Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 471
Alerts This Week
Warning Icon 1 471

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 5 articles for you...
100

SUSE Linux: 2025:1540-1 moderate: transfig heap overflow and more

* bsc#1240379 * bsc#1240380 * bsc#1240381 Cross-References: . # Security update for transfig Announcement ID: SUSE-SU-2025:1540-1 Release Date: 2025-05-13T08:54:18Z Rating: moderate References: * bsc#1240379 * bsc#1240380 * bsc#1240381 Cross-References: * CVE-2025-31162 * CVE-2025-31163 * CVE-2025-31164 CVSS scores: * CVE-2025-31162 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31162 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31163 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31163 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31164 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31164 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for transfig fixes the following issues: * CVE-2025-31164: Fixed heap-buffer overflow in fig2dev create_line_with_spline() function (bsc#1240379) * CVE-2025-31162: Fixed floating point exception in fig2dev get_slope() function (bsc#1240380) * CVE-2025-31163: Fixed segmentation fault in fig2dev put_patternarc() function (bsc#1240381) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1540=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * transfig-debuginfo-3.2.8b-2.23.1 * transfig-3.2.8b-2.23.1 * transfig-debugsource-3.2.8b-2.23.1 ## References: *https://www.suse.com/security/cve/CVE-2025-31162.html * https://www.suse.com/security/cve/CVE-2025-31163.html * https://www.suse.com/security/cve/CVE-2025-31164.html * https://bugzilla.suse.com/show_bug.cgi?id=1240379 * https://bugzilla.suse.com/show_bug.cgi?id=1240380 * https://bugzilla.suse.com/show_bug.cgi?id=1240381 . A balanced security patch for transfig tackles three significant vulnerabilities in SUSE Linux Enterprise Server 12 SP5.. transfig security update, SUSE Linux Enterprise, heap overflow fix, floating point exception, segmentation fault fix. . LinuxSecurity.com Team

Calendar%202 May 13, 2025 SuSE
100

openSUSE 15.4: SUSE-SU-2025:1172-1 moderate: poppler issues

* bsc#1240880 * bsc#1240881 Cross-References: * CVE-2025-32364 . # Security update for poppler Announcement ID: SUSE-SU-2025:1172-1 Release Date: 2025-04-08T13:36:26Z Rating: moderate References: * bsc#1240880 * bsc#1240881 Cross-References: * CVE-2025-32364 * CVE-2025-32365 CVSS scores: * CVE-2025-32364 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-32364 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32364 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32365 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-32365 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32365 