An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for perl-Data-Entropy ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0123-1 Rating: moderate References: #1240395 Cross-References: CVE-2025-1860 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for perl-Data-Entropy fixes the following issues: Updated to 0.8.0 (0.008): see /usr/share/doc/packages/perl-Data-Entropy/Changes Version 0.008; 2025-03-27: * Use Crypt::URandom to seed the default algorithm with cryptographically secure random bytes instead of the builtin rand() function (boo#1240395, CVE-2025-1860). * This module has been marked as deprecated. * A security policy was added. * Remove use of Module::Build. * Updated maintainer information. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-123=1 Package List: - openSUSE Backports SLE-15-SP6 (noarch): perl-Data-Entropy-0.8.0-bp156.4.3.1 References: https://www.suse.com/security/cve/CVE-2025-1860.html https://bugzilla.suse.com/show_bug.cgi?id=1240395 . Security update released for perl-Data-Entropy on openSUSE to resolve a moderate vulnerability. Follow the provided patch instructions for remediation.. openSUSE Security Update, perl-Data-Entropy, security fix. . LinuxSecurity.com Team
tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the sequence of challenges is always identical. (CVE-2024-45751) References: . MGASA-2024-0304 - Updated tgt packages fix security vulnerability Publication date: 16 Sep 2024 URL: https://advisories.mageia.org/MGASA-2024-0304.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-45751 tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the sequence of challenges is always identical. (CVE-2024-45751) References: - https://bugs.mageia.org/show_bug.cgi?id=33545 - https://www.openwall.com/lists/oss-security/2024/09/07/2 - https://www.cve.org/CVERecord?id=CVE-2024-45751 SRPMS: - 9/core/tgt-1.0.85-1.1.mga9 . Revised tgt packages resolve a vulnerability in Mageia, safeguarding effective entropy handling.. Mageia Security Advisory,tgt Framework Vulnerability,Entropy Management. . Severity: Important. LinuxSecurity.com Team
It has been found, that libice, an X11 Inter-Client Exchange library, uses weak entropy to generate keys. . Package : libice Version : 2:1.0.9-1+deb8u1 CVE ID : CVE-2017-2626 It has been found, that libice, an X11 Inter-Client Exchange library, uses weak entropy to generate keys. Using arc4random_buf() from libbsd should avoid this flaw. For Debian 8 "Jessie", this problem has been fixed in version 2:1.0.9-1+deb8u1. We recommend that you upgrade your libice packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Important notification concerning libice on Debian regarding insufficient entropy for secure key generation. Essential patch ready for implementation immediately.. libice, security update, Debian LTS, entropy flaw. . Severity: Critical. LinuxSecurity.com Team
