* bsc#1237093 Cross-References: * CVE-2025-1094 . # Security update for postgresql15 Announcement ID: SUSE-SU-2025:00614-1 Release Date: 2025-09-04T13:26:20Z Rating: important References: * bsc#1237093 Cross-References: * CVE-2025-1094 CVSS scores: * CVE-2025-1094 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-1094 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-1094 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Legacy Module 15-SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for postgresql15 fixes the following issues: Upgrade to 15.12: * CVE-2025-1094: Harden PQescapeString and allied functions against invalidly- encoded input strings (bsc#1237093). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2025-614=1 ## Package List: * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql15-contrib-15.12-150600.16.14.1 * postgresql15-devel-15.12-150600.16.14.1 * postgresql15-pltcl-debuginfo-15.12-150600.16.14.1 * postgresql15-15.12-150600.16.14.1 * postgresql15-plperl-15.12-150600.16.14.1 * postgresql15-plpython-15.12-150600.16.14.1 * postgresql15-server-debuginfo-15.12-150600.16.14.1 * postgresql15-plpython-debuginfo-15.12-150600.16.14.1 * postgresql15-server-devel-15.12-150600.16.14.1 * postgresql15-debuginfo-15.12-150600.16.14.1 * postgresql15-server-devel-debuginfo-15.12-150600.16.14.1 * postgresql15-pltcl-15.12-150600.16.14.1 * postgresql15-contrib-debuginfo-15.12-150600.16.14.1 *postgresql15-plperl-debuginfo-15.12-150600.16.14.1 * postgresql15-server-15.12-150600.16.14.1 * postgresql15-debugsource-15.12-150600.16.14.1 * postgresql15-devel-debuginfo-15.12-150600.16.14.1 ## References: * https://www.suse.com/security/cve/CVE-2025-1094.html * https://bugzilla.suse.com/show_bug.cgi?id=1237093 . New patch issued for PostgreSQL version 15 addressing significant security flaws related to input validation attacks.. PostgreSQL 15 Patch, Input Validation Issue, SUSE Security Update. . Severity: Important. LinuxSecurity.com Team
GNU binutils could be made to crash if it received a specially crafted input.. ======================================================================= Ubuntu Security Notice USN-7718-1 August 26, 2025 binutils vulnerability ======================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: GNU binutils could be made to crash if it received a specially crafted input. Software Description: - binutils: GNU assembler, linker and binary utilities Details: It was discovered that GNU binutils incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS binutils 2.26.1-1ubuntu1~16.04.8+esm12 Available with Ubuntu Pro binutils-multiarch 2.26.1-1ubuntu1~16.04.8+esm12 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7718-1 CVE-2025-7545 . Linux binutils presents a vulnerability in Ubuntu 16.04 when handling specially designed inputs; urgent patches suggested to address potential threats.. Ubuntu binutils security issue, GNU binutils update, Ubuntu 16.04 LTS security advisory. . Severity: Critical. LinuxSecurity.com Team
* bsc#1244705 Cross-References: * CVE-2025-6069 . # Security update for python39 Announcement ID: SUSE-SU-2025:02232-1 Release Date: 2025-07-07T08:17:52Z Rating: moderate References: * bsc#1244705 Cross-References: * CVE-2025-6069 CVSS scores: * CVE-2025-6069 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H * CVE-2025-6069 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2025-6069 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.6 An update that solves one vulnerability can now be installed. ## Description: This update for python39 fixes the following issues: * CVE-2025-6069: Avoid worst case quadratic complexity when processing certain crafted malformed inputs with HTMLParser (bsc#1244705). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-2232=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2232=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * python39-devel-3.9.23-150300.4.78.1 * libpython3_9-1_0-3.9.23-150300.4.78.1 * python39-debuginfo-3.9.23-150300.4.78.1 * python39-doc-3.9.23-150300.4.78.1 * python39-testsuite-debuginfo-3.9.23-150300.4.78.1 * python39-idle-3.9.23-150300.4.78.1 * python39-base-debuginfo-3.9.23-150300.4.78.1 * python39-doc-devhelp-3.9.23-150300.4.78.1 * libpython3_9-1_0-debuginfo-3.9.23-150300.4.78.1 * python39-tk-debuginfo-3.9.23-150300.4.78.1 * python39-tools-3.9.23-150300.4.78.1 * python39-debugsource-3.9.23-150300.4.78.1 * python39-testsuite-3.9.23-150300.4.78.1 * python39-base-3.9.23-150300.4.78.1 * python39-dbm-3.9.23-150300.4.78.1 *python39-core-debugsource-3.9.23-150300.4.78.1 * python39-3.9.23-150300.4.78.1 * python39-dbm-debuginfo-3.9.23-150300.4.78.1 * python39-curses-debuginfo-3.9.23-150300.4.78.1 * python39-curses-3.9.23-150300.4.78.1 * python39-tk-3.9.23-150300.4.78.1 * openSUSE Leap 15.3 (x86_64) * python39-32bit-debuginfo-3.9.23-150300.4.78.1 * python39-32bit-3.9.23-150300.4.78.1 * libpython3_9-1_0-32bit-3.9.23-150300.4.78.1 * libpython3_9-1_0-32bit-debuginfo-3.9.23-150300.4.78.1 * python39-base-32bit-3.9.23-150300.4.78.1 * python39-base-32bit-debuginfo-3.9.23-150300.4.78.1 * openSUSE Leap 15.3 (aarch64_ilp32) * libpython3_9-1_0-64bit-3.9.23-150300.4.78.1 * libpython3_9-1_0-64bit-debuginfo-3.9.23-150300.4.78.1 * python39-64bit-debuginfo-3.9.23-150300.4.78.1 * python39-base-64bit-3.9.23-150300.4.78.1 * python39-64bit-3.9.23-150300.4.78.1 * python39-base-64bit-debuginfo-3.9.23-150300.4.78.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python39-devel-3.9.23-150300.4.78.1 * libpython3_9-1_0-3.9.23-150300.4.78.1 * python39-debuginfo-3.9.23-150300.4.78.1 * python39-doc-3.9.23-150300.4.78.1 * python39-testsuite-debuginfo-3.9.23-150300.4.78.1 * python39-idle-3.9.23-150300.4.78.1 * python39-base-debuginfo-3.9.23-150300.4.78.1 * python39-doc-devhelp-3.9.23-150300.4.78.1 * libpython3_9-1_0-debuginfo-3.9.23-150300.4.78.1 * python39-tk-debuginfo-3.9.23-150300.4.78.1 * python39-tools-3.9.23-150300.4.78.1 * python39-debugsource-3.9.23-150300.4.78.1 * python39-testsuite-3.9.23-150300.4.78.1 * python39-base-3.9.23-150300.4.78.1 * python39-dbm-3.9.23-150300.4.78.1 * python39-core-debugsource-3.9.23-150300.4.78.1 * python39-3.9.23-150300.4.78.1 * python39-dbm-debuginfo-3.9.23-150300.4.78.1 * python39-curses-debuginfo-3.9.23-150300.4.78.1 * python39-curses-3.9.23-150300.4.78.1 * python39-tk-3.9.23-150300.4.78.1 * openSUSE Leap 15.6 (x86_64) *python39-32bit-debuginfo-3.9.23-150300.4.78.1 * python39-32bit-3.9.23-150300.4.78.1 * libpython3_9-1_0-32bit-3.9.23-150300.4.78.1 * libpython3_9-1_0-32bit-debuginfo-3.9.23-150300.4.78.1 * python39-base-32bit-3.9.23-150300.4.78.1 * python39-base-32bit-debuginfo-3.9.23-150300.4.78.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6069.html * https://bugzilla.suse.com/show_bug.cgi?id=1244705 . This announcement covers a critical update for python39 on openSUSE in response to CVE-2025-6069, which impacts how input is handled.. openSUSE Python security fix,SUPE advisory,security issues. . LinuxSecurity.com Team
Fix CVE-2023-26159. ---- Relax requirements.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-9818cb2406 2024-01-23 00:57:15.298490 -------------------------------------------------------------------------------- Name : pgadmin4 Product : Fedora 39 Version : 7.8 Release : 3.fc39 URL : https://www.pgadmin.org/ Summary : Administration tool for PostgreSQL Description : pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world. -------------------------------------------------------------------------------- Update Information: Fix CVE-2023-26159. ---- Relax requirements. -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 14 2024 Sandro Mani - 7.8-3 - Regenerate vendor tarball for newer follow-redirects (CVE-2023-26159) * Sun Jan 14 2024 Sandro Mani - 7.8-2 - Relax boto3, botocore, psycopg3 requirements * Sun Oct 22 2023 Sandro Mani - 7.8-1 - Update to 7.8 * Sat Sep 30 2023 Sandro Mani - 7.7-2 - Relax flask-wtf requires -------------------------------------------------------------------------------- References: [ 1 ] Bug #2256418 - TRIAGE CVE-2023-26159 pgadmin4: follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2256418 [ 2 ] Bug #2258325 - F39FailsToInstall: pgadmin4 https://bugzilla.redhat.com/show_bug.cgi?id=2258325 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-9818cb2406' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
It was discovered that missing input sanitising in libspreadsheet-parseexcel-perl, a Perl module to access information from Excel Spreadsheets, may result in the execution of arbitrary commands if a specially crafted document file is processed. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5592-1