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 An update that solves two vulnerabilities can now be installed. ## Description: This update for poppler fixes the following issues: * CVE-2025-32364: Fixed a floating point exception. (bsc#1240880) * CVE-2025-32365: Fixed the isOk check in JBIG2Bitmap::combine function in JBIG2Stream.cc. (bsc#1240881) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1172=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libpoppler-qt6-3-22.01.0-150400.3.28.1 * poppler-debugsource-22.01.0-150400.3.28.1 * libpoppler-cpp0-22.01.0-150400.3.28.1 * libpoppler-glib-devel-22.01.0-150400.3.28.1 * typelib-1_0-Poppler-0_18-22.01.0-150400.3.28.1 * libpoppler-qt6-3-debuginfo-22.01.0-150400.3.28.1 * libpoppler-cpp0-debuginfo-22.01.0-150400.3.28.1 * poppler-tools-22.01.0-150400.3.28.1 * poppler-tools-debuginfo-22.01.0-150400.3.28.1 * libpoppler-qt5-1-22.01.0-150400.3.28.1 * libpoppler-qt6-devel-22.01.0-150400.3.28.1 * libpoppler117-22.01.0-150400.3.28.1 * libpoppler117-debuginfo-22.01.0-150400.3.28.1 * libpoppler-glib8-22.01.0-150400.3.28.1 * libpoppler-glib8-debuginfo-22.01.0-150400.3.28.1 * poppler-qt5-debugsource-22.01.0-150400.3.28.1 * poppler-qt6-debugsource-22.01.0-150400.3.28.1 * libpoppler-qt5-devel-22.01.0-150400.3.28.1 * libpoppler-qt5-1-debuginfo-22.01.0-150400.3.28.1 * libpoppler-devel-22.01.0-150400.3.28.1 * openSUSE Leap 15.4 (x86_64) * libpoppler117-32bit-22.01.0-150400.3.28.1 * libpoppler-glib8-32bit-22.01.0-150400.3.28.1 * libpoppler117-32bit-debuginfo-22.01.0-150400.3.28.1 * libpoppler-qt5-1-32bit-22.01.0-150400.3.28.1 * libpoppler-glib8-32bit-debuginfo-22.01.0-150400.3.28.1 * libpoppler-cpp0-32bit-debuginfo-22.01.0-150400.3.28.1 * libpoppler-cpp0-32bit-22.01.0-150400.3.28.1 * libpoppler-qt5-1-32bit-debuginfo-22.01.0-150400.3.28.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libpoppler117-64bit-22.01.0-150400.3.28.1 * libpoppler-qt5-1-64bit-22.01.0-150400.3.28.1 * libpoppler-cpp0-64bit-22.01.0-150400.3.28.1 * libpoppler-cpp0-64bit-debuginfo-22.01.0-150400.3.28.1 * libpoppler-qt5-1-64bit-debuginfo-22.01.0-150400.3.28.1 * libpoppler117-64bit-debuginfo-22.01.0-150400.3.28.1 * libpoppler-glib8-64bit-22.01.0-150400.3.28.1 * libpoppler-glib8-64bit-debuginfo-22.01.0-150400.3.28.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32364.html * https://www.suse.com/security/cve/CVE-2025-32365.html * https://bugzilla.suse.com/show_bug.cgi?id=1240880 * https://bugzilla.suse.com/show_bug.cgi?id=1240881 . Update for poppler addresses moderate issues. Installation instructions included for openSUSE. Stay secure!. openSUSE poppler security update, moderate security issues, poppler vulnerabilities, SUSE patch instructions. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 08, 2025 Important SuSE
100

