Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1255 http://linux.oracle.com/errata/ELSA-2025-1255.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: doxygen-1.8.5-4.0.1.el7.x86_64.rpm doxygen-doxywizard-1.8.5-4.0.1.el7.x86_64.rpm doxygen-latex-1.8.5-4.0.1.el7.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//doxygen-1.8.5-4.0.1.el7.src.rpm Related CVEs: CVE-2020-11023 Description of changes: [1:1.8.5-4.0.1] - Fix CVE-2020-11022 and CVE-2022-11023 in vendored jQuery [Orabug: 37577394] _______________________________________________ El-errata mailing list
Moderate: doxygen security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:1314", "synopsis": "Moderate: doxygen security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for doxygen.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Doxygen can generate an online class browser (in HTML) and/or a reference manual (in LaTeX) from a set of documented source files. The documentation is extracted directly from the sources. Doxygen can also be configured to extract the code structure from undocumented source files. \n\nSecurity Fix(es):\n\n* jquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods (CVE-2020-11023)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "1850004", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=1850004", "description": ""}], "cves": [{"name": "CVE-2020-11023", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2020-11023", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2025-02-13T20:34:40.392800Z", "rpms": {"Rocky Linux 8": {"nvras": ["doxygen-1:1.8.14-13.el8_10.x86_64.rpm", "doxygen-1:1.8.14-13.el8_10.src.rpm", "doxygen-1:1.8.14-13.el8_10.aarch64.rpm", "doxygen-debuginfo-1:1.8.14-13.el8_10.aarch64.rpm", "doxygen-debuginfo-1:1.8.14-13.el8_10.x86_64.rpm", "doxygen-debugsource-1:1.8.14-13.el8_10.aarch64.rpm", "doxygen-debugsource-1:1.8.14-13.el8_10.x86_64.rpm", "doxygen-doxywizard-1:1.8.14-13.el8_10.aarch64.rpm", "doxygen-doxywizard-1:1.8.14-13.el8_10.x86_64.rpm","doxygen-doxywizard-debuginfo-1:1.8.14-13.el8_10.aarch64.rpm", "doxygen-doxywizard-debuginfo-1:1.8.14-13.el8_10.x86_64.rpm", "doxygen-latex-1:1.8.14-13.el8_10.aarch64.rpm", "doxygen-latex-1:1.8.14-13.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux releases a medium-level security notice concerning doxygen. Discover the implications and the essential updates required to ensure safety.. doxygen update, Rocky Linux security, code execution, software update. . LinuxSecurity.com Team
doxygen: cross-site scripting in templates/html/search_opensearch.php SL7 x86_64 doxygen-1.8.5-4.el7.x86_64.rpm doxygen-debuginfo-1.8.5-4.el7.x86_64.rpm doxygen-doxywizard-1.8.5-4.el7.x86_64.rpm doxygen-latex-1.8.5-4.el7.x86_64.rpm - Scientific Linux Development Team. Synopsis: Low: doxygen security and bug fix update Advisory ID: SLSA-2020:1034-1 Issue Date: 2020-04-07 CVE Numbers: CVE-2016-10245 -- * doxygen: cross-site scripting in templates/html/search_opensearch.php -- SL7 x86_64 doxygen-1.8.5-4.el7.x86_64.rpm doxygen-debuginfo-1.8.5-4.el7.x86_64.rpm doxygen-doxywizard-1.8.5-4.el7.x86_64.rpm doxygen-latex-1.8.5-4.el7.x86_64.rpm - Scientific Linux Development Team . Doxygen security patch for SL7 tackling cross-origin scripting vulnerabilities. Advisory Reference: SLSA-2020-1034-1.. Doxygen Update, Cross-Site Scripting, SL7 Bug Fix. . Severity: Low. LinuxSecurity.com Team
