Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 23 articles for you...
100

SUSE: 2024:1351-2 Low: Fix for Graphviz Out-Of-Bounds Read Issue

* bsc#1219491 Cross-References: * CVE-2023-46045 . # Security update for graphviz Announcement ID: SUSE-SU-2024:1351-2 Rating: low References: * bsc#1219491 Cross-References: * CVE-2023-46045 CVSS scores: * CVE-2023-46045 ( SUSE ): 3.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L * CVE-2023-46045 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP5 * Desktop Applications Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for graphviz fixes the following issues: * CVE-2023-46045: Fixed out-of-bounds read via a crafted config6a file (bsc#1219491) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2024-1351=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2024-1351=1 ## Package List: * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * graphviz-gd-2.48.0-150400.3.3.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * graphviz-gd-2.48.0-150400.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-46045.html * https://bugzilla.suse.com/show_bug.cgi?id=1219491 . Graphviz now addresses minor vulnerabilities related to out-of-bounds readoperations. You can install the latest version using the SUSE package manager.. graphviz update, SUSE security fix, out-of-bounds read, security advisory, low severity fix. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Sep 03, 2024 Low SuSE
172

Ubuntu 20.04 ESM USN-5971-1 Critical: Graphviz Denial Of Service

Several security issues were fixed in graphviz.. =========================================================================Ubuntu Security Notice USN-5971-1 March 24, 2023 graphviz vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 ESM - Ubuntu 18.04 ESM - Ubuntu 14.04 ESM Summary: Several security issues were fixed in graphviz. Software Description: - graphviz: rich set of graph drawing tools Details: It was discovered that graphviz contains null pointer dereference vulnerabilities. Exploitation via a specially crafted input file can cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-10196) It was discovered that graphviz contains null pointer dereference vulnerabilities. Exploitation via a specially crafted input file can cause a denial of service. These issues only affected Ubuntu 14.04 ESM and Ubuntu 18.04 LTS. (CVE-2019-11023) It was discovered that graphviz contains a buffer overflow vulnerability. Exploitation via a specially crafted input file can cause a denial of service or possibly allow for arbitrary code execution. These issues only affected Ubuntu 14.04 ESM, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-18032) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 ESM: graphviz 2.42.2-3ubuntu0.1~esm1 Ubuntu 18.04 ESM: graphviz 2.40.1-2ubuntu0.1~esm1 Ubuntu 14.04 ESM: graphviz 2.36.0-0ubuntu3.2+esm1 The problem can be corrected by updating your system to the following package versions: References: https://ubuntu.com/security/notices/USN-5971-1 CVE-2018-10196, CVE-2019-11023, CVE-2020-18032 . Various flaws addressed in Graphviz for Ubuntu users to mitigate denial of service and security risks.. Graphviz Vulnerabilities, Denial of Service, Software Fixes, Security Update. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Mar 24, 2023 Critical Ubuntu
172

Ubuntu 16.04 ESM: USN-5264-1 Critical: Graphviz Buffer Overflow

Several security issues were fixed in graphviz.. =========================================================================Ubuntu Security Notice USN-5264-1 February 03, 2022 graphviz vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Several security issues were fixed in graphviz. Software Description: - graphviz: rich set of graph drawing tools Details: It was discovered that graphviz contains null pointer dereference vulnerabilities. Exploitation via a specially crafted input file can cause a denial of service. (CVE-2018-10196, CVE-2019-11023) It was discovered that graphviz contains a buffer overflow vulnerability. Exploitation via a specially crafted input file can cause a denial of service or possibly allow for arbitrary code execution. (CVE-2020-18032) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: graphviz 2.38.0-12ubuntu2.1+esm1 libcdt5 2.38.0-12ubuntu2.1+esm1 libcgraph6 2.38.0-12ubuntu2.1+esm1 libgvc6 2.38.0-12ubuntu2.1+esm1 libgvc6-plugins-gtk 2.38.0-12ubuntu2.1+esm1 libgvpr2 2.38.0-12ubuntu2.1+esm1 libpathplan4 2.38.0-12ubuntu2.1+esm1 libxdot4 2.38.0-12ubuntu2.1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5264-1 CVE-2018-10196, CVE-2019-11023, CVE-2020-18032 . A series of security issues rectified in graphviz for Ubuntu 16.04 ESM, tackling severe safety threats.. Graphviz Security, Ubuntu Graphviz Fix, Denial of Service, Buffer Overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 03, 2022 Critical Ubuntu
98