SUSE: 2024:3114-1 Moderate: ffmpeg Buffer Overflow Fixes

* bsc#1186607 * bsc#1189428 * bsc#1223304 Cross-References: . # Security update for ffmpeg Announcement ID: SUSE-SU-2024:3114-1 Rating: moderate References: * bsc#1186607 * bsc#1189428 * bsc#1223304 Cross-References: * CVE-2020-22027 * CVE-2021-38291 * CVE-2023-51798 CVSS scores: * CVE-2020-22027 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2020-22027 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2021-38291 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2021-38291 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-51798 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Desktop Applications Module 15-SP5 * Desktop Applications Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP5 * SUSE Linux Enterprise Workstation Extension 15 SP6 * SUSE Package Hub 15 15-SP5 * SUSE Package Hub 15 15-SP6 An update that solves three vulnerabilities can now be installed. ## Description: This update for ffmpeg fixes the following issues: * CVE-2020-22027: Fixed heap-based Buffer Overflow vulnerability exits in deflate16 at libavfilter/vf_neighbor.c (bsc#1186607) * CVE-2021-38291: Fixed an assertion failure at src/libavutil/mathematics.c (bsc#1189428) * CVE-2023-51798: Fixed floating point exception(FPE) via the interpolate function (bsc#1223304) ## Patch Instructions: To install this SUSE update use the SUSE recommendedinstallation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3114=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3114=1 * Desktop Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2024-3114=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2024-3114=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-3114=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-3114=1 * SUSE Linux Enterprise Workstation Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-WE-15-SP5-2024-3114=1 * SUSE Linux Enterprise Workstation Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2024-3114=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libavcodec57-3.4.2-150200.11.57.1 * libswscale-devel-3.4.2-150200.11.57.1 * libavformat-devel-3.4.2-150200.11.57.1 * libavcodec-devel-3.4.2-150200.11.57.1 * ffmpeg-private-devel-3.4.2-150200.11.57.1 * libswresample2-debuginfo-3.4.2-150200.11.57.1 * libpostproc54-3.4.2-150200.11.57.1 * libavresample3-3.4.2-150200.11.57.1 * libavformat57-debuginfo-3.4.2-150200.11.57.1 * libavformat57-3.4.2-150200.11.57.1 * libavfilter6-3.4.2-150200.11.57.1 * libswresample2-3.4.2-150200.11.57.1 * ffmpeg-debugsource-3.4.2-150200.11.57.1 * libavutil-devel-3.4.2-150200.11.57.1 * libavcodec57-debuginfo-3.4.2-150200.11.57.1 * libavdevice57-debuginfo-3.4.2-150200.11.57.1 * libavresample-devel-3.4.2-150200.11.57.1 * libpostproc54-debuginfo-3.4.2-150200.11.57.1 * libavdevice57-3.4.2-150200.11.57.1 * libavresample3-debuginfo-3.4.2-150200.11.57.1 * libpostproc-devel-3.4.2-150200.11.57.1 *libswresample-devel-3.4.2-150200.11.57.1 * libavdevice-devel-3.4.2-150200.11.57.1 * libavutil55-debuginfo-3.4.2-150200.11.57.1 * libswscale4-3.4.2-150200.11.57.1 * libavfilter-devel-3.4.2-150200.11.57.1 * ffmpeg-debuginfo-3.4.2-150200.11.57.1 * ffmpeg-3.4.2-150200.11.57.1 * libavfilter6-debuginfo-3.4.2-150200.11.57.1 * libavutil55-3.4.2-150200.11.57.1 * libswscale4-debuginfo-3.4.2-150200.11.57.1 * openSUSE Leap 15.5 (x86_64) * libavformat57-32bit-debuginfo-3.4.2-150200.11.57.1 * libavresample3-32bit-debuginfo-3.4.2-150200.11.57.1 * libswscale4-32bit-3.4.2-150200.11.57.1 * libpostproc54-32bit-3.4.2-150200.11.57.1 * libavcodec57-32bit-debuginfo-3.4.2-150200.11.57.1 * libavfilter6-32bit-debuginfo-3.4.2-150200.11.57.1 * libswresample2-32bit-debuginfo-3.4.2-150200.11.57.1 * libavutil55-32bit-debuginfo-3.4.2-150200.11.57.1 * libswresample2-32bit-3.4.2-150200.11.57.1 * libpostproc54-32bit-debuginfo-3.4.2-150200.11.57.1 * libavdevice57-32bit-3.4.2-150200.11.57.1 * libavutil55-32bit-3.4.2-150200.11.57.1 * libavcodec57-32bit-3.4.2-150200.11.57.1 * libavresample3-32bit-3.4.2-150200.11.57.1 * libavfilter6-32bit-3.4.2-150200.11.57.1 * libavdevice57-32bit-debuginfo-3.4.2-150200.11.57.1 * libavformat57-32bit-3.4.2-150200.11.57.1 * libswscale4-32bit-debuginfo-3.4.2-150200.11.57.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libavcodec57-3.4.2-150200.11.57.1 * libswscale-devel-3.4.2-150200.11.57.1 * libavformat-devel-3.4.2-150200.11.57.1 * libavcodec-devel-3.4.2-150200.11.57.1 * ffmpeg-private-devel-3.4.2-150200.11.57.1 * libswresample2-debuginfo-3.4.2-150200.11.57.1 * libpostproc54-3.4.2-150200.11.57.1 * libavresample3-3.4.2-150200.11.57.1 * libavformat57-debuginfo-3.4.2-150200.11.57.1 * libavformat57-3.4.2-150200.11.57.1 * libavfilter6-3.4.2-150200.11.57.1 * libswresample2-3.4.2-150200.11.57.1 * ffmpeg-debugsource-3.4.2-150200.11.57.1 *libavutil-devel-3.4.2-150200.11.57.1 * libavcodec57-debuginfo-3.4.2-150200.11.57.1 * libavdevice57-debuginfo-3.4.2-150200.11.57.1 * libavresample-devel-3.4.2-150200.11.57.1 * libpostproc54-debuginfo-3.4.2-150200.11.57.1 * libavdevice57-3.4.2-150200.11.57.1 * libavresample3-debuginfo-3.4.2-150200.11.57.1 * libpostproc-devel-3.4.2-150200.11.57.1 * libswresample-devel-3.4.2-150200.11.57.1 * libavdevice-devel-3.4.2-150200.11.57.1 * libavutil55-debuginfo-3.4.2-150200.11.57.1 * libswscale4-3.4.2-150200.11.57.1 * libavfilter-devel-3.4.2-150200.11.57.1 * ffmpeg-debuginfo-3.4.2-150200.11.57.1 * ffmpeg-3.4.2-150200.11.57.1 * libavfilter6-debuginfo-3.4.2-150200.11.57.1 * libavutil55-3.4.2-150200.11.57.1 * libswscale4-debuginfo-3.4.2-150200.11.57.1 * openSUSE Leap 15.6 (x86_64) * libavformat57-32bit-debuginfo-3.4.2-150200.11.57.1 * libavresample3-32bit-debuginfo-3.4.2-150200.11.57.1 * libswscale4-32bit-3.4.2-150200.11.57.1 * libpostproc54-32bit-3.4.2-150200.11.57.1 * libavcodec57-32bit-debuginfo-3.4.2-150200.11.57.1 * libavfilter6-32bit-debuginfo-3.4.2-150200.11.57.1 * libswresample2-32bit-debuginfo-3.4.2-150200.11.57.1 * libavutil55-32bit-debuginfo-3.4.2-150200.11.57.1 * libswresample2-32bit-3.4.2-150200.11.57.1 * libpostproc54-32bit-debuginfo-3.4.2-150200.11.57.1 * libavdevice57-32bit-3.4.2-150200.11.57.1 * libavutil55-32bit-3.4.2-150200.11.57.1 * libavcodec57-32bit-3.4.2-150200.11.57.1 * libavresample3-32bit-3.4.2-150200.11.57.1 * libavfilter6-32bit-3.4.2-150200.11.57.1 * libavdevice57-32bit-debuginfo-3.4.2-150200.11.57.1 * libavformat57-32bit-3.4.2-150200.11.57.1 * libswscale4-32bit-debuginfo-3.4.2-150200.11.57.1 * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libavcodec57-3.4.2-150200.11.57.1 * libavcodec57-debuginfo-3.4.2-150200.11.57.1 * libswscale-devel-3.4.2-150200.11.57.1 * libavutil55-debuginfo-3.4.2-150200.11.57.1 *libswscale4-debuginfo-3.4.2-150200.11.57.1 * libswresample2-3.4.2-150200.11.57.1 * libswscale4-3.4.2-150200.11.57.1 * libpostproc54-debuginfo-3.4.2-150200.11.57.1 * ffmpeg-debuginfo-3.4.2-150200.11.57.1 * libswresample2-debuginfo-3.4.2-150200.11.57.1 * libpostproc-devel-3.4.2-150200.11.57.1 * libpostproc54-3.4.2-150200.11.57.1 * libavutil55-3.4.2-150200.11.57.1 * ffmpeg-debugsource-3.4.2-150200.11.57.1 * libavutil-devel-3.4.2-150200.11.57.1 * libswresample-devel-3.4.2-150200.11.57.