Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 14 articles for you...
202

openSUSE Leap 15.3 Security Update: 2021:3236-1 Moderate gd Issue

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for gd ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:3236-1 Rating: moderate References: #1190400 Cross-References: CVE-2021-40812 CVSS scores: CVE-2021-40812 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gd fixes the following issues: - CVE-2021-40812: Fixed out-of-bounds read caused by the lack of certain gdGetBuf and gdPutBuf return value checks (bsc#1190400). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-3236=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): gd-2.2.5-11.3.1 gd-debuginfo-2.2.5-11.3.1 gd-debugsource-2.2.5-11.3.1 gd-devel-2.2.5-11.3.1 libgd3-2.2.5-11.3.1 libgd3-debuginfo-2.2.5-11.3.1 - openSUSE Leap 15.3 (x86_64): libgd3-32bit-2.2.5-11.3.1 libgd3-32bit-debuginfo-2.2.5-11.3.1 References: https://www.suse.com/security/cve/CVE-2021-40812.html https://bugzilla.suse.com/1190400 . openSUSE Security Patch released for libxml2 tackling CVE-2021-40813, along with detailed guidance for impacted systems.. openSUSE Security Fix,gd Vulnerability Update,Software Patch Instructions. . LinuxSecurity.com Team

Calendar%202 Sep 27, 2021 OpenSUSE
100

SUSE: 2021:3214-1 Moderate: gd Out-Of-Bounds Read Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for gd ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:3214-1 Rating: moderate References: #1190400 Cross-References: CVE-2021-40812 CVSS scores: CVE-2021-40812 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gd fixes the following issues: - CVE-2021-40812: Fixed out-of-bounds read caused by the lack of certain gdGetBuf and gdPutBuf return value checks (bsc#1190400). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2021-3214=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-3214=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-3214=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): gd-32bit-2.1.0-24.20.1 gd-debuginfo-32bit-2.1.0-24.20.1 gd-debugsource-2.1.0-24.20.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): gd-debuginfo-2.1.0-24.20.1 gd-debugsource-2.1.0-24.20.1 gd-devel-2.1.0-24.20.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): gd-2.1.0-24.20.1 gd-debuginfo-2.1.0-24.20.1 gd-debugsource-2.1.0-24.20.1 References: https://www.suse.com/security/cve/CVE-2021-40812.html https://bugzilla.suse.com/1190400 . SUSE Security Patch for gd is now out. Addresses a medium severity flaw. Deploy using suggested procedures for your system.. SUSE Security Update,gd vulnerability fix,moderate security patch. . LinuxSecurity.com Team

Calendar%202 Sep 23, 2021 SuSE
200

Scientific Linux SL7 SLSA-2020:5443-1 Moderate: gd Heap Overflow

gd: Integer overflow in _gd2GetHeader() resulting in heap overflow (CVE-2016-5766) SL7 x86_64 gd-2.0.35-27.el7_9.i686.rpm gd-2.0.35-27.el7_9.x86_64.rpm gd-debuginfo-2.0.35-27.el7_9.i686.rpm gd-debuginfo-2.0.35-27.el7_9.x86_64.rpm gd-devel-2.0.35-27.el7_9.i686.rpm gd-devel-2.0.35-27.el7_9.x86_64.rpm gd-progs-2.0.35-27.el7_9.x86_64.rpm - Scientific Linux Developme [More...]. Synopsis: Moderate: gd security update Advisory ID: SLSA-2020:5443-1 Issue Date: 2020-12-15 CVE Numbers: None -- Security Fix(es): * gd: Integer overflow in _gd2GetHeader() resulting in heap overflow (CVE-2016-5766) -- SL7 x86_64 gd-2.0.35-27.el7_9.i686.rpm gd-2.0.35-27.el7_9.x86_64.rpm gd-debuginfo-2.0.35-27.el7_9.i686.rpm gd-debuginfo-2.0.35-27.el7_9.x86_64.rpm gd-devel-2.0.35-27.el7_9.i686.rpm gd-devel-2.0.35-27.el7_9.x86_64.rpm gd-progs-2.0.35-27.el7_9.x86_64.rpm - Scientific Linux Development Team . Critical security patch released for GD concerning integer overflow in the header method impacting SL7. Urgent response necessary.. gd Update, Heap Overflow Fix, Scientific Linux Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 15, 2020 Important Scientific Linux
98

