Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355025) CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355023) CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-3a7a29de24 2025-04-10 02:44:37.887866+00:00 -------------------------------------------------------------------------------- Name : ghostscript Product : Fedora 40 Version : 10.02.1 Release : 14.fc40 URL : https://ghostscript.com/ Summary : Interpreter for PostScript language & PDF Description : This package provides useful conversion utilities based on Ghostscript software, for converting PS, PDF and other document formats between each other. Ghostscript is a suite of software providing an interpreter for Adobe Systems' PostScript (PS) and Portable Document Format (PDF) page description languages. Its primary purpose includes displaying (rasterization & rendering) and printing of document pages, as well as conversions between different document formats. -------------------------------------------------------------------------------- Update Information: CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355025) CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355023) CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow (fedora#2355021) CVE-2025-27836 ghostscript: device: Print buffer overflow (fedora#2355019) CVE-2025-27830 ghostscript: Buffer overflow during serialization of DollarBlend in font (fedora#2355015) CVE-2025-27833 ghostscript: Buffer overflow with long TTF font name (fedora#2355011) CVE-2025-27837 ghostscript: Access to arbitrary files through truncated path with invalid UTF-8 (fedora#2355009) CVE-2025-27831 ghostscript: Text bufferoverflow with long characters (fedora#2355007) -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 28 2025 Zdenek Dohnal - 10.02.1-14 - CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355025) - CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355023) - CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow (fedora#2355021) - CVE-2025-27836 ghostscript: device: Print buffer overflow (fedora#2355019) - CVE-2025-27830 ghostscript: Buffer overflow during serialization of DollarBlend in font (fedora#2355015) - CVE-2025-27833 ghostscript: Buffer overflow with long TTF font name (fedora#2355011) - CVE-2025-27837 ghostscript: Access to arbitrary files through truncated path with invalid UTF-8 (fedora#2355009) - CVE-2025-27831 ghostscript: Text buffer overflow with long characters (fedora#2355007) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2354947 - CVE-2025-27835 Ghostscript: Buffer overflow when converting glyphs to unicode https://bugzilla.redhat.com/show_bug.cgi?id=2354947 [ 2 ] Bug #2354948 - CVE-2025-27834 Ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF https://bugzilla.redhat.com/show_bug.cgi?id=2354948 [ 3 ] Bug #2354949 - CVE-2025-27832 Ghostscript: NPDL device: Compression buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=2354949 [ 4 ] Bug #2354952 - CVE-2025-27836 Ghostscript: device: Print buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=2354952 [ 5 ] Bug #2354953 - CVE-2025-27830 Ghostscript: Buffer overflow during serialization of DollarBlend in font https://bugzilla.redhat.com/show_bug.cgi?id=2354953 [ 6 ] Bug #2354954 - CVE-2025-27833 Ghostscript: Buffer overflow with long TTF font name https://bugzilla.redhat.com/show_bug.cgi?id=2354954 [ 7 ] Bug#2354961 - CVE-2025-27837 Ghostscript: Access to arbitrary files through truncated path with invalid UTF-8 https://bugzilla.redhat.com/show_bug.cgi?id=2354961 [ 8 ] Bug #2354963 - CVE-2025-27831 Ghostscript: Text buffer overflow with long characters https://bugzilla.redhat.com/show_bug.cgi?id=2354963 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3a7a29de24' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1229013 Cross-References: * CVE-2024-7348 . # Security update for postgresql16 Announcement ID: SUSE-SU-2024:3158-3 Release Date: 2024-10-02T15:11:48Z Rating: important References: * bsc#1229013 Cross-References: * CVE-2024-7348 CVSS scores: * CVE-2024-7348 