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libavcodec57-3.4.2-150200.11.57.1 * libavcodec57-debuginfo-3.4.2-150200.11.57.1 * libswscale-devel-3.4.2-150200.11.57.1 * libavutil55-debuginfo-3.4.2-150200.11.57.1 * libswscale4-debuginfo-3.4.2-150200.11.57.1 * libswresample2-3.4.2-150200.11.57.1 * libswscale4-3.4.2-150200.11.57.1 * libpostproc54-debuginfo-3.4.2-150200.11.57.1 * ffmpeg-debuginfo-3.4.2-150200.11.57.1 * libswresample2-debuginfo-3.4.2-150200.11.57.1 * libpostproc-devel-3.4.2-150200.11.57.1 * libpostproc54-3.4.2-150200.11.57.1 * libavutil55-3.4.2-150200.11.57.1 * ffmpeg-debugsource-3.4.2-150200.11.57.1 * libavutil-devel-3.4.2-150200.11.57.1 * libswresample-devel-3.4.2-150200.11.57.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * libavformat57-debuginfo-3.4.2-150200.11.57.1 * libavformat57-3.4.2-150200.11.57.1 * libavfilter6-3.4.2-150200.11.57.1 * libavdevice57-debuginfo-3.4.2-150200.11.57.1 * ffmpeg-debuginfo-3.4.2-150200.11.57.1 * ffmpeg-3.4.2-150200.11.57.1 * libavdevice57-3.4.2-150200.11.57.1 * libavresample3-debuginfo-3.4.2-150200.11.57.1 * libavfilter6-debuginfo-3.4.2-150200.11.57.1 * libavresample3-3.4.2-150200.11.57.1 * ffmpeg-debugsource-3.4.2-150200.11.57.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * libavformat57-debuginfo-3.4.2-150200.11.57.1 * libavformat57-3.4.2-150200.11.57.1 *libavfilter6-3.4.2-150200.11.57.1 * libavdevice57-debuginfo-3.4.2-150200.11.57.1 * ffmpeg-debuginfo-3.4.2-150200.11.57.1 * ffmpeg-3.4.2-150200.11.57.1 * libavdevice57-3.4.2-150200.11.57.1 * libavresample3-debuginfo-3.4.2-150200.11.57.1 * libavfilter6-debuginfo-3.4.2-150200.11.57.1 * libavresample3-3.4.2-150200.11.57.1 * ffmpeg-debugsource-3.4.2-150200.11.57.1 * SUSE Linux Enterprise Workstation Extension 15 SP5 (x86_64) * libavformat57-debuginfo-3.4.2-150200.11.57.1 * libavformat57-3.4.2-150200.11.57.1 * libavformat-devel-3.4.2-150200.11.57.1 * libavresample-devel-3.4.2-150200.11.57.1 * libavcodec-devel-3.4.2-150200.11.57.1 * ffmpeg-debuginfo-3.4.2-150200.11.57.1 * libavresample3-debuginfo-3.4.2-150200.11.57.1 * libavresample3-3.4.2-150200.11.57.1 * ffmpeg-debugsource-3.4.2-150200.11.57.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64) * libavformat57-debuginfo-3.4.2-150200.11.57.1 * libavformat57-3.4.2-150200.11.57.1 * libavformat-devel-3.4.2-150200.11.57.1 * libavresample-devel-3.4.2-150200.11.57.1 * libavcodec-devel-3.4.2-150200.11.57.1 * ffmpeg-debuginfo-3.4.2-150200.11.57.1 * libavresample3-debuginfo-3.4.2-150200.11.57.1 * libavresample3-3.4.2-150200.11.57.1 * ffmpeg-debugsource-3.4.2-150200.11.57.1 ## References: * https://www.suse.com/security/cve/CVE-2020-22027.html * https://www.suse.com/security/cve/CVE-2021-38291.html * https://www.suse.com/security/cve/CVE-2023-51798.html * https://bugzilla.suse.com/show_bug.cgi?id=1186607 * https://bugzilla.suse.com/show_bug.cgi?id=1189428 * https://bugzilla.suse.com/show_bug.cgi?id=1223304 . This notification outlines significant enhancements for libav addressing severe memory corruption vulnerabilities. Important for Ubuntu users!. ffmpeg security update,SUSE moderate patch,buffer overflow fix,openSUSE ffmpeg advisory. . LinuxSecurity.com Team