An integer overflow flaw leading to a heap-based buffer overflow was found in libXpm. An attacker could use this flaw to crash an application using libXpm via a specially crafted XPM file. (CVE-2016-10164) * It was discovered that libXdmcp used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the proce [More...]. Synopsis: Moderate: X.org X11 libraries security, bug fix and Advisory ID: SLSA-2017:1865-1 Issue Date: 2017-08-01 CVE Numbers: CVE-2016-10164 CVE-2017-2625 CVE-2017-2626 -- The following packages have been upgraded to a later upstream version: libX11 (1.6.5), libXaw (1.0.13), libXdmcp (1.1.2), libXfixes (5.0.3), libXfont (1.5.2), libXi (1.7.9), libXpm (3.5.12), libXrandr (1.5.1), libXrender (0.9.10), libXt (1.1.5), libXtst (1.2.3), libXv (1.0.11), libXvMC (1.0.10), libXxf86vm (1.1.4), libdrm (2.4.74), libepoxy (1.3.1), libevdev (1.5.6), libfontenc (1.1.3), libvdpau (1.1.1), libwacom (0.24), libxcb (1.12), libxkbfile (1.0.9), mesa (17.0.1), mesa-private-llvm (3.9.1), xcb-proto (1.12), xkeyboard-config (2.20), xorg-x11-proto-devel (7.7). Security Fix(es): * An integer overflow flaw leading to a heap-based buffer overflow was found in libXpm. An attacker could use this flaw to crash an application using libXpm via a specially crafted XPM file. (CVE-2016-10164) * It was discovered that libXdmcp used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions. (CVE-2017-2625) * It was discovered that libICE used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list. (CVE-2017-2626) -- SL7 x86_64 libICE-1.0.9-9.el7.i686.rpm libICE-1.0.9-9.el7.x86_64.rpm libICE-debuginfo-1.0.9-9.el7.i686.rpm libICE-debuginfo-1.0.9-9.el7.x86_64.rpm libX11-1.6.5-1.el7.i686.rpm libX11-1.6.5-1.el7.x86_64.rpm libX11-debuginfo-1.6.5-1.el7.i686.rpm libX11-debuginfo-1.6.5-1.el7.x86_64.rpm libXaw-1.0.13-4.el7.i686.rpm libXaw-1.0.13-4.el7.x86_64.rpm libXaw-debuginfo-1.0.13-4.el7.i686.rpm libXaw-debuginfo-1.0.13-4.el7.x86_64.rpm libXcursor-1.1.14-8.el7.i686.rpm libXcursor-1.1.14-8.el7.x86_64.rpm libXcursor-debuginfo-1.1.14-8.el7.i686.rpm libXcursor-debuginfo-1.1.14-8.el7.x86_64.rpm libXdmcp-1.1.2-6.el7.i686.rpm libXdmcp-1.1.2-6.el7.x86_64.rpm libXdmcp-debuginfo-1.1.2-6.el7.i686.rpm libXdmcp-debuginfo-1.1.2-6.el7.x86_64.rpm libXfixes-5.0.3-1.el7.i686.rpm libXfixes-5.0.3-1.el7.x86_64.rpm libXfixes-debuginfo-5.0.3-1.el7.i686.rpm libXfixes-debuginfo-5.0.3-1.el7.x86_64.rpm libXfont-1.5.2-1.el7.i686.rpm libXfont-1.5.2-1.el7.x86_64.rpm libXfont-debuginfo-1.5.2-1.el7.i686.rpm libXfont-debuginfo-1.5.2-1.el7.x86_64.rpm libXfont2-2.0.1-2.el7.i686.rpm libXfont2-2.0.1-2.el7.x86_64.rpm libXfont2-debuginfo-2.0.1-2.el7.i686.rpm libXfont2-debuginfo-2.0.1-2.el7.x86_64.rpm libXi-1.7.9-1.el7.i686.rpm libXi-1.7.9-1.el7.x86_64.rpm