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-7348 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-7348 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * Legacy Module 15-SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for postgresql16 fixes the following issues: * Upgrade to 15.8 (bsc#1229013) * CVE-2024-7348: PostgreSQL relation replacement during pg_dump executes arbitrary SQL. (bsc#1229013) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Legacy Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2024-3158=1 ## Package List: * Legacy Module 15-SP6 (aarch64 ppc64le s390x x86_64) * postgresql15-server-devel-15.8-150600.16.6.1 * postgresql15-contrib-15.8-150600.16.6.1 * postgresql15-pltcl-debuginfo-15.8-150600.16.6.1 * postgresql15-pltcl-15.8-150600.16.6.1 * postgresql15-server-devel-debuginfo-15.8-150600.16.6.1 * postgresql15-devel-debuginfo-15.8-150600.16.6.1 * postgresql15-debuginfo-15.8-150600.16.6.1 * postgresql15-plpython-debuginfo-15.8-150600.16.6.1 * postgresql15-server-debuginfo-15.8-150600.16.6.1 * postgresql15-plpython-15.8-150600.16.6.1 * postgresql15-devel-15.8-150600.16.6.1 * postgresql15-15.8-150600.16.6.1 * postgresql15-server-15.8-150600.16.6.1 * postgresql15-contrib-debuginfo-15.8-150600.16.6.1 *postgresql15-plperl-debuginfo-15.8-150600.16.6.1 * postgresql15-debugsource-15.8-150600.16.6.1 * postgresql15-plperl-15.8-150600.16.6.1 * Legacy Module 15-SP6 (noarch) * postgresql15-docs-15.8-150600.16.6.1 ## References: * https://www.suse.com/security/cve/CVE-2024-7348.html * https://bugzilla.suse.com/show_bug.cgi?id=1229013 . Critical PostgreSQL 16 security update for SUSE users. Implement patch to fix SQL execution vulnerabilities, enhancing overall system protection.. postgresql16 security advisory, SQL execution risk, SUSE update, database security notification, system patch details. . Severity: Important. LinuxSecurity.com Team
* bsc#1207666 * bsc#1211708 * bsc#1211709 * bsc#1213318 * bsc#1215959 . # Security update for wireshark Announcement ID: SUSE-SU-2024:3165-1 Rating: important References: * bsc#1207666 * bsc#1211708 * bsc#1211709 * bsc#1213318 * bsc#1215959 * bsc#1217247 * bsc#1217272 * bsc#1218503 * bsc#1218506 * bsc#1218507 * bsc#1222030 * jsc#PED-8517 Cross-References: * CVE-2023-0414 * CVE-2023-0666 * CVE-2023-2854 * CVE-2023-3649 * CVE-2023-5371 * CVE-2023-6174 * CVE-2023-6175 * CVE-2024-0207 * CVE-2024-0210 * CVE-2024-0211 * CVE-2024-2955 CVSS scores: * CVE-2023-0414 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-0414 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-0666 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-0666 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-2854 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-2854 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2023-3649 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-3649 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2023-5371 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-5371 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-6174 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-6174 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-6175 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-0207 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-0207 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-0210 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-0210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-0211 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-0211 ( NVD ): 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-2955 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP6 * Desktop Applications Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 11 vulnerabilities and contains one feature can now be installed. ## Description: This update for wireshark fixes the following issues: wireshark was updated from version 3.6.23 to version 4.2.6 (jsc#PED-8517): * Security issues fixed with this update: * CVE-2024-0207: HTTP3 dissector crash (bsc#1218503) * CVE-2024-0210: Zigbee TLV dissector crash (bsc#1218506) * CVE-2024-0211: DOCSIS dissector crash (bsc#1218507) * CVE-2023-6174: Fixed SSH dissector crash (bsc#1217247) * CVE-2023-6175: NetScreen file parser crash (bsc#1217272) * CVE-2023-5371: RTPS dissector memory leak (bsc#1215959) * CVE-2023-3649: iSCSI dissector crash (bsc#1213318) * CVE-2023-2854: BLF file parser crash (bsc#1211708) * CVE-2023-0666: RTPS dissector crash (bsc#1211709) * CVE-2023-0414: EAP dissector crash (bsc#1207666) * Major changes introduced with versions 4.2.0 and 4.0.0: * Version 4.2.0 https://www.wireshark.org/docs/relnotes/wireshark-4.2.0.html * Version 4.0.0 https://www.wireshark.org/docs/relnotes/wireshark-4.0.0.html * Added an aditional desktopfile to start wireshark which asks for the super user password. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3165=1 SUSE-2024-3165=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-3165=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2024-3165=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * wireshark-devel-4.2.6-150600.18.6.1 * wireshark-debuginfo-4.2.6-150600.18.6.1 * libwiretap14-4.2.6-150600.18.6.1 * wireshark-4.2.6-150600.18.6.1 * wireshark-ui-qt-4.2.6-150600.18.6.1 * libwireshark17-4.2.6-150600.18.6.1 * libwsutil15-debuginfo-4.2.6-150600.18.6.1 * libwsutil15-4.2.6-150600.18.6.1 * libwireshark17-debuginfo-4.2.6-150600.18.6.1 * libwiretap14-debuginfo-4.2.6-150600.18.6.1 * wireshark-debugsource-4.2.6-150600.18.6.1 * wireshark-ui-qt-debuginfo-4.2.6-150600.18.6.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * wireshark-debuginfo-4.2.6-150600.18.6.1 * libwiretap14-4.2.6-150600.18.6.1 * wireshark-4.2.6-150600.18.6.1 * libwireshark17-4.2.6-150600.18.6.1 * libwsutil15-debuginfo-4.2.6-150600.18.6.1 * libwsutil15-4.2.6-150600.18.6.1 * libwireshark17-debuginfo-4.2.6-150600.18.6.1 * libwiretap14-debuginfo-4.2.6-150600.18.6.1 * wireshark-debugsource-4.2.6-150600.18.6.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * wireshark-devel-4.2.6-150600.18.6.1 * wireshark-debuginfo-4.2.6-150600.18.6.1 * wireshark-ui-qt-4.2.6-150600.18.6.1 * wireshark-ui-qt-debuginfo-4.2.6-150600.18.6.1 * wireshark-debugsource-4.2.6-150600.18.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-0414.html * https://www.suse.com/security/cve/CVE-2023-0666.html * https://www.suse.com/security/cve/CVE-2023-2854.html * https://www.suse.com/security/cve/CVE-2023-3649.html * https://www.suse.com/security/cve/CVE-2023-5371.html * https://www.suse.com/security/cve/CVE-2023-6174.html * https://www.suse.com/security/cve/CVE-2023-6175.html * https://www.suse.com/security/cve/CVE-2024-0207.html * https://www.suse.com/security/cve/CVE-2024-0210.html * https://www.suse.com/security/cve/CVE-2024-0211.html *https://www.suse.com/security/cve/CVE-2024-2955.html * https://bugzilla.suse.com/show_bug.cgi?id=1207666 * https://bugzilla.suse.com/show_bug.cgi?id=1211708 * https://bugzilla.suse.com/show_bug.cgi?id=1211709 * https://bugzilla.suse.com/show_bug.cgi?id=1213318 * https://bugzilla.suse.com/show_bug.cgi?id=1215959 * https://bugzilla.suse.com/show_bug.cgi?id=1217247 * https://bugzilla.suse.com/show_bug.cgi?id=1217272 * https://bugzilla.suse.com/show_bug.cgi?id=1218503 * https://bugzilla.suse.com/show_bug.cgi?id=1218506 * https://bugzilla.suse.com/show_bug.cgi?id=1218507 * https://bugzilla.suse.com/show_bug.cgi?id=1222030 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-8517&page_caps=&user_role= . Canonical unveils significant improvements for netstat tackling various reliability concerns, boosting performance and robustness.. wireshark update, SUSE important advisory, software security, wireshark vulnerabilities. . Severity: Important. LinuxSecurity.com Team