Calendar%202 Sep 03, 2024 SuSE
89

Fedora 38 - Gifsicle 2024-4672c1ff2d Moderate: DoS, FP Exception

Update to 1.95. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-4672c1ff2d 2024-03-01 01:39:46.018133 -------------------------------------------------------------------------------- Name : gifsicle Product : Fedora 38 Version : 1.95 Release : 1.fc38 URL : http://www.lcdf.org/gifsicle/ Summary : Powerful program for manipulating GIF images and animations Description : Gifsicle is a command-line tool for creating, editing, and getting information about GIF images and animations. Some more gifsicle features: * Batch mode for changing GIFs in place. * Prints detailed information about GIFs, including comments. * Control over interlacing, comments, looping, transparency... * Creates well-behaved GIFs: removes redundant colors, only uses local color tables if it absolutely has to (local color tables waste space and can cause viewing artifacts), etc. * It can shrink colormaps and change images to use the Web-safe palette (or any colormap you choose). * It can optimize your animations! This stores only the changed portion of each frame, and can radically shrink your GIFs. You can also use transparency to make them even smaller. Gifsicle?s optimizer is pretty powerful, and usually reduces animations to within a couple bytes of the best commercial optimizers. * Unoptimizing animations, which makes them easier to edit. * A dumb-ass name. One other program is included with gifsicle and gifdiff compares two GIFs for identical visual appearance. -------------------------------------------------------------------------------- Update Information: Update to 1.95 -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 21 2024 Orion Poplawski - 1.95-1 - Update to 1.95 CVE-2023-46009 (bz#2244935) CVE-2023-44821 (bz#2250064) * Wed Jan 24 2024 Fedora ReleaseEngineering - 1.94-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering - 1.94-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Wed Jul 19 2023 Fedora Release Engineering - 1.94-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Sun Jul 16 2023 Orion Poplawski - 1.94-1 - Update to 1.94 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2244935 - CVE-2023-46009 gifsicle: floating point exception vulnerability via resize_stream at src/xform.c https://bugzilla.redhat.com/show_bug.cgi?id=2244935 [ 2 ] Bug #2250064 - CVE-2023-44821 gifsicle: denial of service in Gif_Realloc calls https://bugzilla.redhat.com/show_bug.cgi?id=2250064 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-4672c1ff2d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Explore the latest updates from Fedora regarding gifsicle, addressing critical concerns such as adenial of service vulnerability and a potential floating point anomaly.. Fedora Update,Gifsicle Tool,Security Advisory,Fedora 38,Image Manipulation. . LinuxSecurity.com Team

Calendar%202 Mar 01, 2024 Fedora
100

SUSE: 2020:1626-1 Moderate: Poppler Denial of Service Issues

An update that fixes 5 vulnerabilities is now available. . SUSE Security Update: Security update for poppler ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1626-1 Rating: moderate References: #1059066 #1060220 #1064593 #1074453 #1092105 Cross-References: CVE-2017-1000456 CVE-2017-14517 CVE-2017-14617 CVE-2017-15565 CVE-2018-10768 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP4 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for poppler fixes the following issues: These security issues were fixed: - CVE-2017-14617: Fixed a floating point exception in Stream.cc, which may lead to a potential attack when handling malicious PDF files. (bsc#1060220) - CVE-2017-1000456: Validate boundaries in TextPool::addWord to prevent overflows in subsequent calculations (bsc#1074453) - CVE-2017-15565: Prevent NULL Pointer dereference in the GfxImageColorMap::getGrayLine() function via a crafted PDF document (bsc#1064593) - CVE-2018-10768: Prevent NULL pointer dereference in the AnnotPath::getCoordsLength function. A crafted input could have lead to a remote denial of service attack (bsc#1092105). This update also fixes an additional segmentation fault that is trigger by the reproducer for CVE-2017-14517 (bsc#1059066). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-1626=1 - SUSE Linux Enterprise Software DevelopmentKit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2020-1626=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libpoppler44-0.24.4-14.16.6 libpoppler44-debuginfo-0.24.4-14.16.6 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): libpoppler44-0.24.4-14.16.6 libpoppler44-debuginfo-0.24.4-14.16.6 References: https://www.suse.com/security/cve/CVE-2017-1000456.html https://www.suse.com/security/cve/CVE-2017-14517.html https://www.suse.com/security/cve/CVE-2017-14617.html https://www.suse.com/security/cve/CVE-2017-15565.html https://www.suse.com/security/cve/CVE-2018-10768.html https://bugzilla.suse.com/1059066 https://bugzilla.suse.com/1060220 https://bugzilla.suse.com/1064593 https://bugzilla.suse.com/1074453 https://bugzilla.suse.com/1092105 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Patch addresses numerous vulnerabilities in ImageMagick, notably problems related to denial of service and invalid memory access.. SUSE Linux Enterprise, Poppler Security Update, Denial of Service, Security Fix, Floating Point Exception. . LinuxSecurity.com Team

