Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
203

Mageia: 2023-0143 Critical Security Issue: Jpegoptim Heap Overflow Alert

A heap overflow can occur with crafted JPEG image file. (CVE-2023-27781) References: - https://bugs.mageia.org/show_bug.cgi?id=31764 - https://github.com/tjko/jpegoptim/issues/132 . MGASA-2023-0143 - Updated jpegoptim packages fix security vulnerability Publication date: 15 Apr 2023 URL: https://advisories.mageia.org/MGASA-2023-0143.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-27781 A heap overflow can occur with crafted JPEG image file. (CVE-2023-27781) References: - https://bugs.mageia.org/show_bug.cgi?id=31764 - https://github.com/tjko/jpegoptim/issues/132 - https://nvd.nist.gov/vuln/detail/CVE-2023-27781 - https://www.cve.org/CVERecord?id=CVE-2023-27781 SRPMS: - 8/core/jpegoptim-1.5.1-1.1.mga8 . Buffer overflow in pngcrush exposes security vulnerabilities. Upgrade to address risks and guarantee safe image compression.. Mageia, jpegoptim, heap overflow, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 15, 2023 Critical Mageia
89

Fedora 38: FEDORA-2023-ee0bc9afb6 moderate: jpegoptim heap overflow

v1.5.3 - fix potential heap-buffer-overflow (read) when using stdin/stdout and processing corrupt JPEG. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-ee0bc9afb6 2023-04-04 00:16:16.774552 --------------------------------------------------------------------------------Name : jpegoptim Product : Fedora 38 Version : 1.5.3 Release : 1.fc38 URL : https://www.kokkonen.net/tjko/projects.html Summary : Utility to optimize JPEG files Description : Jpegoptim is an utility to optimize JPEG files. Provides lossless optimization (based on optimizing the Huffman tables) and "lossy" optimization based on setting maximum quality factor. --------------------------------------------------------------------------------Update Information: v1.5.3 - fix potential heap-buffer-overflow (read) when using stdin/stdout and processing corrupt JPEG --------------------------------------------------------------------------------ChangeLog: * Sat Mar 25 2023 Denis Fateyev - 1.5.3-1 - Update to version 1.5.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #2169077 - jpegoptim-1.5.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2169077 [ 2 ] Bug #2178809 - CVE-2023-27781 jpegoptim: Heap overflow in the optimize function at jpegoptim.c. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2178809 [ 3 ] Bug #2178810 - CVE-2023-27781 jpegoptim: Heap overflow in the optimize function at jpegoptim.c. [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2178810 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ee0bc9afb6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packagesare signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 38's jpegoptim update notification addresses a critical heap overflow vulnerability. It is essential to implement the necessary patches without delay.. jpegoptim software update,Fedora security advisory,heap overflow issue,JPEG optimization tool. . LinuxSecurity.com Team

Calendar 2 Apr 04, 2023 Fedora
203

Mageia 8: MGASA-2023-0023 Critical: Jpegoptim Segmentation Fault

JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim.c. (CVE-2022-32325) References: - https://bugs.mageia.org/show_bug.cgi?id=31424 . MGASA-2023-0023 - Updated jpegoptim packages fix security vulnerability Publication date: 24 Jan 2023 URL: https://advisories.mageia.org/MGASA-2023-0023.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-32325 JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim.c. (CVE-2022-32325) References: - https://bugs.mageia.org/show_bug.cgi?id=31424 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/XRPXTW3IARYQVKZBPIPIEKABN7DSS5XY/ - https://www.cve.org/CVERecord?id=CVE-2022-32325 SRPMS: - 8/core/jpegoptim-1.5.1-1.mga8 . The update MGASA-2023-0024 provides crucial information on a security fix for jpegoptim issued on February 12, 2023, resolving a severe buffer overflow vulnerability.. jpegoptim, segmentation fault, critical security update,Mageia 8. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 24, 2023 Critical Mageia
89

Fedora 37: FEDORA-2023-d9c91f39a5 Moderate: Jpegoptim Memory Leak Fix

v1.5.1 - fix logging to stdout when --stdout is used *thanks to Eta - update --treshold option accept decimal numbers as parameter - fix crashes when processing certain broken JPEG images - fix memory leaks - fix (logging) output in parallel processing mode. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-d9c91f39a5 2023-01-14 01:09:31.700570 --------------------------------------------------------------------------------Name : jpegoptim Product : Fedora 37 Version : 1.5.1 Release : 1.fc37 URL : https://www.kokkonen.net/tjko/projects.html Summary : Utility to optimize JPEG files Description : Jpegoptim is an utility to optimize JPEG files. Provides lossless optimization (based on optimizing the Huffman tables) and "lossy" optimization based on setting maximum quality factor. --------------------------------------------------------------------------------Update Information: v1.5.1 - fix logging to stdout when --stdout is used *thanks to Eta - update --treshold option accept decimal numbers as parameter - fix crashes when processing certain broken JPEG images - fix memory leaks - fix (logging) output in parallel processing mode --------------------------------------------------------------------------------ChangeLog: * Thu Jan 5 2023 Denis Fateyev - 1.5.1-1 - Update to version 1.5.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #2112859 - CVE-2022-32325 jpegoptim: segmentation violation by a READ memory access at jpegoptim.c. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2112859 [ 2 ] Bug #2158407 - jpegoptim-1.5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2158407 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-d9c91f39a5' at thecommand line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest update to jpegoptim version 1.5.1 addresses memory leaks, enhances logging functionalities, and streamlines JPEG file handling for the Fedora 37 distribution.. jpegoptim, Memory Leak Fix, Fedora 37 Update, Software Optimization. . LinuxSecurity.com Team

Calendar 2 Jan 14, 2023 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here