* bsc#1196025 * bsc#1210638 * bsc#1219666 Cross-References: . # Security update for python311 Announcement ID: SUSE-SU-2024:0782-2 Rating: important References: * bsc#1196025 * bsc#1210638 * bsc#1219666 Cross-References: * CVE-2022-25236 * CVE-2023-27043 * CVE-2023-6597 CVSS scores: * CVE-2022-25236 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2022-25236 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-6597 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves three vulnerabilities can now be installed. ## Description: This update for python311 fixes the following issues: * CVE-2023-6597: Fixed symlink bug in cleanup of tempfile.TemporaryDirectory (bsc#1219666). * CVE-2023-27043: Fixed incorrect e-mqil parsing (bsc#1210638). * CVE-2022-25236: Fixed an expat vulnerability by supporting expat > = 2.4.4 (bsc#1212015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2024-782=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python311-3.11.8-150400.9.23.1 * python311-base-3.11.8-150400.9.23.1 * libpython3_11-1_0-3.11.8-150400.9.23.1 ## References: * https://www.suse.com/security/cve/CVE-2022-25236.html *https://www.suse.com/security/cve/CVE-2023-27043.html * https://www.suse.com/security/cve/CVE-2023-6597.html * https://bugzilla.suse.com/show_bug.cgi?id=1196025 * https://bugzilla.suse.com/show_bug.cgi?id=1210638 * https://bugzilla.suse.com/show_bug.cgi?id=1219666 . Address crucial Python vulnerabilities in SUSE offerings. Apply suggested updates for improved security.. SUSE Python Security Update, Important Python Advisory, Python Vulnerability Patches, SUSE Security Updates. . Severity: Important. LinuxSecurity.com Team
open-vm-tools: authentication bypass vulnerability in the vgauth module (CVE-2023-20867) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * [ESXi] [SL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml' * [ESX [More...]. Synopsis: Low: open-vm-tools security and bug fix update Advisory ID: SLSA-2023:3944-1 Issue Date: 2023-06-30 CVE Numbers: CVE-2023-20867 -- Security Fix(es): * open-vm-tools: authentication bypass vulnerability in the vgauth module (CVE-2023-20867) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * [ESXi] [SL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml' * [ESXi][SL7.9][open-vm-tools] Snapshot of the SL7 guest on the VMWare ESXi hypervisor failed vm hangs -- SL7 x86_64 open-vm-tools-11.0.5-3.el7_9.6.x86_64.rpm open-vm-tools-debuginfo-11.0.5-3.el7_9.6.x86_64.rpm open-vm-tools-desktop-11.0.5-3.el7_9.6.x86_64.rpm open-vm-tools-devel-11.0.5-3.el7_9.6.x86_64.rpm open-vm-tools-test-11.0.5-3.el7_9.6.x86_64.rpm - Scientific Linux Development Team . Minor advisory regarding open-vm-tools concerning a vulnerability in authentication bypass on SL7.x systems. Resolution specifics have been provided.. open-vm-tools, authentication, SL7, security patch, bug fix. . Severity: Low. LinuxSecurity.com Team
Several security issues were fixed in Python.. =========================================================================Ubuntu Security Notice USN-4151-1 October 09, 2019 python2.7, python3.5, python3.6, python3.7 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.04 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Python. Software Description: - python2.7: An interactive high-level object-oriented language - python3.7: An interactive high-level object-oriented language - python3.6: An interactive high-level object-oriented language - python3.5: An interactive high-level object-oriented language Details: It was discovered that Python incorrectly parsed certain email addresses. A remote attacker could possibly use this issue to trick Python applications into accepting email addresses that should be denied. (CVE-2019-16056) It was discovered that the Python documentation XML-RPC server incorrectly handled certain fields. A remote attacker could use this issue to execute a cross-site scripting (XSS) attack. (CVE-2019-16935) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: python2.7 2.7.16-2ubuntu0.2 python2.7-minimal 2.7.16-2ubuntu0.2 python3.7 3.7.3-2ubuntu0.2 python3.7-minimal 3.7.3-2ubuntu0.2 Ubuntu 18.04 LTS: python2.7 2.7.15-4ubuntu4~18.04.2 python2.7-minimal 2.7.15-4ubuntu4~18.04.2 python3.6 3.6.8-1~18.04.3 python3.6-minimal 3.6.8-1~18.04.3 Ubuntu 16.04 LTS: python2.7 2.7.12-1ubuntu0~16.04.9 python2.7-minimal 2.7.12-1ubuntu0~16.04.9 python3.5 