Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
172

Ubuntu 24.10: USN-7587-1 critical: fig2dev denial of service

Several security issues were fixed in Fig2dev.. ========================================================================== Ubuntu Security Notice USN-7587-1 June 23, 2025 fig2dev vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Fig2dev. Software Description: - fig2dev: Tools for creating TeX documents with portable graphics Details: Suhwan Song discovered that Fig2dev did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-21680, CVE-2020-21682, CVE-2020-21683) It was discovered that Fig2dev did not limit the size of certain inputs. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. (CVE-2025-31162, CVE-2025-31163) It was discovered that Fig2dev did not correctly handle certain inputs. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2025-31164) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 fig2dev 1:3.2.9-4ubuntu0.1 Ubuntu 24.04 LTS fig2dev 1:3.2.9-3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS fig2dev 1:3.2.8b-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS fig2dev 1:3.2.7a-7ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS fig2dev 1:3.2.6a-6ubuntu1.1+esm1 Available with Ubuntu Pro transfig 1:3.2.6a-6ubuntu1.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7587-1 CVE-2020-21680, CVE-2020-21682, CVE-2020-21683, CVE-2025-31162, CVE-2025-31163, CVE-2025-31164 Package Information: https://launchpad.net/ubuntu/+source/fig2dev/1:3.2.9-4ubuntu0.1 . Multiple vulnerabilities addressed in Fig2dev for Ubuntu 24.10 and older releases. Urgent patches are necessary.. Ubuntu security, fig2dev updates, denial of service fix, Ubuntu advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 23, 2025 Critical Ubuntu
197

Debian 11 bullseye DLA-4147-1 moderate: fig2dev code execution and DoS

Multiple vulnerabilities were found in fig2dev, a utility for converting XFig figure files, which could lead to code execution or denial of service upon specially crafted input files. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4147-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin April 30, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : fig2dev Version : 1:3.2.8-3+deb11u3 CVE ID : CVE-2025-46397 CVE-2025-46398 CVE-2025-46399 CVE-2025-46400 Multiple vulnerabilities were found in fig2dev, a utility for converting XFig figure files, which could lead to code execution or denial of service upon specially crafted input files. CVE-2025-46397 A stack overflow vulnerability could allow code execution via local input manipulation via bezier_spline() function. CVE-2025-46398 A stack overflow vulnerability could allow code execution via local input manipulation via read_objects() function. CVE-2025-46399 A segmentation fault issue could lead to denial of service via local input manipulation via genge_itp_spline() function. CVE-2025-46400 A segmentation fault issue could lead to denial of service via local input manipulation via read_arcobject() function. For Debian 11 bullseye, these problems have been fixed in version 1:3.2.8-3+deb11u3. We recommend that you upgrade your fig2dev packages. For the detailed security status of fig2dev please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/fig2dev Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS advisory DLA-4147-1 highlights critical vulnerabilities in fig2dev, allowing unauthorized codeexecution and potential service disruptions, jeopardizing system integrity. Debian LTS, fig2dev update, security threats, code execution, denial of service. . LinuxSecurity.com Team

Calendar 2 Apr 30, 2025 Debian LTS
197

Debian LTS: DLA-4134-1 critical: fig2dev heap overflow issues

Multiple vulnerabilities have been fixed in the fig2dev utilities for converting XFig figure files. CVE-2025-31162 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4134-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk April 21, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : fig2dev Version : 1:3.2.8-3+deb11u2 CVE ID : CVE-2025-31162 CVE-2025-31163 CVE-2025-31164 Multiple vulnerabilities have been fixed in the fig2dev utilities for converting XFig figure files. CVE-2025-31162 floating point exception with huge pattern lengths CVE-2025-31163 non-rejection of arcs with co-incident points CVE-2025-31164 heap buffer overflow on arc-box with zero radius For Debian 11 bullseye, these problems have been fixed in version 1:3.2.8-3+deb11u2. We recommend that you upgrade your fig2dev packages. For the detailed security status of fig2dev please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/fig2dev Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu LTS patches rectify several vulnerabilities within the fig2dev tools. Update for enhanced reliability in your operating environment.. Debian Security, fig2dev Update, Bug Fixes, Open Source Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 21, 2025 Critical Debian LTS
172

