An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for duc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0496-1 Rating: moderate References: #1254566 Cross-References: CVE-2025-13654 CVSS scores: CVE-2025-13654 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for duc fixes the following issues: Update to 1.4.6: * new: added LICENCE to 'make release' target * fix: fixed logic error in buffer_get() (boo#1254566, CVE-2025-13654) * cha: updated tests Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-496=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): duc-1.4.6-bp156.3.3.1 References: https://www.suse.com/security/cve/CVE-2025-13654.html https://bugzilla.suse.com/1254566 . Moderate security advisory for openSUSE fixing buffer error in duc. Install patch promptly to mitigate risks.. openSUSE Security Update, duc application, buffer overflow fix. . LinuxSecurity.com Team
Update to 1.4.6: fixes CVE-2025-13654. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d73e0a567d 2025-12-31 01:09:31.157697+00:00 -------------------------------------------------------------------------------- Name : duc Product : Fedora 42 Version : 1.4.6 Release : 1.fc42 URL : https://duc.zevv.nl/ Summary : Disk usage tools Description : Duc is a collection of tools for indexing, inspecting and visualizing disk usage. Duc maintains a database of accumulated sizes of directories of the file system, and allows you to query this database with some tools, or create fancy graphs showing you where your bytes are. -------------------------------------------------------------------------------- Update Information: Update to 1.4.6: fixes CVE-2025-13654 -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 17 2025 Jens Petersen - 1.4.6-1 - Update to 1.4.6: fixes CVE-2025-13654 * Wed Jul 23 2025 Fedora Release Engineering - 1.4.5-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2423079 - CVE-2025-13654 duc: duc: Stack Buffer Overflow in buffer_get function [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2423079 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d73e0a567d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 1.4.6: fixes CVE-2025-13654. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4d1c51d90a 2025-12-28 01:06:50.261957+00:00 -------------------------------------------------------------------------------- Name : duc Product : Fedora 43 Version : 1.4.6 Release : 1.fc43 URL : https://duc.zevv.nl/ Summary : Disk usage tools Description : Duc is a collection of tools for indexing, inspecting and visualizing disk usage. Duc maintains a database of accumulated sizes of directories of the file system, and allows you to query this database with some tools, or create fancy graphs showing you where your bytes are. -------------------------------------------------------------------------------- Update Information: Update to 1.4.6: fixes CVE-2025-13654 -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 17 2025 Jens Petersen - 1.4.6-1 - Update to 1.4.6: fixes CVE-2025-13654 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2423080 - CVE-2025-13654 duc: duc: Stack Buffer Overflow in buffer_get function [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2423080 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4d1c51d90a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for duc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0487-1 Rating: moderate References: #1254566 Cross-References: CVE-2025-13654 CVSS scores: CVE-2025-13654 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for duc fixes the following issues: Update to 1.4.6: * new: added LICENCE to 'make release' target * fix: fixed logic error in buffer_get() (boo#1254566, CVE-2025-13654) * cha: updated tests Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2025-487=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): duc-1.4.6-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2025-13654.html https://bugzilla.suse.com/1254566 . Update available for duc with moderate severity fixing a buffer logic error in openSUSE Backports SLE-15-SP7.. duc security update, openSUSE moderate patch, buffer logic error, openSUSE Backports, software update. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # duc-1.4.6-1.1 on GA media Announcement ID: openSUSE-SU-2025:15835-1 Rating: moderate Cross-References: * CVE-2025-13654 CVSS scores: * CVE-2025-13654 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the duc-1.4.6-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * duc 1.4.6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-13654.html . This update for openSUSE addresses a moderate security issue in the duc application, improving system security.. openSUSE duc update security patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.