Red Hat: RHSA-2020:4659-01 Update on Moderate GD Security Patch

An update for gd is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: gd security update Advisory ID: RHSA-2020:4659-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4659 Issue date: 2020-11-03 CVE Names: CVE-2018-14553 CVE-2019-6977 CVE-2019-6978 ==================================================================== 1. Summary: An update for gd is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: GD is an open source code library for the dynamic creation of images by programmers. GD creates PNG, JPEG, GIF, WebP, XPM, BMP images, among other formats. Security Fix(es): * gd: Heap-based buffer overflow in gdImageColorMatch() in gd_color_match.c (CVE-2019-6977) * gd: NULL pointer dereference in gdImageClone (CVE-2018-14553) * gd: Double free in the gdImage*Ptr in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c (CVE-2019-6978) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Noteslinked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1600727 - CVE-2018-14553 gd: NULL pointer dereference in gdImageClone 1671390 - CVE-2019-6978 gd: Double free in the gdImage*Ptr in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c 1672207 - CVE-2019-6977 gd: Heap-based buffer overflow in gdImageColorMatch() in gd_color_match.c 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: gd-2.2.5-7.el8.src.rpm aarch64: gd-2.2.5-7.el8.aarch64.rpm gd-debuginfo-2.2.5-7.el8.aarch64.rpm gd-debugsource-2.2.5-7.el8.aarch64.rpm gd-devel-2.2.5-7.el8.aarch64.rpm gd-progs-debuginfo-2.2.5-7.el8.aarch64.rpm ppc64le: gd-2.2.5-7.el8.ppc64le.rpm gd-debuginfo-2.2.5-7.el8.ppc64le.rpm gd-debugsource-2.2.5-7.el8.ppc64le.rpm gd-devel-2.2.5-7.el8.ppc64le.rpm gd-progs-debuginfo-2.2.5-7.el8.ppc64le.rpm s390x: gd-2.2.5-7.el8.s390x.rpm gd-debuginfo-2.2.5-7.el8.s390x.rpm gd-debugsource-2.2.5-7.el8.s390x.rpm gd-devel-2.2.5-7.el8.s390x.rpm gd-progs-debuginfo-2.2.5-7.el8.s390x.rpm x86_64: gd-2.2.5-7.el8.i686.rpm gd-2.2.5-7.el8.x86_64.rpm gd-debuginfo-2.2.5-7.el8.i686.rpm gd-debuginfo-2.2.5-7.el8.x86_64.rpm gd-debugsource-2.2.5-7.el8.i686.rpm gd-debugsource-2.2.5-7.el8.x86_64.rpm gd-devel-2.2.5-7.el8.i686.rpm gd-devel-2.2.5-7.el8.x86_64.rpm gd-progs-debuginfo-2.2.5-7.el8.i686.rpm gd-progs-debuginfo-2.2.5-7.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-14553 https://access.redhat.com/security/cve/CVE-2019-6977 https://access.redhat.com/security/cve/CVE-2019-6978 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/ 8. Contact: The RedHat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX6I4RdzjgjWX9erEAQg5GQ//fIftIRqe8CYtoqUHk60BpYn7408Ep/qO 4MdzVop1fEKeJhE2WpPDbjdTOW38kSxHzFBrLEqkdjzZIRJh5yR3vNAWXUaSD8h3 6SdS/vbZS0Awy8SKygIMLrL7Ouuo3kjC7LyoaXvjkYlT9g0cCglhfPiEv4xjNqeH Ib0iZyp+BGTD3CJpQT29Kxi+XDz0j95aDsLaoPDEdMvM0skN6S+swXE7lJj5D9DE dgp2Prf/dkal+jRhXrOVcdNzsV/Zz/BZIEDdabU2G3IA0BiDJyKeE9BXZBcMxC5o BlICR4tYTuMR6LdIfRe04bKm3bUnRtGQSArPrHzzclmYQWt6LcvBJEnAXEMzof+8 hF1D9rIaU+0MSH+FpWVQz78PY/A+2whvMeXiKzJWgGDarin0Tr0iv9BTViIgefJx PgJ5Z3SBpqFHrOfpgqqw3l+86+J0yndBaYpDLEXzera8pMro1ICrHwW+u8mddF1S fJDAjxIZbFoghhraQqRgGPGHFI06zxomua2/C8CWRYz1ZB80evLQAe4RA32wt/5K aTt417pDEOLsGfm8whyTfbQXLXqeIqZmEgqc8GYo4V4XMY3hYVWwgwjV8u01e29a xBXOZqqPaY6/WRgz3kpFebVnjRbdzqBTkzBBSMQptGiqJSmzXb3NU8dMdkUQEyGE lSWdq037gdg=vII2 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu releases a minor security patch for libjpeg in 20.04 LTS, tackling several vulnerabilities and enhancements.. gd security update, Red Hat security advisory, buffer overflow, NULL pointer dereference, Open source GD library. . LinuxSecurity.com Team