Red Hat Enterprise Linux 8: RHSA-2021-4256 Moderate: Graphviz Security Fix

An update for graphviz is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: graphviz security update Advisory ID: RHSA-2021:4256-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:4256 Issue date: 2021-11-09 CVE Names: CVE-2020-18032 ==================================================================== 1. Summary: An update for graphviz is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux CRB (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: Graphviz is open-source graph-visualization software. Graph visualization is a way of representing structural information as diagrams of abstract graphs and networks. It has important applications in networking, bioinformatics, software engineering, database and web design, machine learning, and in visual interfaces for other technical domains. Security Fix(es): * graphviz: off-by-one in parse_reclbl() in lib/common/shapes.c (CVE-2020-18032) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information onchanges in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1966272 - CVE-2020-18032 graphviz: off-by-one in parse_reclbl() in lib/common/shapes.c 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: graphviz-2.40.1-43.el8.src.rpm aarch64: graphviz-2.40.1-43.el8.aarch64.rpm graphviz-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-debugsource-2.40.1-43.el8.aarch64.rpm graphviz-gd-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-guile-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-java-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-lua-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-ocaml-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-perl-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-python3-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-ruby-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-tcl-debuginfo-2.40.1-43.el8.aarch64.rpm ppc64le: graphviz-2.40.1-43.el8.ppc64le.rpm graphviz-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-debugsource-2.40.1-43.el8.ppc64le.rpm graphviz-gd-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-guile-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-java-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-lua-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-ocaml-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-perl-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-python3-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-ruby-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-tcl-debuginfo-2.40.1-43.el8.ppc64le.rpm s390x: graphviz-2.40.1-43.el8.s390x.rpm graphviz-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-debugsource-2.40.1-43.el8.s390x.rpm graphviz-gd-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-guile-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-java-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-lua-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-ocaml-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-perl-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-python3-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-ruby-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-tcl-debuginfo-2.40.1-43.el8.s390x.rpm x86_64: graphviz-2.40.1-43.el8.i686.rpm graphviz-2.40.1-43.el8.x86_64.rpm graphviz-debuginfo-2.40.1-43.el8.i686.rpm graphviz-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-debugsource-2.40.1-43.el8.i686.rpm graphviz-debugsource-2.40.1-43.el8.x86_64.rpm graphviz-gd-debuginfo-2.40.1-43.el8.i686.rpm graphviz-gd-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-guile-debuginfo-2.40.1-43.el8.i686.rpm graphviz-guile-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-java-debuginfo-2.40.1-43.el8.i686.rpm graphviz-java-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-lua-debuginfo-2.40.1-43.el8.i686.rpm graphviz-lua-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-ocaml-debuginfo-2.40.1-43.el8.i686.rpm graphviz-ocaml-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-perl-debuginfo-2.40.1-43.el8.i686.rpm graphviz-perl-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-python3-debuginfo-2.40.1-43.el8.i686.rpm graphviz-python3-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-ruby-debuginfo-2.40.1-43.el8.i686.rpm graphviz-ruby-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-tcl-debuginfo-2.40.1-43.el8.i686.rpm graphviz-tcl-debuginfo-2.40.1-43.el8.x86_64.rpm Red Hat Enterprise Linux CRB (v.8): aarch64: graphviz-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-debugsource-2.40.1-43.el8.aarch64.rpm graphviz-devel-2.40.1-43.el8.aarch64.rpm graphviz-doc-2.40.1-43.el8.aarch64.rpm