An update for doxygen is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: doxygen security and bug fix update Advisory ID: RHSA-2020:1034-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:1034 Issue date: 2020-03-31 CVE Names: CVE-2016-10245 ==================================================================== 1. Summary: An update for doxygen is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: Doxygen can generate an online class browser (in HTML) and/or a reference manual (in LaTeX) from a set of documented source files. The documentation is extracted directly from the sources. Doxygen can also be configured to extract the code structure from undocumented source files. Security Fix(es): * doxygen: cross-site scripting in templates/html/search_opensearch.php (CVE-2016-10245) For more details about the security issue(s), including theimpact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1483569 - Incorrect processing of code blocks in doxygen 1714190 - CVE-2016-10245 doxygen: cross-site scripting in templates/html/search_opensearch.php 6. Package List: Red Hat Enterprise Linux Client Optional (v. 7): Source: doxygen-1.8.5-4.el7.src.rpm x86_64: doxygen-1.8.5-4.el7.x86_64.rpm doxygen-debuginfo-1.8.5-4.el7.x86_64.rpm doxygen-doxywizard-1.8.5-4.el7.x86_64.rpm doxygen-latex-1.8.5-4.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): Source: doxygen-1.8.5-4.el7.src.rpm x86_64: doxygen-1.8.5-4.el7.x86_64.rpm doxygen-debuginfo-1.8.5-4.el7.x86_64.rpm doxygen-doxywizard-1.8.5-4.el7.x86_64.rpm doxygen-latex-1.8.5-4.el7.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: doxygen-1.8.5-4.el7.src.rpm ppc64: doxygen-1.8.5-4.el7.ppc64.rpm doxygen-debuginfo-1.8.5-4.el7.ppc64.rpm ppc64le: doxygen-1.8.5-4.el7.ppc64le.rpm doxygen-debuginfo-1.8.5-4.el7.ppc64le.rpm s390x: doxygen-1.8.5-4.el7.s390x.rpm doxygen-debuginfo-1.8.5-4.el7.s390x.rpm x86_64: doxygen-1.8.5-4.el7.x86_64.rpm doxygen-debuginfo-1.8.5-4.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: doxygen-debuginfo-1.8.5-4.el7.ppc64.rpm doxygen-doxywizard-1.8.5-4.el7.ppc64.rpm doxygen-latex-1.8.5-4.el7.ppc64.rpm ppc64le: doxygen-debuginfo-1.8.5-4.el7.ppc64le.rpm doxygen-doxywizard-1.8.5-4.el7.ppc64le.rpm doxygen-latex-1.8.5-4.el7.ppc64le.rpm s390x: doxygen-debuginfo-1.8.5-4.el7.s390x.rpm doxygen-doxywizard-1.8.5-4.el7.s390x.rpm doxygen-latex-1.8.5-4.el7.s390x.rpm x86_64: doxygen-debuginfo-1.8.5-4.el7.x86_64.rpm doxygen-doxywizard-1.8.5-4.el7.x86_64.rpm doxygen-latex-1.8.5-4.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: doxygen-1.8.5-4.el7.src.rpm x86_64: doxygen-1.8.5-4.el7.x86_64.rpm doxygen-debuginfo-1.8.5-4.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: doxygen-debuginfo-1.8.5-4.el7.x86_64.rpm doxygen-doxywizard-1.8.5-4.el7.x86_64.rpm doxygen-latex-1.8.5-4.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2016-10245 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.8_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXoObhtzjgjWX9erEAQj2vg//a85uxdSTjY92R5p4Nhzz5tFoXLaDsEp8 ePvZUlQpvAtkGLZMAqo25+GF1Dv0YP5tJhWHSLD+otl66VDybv/RmXjsOmS3+9/p 9CADSyx1ntkwzMBOsF8TTZAT5XMS1WSm6HnSwkk1lhSMay9ZoW07ZsPBRCzPBH68 K4DfZEcA4TsD2EIIC+Pj5xNH/WMIx46paU1mbryQnOl6U7LPcOjRn4JigXDO5m5a cwSfYhIT50Ety1HLH9VG+3UflLvzfJNbvlr+rW9kazgxaLl7CxwsaGh6Xj7kB89B l+Xnnri965ejEG4cEhq8bhutIgUgK3vpGMXmKKFe+NL/h3G0jySOShPOCIOY3gFT VfJSD77dFDvbiT4yE87c2q+YMSqP03eNcTMi5vgYef+7TesU9ZN6d0briOuZ9I8u 6ptnh8A35zKwX+KA0wa/5e9GdlNuzTlxodogjZiPqaxiD9gj/JwP0YhY7vv2Cdtl WWFCJhB0INT/PjOXMqAJf7xa+AaATByvhzK4y3dOR35KY1BXVHwzGgH0FfNdS76a Mlqt4KjzIMxWxiV8oW5oMIn/+7/DcrjQf7mBlh7RzvyIksRjNHF/VBwClr4nBPDc kCPIMvHxdrDQs9FmzAxjRoAQiiDTSUybAjthwnfJYEITkTa66Q7VzRP4+WxFBpwE JOslzO4ehSs=AJVc -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for doxygen ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1570-1 Rating: moderate References: #1136364 Cross-References: CVE-2016-10245 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP4 SUSE Linux Enterprise Workstation Extension 12-SP3 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Desktop 12-SP4 SUSE Linux Enterprise Desktop 12-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for doxygen fixes the following issues: - CVE-2016-10245: XSS was possible via insufficient sanitization of the query parameter in templates/html/search_opensearch.php (bsc#1136364) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP4: zypper in -t patch SUSE-SLE-WE-12-SP4-2019-1570=1 - SUSE Linux Enterprise Workstation Extension 12-SP3: zypper in -t patch SUSE-SLE-WE-12-SP3-2019-1570=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-1570=1 - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2019-1570=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-1570=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2019-1570=1 Package List: - SUSELinux Enterprise Workstation Extension 12-SP4 (x86_64): doxygen-1.8.6-3.3.1 doxygen-debuginfo-1.8.6-3.3.1 doxygen-debugsource-1.8.6-3.3.1 - SUSE Linux Enterprise Workstation Extension 12-SP3 (x86_64): doxygen-1.8.6-3.3.1 doxygen-debuginfo-1.8.6-3.3.1 doxygen-debugsource-1.8.6-3.3.