Calendar%202 Nov 04, 2020 Red Hat
100

SUSE: 2020:0594-2 Moderate: gd Information Disclosure and Fix

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for gd ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0594-2 Rating: moderate References: #1140120 #1165471 Cross-References: CVE-2018-14553 CVE-2019-11038 Affected Products: SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for gd fixes the following issues: Security issue fixed: - CVE-2018-14553: Fixed a null pointer dereference in gdImageClone (bsc#1165471). - CVE-2019-11038: Fixed a information disclosure in gdImageCreateFromXbm() (bsc#1140120). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP1-2020-594=1 Package List: - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1 (x86_64): gd-debugsource-2.2.5-4.14.1 libgd3-32bit-2.2.5-4.14.1 libgd3-32bit-debuginfo-2.2.5-4.14.1 References: https://www.suse.com/security/cve/CVE-2018-14553.html https://www.suse.com/security/cve/CVE-2019-11038.html https://bugzilla.suse.com/1140120 https://bugzilla.suse.com/1165471 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . The gd addresses have been revised to tackle two primary concerns: addressing moderate security vulnerabilities and detailing the installation process specifically for SUSE users.. SUSE Security Update, gdvulnerabilities, software patch, system security. . LinuxSecurity.com Team

Calendar%202 Jul 07, 2020 SuSE
202

openSUSE Leap 15.1: SUSE-SU-2020:0332-1 Moderate: gd Issues Fixed

An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for gd ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0332-1 Rating: moderate References: #1140120 #1165471 Cross-References: CVE-2018-14553 CVE-2019-11038 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for gd fixes the following issues: Security issue fixed: - CVE-2018-14553: Fixed a null pointer dereference in gdImageClone (bsc#1165471). - CVE-2019-11038: Fixed a information disclosure in gdImageCreateFromXbm() (bsc#1140120). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-332=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): gd-2.2.5-lp151.6.6.1 gd-debuginfo-2.2.5-lp151.6.6.1 gd-debugsource-2.2.5-lp151.6.6.1 gd-devel-2.2.5-lp151.6.6.1 libgd3-2.2.5-lp151.6.6.1 libgd3-debuginfo-2.2.5-lp151.6.6.1 - openSUSE Leap 15.1 (x86_64): libgd3-32bit-2.2.5-lp151.6.6.1 libgd3-32bit-debuginfo-2.2.5-lp151.6.6.1 References: https://www.suse.com/security/cve/CVE-2018-14553.html https://www.suse.com/security/cve/CVE-2019-11038.html https://bugzilla.suse.com/1140120 https://bugzilla.suse.com/1165471 -- . This release for Fedora addresses multiple vulnerabilities in php that could compromise security. Discover how to implement the fix efficiently.. openSUSE Update, gd Security Fix, Software Vulnerability, Linux Patching. . LinuxSecurity.comTeam