libXi-debuginfo-1.7.9-1.el7.i686.rpm libXi-debuginfo-1.7.9-1.el7.x86_64.rpm libXpm-3.5.12-1.el7.i686.rpm libXpm-3.5.12-1.el7.x86_64.rpm libXpm-debuginfo-3.5.12-1.el7.i686.rpm libXpm-debuginfo-3.5.12-1.el7.x86_64.rpm libXrandr-1.5.1-2.el7.i686.rpm libXrandr-1.5.1-2.el7.x86_64.rpm libXrandr-debuginfo-1.5.1-2.el7.i686.rpm libXrandr-debuginfo-1.5.1-2.el7.x86_64.rpm libXrender-0.9.10-1.el7.i686.rpm libXrender-0.9.10-1.el7.x86_64.rpm libXrender-debuginfo-0.9.10-1.el7.i686.rpm libXrender-debuginfo-0.9.10-1.el7.x86_64.rpm libXt-1.1.5-3.el7.i686.rpm libXt-1.1.5-3.el7.x86_64.rpm libXt-debuginfo-1.1.5-3.el7.i686.rpm libXt-debuginfo-1.1.5-3.el7.x86_64.rpm libXtst-1.2.3-1.el7.i686.rpm libXtst-1.2.3-1.el7.x86_64.rpm libXtst-debuginfo-1.2.3-1.el7.i686.rpm libXtst-debuginfo-1.2.3-1.el7.x86_64.rpm libXv-1.0.11-1.el7.i686.rpm libXv-1.0.11-1.el7.x86_64.rpm libXv-debuginfo-1.0.11-1.el7.i686.rpm libXv-debuginfo-1.0.11-1.el7.x86_64.rpm libXvMC-1.0.10-1.el7.i686.rpm libXvMC-1.0.10-1.el7.x86_64.rpm libXvMC-debuginfo-1.0.10-1.el7.i686.rpm libXvMC-debuginfo-1.0.10-1.el7.x86_64.rpm libXxf86vm-1.1.4-1.el7.i686.rpm libXxf86vm-1.1.4-1.el7.x86_64.rpm libXxf86vm-debuginfo-1.1.4-1.el7.i686.rpm libXxf86vm-debuginfo-1.1.4-1.el7.x86_64.rpm libdrm-2.4.74-1.el7.i686.rpm libdrm-2.4.74-1.el7.x86_64.rpm libdrm-debuginfo-2.4.74-1.el7.i686.rpm libdrm-debuginfo-2.4.74-1.el7.x86_64.rpm libepoxy-1.3.1-1.el7.i686.rpm libepoxy-1.3.1-1.el7.x86_64.rpm libepoxy-debuginfo-1.3.1-1.el7.i686.rpm libepoxy-debuginfo-1.3.1-1.el7.x86_64.rpm libevdev-1.5.6-1.el7.i686.rpm libevdev-1.5.6-1.el7.x86_64.rpm libevdev-debuginfo-1.5.6-1.el7.i686.rpm libevdev-debuginfo-1.5.6-1.el7.x86_64.rpm libfontenc-1.1.3-3.el7.i686.rpm libfontenc-1.1.3-3.el7.x86_64.rpm libfontenc-debuginfo-1.1.3-3.el7.i686.rpm libfontenc-debuginfo-1.1.3-3.el7.x86_64.rpm libinput-1.6.3-2.el7.i686.rpm libinput-1.6.3-2.el7.x86_64.rpm libinput-debuginfo-1.6.3-2.el7.i686.rpm libinput-debuginfo-1.6.3-2.el7.x86_64.rpm libvdpau-1.1.1-3.el7.i686.rpm libvdpau-1.1.1-3.el7.x86_64.rpm libvdpau-debuginfo-1.1.1-3.el7.i686.rpm libvdpau-debuginfo-1.1.1-3.el7.x86_64.rpm libwacom-0.24-1.el7.i686.rpm libwacom-0.24-1.el7.x86_64.rpm libwacom-debuginfo-0.24-1.el7.i686.rpm libwacom-debuginfo-0.24-1.el7.x86_64.rpm libxcb-1.12-1.el7.i686.rpm libxcb-1.12-1.el7.x86_64.rpm libxcb-debuginfo-1.12-1.el7.i686.rpm libxcb-debuginfo-1.12-1.el7.x86_64.rpm libxkbcommon-0.7.1-1.el7.i686.rpm libxkbcommon-0.7.1-1.el7.x86_64.rpm libxkbcommon-debuginfo-0.7.1-1.el7.i686.rpm libxkbcommon-debuginfo-0.7.1-1.el7.x86_64.rpm libxkbcommon-x11-0.7.1-1.el7.i686.rpm libxkbcommon-x11-0.7.1-1.el7.x86_64.rpm libxkbfile-1.0.9-3.el7.i686.rpm libxkbfile-1.0.9-3.el7.x86_64.rpm libxkbfile-debuginfo-1.0.9-3.el7.i686.rpm libxkbfile-debuginfo-1.0.9-3.el7.x86_64.rpm mesa-debuginfo-17.0.1-6.20170307.el7.i686.rpm