An update that solves 2 vulnerabilities can now be installed.. # glow-2.1.1-2.1 on GA media Announcement ID: openSUSE-SU-2025:15607-1 Rating: moderate Cross-References: * CVE-2025-47911 * CVE-2025-58190 CVSS scores: * CVE-2025-47911 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58190 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the glow-2.1.1-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * glow 2.1.1-2.1 * glow-bash-completion 2.1.1-2.1 * glow-fish-completion 2.1.1-2.1 * glow-zsh-completion 2.1.1-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-47911.html * https://www.suse.com/security/cve/CVE-2025-58190.html . Update for glow-2.1.1-2.1 resolves two moderate security issues in openSUSE Tumbleweed.. openSUSE update, glow application, moderate security, application vulnerabilities. . LinuxSecurity.com Team
Update to version 2.1.1 for various bugfixes. This also fixes CVE-2025-22872 in the bundled golang.org/x/net/html.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-0f0b3d191c 2025-06-27 01:57:49.068480+00:00 -------------------------------------------------------------------------------- Name : glow Product : Fedora 41 Version : 2.1.1 Release : 1.fc41 URL : https://github.com/charmbracelet/glow Summary : Terminal based markdown reader Description : Glow is a terminal based markdown reader designed from the ground up to bring out the beautyâand powerâof the CLI. Use it to discover markdown files, read documentation directly on the command line. Glow will find local markdown files in subdirectories or a local Git repository. -------------------------------------------------------------------------------- Update Information: Update to version 2.1.1 for various bugfixes. This also fixes CVE-2025-22872 in the bundled golang.org/x/net/html. -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 18 2025 Carl George - 2.1.1-1 - Update to version 2.1.1 rhbz#2369460 * Fri Apr 18 2025 Carl George - 2.1.0-1 - Update to version 2.1.0 rhbz#2348672 * Thu Jan 16 2025 Fedora Release Engineering - 2.0.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2360594 - CVE-2025-22872 glow: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2360594 [ 2 ] Bug #2369460 - glow-2.1.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2369460 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2025-0f0b3d191c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 41 users, ensure you update glow to version 2.1.1 for vital fixes that address major vulnerabilities and improve system stability and security. Fedora Update, glow, security advisory, software update. . Severity: Important. LinuxSecurity.com Team
Update to version 2.1.1 for various bugfixes. This also fixes CVE-2025-22872 in the bundled golang.org/x/net/html.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e023994b32 2025-06-27 01:19:29.251079+00:00 -------------------------------------------------------------------------------- Name : glow Product : Fedora 42 Version : 2.1.1 Release : 1.fc42 URL : https://github.com/charmbracelet/glow Summary : Terminal based markdown reader Description : Glow is a terminal based markdown reader designed from the ground up to bring out the beautyâand powerâof the CLI. Use it to discover markdown files, read documentation directly on the command line. Glow will find local markdown files in subdirectories or a local Git repository. -------------------------------------------------------------------------------- Update Information: Update to version 2.1.1 for various bugfixes. This also fixes CVE-2025-22872 in the bundled golang.org/x/net/html. -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 18 2025 Carl George - 2.1.1-1 - Update to version 2.1.1 rhbz#2369460 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2360634 - CVE-2025-22872 glow: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2360634 [ 2 ] Bug #2369460 - glow-2.1.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2369460 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e023994b32' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with theFedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Addresses major vulnerabilities, specifically CVE-2025-22873, enhancing performance on Ubuntu 24. Make sure to update today for a safer computing environment!. CVE-2025-22872, terminal reader, Fedora 42, glow, security fixes. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.