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): doxygen-1.8.6-3.3.1 doxygen-debuginfo-1.8.6-3.3.1 doxygen-debugsource-1.8.6-3.3.1 - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): doxygen-1.8.6-3.3.1 doxygen-debuginfo-1.8.6-3.3.1 doxygen-debugsource-1.8.6-3.3.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): doxygen-1.8.6-3.3.1 doxygen-debuginfo-1.8.6-3.3.1 doxygen-debugsource-1.8.6-3.3.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): doxygen-1.8.6-3.3.1 doxygen-debuginfo-1.8.6-3.3.1 doxygen-debugsource-1.8.6-3.3.1 References: https://www.suse.com/security/cve/CVE-2016-10245.html https://bugzilla.suse.com/1136364 _______________________________________________ sle-security-updates mailing list
Doxygen could be made to run scripts as your login if it received a specially crafted query.. =========================================================================Ubuntu Security Notice USN-4002-1 June 03, 2019 doxygen vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Doxygen could be made to run scripts as your login if it received a specially crafted query. Software Description: - doxygen: Documentation system for C, C++, Java, Python and other languages Details: It was discovered that Doxygen incorrectly handled certain queries. An attacker could possibly use this issue to execute arbitrary code and compromise sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: doxygen 1.8.11-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4002-1 CVE-2016-10245 Package Information: https://launchpad.net/ubuntu/+source/doxygen/1.8.11-1ubuntu0.1 . Security flaw in Ubuntu allows execution of scripts via carefully crafted requests in Doxygen.. Doxygen vulnerability, Ubuntu advisory, arbitrary code execution. . Severity: Medium. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for doxygen ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1486-1 Rating: moderate References: #1136364 Cross-References: CVE-2016-10245 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for doxygen fixes the following issues: - CVE-2016-10245: Fixed XSS via insufficient sanitization of the query parameter in templates/html/search_opensearch.php [boo#1136364] Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2019-1486=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): doxygen-1.8.11-4.3.1 doxygen-debuginfo-1.8.11-4.3.1 doxygen-debugsource-1.8.11-4.3.1 doxygen-doc-1.8.11-4.3.1 doxywizard-1.8.11-4.3.1 doxywizard-debuginfo-1.8.11-4.3.1 doxywizard-debugsource-1.8.11-4.3.1 References: https://www.suse.com/security/cve/CVE-2016-10245.html https://bugzilla.suse.com/1136364 -- . A recent enhancement for openSUSE addresses a critical XSS vulnerability in doxygen. Comprehensive information and guidance for applying the patch are provided.. openSUSE, doxygen, security patch. . LinuxSecurity.com Team
Insufficient sanitization of the query parameter in search_opensearch.php could lead to reflected cross-site scripting or iframe injection. . Package : doxygen Version : 1.8.8-5+deb8u1 CVE ID : CVE-2016-10245 Insufficient sanitization of the query parameter in search_opensearch.php could lead to reflected cross-site scripting or iframe injection. For Debian 8 "Jessie", this problem has been fixed in version 1.8.8-5+deb8u1. We recommend that you upgrade your doxygen packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail:
Get the latest Linux and open source security news straight to your inbox.