Ghostscript could be made to crash, run programs, or read files if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7473-1 May 01, 2025 ghostscript vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS Summary: Ghostscript could be made to crash, run programs, or read files if it opened a specially crafted file. Software Description: - ghostscript: PostScript and PDF interpreter Details: It was discovered that Ghostscript incorrectly handled parsing certain PS files. An attacker could use this issue to cause Ghostscript to crash, resulting in a denial of service, or possibly bypass file path validation. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 ghostscript 10.03.1~dfsg1-0ubuntu2.3 libgs10 10.03.1~dfsg1-0ubuntu2.3 Ubuntu 24.04 LTS ghostscript 10.02.1~dfsg1-0ubuntu7.6 libgs10 10.02.1~dfsg1-0ubuntu7.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7473-1 CVE-2025-46646 Package Information: https://launchpad.net/ubuntu/+source/ghostscript/10.03.1~dfsg1-0ubuntu2.3 https://launchpad.net/ubuntu/+source/ghostscript/10.02.1~dfsg1-0ubuntu7.6 . Security vulnerability in Ghostscript on Ubuntu could result in system instability or unauthorized file access from maliciously designed files. Update advised.. Ghostscript vulnerability, Ubuntu 24.10, Ubuntu 24.04 LTS, security notice, software updates. . LinuxSecurity.com Team
Multiple file parsing vulnerabilities have been fixed in libraw. They are concerned with the dng and x3f formats. CVE-2020-35530 . -------------------------------------------------------------------------Debian LTS Advisory DLA-3113-1
Updated sleuthkit packages fix security vulnerability: In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c (CVE-2020-10232). . MGASA-2020-0143 - Updated sleuthkit packages fix security vulnerability Publication date: 18 Mar 2020 URL: https://advisories.mageia.org/MGASA-2020-0143.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-10232 Updated sleuthkit packages fix security vulnerability: In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c (CVE-2020-10232). References: - https://bugs.mageia.org/show_bug.cgi?id=26336 - https://lists.debian.org/debian-lts-announce/2020/03/msg00011.html - https://www.cve.org/CVERecord?id=CVE-2020-10232 SRPMS: - 7/core/sleuthkit-4.6.6-1.1.mga7 . Recent updates to Sleuthkit packages fix a critical stack buffer overflow vulnerability in Mageia 7. This patch boosts security and lowers exploitation risks.. SleuthKit Security Update, Mageia Security Patch, Stack Overflow, File Timestamp Parsing. . Severity: Critical. LinuxSecurity.com Team
An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for libopenmpt ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2212-1 Rating: moderate References: #1143578 #1143581 #1143582 #1143584 Cross-References: CVE-2018-20860 CVE-2018-20861 CVE-2019-14382 CVE-2019-14383 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for libopenmpt fixes the following issues: Security issues fixed: - CVE-2018-20861: Fixed crash with certain malformed custom tunings in MPTM files (bsc#1143578). - CVE-2018-20860: Fixed crash with malformed MED files (bsc#1143581). - CVE-2019-14383: Fixed J2B that allows an assertion failure during file parsing with debug STLs (bsc#1143584). - CVE-2019-14382: Fixed DSM that allows an assertion failure during file parsing with debug STLs (bsc#1143582). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-2212=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): libmodplug-devel-0.3.17-lp150.7.1 libmodplug1-0.3.17-lp150.7.1 libmodplug1-debuginfo-0.3.17-lp150.7.1 libopenmpt-debugsource-0.3.17-lp150.7.1 libopenmpt-devel-0.3.17-lp150.7.1 libopenmpt0-0.3.17-lp150.7.1 libopenmpt0-debuginfo-0.3.17-lp150.7.1 libopenmpt_modplug1-0.3.17-lp150.7.1 libopenmpt_modplug1-debuginfo-0.3.17-lp150.7.1 openmpt123-0.3.17-lp150.7.1 openmpt123-debuginfo-0.3.17-lp150.7.1 - openSUSE Leap 15.0 (x86_64): libmodplug1-32bit-0.3.17-lp150.7.1 libmodplug1-32bit-debuginfo-0.3.17-lp150.7.1 libopenmpt0-32bit-0.3.17-lp150.7.1 libopenmpt0-32bit-debuginfo-0.3.17-lp150.7.1 libopenmpt_modplug1-32bit-0.3.17-lp150.7.1 libopenmpt_modplug1-32bit-debuginfo-0.3.17-lp150.7.1 References: https://www.suse.com/security/cve/CVE-2018-20860.html https://www.suse.com/security/cve/CVE-2018-20861.html https://www.suse.com/security/cve/CVE-2019-14382.html https://www.suse.com/security/cve/CVE-2019-14383.html https://bugzilla.suse.com/1143578 https://bugzilla.suse.com/1143581 https://bugzilla.suse.com/1143582 https://bugzilla.suse.com/1143584 -- . An update for openSUSE has resolved four vulnerabilities found in libopenmpt. Discover the details about the particular issues that have been fixed.. openSUSE Update, libopenmpt Fix, Security Patch. . LinuxSecurity.com Team
An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for libopenmpt ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2213-1 Rating: moderate References: #1143578 #1143581 #1143582 #1143584 Cross-References: CVE-2018-20860 CVE-2018-20861 CVE-2019-14382 CVE-2019-14383 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for libopenmpt fixes the following issues: Security issues fixed: - CVE-2018-20861: Fixed crash with certain malformed custom tunings in MPTM files (bsc#1143578). - CVE-2018-20860: Fixed crash with malformed MED files (bsc#1143581). - CVE-2019-14383: Fixed J2B that allows an assertion failure during file parsing with debug STLs (bsc#1143584). - CVE-2019-14382: Fixed DSM that allows an assertion failure during file parsing with debug STLs (bsc#1143582). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-2213=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): libmodplug-devel-0.3.17-lp151.2.3.1 libmodplug1-0.3.17-lp151.2.3.1 libmodplug1-debuginfo-0.3.17-lp151.2.3.1 libopenmpt-debugsource-0.3.17-lp151.2.3.1 libopenmpt-devel-0.3.17-lp151.2.3.1 libopenmpt0-0.3.17-lp151.2.3.1 libopenmpt0-debuginfo-0.3.17-lp151.2.3.1 libopenmpt_modplug1-0.3.17-lp151.2.3.1 libopenmpt_modplug1-debuginfo-0.3.17-lp151.2.3.1 openmpt123-0.3.17-lp151.2.3.1 openmpt123-debuginfo-0.3.17-lp151.2.3.1 - openSUSE Leap 15.1 (x86_64): libmodplug1-32bit-0.3.17-lp151.2.3.1 libmodplug1-32bit-debuginfo-0.3.17-lp151.2.3.1 libopenmpt0-32bit-0.3.17-lp151.2.3.1 libopenmpt0-32bit-debuginfo-0.3.17-lp151.2.3.1 libopenmpt_modplug1-32bit-0.3.17-lp151.2.3.1 libopenmpt_modplug1-32bit-debuginfo-0.3.17-lp151.2.3.1 References: https://www.suse.com/security/cve/CVE-2018-20860.html https://www.suse.com/security/cve/CVE-2018-20861.html https://www.suse.com/security/cve/CVE-2019-14382.html https://www.suse.com/security/cve/CVE-2019-14383.html https://bugzilla.suse.com/1143578 https://bugzilla.suse.com/1143581 https://bugzilla.suse.com/1143582 https://bugzilla.suse.com/1143584 -- . Security update for libopenmpt addresses four distinct vulnerabilities to improve system protection.. update, security, fixes, vulnerabilities, opensuse, updat. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.