Calendar%202 Mar 10, 2020 OpenSUSE
100

SUSE: 2020:0623-1 Moderate: gd Buffer Over-Read and Info Exposure

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for gd ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0623-1 Rating: moderate References: #1050241 #1140120 #1165471 Cross-References: CVE-2017-7890 CVE-2018-14553 CVE-2019-11038 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP5 SUSE Linux Enterprise Workstation Extension 12-SP4 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Desktop 12-SP4 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for gd fixes the following issues: - CVE-2017-7890: Fixed a buffer over-read into uninitialized memory (bsc#1050241). - CVE-2018-14553: Fixed a null pointer dereference in gdImageClone() (bsc#1165471). - CVE-2019-11038: Fixed a information disclosure in gdImageCreateFromXbm() (bsc#1140120). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2020-623=1 - SUSE Linux Enterprise Workstation Extension 12-SP4: zypper in -t patch SUSE-SLE-WE-12-SP4-2020-623=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-623=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patchSUSE-SLE-SDK-12-SP4-2020-623=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-623=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2020-623=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2020-623=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): gd-32bit-2.1.0-24.17.1 gd-debuginfo-32bit-2.1.0-24.17.1 gd-debugsource-2.1.0-24.17.1 - SUSE Linux Enterprise Workstation Extension 12-SP4 (x86_64): gd-32bit-2.1.0-24.17.1 gd-debuginfo-32bit-2.1.0-24.17.1 gd-debugsource-2.1.0-24.17.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): gd-debuginfo-2.1.0-24.17.1 gd-debugsource-2.1.0-24.17.1 gd-devel-2.1.0-24.17.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): gd-debuginfo-2.1.0-24.17.1 gd-debugsource-2.1.0-24.17.1 gd-devel-2.1.0-24.17.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): gd-2.1.0-24.17.1 gd-debuginfo-2.1.0-24.17.1 gd-debugsource-2.1.0-24.17.1 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): gd-2.1.0-24.17.1 gd-debuginfo-2.1.0-24.17.1 gd-debugsource-2.1.0-24.17.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): gd-2.1.0-24.17.1 gd-32bit-2.1.0-24.17.1 gd-debuginfo-2.1.0-24.17.1 gd-debuginfo-32bit-2.1.0-24.17.1 gd-debugsource-2.1.0-24.17.1 References: https://www.suse.com/security/cve/CVE-2017-7890.html https://www.suse.com/security/cve/CVE-2018-14553.html https://www.suse.com/security/cve/CVE-2019-11038.html https://bugzilla.suse.com/1050241 https://bugzilla.suse.com/1140120 https://bugzilla.suse.com/1165471 _______________________________________________ sle-security-updates mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . A significant notification regarding various security flaws in gd for SUSE platforms is ready for download. More information within!. SUSE Security Update, gd vulnerabilities, security patch. . LinuxSecurity.com Team

Calendar%202 Mar 09, 2020 SuSE
100

SUSE: 2020:0594-1 Moderate: gd Information Disclosure and Null Pointer

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for gd ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0594-1 Rating: moderate References: #1140120 #1165471 Cross-References: CVE-2018-14553 CVE-2019-11038 Affected Products: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Desktop Applications 15-SP1 SUSE Linux Enterprise Module for Basesystem 15-SP1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for gd fixes the following issues: Security issue fixed: - CVE-2018-14553: Fixed a null pointer dereference in gdImageClone (bsc#1165471). - CVE-2019-11038: Fixed a information disclosure in gdImageCreateFromXbm() (bsc#1140120). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2020-594=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP1: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP1-2020-594=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2020-594=1 Package List: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (x86_64): gd-debugsource-2.2.5-4.14.1 libgd3-32bit-2.2.5-4.14.1 libgd3-32bit-debuginfo-2.2.5-4.14.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP1 (aarch64 ppc64le s390x x86_64): gd-2.2.5-4.14.1 gd-debuginfo-2.2.5-4.14.1 gd-debugsource-2.2.5-4.14.1 gd-devel-2.2.5-4.14.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): gd-debuginfo-2.2.5-4.14.1 gd-debugsource-2.2.5-4.14.1 libgd3-2.2.5-4.14.1 libgd3-debuginfo-2.2.5-4.14.1 References: https://www.suse.com/security/cve/CVE-2018-14553.html https://www.suse.com/security/cve/CVE-2019-11038.html https://bugzilla.suse.com/1140120 https://bugzilla.suse.com/1165471 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Patch resolves minor vulnerabilities in gd across various business modules, notably concerning data exposure.. SUSE Security Update, gd information disclosure, Linux Enterprise Module, null pointer dereference, SUSE patch instructions. . LinuxSecurity.com Team

Calendar%202 Mar 05, 2020 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200