3.5.2-2ubuntu0~16.04.9 python3.5-minimal 3.5.2-2ubuntu0~16.04.9 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4151-1 CVE-2019-16056, CVE-2019-16935 Package Information: https://launchpad.net/ubuntu/+source/python2.7/2.7.16-2ubuntu0.2 https://launchpad.net/ubuntu/+source/python3.7/3.7.3-2ubuntu0.2 https://launchpad.net/ubuntu/+source/python2.7/2.7.15-4ubuntu4~18.04.2 https://launchpad.net/ubuntu/+source/python3.6/3.6.8-1~18.04.3 https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.9 https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.9 . Keep updated regarding Ubuntu USN-4151-1 related to Python security flaws impacting several editions and their solutions.. Python Security Fix, Ubuntu Vulnerability Management, Software Update Instructions. . LinuxSecurity.com Team
An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: java-1.7.1-ibm security update Advisory ID: RHSA-2019:1165-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2019:1165 Issue date: 2019-05-13 CVE Names: CVE-2019-2602 CVE-2019-2684 CVE-2019-2697 CVE-2019-2698 CVE-2019-10245 ==================================================================== 1. Summary: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node Supplementary (v. 6) - x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: IBM Java SE version 7 Release 1 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit. This update upgrades IBM Java SE 7 to version 7R1 SR4-FP45. Security Fix(es): * Oracle JDK: Unspecified vulnerability fixed in 7u221 and 8u211 (2D) (CVE-2019-2697) * OpenJDK: Font layout engine out of bounds access setCurrGlyphID() (2D, 8219022) (CVE-2019-2698) * OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936) (CVE-2019-2602) * OpenJDK:Incorrect skeleton selection in RMI registry server-side dispatch handling (RMI, 8218453) (CVE-2019-2684) * IBM JDK: Read beyond the end of bytecode array causing JVM crash (CVE-2019-10245) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of IBM Java must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1700440 - CVE-2019-2602 OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936) 1700447 - CVE-2019-2698 OpenJDK: Font layout engine out of bounds access setCurrGlyphID() (2D, 8219022) 1700564 - CVE-2019-2684 OpenJDK: Incorrect skeleton selection in RMI registry server-side dispatch handling (RMI, 8218453) 1704480 - CVE-2019-2697 Oracle JDK: Unspecified vulnerability fixed in 7u221 and 8u211 (2D) 1704799 - CVE-2019-10245 IBM JDK: Read beyond the end of bytecode array causing JVM crash 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: java-1.7.1-ibm-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-demo-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-devel-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-jdbc-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-plugin-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-src-1.7.1.4.45-1jpp.1.el6_10.i686.rpm x86_64: java-1.7.1-ibm-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-demo-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-devel-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-jdbc-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-plugin-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-src-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm Red Hat Enterprise Linux HPC Node Supplementary (v.6): x86_64: java-1.7.1-ibm-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-demo-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-devel-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-src-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: java-1.7.1-ibm-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-demo-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-devel-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-jdbc-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-plugin-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-src-1.7.1.4.45-1jpp.1.el6_10.i686.rpm ppc64: java-1.7.1-ibm-1.7.1.4.45-1jpp.1.el6_10.ppc64.rpm java-1.7.1-ibm-demo-1.7.1.4.45-1jpp.1.el6_10.ppc64.rpm