graphviz-gd-2.40.1-43.el8.aarch64.rpm graphviz-gd-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-guile-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-java-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-lua-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-ocaml-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-perl-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-python3-2.40.1-43.el8.aarch64.rpm graphviz-python3-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-ruby-debuginfo-2.40.1-43.el8.aarch64.rpm graphviz-tcl-debuginfo-2.40.1-43.el8.aarch64.rpm ppc64le: graphviz-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-debugsource-2.40.1-43.el8.ppc64le.rpm graphviz-devel-2.40.1-43.el8.ppc64le.rpm graphviz-doc-2.40.1-43.el8.ppc64le.rpm graphviz-gd-2.40.1-43.el8.ppc64le.rpm graphviz-gd-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-guile-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-java-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-lua-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-ocaml-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-perl-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-python3-2.40.1-43.el8.ppc64le.rpm graphviz-python3-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-ruby-debuginfo-2.40.1-43.el8.ppc64le.rpm graphviz-tcl-debuginfo-2.40.1-43.el8.ppc64le.rpm s390x: graphviz-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-debugsource-2.40.1-43.el8.s390x.rpm graphviz-devel-2.40.1-43.el8.s390x.rpm graphviz-doc-2.40.1-43.el8.s390x.rpm graphviz-gd-2.40.1-43.el8.s390x.rpm graphviz-gd-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-guile-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-java-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-lua-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-ocaml-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-perl-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-python3-2.40.1-43.el8.s390x.rpm graphviz-python3-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-ruby-debuginfo-2.40.1-43.el8.s390x.rpm graphviz-tcl-debuginfo-2.40.1-43.el8.s390x.rpm x86_64: graphviz-debuginfo-2.40.1-43.el8.i686.rpm graphviz-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-debugsource-2.40.1-43.el8.i686.rpm graphviz-debugsource-2.40.1-43.el8.x86_64.rpm graphviz-devel-2.40.1-43.el8.i686.rpm graphviz-devel-2.40.1-43.el8.x86_64.rpm graphviz-doc-2.40.1-43.el8.x86_64.rpm graphviz-gd-2.40.1-43.el8.i686.rpm graphviz-gd-2.40.1-43.el8.x86_64.rpm graphviz-gd-debuginfo-2.40.1-43.el8.i686.rpm graphviz-gd-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-guile-debuginfo-2.40.1-43.el8.i686.rpm graphviz-guile-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-java-debuginfo-2.40.1-43.el8.i686.rpm graphviz-java-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-lua-debuginfo-2.40.1-43.el8.i686.rpm graphviz-lua-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-ocaml-debuginfo-2.40.1-43.el8.i686.rpm graphviz-ocaml-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-perl-debuginfo-2.40.1-43.el8.i686.rpm graphviz-perl-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-python3-2.40.1-43.el8.x86_64.rpm graphviz-python3-debuginfo-2.40.1-43.el8.i686.rpm graphviz-python3-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-ruby-debuginfo-2.40.1-43.el8.i686.rpm graphviz-ruby-debuginfo-2.40.1-43.el8.x86_64.rpm graphviz-tcl-debuginfo-2.40.1-43.el8.i686.rpm graphviz-tcl-debuginfo-2.40.1-43.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-18032 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.5_release_notes/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYYrestzjgjWX9erEAQhXZQ//aut5YnStZG6vpKvWKL3s8fZLv0i4Qe3v ATPqs/6HyvEJj+D/YJiWDoh/dClSVwzPYR2injoXNlAtIFfG1njFQR5VQIcnB7PG U4r37NybEMhUrNmPGkOHL3aCCaDG3Lv2LKV+YKRAhpFOcRnANTo2idQOYRPwpU1D BJne60A9CD4mXSARqBzAdHwE+Txykka4hpwfYFlFPr6Otxle1+VovO4cZ3CXGdTS kuhAivN3h5fXQCfwc4HXmDt7L5C2xans+kPqIOjN5JR66ISDMckNgQUu9668r3BN D3wpT+1n58v4dN/R0kr02M3R5rEcZS+oWdyNKc8IUelv+fp27GHRe5cr8FzYBx0C mQhQvgbn3vbtNMG9C2tMV642oS7nBqsNY8XcLz0ASOXBsxvp5d7U5RgoAZ/whFH8 1xYuXrzbxmNKidy0o1VSdOCr4iLqRM3qQTFl0z34Vhi4Er7e+lFy0cGMQat4RKJA vqvaAUgVD6c4rcr7k84b+YqV9DXbpWbpL9sSfIGpiJS9ROY08d9FpxkWY2lbJ8J9 fm7Vw7Or7na5geK6MIbVeHfQl7/c3erSdRdPL2uBVPaUDE6SP4yzw8G9dPjmOVii X3YYs/7dMb4o2TbRnAy+PLBKUEj0r6S3gRi1ObH1qtqeHe4luu5wuN8UrLMVUGTK 1QSJLN5+Uho=LTtI -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest update for Red Hat Enterprise Linux 8 addresses a critical vulnerability in Graphviz, rectifying an off-by-one flaw to enhance system security.. graphviz Update, Red Hat Security, Linux Patch, Software Update. . LinuxSecurity.com Team

