly and can be smoothly zoomed and panned with no lengthy re-rendering. DjVuLibre is a free (GPL'ed) implementation of DjVu, including viewers, decoders, simple encoders, and utilities. The browser plugin is in its own separate sub-package. -------------------------------------------------------------------------------- Update Information: Update to 3.5.30. -------------------------------------------------------------------------------- ChangeLog: * Thu May 21 2026 Marek Kasik - 3.5.30-1 - Rebase to 3.5.30 - Resolves: #2376253 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2376253 - CVE-2025-53367 djvulibre: DjVuLibre out of bounds write [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2376253 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-956f05a733' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update to Fedora 44 djvulibre 3.5.30 addresses important out of bounds write issue.. Fedora, djvulibre, update, out of bounds write, open source. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 30, 2026 Important Fedora
172

Ubuntu 22.04 LTS DjVuLibre Important Denial of Service USN-8054-1

Several security issues were fixed in DjVuLibre.. ========================================================================== Ubuntu Security Notice USN-8054-1 February 23, 2026 djvulibre vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in DjVuLibre. Software Description: - djvulibre: DjVu image format library and tools Details: It was discovered that DjVuLibre could be forced to execute a division by zero in certain instances. A remote attacker could possibly use this issue to cause applications to stop responding or crash, resulting in a denial of service. (CVE-2021-46312) It was discovered that DjVuLibre incorrectly handled certain memory operations. If a user or automated system were tricked into processing a specially crafted DjVu file, a remote attacker could cause applications to stop responding or crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2025-53367) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libdjvulibre21 3.5.28-2ubuntu0.24.04.2 Ubuntu 22.04 LTS libdjvulibre21 3.5.28-2ubuntu0.22.04.2 Ubuntu 20.04 LTS libdjvulibre21 3.5.27.1-14ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libdjvulibre21 3.5.27.1-8ubuntu0.4+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libdjvulibre21 3.5.27.1-5ubuntu0.1+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8054-1 CVE-2021-46312, CVE-2025-53367 Package Information: https://launchpad.net/ubuntu/+source/djvulibre/3.5.28-2ubuntu0.24.04.2 https://launchpad.net/ubuntu/+source/djvulibre/3.5.28-2ubuntu0.22.04.2 . Several security issues in DjVuLibre for Ubuntu require immediate action to prevent denial of service risks.. DjVuLibre Update, Ubuntu Security Notice, Denial of Service, Important Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 23, 2026 Important Ubuntu
100

SUSE: libjpeg Moderate Memory Leak Security Update for 2025:02995-1

* bsc#1245773 Cross-References: * CVE-2025-53367 . # Security update for djvulibre Announcement ID: SUSE-SU-2025:02695-1 Release Date: 2025-08-05T08:08:58Z Rating: moderate References: * bsc#1245773 Cross-References: * CVE-2025-53367 CVSS scores: * CVE-2025-53367 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-53367 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-53367 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for djvulibre fixes the following issues: * CVE-2025-53367: Fixed a bug where a crafted document may lead to an out of bound write. (bsc#1245773) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-2695=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * djvulibre-debugsource-3.5.25.3-5.25.1 * libdjvulibre21-3.5.25.3-5.25.1 * libdjvulibre21-debuginfo-3.5.25.3-5.25.1 * libdjvulibre-devel-3.5.25.3-5.25.1 * djvulibre-debuginfo-3.5.25.3-5.25.1 ## References: * https://www.suse.com/security/cve/CVE-2025-53367.html * https://bugzilla.suse.com/show_bug.cgi?id=1245773 . Explore the recent SUSE patch for djvulibre, which rectifies a significant vulnerability linked to out of bounds write issues.. SUSE Update, djvulibreFix, Moderate Severity, Security Patch, Linux Security Advisory. . LinuxSecurity.com Team

Calendar%202 Aug 05, 2025 SuSE
202

openSUSE: djvulibre Moderate Out Of Bounds Fix CVE-2025-53367 2025:02703-1

An update that solves one vulnerability can now be installed.. # Security update for djvulibre Announcement ID: SUSE-SU-2025:02703-1 Release Date: 2025-08-05T09:33:28Z Rating: moderate References: * bsc#1245773 Cross-References: * CVE-2025-53367 CVSS scores: * CVE-2025-53367 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-53367 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-53367 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for djvulibre fixes the following issues: * CVE-2025-53367: Fixed a bug where a crafted document may lead to an out of bound write. (bsc#1245773) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2703=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-2703=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-2703=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2703=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-2703=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.17.1 * libdjvulibre21-3.5.27-150200.11.17.1 * djvulibre-debugsource-3.5.27-150200.11.17.1 * libdjvulibre-devel-3.5.27-150200.11.17.1 * libdjvulibre21-debuginfo-3.5.27-150200.11.17.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.17.1 * djvulibre-3.5.27-150200.11.17.1 * djvulibre-debugsource-3.5.27-150200.11.17.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.17.1 * djvulibre-3.5.27-150200.11.17.1 * djvulibre-debugsource-3.5.27-150200.11.17.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.17.1 * libdjvulibre21-3.5.27-150200.11.17.1 * djvulibre-debugsource-3.5.27-150200.11.17.1 * libdjvulibre-devel-3.5.27-150200.11.17.1 * djvulibre-3.5.27-150200.11.17.1 * libdjvulibre21-debuginfo-3.5.27-150200.11.17.1 * openSUSE Leap 15.6 (noarch) * djvulibre-doc-3.5.27-150200.11.17.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.17.1 * libdjvulibre21-3.5.27-150200.11.17.1 * djvulibre-debugsource-3.5.27-150200.11.17.1 * libdjvulibre-devel-3.5.27-150200.11.17.1 * libdjvulibre21-debuginfo-3.5.27-150200.11.17.1 ## References: * https://www.suse.com/security/cve/CVE-2025-53367.html * https://bugzilla.suse.com/show_bug.cgi?id=1245773 . Patch addresses significant vulnerability within djvulibre for openSUSE users. Rectifies buffer overflow weakness, bolstering overall security.. SUSE Linux, djvulibre update, out of bounds write, Linux security. . LinuxSecurity.com Team