mesa-debuginfo-17.0.1-6.20170307.el7.x86_64.rpm mesa-dri-drivers-17.0.1-6.20170307.el7.i686.rpm mesa-dri-drivers-17.0.1-6.20170307.el7.x86_64.rpm mesa-filesystem-17.0.1-6.20170307.el7.i686.rpm mesa-filesystem-17.0.1-6.20170307.el7.x86_64.rpm mesa-libEGL-17.0.1-6.20170307.el7.i686.rpm mesa-libEGL-17.0.1-6.20170307.el7.x86_64.rpm mesa-libGL-17.0.1-6.20170307.el7.i686.rpm mesa-libGL-17.0.1-6.20170307.el7.x86_64.rpm mesa-libGLES-17.0.1-6.20170307.el7.i686.rpm mesa-libGLES-17.0.1-6.20170307.el7.x86_64.rpm mesa-libgbm-17.0.1-6.20170307.el7.i686.rpm mesa-libgbm-17.0.1-6.20170307.el7.x86_64.rpm mesa-libglapi-17.0.1-6.20170307.el7.i686.rpm mesa-libglapi-17.0.1-6.20170307.el7.x86_64.rpm mesa-libxatracker-17.0.1-6.20170307.el7.i686.rpm mesa-libxatracker-17.0.1-6.20170307.el7.x86_64.rpm mesa-private-llvm-3.9.1-3.el7.i686.rpm mesa-private-llvm-3.9.1-3.el7.x86_64.rpm mesa-private-llvm-debuginfo-3.9.1-3.el7.i686.rpm mesa-private-llvm-debuginfo-3.9.1-3.el7.x86_64.rpm drm-utils-2.4.74-1.el7.x86_64.rpm libICE-devel-1.0.9-9.el7.i686.rpm libICE-devel-1.0.9-9.el7.x86_64.rpm libX11-devel-1.6.5-1.el7.i686.rpm libX11-devel-1.6.5-1.el7.x86_64.rpm libXaw-devel-1.0.13-4.el7.i686.rpm libXaw-devel-1.0.13-4.el7.x86_64.rpm libXcursor-devel-1.1.14-8.el7.i686.rpm libXcursor-devel-1.1.14-8.el7.x86_64.rpm libXdmcp-devel-1.1.2-6.el7.i686.rpm libXdmcp-devel-1.1.2-6.el7.x86_64.rpm libXfixes-devel-5.0.3-1.el7.i686.rpm libXfixes-devel-5.0.3-1.el7.x86_64.rpm libXfont-devel-1.5.2-1.el7.i686.rpm libXfont-devel-1.5.2-1.el7.x86_64.rpm libXfont2-devel-2.0.1-2.el7.i686.rpm libXfont2-devel-2.0.1-2.el7.x86_64.rpm libXi-devel-1.7.9-1.el7.i686.rpm libXi-devel-1.7.9-1.el7.x86_64.rpm libXpm-devel-3.5.12-1.el7.i686.rpm libXpm-devel-3.5.12-1.el7.x86_64.rpm libXrandr-devel-1.5.1-2.el7.i686.rpm libXrandr-devel-1.5.1-2.el7.x86_64.rpm libXrender-devel-0.9.10-1.el7.i686.rpm libXrender-devel-0.9.10-1.el7.x86_64.rpm libXt-devel-1.1.5-3.el7.i686.rpm libXt-devel-1.1.5-3.el7.x86_64.rpm libXtst-devel-1.2.3-1.el7.i686.rpm libXtst-devel-1.2.3-1.el7.x86_64.rpm libXv-devel-1.0.11-1.el7.i686.rpm libXv-devel-1.0.11-1.el7.x86_64.rpm libXvMC-devel-1.0.10-1.el7.i686.rpm libXvMC-devel-1.0.10-1.el7.x86_64.rpm libXxf86vm-devel-1.1.4-1.el7.i686.rpm libXxf86vm-devel-1.1.4-1.el7.x86_64.rpm libdrm-devel-2.4.74-1.el7.i686.rpm libdrm-devel-2.4.74-1.el7.x86_64.rpm libepoxy-devel-1.3.1-1.el7.i686.rpm libepoxy-devel-1.3.1-1.el7.x86_64.rpm libevdev-devel-1.5.6-1.el7.i686.rpm libevdev-devel-1.5.6-1.el7.x86_64.rpm libevdev-utils-1.5.6-1.el7.x86_64.rpm libfontenc-devel-1.1.3-3.el7.i686.rpm libfontenc-devel-1.1.3-3.el7.x86_64.rpm libinput-devel-1.6.3-2.el7.i686.rpm libinput-devel-1.6.3-2.el7.x86_64.rpm libvdpau-devel-1.1.1-3.el7.i686.rpm libvdpau-devel-1.1.1-3.el7.x86_64.rpm libwacom-devel-0.24-1.el7.i686.rpm libwacom-devel-0.24-1.el7.x86_64.rpm