Ubuntu 20.04 LTS: USN-5864-1 Critical Fig2dev Denial Of Service

Several security issues were fixed in Fig2dev.. =========================================================================Ubuntu Security Notice USN-5864-1 February 13, 2023 fig2dev vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Fig2dev. Software Description: - fig2dev: Utilities for converting XFig figure files Details: Frederic Cambus discovered that Fig2dev incorrectly handled certain image files. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-14275) It was discovered that Fig2dev incorrectly handled certain image files. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2019-19555, CVE-2019-19797, CVE-2020-21529, CVE-2020-21530, CVE-2020-21531, CVE-2020-21532, CVE-2020-21533, CVE-2020-21534, CVE-2020-21535, CVE-2020-21675, CVE-2020-21676, CVE-2021-3561) It was discovered that Fig2dev incorrectly handled certain image files. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2021-32280) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: fig2dev 1:3.2.7a-7ubuntu0.1 Ubuntu 18.04 LTS: fig2dev 1:3.2.6a-6ubuntu1.1 transfig 1:3.2.6a-6ubuntu1.1 In general, a standard system update will makeall the necessary changes. References: https://ubuntu.com/security/notices/USN-5864-1 CVE-2019-14275, CVE-2019-19555, CVE-2019-19797, CVE-2020-21529, CVE-2020-21530, CVE-2020-21531, CVE-2020-21532, CVE-2020-21533, CVE-2020-21534, CVE-2020-21535, CVE-2020-21675, CVE-2020-21676, CVE-2021-32280, CVE-2021-3561 Package Information: https://launchpad.net/ubuntu/+source/fig2dev/1:3.2.7a-7ubuntu0.1 https://launchpad.net/ubuntu/+source/fig2dev/1:3.2.6a-6ubuntu1.1 . A range of security flaws has been addressed in Libjpeg-turbo impacting various Debian versions, enhancing overall system protection.. Fig2dev Issues, Ubuntu Advisory, Software Vulnerability Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 13, 2023 Critical Ubuntu
197

Debian 10 Buster DLA-3305-1 Moderate: Libxml2 Buffer Overflows

Brief introduction CVE-2020-21529 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3304-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk January 31, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : fig2dev Version : 1:3.2.7a-5+deb10u5 CVE ID : CVE-2020-21529 CVE-2020-21531 CVE-2020-21532 CVE-2020-21676 CVE-2021-32280 Debian Bug : 960736 Brief introduction CVE-2020-21529 Stack buffer overflow in bezier_spline(). CVE-2020-21531 Global buffer overflow in conv_pattern_index(). CVE-2020-21532 Global buffer overflow in setfigfont(). CVE-2020-21676 Stack-based buffer overflow in genpstrx_text(). CVE-2021-32280 NULL pointer dereference in compute_closed_spline(). For Debian 10 buster, these problems have been fixed in version 1:3.2.7a-5+deb10u5. We recommend that you upgrade your fig2dev packages. For the detailed security status of fig2dev please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/fig2dev Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3304-2 resolves multiple vulnerabilities in fig2dev. Prompt update is advised for enhanced security.. Debian LTS, fig2dev security, buffer overflow fix, DLA-3304-1. . LinuxSecurity.com Team

Calendar 2 Jan 31, 2023 Debian LTS
197

Debian 9 Stretch: DLA-2778-1 Critical: fig2dev Denial Of Service Risks

Multiple security vulnerabilities have been discovered in fig2dev, utilities for converting XFig figure files. Buffer overflows, out-of-bounds reads and NULL pointer dereferences could lead to a denial-of-service or other unspecified impact. . -------------------------------------------------------------------------Debian LTS Advisory DLA-2778-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany October 04, 2021 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : fig2dev Version : 1:3.2.6a-2+deb9u4 CVE ID : CVE-2019-19797 CVE-2020-21529 CVE-2020-21530 CVE-2020-21531 CVE-2020-21532 CVE-2020-21533 CVE-2020-21534 CVE-2020-21535 CVE-2020-21675 CVE-2020-21676 CVE-2021-3561 CVE-2021-32280 Multiple security vulnerabilities have been discovered in fig2dev, utilities for converting XFig figure files. Buffer overflows, out-of-bounds reads and NULL pointer dereferences could lead to a denial-of-service or other unspecified impact. For Debian 9 stretch, these problems have been fixed in version 1:3.2.6a-2+deb9u4. We recommend that you upgrade your fig2dev packages. For the detailed security status of fig2dev please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/fig2dev Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian Long-Term Support Notice for fig2dev highlights severe security vulnerabilities and suggests immediate patch installations to mitigate possible attacks.. Debian LTS, Fig2dev Security, Denial Of Service, Buffer Overflow, Out Of Bounds. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 04, 2021 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here