Calendar%202 Aug 05, 2025 OpenSUSE
100

SUSE: djvulibre Moderate Out of Bounds Risk CVE-2025-53367 2025:02703-1

* bsc#1245773 Cross-References: * CVE-2025-53367 . # Security update for djvulibre Announcement ID: SUSE-SU-2025:02703-1 Release Date: 2025-08-05T09:33:28Z Rating: moderate References: * bsc#1245773 Cross-References: * CVE-2025-53367 CVSS scores: * CVE-2025-53367 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-53367 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-53367 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for djvulibre fixes the following issues: * CVE-2025-53367: Fixed a bug where a crafted document may lead to an out of bound write. (bsc#1245773) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2703=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-2703=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-2703=1 * openSUSELeap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2703=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-2703=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.17.1 * libdjvulibre21-3.5.27-150200.11.17.1 * djvulibre-debugsource-3.5.27-150200.11.17.1 * libdjvulibre-devel-3.5.27-150200.11.17.1 * libdjvulibre21-debuginfo-3.5.27-150200.11.17.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.17.1 * djvulibre-3.5.27-150200.11.17.1 * djvulibre-debugsource-3.5.27-150200.11.17.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.17.1 * djvulibre-3.5.27-150200.11.17.1 * djvulibre-debugsource-3.5.27-150200.11.17.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.17.1 * libdjvulibre21-3.5.27-150200.11.17.1 * djvulibre-debugsource-3.5.27-150200.11.17.1 * libdjvulibre-devel-3.5.27-150200.11.17.1 * djvulibre-3.5.27-150200.11.17.1 * libdjvulibre21-debuginfo-3.5.27-150200.11.17.1 * openSUSE Leap 15.6 (noarch) * djvulibre-doc-3.5.27-150200.11.17.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * djvulibre-debuginfo-3.5.27-150200.11.17.1 * libdjvulibre21-3.5.27-150200.11.17.1 * djvulibre-debugsource-3.5.27-150200.11.17.1 * libdjvulibre-devel-3.5.27-150200.11.17.1 * libdjvulibre21-debuginfo-3.5.27-150200.11.17.1 ## References: * https://www.suse.com/security/cve/CVE-2025-53367.html * https://bugzilla.suse.com/show_bug.cgi?id=1245773 . Routine security enhancement for djvulibre tackling CVE-2025-53368 impacting various SUSE offerings.. djvulibre update, SUSE Linux patch, CVE-2025-53367 fix. . LinuxSecurity.com Team

Calendar%202 Aug 05, 2025 SuSE
197

Debian 11: DjVuLibre Critical Buffer Overflow and Zero Division DLA-4247-1

Multiple vulnerabilities have been fixed in DjVuLibre, a library and tools to handle documents in the DjVu format. CVE-2021-46310 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4247-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk July 21, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : djvulibre Version : 3.5.28-2.2~deb11u1 CVE ID : CVE-2021-46310 CVE-2021-46312 CVE-2025-53367 Debian Bug : 1052668 1052669 1108729 Multiple vulnerabilities have been fixed in DjVuLibre, a library and tools to handle documents in the DjVu format. CVE-2021-46310 Divide by zero in IW44Image::Map::image() CVE-2021-46312 Divide by zero in IWBitmap::Encode::init() CVE-2025-53367 Buffer overflow in MMRDecoder For Debian 11 bullseye, these problems have been fixed in version 3.5.28-2.2~deb11u1. We recommend that you upgrade your djvulibre packages. For the detailed security status of djvulibre please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/djvulibre Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . DjVuLibre has been enhanced to address significant security vulnerabilities, resolving problems like division by zero errors and potential buffer overflow risks.. Debian, DjVuLibre, security update, vulnerabilities, buffer overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 21, 2025 Critical Debian LTS
203

Mageia 9: djvulibre Important Out-of-Bounds Code Execution MGASA-2025-0209

An out-of-bounds write in the MMRDecoder::scanruns method was fixed. The vulnerability could be exploited to gain code execution on a Linux Desktop system when the user tries to open a crafted document. References: . MGASA-2025-0209 - Updated djvulibre packages fix security vulnerability Publication date: 19 Jul 2025 URL: https://advisories.mageia.org/MGASA-2025-0209.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-53367 An out-of-bounds write in the MMRDecoder::scanruns method was fixed. The vulnerability could be exploited to gain code execution on a Linux Desktop system when the user tries to open a crafted document. References: - https://bugs.mageia.org/show_bug.cgi?id=34423 - https://www.openwall.com/lists/oss-security/2025/07/03/1 - https://ubuntu.com/security/notices/USN-7631-1 - https://www.cve.org/CVERecord?id=CVE-2025-53367 SRPMS: - 9/core/djvulibre-3.5.29-1.mga9 . Explore the essential djvulibre patch in Mageia, which mitigates potential code execution threats arising from specially designed documents.. Mageia, djvulibre, security, code execution, out-of-bounds. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 19, 2025 Important Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200