RedCloth could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-6358-1 September 12, 2023 ruby-redcloth vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: RedCloth could be made to crash if it received specially crafted input. Software Description: - ruby-redcloth: Textile module for Ruby Details: It was discovered that RedCloth incorrectly handled certain inputs during html sanitisation. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: ruby-redcloth 4.3.2-4ubuntu0.23.04.1 Ubuntu 22.04 LTS: ruby-redcloth 4.3.2-4ubuntu0.22.04.1 Ubuntu 20.04 LTS: ruby-redcloth 4.3.2-3+deb10u1build0.20.04.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): ruby-redcloth 4.3.2-3ubuntu0.1~esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): ruby-redcloth 4.2.9-5ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6358-1 CVE-2023-31606 Package Information: https://launchpad.net/ubuntu/+source/ruby-redcloth/4.3.2-4ubuntu0.23.04.1 https://launchpad.net/ubuntu/+source/ruby-redcloth/4.3.2-4ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/ruby-redcloth/4.3.2-3+deb10u1build0.20.04.1 . BlueFabric security flaw identified within Ubuntu releases, posing risk of service interruption stemming from improper input management.. RedCloth Vulnerability,Ubuntu Security, Denial Of Service. . LinuxSecurity.com Team
update to 2.40.1 (CVE-2023-25652, CVE-2023-25815, CVE-2023-29007) Refer to the release notes for 2.30.9 for details of each CVE as well as the following security advisories from the git project: https://github.com/git/git/security/advisories/GHSA-2hvf-7c8p-28fx (CVE-2023-25652). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-eaf1bdd5ae 2023-04-28 02:35:08.160953 --------------------------------------------------------------------------------Name : git Product : Fedora 38 Version : 2.40.1 Release : 1.fc38 URL : https://git-scm.com/ Summary : Fast Version Control System Description : Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. The git rpm installs common set of tools which are usually using with small amount of dependencies. To install all git packages, including tools for integrating with other SCMs, install the git-all meta-package. --------------------------------------------------------------------------------Update Information: update to 2.40.1 (CVE-2023-25652, CVE-2023-25815, CVE-2023-29007) Refer to the release notes for 2.30.9 for details of each CVE as well as the following security advisories from the git project: https://github.com/git/git/security/advisories/GHSA-2hvf-7c8p-28fx (CVE-2023-25652) https://github.com/git/git/security/advisories/GHSA-v48j-4xgg-4844 (CVE-2023-29007) (At this time there is no upstream advisory for CVE-2023-25815. This issue does not affect the Fedora packages as we do not use the runtime prefix support.) Release notes: https://raw.githubusercontent.com/git/git/v2.30.9/Documentation/RelNotes/2.30.9.txt https://raw.githubusercontent.com/git/git/v2.40.1/Documentation/RelNotes/2.40.1.txt --------------------------------------------------------------------------------ChangeLog: * Tue Apr 25 2023 ToddZullinger - 2.40.1-1 - update to 2.40.1 (CVE-2023-25652, CVE-2023-25815, CVE-2023-29007) --------------------------------------------------------------------------------References: [ 1 ] Bug #2188333 - CVE-2023-25652 git: by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwritten with partially controlled contents https://bugzilla.redhat.com/show_bug.cgi?id=2188333 [ 2 ] Bug #2188338 - CVE-2023-29007 git: arbitrary configuration injection when renaming or deleting a section from a configuration file https://bugzilla.redhat.com/show_bug.cgi?id=2188338 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-eaf1bdd5ae' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
**Version 0.16.3** (2023-04-11) Security * Fixed issue with possible hang on malformed inputs (**CVE-2023-29479**). * Fixed issue where in some cases, secret keys remain unlocked after use (**CVE-2023-29480**).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-609db87741 2023-04-22 01:11:17.771496 --------------------------------------------------------------------------------Name : rnp Product : Fedora 36 Version : 0.16.3 Release : 1.fc36 URL : https://github.com/rnpgp/rnp Summary : OpenPGP (RFC4880) tools Description : RNP is a set of OpenPGP (RFC4880) tools. --------------------------------------------------------------------------------Update Information: **Version 0.16.3** (2023-04-11) Security * Fixed issue with possible hang on malformed inputs (**CVE-2023-29479**). * Fixed issue where in some cases, secret keys remain unlocked after use (**CVE-2023-29480**). --------------------------------------------------------------------------------ChangeLog: * Thu Apr 13 2023 Remi Collet - 0.16.3-1 - update to 0.16.3 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-609db87741' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.