libxcb-devel-1.12-1.el7.i686.rpm libxcb-devel-1.12-1.el7.x86_64.rpm libxkbcommon-devel-0.7.1-1.el7.i686.rpm libxkbcommon-devel-0.7.1-1.el7.x86_64.rpm libxkbcommon-x11-devel-0.7.1-1.el7.i686.rpm libxkbcommon-x11-devel-0.7.1-1.el7.x86_64.rpm libxkbfile-devel-1.0.9-3.el7.i686.rpm libxkbfile-devel-1.0.9-3.el7.x86_64.rpm mesa-libEGL-devel-17.0.1-6.20170307.el7.i686.rpm mesa-libEGL-devel-17.0.1-6.20170307.el7.x86_64.rpm mesa-libGL-devel-17.0.1-6.20170307.el7.i686.rpm mesa-libGL-devel-17.0.1-6.20170307.el7.x86_64.rpm mesa-libGLES-devel-17.0.1-6.20170307.el7.i686.rpm mesa-libGLES-devel-17.0.1-6.20170307.el7.x86_64.rpm mesa-libOSMesa-17.0.1-6.20170307.el7.i686.rpm mesa-libOSMesa-17.0.1-6.20170307.el7.x86_64.rpm mesa-libOSMesa-devel-17.0.1-6.20170307.el7.i686.rpm mesa-libOSMesa-devel-17.0.1-6.20170307.el7.x86_64.rpm mesa-libgbm-devel-17.0.1-6.20170307.el7.i686.rpm mesa-libgbm-devel-17.0.1-6.20170307.el7.x86_64.rpm mesa-libxatracker-devel-17.0.1-6.20170307.el7.i686.rpm mesa-libxatracker-devel-17.0.1-6.20170307.el7.x86_64.rpm mesa-private-llvm-devel-3.9.1-3.el7.i686.rpm mesa-private-llvm-devel-3.9.1-3.el7.x86_64.rpm mesa-vulkan-drivers-17.0.1-6.20170307.el7.x86_64.rpm vulkan-1.0.39.1-2.el7.i686.rpm vulkan-1.0.39.1-2.el7.x86_64.rpm vulkan-debuginfo-1.0.39.1-2.el7.i686.rpm vulkan-debuginfo-1.0.39.1-2.el7.x86_64.rpm vulkan-devel-1.0.39.1-2.el7.i686.rpm vulkan-devel-1.0.39.1-2.el7.x86_64.rpm noarch libX11-common-1.6.5-1.el7.noarch.rpm libwacom-data-0.24-1.el7.noarch.rpm xkeyboard-config-2.20-1.el7.noarch.rpm libvdpau-docs-1.1.1-3.el7.noarch.rpm libxcb-doc-1.12-1.el7.noarch.rpm vulkan-filesystem-1.0.39.1-2.el7.noarch.rpm xcb-proto-1.12-2.el7.noarch.rpm xkeyboard-config-devel-2.20-1.el7.noarch.rpm xorg-x11-proto-devel-7.7-20.el7.noarch.rpm - Scientific Linux Development Team . Several moderate vulnerabilities have been identified in the X.org X11 libraries, particularly concerning session fixation and buffer overflow weaknesses.. buffer Overflow, session Hijacking, Xorg Libraries, libXpm Fixes. . LinuxSecurity.com Team
Security fix for CVE-2017-2625. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-9a9328c159 2017-03-02 22:38:19.065555 -------------------------------------------------------------------------------- Name : libXdmcp Product : Fedora 25 Version : 1.1.2 Release : 5.fc25 URL : https://www.x.org/wiki/ Summary : X Display Manager Control Protocol library Description : X Display Manager Control Protocol library. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2017-2625 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1427716 - CVE-2017-2625 libXdmcp: weak entropy usage for session keys [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1427716 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libXdmcp' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.