Calendar%202 Jun 16, 2020 SuSE
100

SUSE: 2019:2745-1 Moderate: Libcaca Memory Access Fixes

An update that fixes 6 vulnerabilities is now available. . SUSE Security Update: Security update for libcaca ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2745-1 Rating: moderate References: #1120470 #1120502 #1120503 #1120504 #1120584 #1120589 Cross-References: CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Desktop 12-SP4 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for libcaca fixes the following issues: Security issues fixed: - CVE-2018-20544: Fixed a floating point exception at caca/dither.c (bsc#1120502) - CVE-2018-20545: Fixed a WRITE memory access in the load_image function at common-image.c for 4bpp (bsc#1120584) - CVE-2018-20546: Fixed a READ memory access in the get_rgba_default function at caca/dither.c for bpp (bsc#1120503) - CVE-2018-20547: Fixed a READ memory access in the get_rgba_default function at caca/dither.c for 24bpp (bsc#1120504) - CVE-2018-20548: Fixed a WRITE memory access in the load_image function at common-image.c for 1bpp (bsc#1120589) - CVE-2018-20549: Fixed a WRITE memory access in the caca_file_read function at caca/file.c (bsc#1120470) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-2745=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-2745=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-2745=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): libcaca-debugsource-0.99.beta18-14.3.27 libcaca-devel-0.99.beta18-14.3.27 libcaca0-plugins-0.99.beta18-14.3.27 libcaca0-plugins-debuginfo-0.99.beta18-14.3.27 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): libcaca-debugsource-0.99.beta18-14.3.27 libcaca0-0.99.beta18-14.3.27 libcaca0-debuginfo-0.99.beta18-14.3.27 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): libcaca-debugsource-0.99.beta18-14.3.27 libcaca0-0.99.beta18-14.3.27 libcaca0-debuginfo-0.99.beta18-14.3.27 References: https://www.suse.com/security/cve/CVE-2018-20544.html https://www.suse.com/security/cve/CVE-2018-20545.html https://www.suse.com/security/cve/CVE-2018-20546.html https://www.suse.com/security/cve/CVE-2018-20547.html https://www.suse.com/security/cve/CVE-2018-20548.html https://www.suse.com/security/cve/CVE-2018-20549.html https://bugzilla.suse.com/1120470 https://bugzilla.suse.com/1120502 https://bugzilla.suse.com/1120503 https://bugzilla.suse.com/1120504 https://bugzilla.suse.com/1120584 https://bugzilla.suse.com/1120589 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE has released a security update for libcaca addressing several vulnerabilities of moderate severity, thereby improving the overall security of the product.. SUSE Update, Memory Access Issues, Libcaca Security Patch. . LinuxSecurity.com Team

Calendar%202 Oct 22, 2019 SuSE
100

SUSE: 2019:14076-1 Important: gstreamer-0_10-plugins-base Patch Details

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for gstreamer-0_10-plugins-base ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:14076-1 Rating: important References: #1024076 #1024079 #1133375 Cross-References: CVE-2017-5837 CVE-2017-5844 CVE-2019-9928 Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for gstreamer-0_10-plugins-base fixes the following issues: Security issues fixed: - CVE-2017-5837: Fixed a floating point exception in gst_riff_create_audio_caps (bsc#1024076). - CVE-2017-5844: Fixed a floating point exception in gst_riff_create_audio_caps (bsc#1024079). - CVE-2019-9928: Fixed a heap-based overflow in the rtsp connection parser (bsc#1133375). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-gstreamer-0_10-plugins-base-14076=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-gstreamer-0_10-plugins-base-14076=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-gstreamer-0_10-plugins-base-14076=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (i586 ppc64 s390x x86_64): gstreamer-0_10-plugins-base-0.10.35-5.18.5.1 gstreamer-0_10-plugins-base-doc-0.10.35-5.18.5.1 gstreamer-0_10-plugins-base-lang-0.10.35-5.18.5.1 libgstapp-0_10-0-0.10.35-5.18.5.1 libgstinterfaces-0_10-0-0.10.35-5.18.5.1 - SUSE Linux Enterprise Server 11-SP4-LTSS (ppc64 s390x x86_64): gstreamer-0_10-plugins-base-32bit-0.10.35-5.18.5.1 libgstapp-0_10-0-32bit-0.10.35-5.18.5.1 libgstinterfaces-0_10-0-32bit-0.10.35-5.18.5.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): gstreamer-0_10-plugins-base-0.10.35-5.18.5.1 gstreamer-0_10-plugins-base-doc-0.10.35-5.18.5.1 gstreamer-0_10-plugins-base-lang-0.10.35-5.18.5.1 libgstapp-0_10-0-0.10.35-5.18.5.1 libgstinterfaces-0_10-0-0.10.35-5.18.5.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390x x86_64): gstreamer-0_10-plugins-base-debuginfo-0.10.35-5.18.5.1 gstreamer-0_10-plugins-base-debugsource-0.10.35-5.18.5.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (ppc64 s390x x86_64): gstreamer-0_10-plugins-base-debuginfo-32bit-0.10.35-5.18.5.1 References: https://www.suse.com/security/cve/CVE-2017-5837.html https://www.suse.com/security/cve/CVE-2017-5844.html https://www.suse.com/security/cve/CVE-2019-9928.html https://bugzilla.suse.com/1024076 https://bugzilla.suse.com/1024079 https://bugzilla.suse.com/1133375 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Update for gstreamer-0_10-plugins-base addresses significant vulnerabilities. Discover the necessary steps to update promptly.. gstreamer update, SUSE security, important patch, system vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 11, 2019 Important SuSE
89