java-1.7.1-ibm-devel-1.7.1.4.45-1jpp.1.el6_10.ppc64.rpm java-1.7.1-ibm-jdbc-1.7.1.4.45-1jpp.1.el6_10.ppc64.rpm java-1.7.1-ibm-src-1.7.1.4.45-1jpp.1.el6_10.ppc64.rpm s390x: java-1.7.1-ibm-1.7.1.4.45-1jpp.1.el6_10.s390x.rpm java-1.7.1-ibm-demo-1.7.1.4.45-1jpp.1.el6_10.s390x.rpm java-1.7.1-ibm-devel-1.7.1.4.45-1jpp.1.el6_10.s390x.rpm java-1.7.1-ibm-jdbc-1.7.1.4.45-1jpp.1.el6_10.s390x.rpm java-1.7.1-ibm-src-1.7.1.4.45-1jpp.1.el6_10.s390x.rpm x86_64: java-1.7.1-ibm-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-demo-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-devel-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-jdbc-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-plugin-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-src-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm Red Hat Enterprise Linux Workstation Supplementary (v.6): i386: java-1.7.1-ibm-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-demo-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-devel-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-jdbc-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-plugin-1.7.1.4.45-1jpp.1.el6_10.i686.rpm java-1.7.1-ibm-src-1.7.1.4.45-1jpp.1.el6_10.i686.rpm x86_64: java-1.7.1-ibm-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-demo-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-devel-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-jdbc-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-plugin-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm java-1.7.1-ibm-src-1.7.1.4.45-1jpp.1.el6_10.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-2602 https://access.redhat.com/security/cve/CVE-2019-2684 https://access.redhat.com/security/cve/CVE-2019-2697 https://access.redhat.com/security/cve/CVE-2019-2698 https://access.redhat.com/security/cve/CVE-2019-10245 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXNndFtzjgjWX9erEAQirUA/9HQfmibGrrJGZlLZjGgV2jECu3A2dsf+G 6aLS/0ESUCRMwHyG9gyEPY0qhGY8k26EINu//z3zTBBjNzJI6WIfOeGaJMG2rk6W Sl8i9KPaKDPsXpU0co5p6PBMd9DypcXNUByljFxJKny3Vzm490lN5pjP6ReVZZk2 IfX/1EjIGCnOSTQkzrMJNsOijRo9LcF7ehFb2s3AEjI+ISPm8sD8xMQ6lGUE9D4a LY0W1g0mmQClqyDtg2tRZs0mB8Z2w3QlMuOHeLpeGJjlokQb0p5/tDytgl37yJkD PnQFHQBx4VKQzssDcfeB3D83Sta7SdYZ8rN3gZmaaEtq898hX3eiKFJxuzgOV/Ry vy/0HciAHXjj7lYrp8qzslkxjihWBhhbwwoqvCbLe/o1dTKSExo6vxN/HtFZm5Db GQ0kUK8DyZvmFV0NhwWTJob5KafCLqzOWX+A9NyoymkHjbrl21VlRD2948dfzHot IlBM87NtNRSr2lnQ6ZXX05pL/POuCZEH4Xw69TYFt48//5u8qJE2JkmNg9Ad6uvP 6WBTk7dQGbNayqnTwEqY+QMpYH8lC0ud/MUW/xW1s2/7sfxcxh64NJi7Q31mXzCA g0SMx4/4dDA+2PVJn+47Y/jWnNAB3QVQ2Dbb9ijkUhwpxeLZC7QWuZauK9TO0UQM CrfrpgWvPfE=hb3f -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Spice could be made to crash or run programs if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-3202-1 February 20, 2017 spice vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Spice could be made to crash or run programs if it received specially crafted network traffic. Software Description: - spice: SPICE protocol client and server library Details: Frediano Ziglio discovered that Spice incorrectly handled certain client messages. A remote attacker could use this issue to cause Spice to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: libspice-server1 0.12.8-1ubuntu0.1 Ubuntu 16.04 LTS: libspice-server1 0.12.6-4ubuntu0.2 Ubuntu 14.04 LTS: libspice-server1 0.12.4-0nocelt2ubuntu1.4 After a standard system update you need to restart qemu guests to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3202-1 CVE-2016-9577, CVE-2016-9578 Package Information: https://launchpad.net/ubuntu/+source/spice/0.12.8-1ubuntu0.1 https://launchpad.net/ubuntu/+source/spice/0.12.6-4ubuntu0.2 https://launchpad.net/ubuntu/+source/spice/0.12.4-0nocelt2ubuntu1.4 . The Ubuntu Security Notice USN-3202-1 brings attention to vulnerabilities in spice and outlines the steps necessary for mitigation through package upgrades.. Spice Security Flaws, Ubuntu Security Patch, Denial Of Service Threat. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.