Calendar%202 Nov 09, 2021 Red Hat
202

openSUSE Leap 15.3: 2021:1651-1 Critical: Graphviz Remote Code Execution

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for graphviz ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1651-1 Rating: critical References: #1185833 Cross-References: CVE-2020-18032 CVSS scores: CVE-2020-18032 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2020-18032 (SUSE): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for graphviz fixes the following issues: - CVE-2020-18032: Fixed possible remote code execution via buffer overflow (bsc#1185833). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-1651=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): graphviz-2.40.1-6.9.1 graphviz-addons-debuginfo-2.40.1-6.9.1 graphviz-addons-debugsource-2.40.1-6.9.1 graphviz-debuginfo-2.40.1-6.9.1 graphviz-debugsource-2.40.1-6.9.1 graphviz-devel-2.40.1-6.9.1 graphviz-doc-2.40.1-6.9.1 graphviz-gd-2.40.1-6.9.1 graphviz-gd-debuginfo-2.40.1-6.9.1 graphviz-gnome-2.40.1-6.9.1 graphviz-gnome-debuginfo-2.40.1-6.9.1 graphviz-guile-2.40.1-6.9.1 graphviz-guile-debuginfo-2.40.1-6.9.1 graphviz-gvedit-2.40.1-6.9.1 graphviz-gvedit-debuginfo-2.40.1-6.9.1 graphviz-java-2.40.1-6.9.1 graphviz-java-debuginfo-2.40.1-6.9.1 graphviz-lua-2.40.1-6.9.1 graphviz-lua-debuginfo-2.40.1-6.9.1 graphviz-perl-2.40.1-6.9.1 graphviz-perl-debuginfo-2.40.1-6.9.1 graphviz-php-2.40.1-6.9.1 graphviz-php-debuginfo-2.40.1-6.9.1 graphviz-plugins-core-2.40.1-6.9.1 graphviz-plugins-core-debuginfo-2.40.1-6.9.1 graphviz-python-2.40.1-6.9.1 graphviz-python-debuginfo-2.40.1-6.9.1 graphviz-ruby-2.40.1-6.9.1 graphviz-ruby-debuginfo-2.40.1-6.9.1 graphviz-smyrna-2.40.1-6.9.1 graphviz-smyrna-debuginfo-2.40.1-6.9.1 graphviz-tcl-2.40.1-6.9.1 graphviz-tcl-debuginfo-2.40.1-6.9.1 libgraphviz6-2.40.1-6.9.1 libgraphviz6-debuginfo-2.40.1-6.9.1 References: https://www.suse.com/security/cve/CVE-2020-18032.html https://bugzilla.suse.com/1185833 . Repair for openSUSE Leap 15.3 addresses crucial vulnerability in graphviz enabling remote code execution. Update is now accessible.. OpenSUSE Security Update, Graphviz Critical Fix, Remote Code Execution Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 10, 2021 Critical OpenSUSE
91

Gentoo: GLSA-202201-03 Normal: Graphviz Security Vulnerabilities

Multiple vulnerabilities have been found in Graphviz, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Graphviz: Multiple vulnerabilities Date: July 03, 2021 Bugs: #684844 ID: 202107-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Graphviz, the worst of which could result in the arbitrary execution of code. Background ========= Graphviz is an open source graph visualization software. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/graphviz < 2.47.1 > = 2.47.1 Description ========== Multiple vulnerabilities have been discovered in Graphviz. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could entice a user to process a specially crafted file using Graphviz, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Graphviz users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/graphviz-2.47.1" References ========= [ 1 ] CVE-2019-9904 https://nvd.nist.gov/vuln/detail/CVE-2019-9904 [ 2 ] CVE-2020-18032 https://nvd.nist.gov/vuln/detail/CVE-2020-18032 Availability =========== This GLSA and anyupdates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202107-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Several security flaws found in Graphviz may result in unauthorized code execution or Denial of Service issues on Gentoo systems.. Graphviz Security Advisory,Gentoo Update,Open Source Vulnerability. . LinuxSecurity.com Team