Fedora 27: 2017-025ff38ac9 Critical: Poppler Memory Corruption

Security fix for CVE-2017-14926, CVE-2017-14927 and CVE-2017-14928. ---- Security fix for CVE-2017-14617 ---- Security fix for CVE-2017-14517, CVE-2017-14518, CVE-2017-14519 and CVE-2017-14929.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-025ff38ac9 2017-11-11 13:29:22.441222 --------------------------------------------------------------------------------Name : poppler Product : Fedora 27 Version : 0.57.0 Release : 5.fc27 URL : http://poppler.freedesktop.org/ Summary : PDF rendering library Description : poppler is a PDF rendering library. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-14926, CVE-2017-14927 and CVE-2017-14928. ----Security fix for CVE-2017-14617 ---- Security fix for CVE-2017-14517, CVE-2017-14518, CVE-2017-14519 and CVE-2017-14929. --------------------------------------------------------------------------------References: [ 1 ] Bug #1500322 - CVE-2017-14928 poppler: NULL pointer dereference in the AnnotRichMedia::Configuration::Configuration https://bugzilla.redhat.com/show_bug.cgi?id=1500322 [ 2 ] Bug #1500323 - CVE-2017-14926 poppler: NULL pointer dereference in the AnnotRichMedia::Content::Content https://bugzilla.redhat.com/show_bug.cgi?id=1500323 [ 3 ] Bug #1500324 - CVE-2017-14927 poppler: NULL pointer dereference in the SplashOutputDev::type3D0() function https://bugzilla.redhat.com/show_bug.cgi?id=1500324 [ 4 ] Bug #1499905 - CVE-2017-14617 poppler: Floating point exception in the ImageStream class https://bugzilla.redhat.com/show_bug.cgi?id=1499905 [ 5 ] Bug #1499162 - CVE-2017-14517 poppler: NULL pointer dereference in the XRef::parseEntry() function https://bugzilla.redhat.com/show_bug.cgi?id=1499162 [ 6 ] Bug #1499163 - CVE-2017-14518 poppler: Floating point exception in the isImageInterpolationRequired()function https://bugzilla.redhat.com/show_bug.cgi?id=1499163 [ 7 ] Bug #1499165 - CVE-2017-14519 poppler: Memory corruption via Gfx.cc infinite loop https://bugzilla.redhat.com/show_bug.cgi?id=1499165 [ 8 ] Bug #1499167 - CVE-2017-14929 poppler: Memory corruption via Gfx.cc infinite loop https://bugzilla.redhat.com/show_bug.cgi?id=1499167 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade poppler' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . This release fixes several vulnerabilities within the libxml2 framework, strengthening Fedora 27's overall security posture.. Fedora Poppler Security Fix, PDF Rendering Library Security, Critical Updates for Poppler. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 11, 2017 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200