Calendar%202 Jul 03, 2021 Gentoo
203

Mageia 7, 8: MGASA-2021-0228 Severe: Graphviz Remote Code Execution

Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component. (CVE-2020-18032) References: - https://bugs.mageia.org/show_bug.cgi?id=28989 - https://lists.debian.org/debian-security-announce/2021/msg00095.html . MGASA-2021-0228 - Updated graphviz packages fix a security vulnerability Publication date: 08 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0228.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2020-18032 Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component. (CVE-2020-18032) References: - https://bugs.mageia.org/show_bug.cgi?id=28989 - https://lists.debian.org/debian-security-announce/2021/msg00095.html - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/D5PQPHJHPU46FK3R5XBP3XDT4X37HMPC/ - - https://www.cve.org/CVERecord?id=CVE-2020-18032 SRPMS: - 8/core/graphviz-2.44.1-2.1.mga8 - 7/core/graphviz-2.40.1-17.2.mga7 . The advisory issued by Mageia on 2021-0228 highlights a critical vulnerability in Graphviz that could enable remote code execution or lead to system crashes.. Graphviz Security Update, Buffer Overflow, Mageia Releases, Code Execution. . LinuxSecurity.com Team

Calendar%202 Jun 08, 2021 Mageia
202

openSUSE Leap 15.2: 2021:0757-1 Critical: Graphviz Remote Execution

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for graphviz ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0757-1 Rating: critical References: #1185833 Cross-References: CVE-2020-18032 CVSS scores: CVE-2020-18032 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2020-18032 (SUSE): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for graphviz fixes the following issues: - CVE-2020-18032: Fixed possible remote code execution via buffer overflow (bsc#1185833). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-757=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): graphviz-2.40.1-lp152.7.10.1 graphviz-addons-debuginfo-2.40.1-lp152.7.10.1 graphviz-addons-debugsource-2.40.1-lp152.7.10.1 graphviz-debuginfo-2.40.1-lp152.7.10.1 graphviz-debugsource-2.40.1-lp152.7.10.1 graphviz-devel-2.40.1-lp152.7.10.1 graphviz-doc-2.40.1-lp152.7.10.1 graphviz-gd-2.40.1-lp152.7.10.1 graphviz-gd-debuginfo-2.40.1-lp152.7.10.1 graphviz-gnome-2.40.1-lp152.7.10.1 graphviz-gnome-debuginfo-2.40.1-lp152.7.10.1 graphviz-guile-2.40.1-lp152.7.10.1 graphviz-guile-debuginfo-2.40.1-lp152.7.10.1 graphviz-gvedit-2.40.1-lp152.7.10.1 graphviz-gvedit-debuginfo-2.40.1-lp152.7.10.1 graphviz-java-2.40.1-lp152.7.10.1 graphviz-java-debuginfo-2.40.1-lp152.7.10.1 graphviz-lua-2.40.1-lp152.7.10.1 graphviz-lua-debuginfo-2.40.1-lp152.7.10.1 graphviz-perl-2.40.1-lp152.7.10.1 graphviz-perl-debuginfo-2.40.1-lp152.7.10.1 graphviz-php-2.40.1-lp152.7.10.1 graphviz-php-debuginfo-2.40.1-lp152.7.10.1 graphviz-plugins-core-2.40.1-lp152.7.10.1 graphviz-plugins-core-debuginfo-2.40.1-lp152.7.10.1 graphviz-python-2.40.1-lp152.7.10.1 graphviz-python-debuginfo-2.40.1-lp152.7.10.1 graphviz-ruby-2.40.1-lp152.7.10.1 graphviz-ruby-debuginfo-2.40.1-lp152.7.10.1 graphviz-smyrna-2.40.1-lp152.7.10.1 graphviz-smyrna-debuginfo-2.40.1-lp152.7.10.1 graphviz-tcl-2.40.1-lp152.7.10.1 graphviz-tcl-debuginfo-2.40.1-lp152.7.10.1 libgraphviz6-2.40.1-lp152.7.10.1 libgraphviz6-debuginfo-2.40.1-lp152.7.10.1 References: https://www.suse.com/security/cve/CVE-2020-18032.html https://bugzilla.suse.com/1185833 . Important openSUSE Security Patch for libcurl addresses vulnerabilities related to arbitrary code execution, notably CVE-2020-8284.. openSUSE Security Update, Graphviz Patch, Remote Execution Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 22, 2021 Critical OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200