An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libredwg ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0147-1 Rating: important References: #1218473 Cross-References: CVE-2023-26157 CVSS scores: CVE-2023-26157 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libredwg fixes the following issues: Update to tag 0.12.5.6924: - CVE-2023-26157: Fixed out-of-bound read involving section-> num_pages in decode_r2007.c (boo#1218473) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-147=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): libredwg-devel-0.12.5.6924-bp155.3.6.1 libredwg-tools-0.12.5.6924-bp155.3.6.1 libredwg0-0.12.5.6924-bp155.3.6.1 References: https://www.suse.com/security/cve/CVE-2023-26157.html https://bugzilla.suse.com/1218473 . Critical security patch released for openSUSE targeting libredwg flaw CVE-2023-26157 safeguards user systems.. openSUSE Update, libredwg Security, Linux Threat Mitigation, Security Advisory, Software Update. . Severity: Important. LinuxSecurity.com Team
An update that fixes 5 vulnerabilities is now available. . openSUSE Security Update: Security update for libredwg ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0201-1 Rating: important References: #1200898 #1212705 #1212706 #1212707 #1212709 Cross-References: CVE-2022-33025 CVE-2023-36271 CVE-2023-36272 CVE-2023-36273 CVE-2023-36274 CVSS scores: CVE-2022-33025 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2023-36271 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2023-36272 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2023-36273 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2023-36274 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for libredwg fixes the following issues: Update to version 0.12.5.5907 Security issues fixed: * CVE-2022-33025: Fixed multiple security issues [boo#1200898] * CVE-2023-36271: Fixed heap buffer overflow via the function bit_wcs2nlen [boo#1212709] * CVE-2023-36272: Fixed heap buffer overflow via the function bit_utf8_to_TU [boo#1212707] * CVE-2023-36273: Fixed heap buffer overflow via the function bit_calc_CRC [boo#1212706] * CVE-2023-36274: Fixed heap buffer overflow via the function bit_write_TF [boo#1212705] Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patchopenSUSE-2023-201=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 x86_64): libredwg-devel-0.12.5.5907-bp155.3.3.1 libredwg-tools-0.12.5.5907-bp155.3.3.1 libredwg0-0.12.5.5907-bp155.3.3.1 References: https://www.suse.com/security/cve/CVE-2022-33025.html https://www.suse.com/security/cve/CVE-2023-36271.html https://www.suse.com/security/cve/CVE-2023-36272.html https://www.suse.com/security/cve/CVE-2023-36273.html https://www.suse.com/security/cve/CVE-2023-36274.html https://bugzilla.suse.com/1200898 https://bugzilla.suse.com/1212705 https://bugzilla.suse.com/1212706 https://bugzilla.suse.com/1212707 https://bugzilla.suse.com/1212709 . The latest libredwg release tackles significant vulnerabilities, boosting the security and reliability of the openSUSE environment.. libredwg update, openSUSE security, software patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libredwg ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0155-1 Rating: moderate References: #1193372 Cross-References: CVE-2021-28237 Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libredwg fixes the following issues: Update to release 0.12.5 [boo#1193372] [CVE-2021-28237] * Restricted accepted DXF objects to all stable and unstable classes, minus MATERIAL, ARC_DIMENSION, SUN, PROXY*. I.e. most unstable objects do not allow unknown DXF codes anymore. This fixed most oss-fuzz errors. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-155=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): libredwg-devel-0.12.5-bp154.2.3.1 libredwg-tools-0.12.5-bp154.2.3.1 libredwg0-0.12.5-bp154.2.3.1 References: https://www.suse.com/security/cve/CVE-2021-28237.html https://bugzilla.suse.com/1193372 . An update for libredwg has been released on openSUSE, tackling a moderate severity vulnerability that boosts system security and stability.. OpenSUSE Libredwg Update, Linux Security Fix, Enhanced Stability. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for libredwg ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0149-1 Rating: moderate References: #1193372 #1194767 Cross-References: CVE-2021-28237 CVE-2022-21658 CVSS scores: CVE-2022-21658 (NVD) : 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H CVE-2022-21658 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: openSUSE Backports SLE-15-SP3 openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for libredwg fixes the following issues: Update to release 0.12.5 [boo#1193372] [CVE-2021-28237] * Restricted accepted DXF objects to all stable and unstable classes, minus MATERIAL, ARC_DIMENSION, SUN, PROXY*. I.e. most unstable objects do not allow unknown DXF codes anymore. This fixed most oss-fuzz errors. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-149=1 - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-149=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): cargo1.56-1.56.1-150300.7.6.1 cargo1.56-debuginfo-1.56.1-150300.7.6.1 rust1.56-1.56.1-150300.7.6.1 rust1.56-debuginfo-1.56.1-150300.7.6.1 - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): libredwg-devel-0.12.5-bp153.2.3.1 libredwg-tools-0.12.5-bp153.2.3.1 libredwg0-0.12.5-bp153.2.3.1 References: https://www.suse.com/security/cve/CVE-2021-28237.html https://www.suse.com/security/cve/CVE-2022-21658.html https://bugzilla.suse.com/1193372 https://bugzilla.suse.com/1194767 . SUSE Security Patch for libredwg addresses issues. Learn about the moderate threat level and upgrade guidelines.. openSUSE Security Update, libredwg Advisory, moderate risk, patching instructions. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for libredwg ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0149-1 Rating: moderate References: #1193372 #1194767 Cross-References: CVE-2021-28237 CVE-2022-21658 CVSS scores: CVE-2022-21658 (NVD) : 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H CVE-2022-21658 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: openSUSE Backports SLE-15-SP3 openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for libredwg fixes the following issues: Update to release 0.12.5 [boo#1193372] [CVE-2021-28237] * Restricted accepted DXF objects to all stable and unstable classes, minus MATERIAL, ARC_DIMENSION, SUN, PROXY*. I.e. most unstable objects do not allow unknown DXF codes anymore. This fixed most oss-fuzz errors. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-149=1 - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-149=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): cargo1.56-1.56.1-150300.7.6.1 cargo1.56-debuginfo-1.56.1-150300.7.6.1 rust1.56-1.56.1-150300.7.6.1 rust1.56-debuginfo-1.56.1-150300.7.6.1 - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): libredwg-devel-0.12.5-bp153.2.3.1 libredwg-tools-0.12.5-bp153.2.3.1 libredwg0-0.12.5-bp153.2.3.1 References: https://www.suse.com/security/cve/CVE-2021-28237.html https://www.suse.com/security/cve/CVE-2022-21658.html https://bugzilla.suse.com/1193372 https://bugzilla.suse.com/1194767 . Important notification regarding libredwg resolves a pair of security flaws for openSUSE. Comprehensive guidance and update procedures included.. openSUSE Security Update, Libredwg, Moderate Management, Software Patch. . LinuxSecurity.com Team
An update that fixes 7 vulnerabilities is now available.. openSUSE Security Update: Security update for libredwg ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0115-1 Rating: moderate References: #1160520 #1160522 #1160523 #1160524 #1160525 #1160526 #1160527 Cross-References: CVE-2020-6609 CVE-2020-6610 CVE-2020-6611 CVE-2020-6612 CVE-2020-6613 CVE-2020-6614 CVE-2020-6615 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: This update for libredwg fixes the following issues: libredwg was updated to release 0.10: API breaking changes: * Added a new int *isnewp argument to all dynapi utf8text getters, if the returned string is freshly malloced or not. * removed the UNKNOWN supertype, there are only UNKNOWN_OBJ and UNKNOWN_ENT left, with common_entity_data. * renamed BLOCK_HEADER.preview_data to preview, preview_data_size to preview_size. * renamed SHAPE.shape_no to style_id. * renamed CLASS.wasazombie to is_zombie. Bugfixes: * Harmonized INDXFB with INDXF, removed extra src/in_dxfb.c. * Fixed encoding of added r2000 AUXHEADER address. * Fixed EED encoding from dwgrewrite. * Add several checks against [CVE-2020-6609, boo#1160520], [CVE-2020-6610, boo#1160522], [CVE-2020-6611, boo#1160523], [CVE-2020-6612, boo#1160524], [CVE-2020-6613, boo#1160525], [CVE-2020-6614, boo#1160526], [CVE-2020-6615, boo#1160527] This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: -openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-115=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): libredwg-devel-0.10-bp151.2.6.1 libredwg-tools-0.10-bp151.2.6.1 libredwg0-0.10-bp151.2.6.1 References: https://www.suse.com/security/cve/CVE-2020-6609.html https://www.suse.com/security/cve/CVE-2020-6610.html https://www.suse.com/security/cve/CVE-2020-6611.html https://www.suse.com/security/cve/CVE-2020-6612.html https://www.suse.com/security/cve/CVE-2020-6613.html https://www.suse.com/security/cve/CVE-2020-6614.html https://www.suse.com/security/cve/CVE-2020-6615.html https://bugzilla.suse.com/1160520 https://bugzilla.suse.com/1160522 https://bugzilla.suse.com/1160523 https://bugzilla.suse.com/1160524 https://bugzilla.suse.com/1160525 https://bugzilla.suse.com/1160526 https://bugzilla.suse.com/1160527 -- . Addresses 7 security flaws in libredwg via openSUSE Security Patch openSUSE-SU-2020:0115-1. openSUSE Security Update, libredwg, patch installation, bug fixes. . LinuxSecurity.com Team
An update that fixes 7 vulnerabilities is now available.. openSUSE Security Update: Security update for libredwg ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0096-1 Rating: moderate References: #1160520 #1160522 #1160523 #1160524 #1160525 #1160526 #1160527 Cross-References: CVE-2020-6609 CVE-2020-6610 CVE-2020-6611 CVE-2020-6612 CVE-2020-6613 CVE-2020-6614 CVE-2020-6615 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: This update for libredwg fixes the following issues: libredwg was updated to release 0.10: API breaking changes: * Added a new int *isnewp argument to all dynapi utf8text getters, if the returned string is freshly malloced or not. * removed the UNKNOWN supertype, there are only UNKNOWN_OBJ and UNKNOWN_ENT left, with common_entity_data. * renamed BLOCK_HEADER.preview_data to preview, preview_data_size to preview_size. * renamed SHAPE.shape_no to style_id. * renamed CLASS.wasazombie to is_zombie. Bugfixes: * Harmonized INDXFB with INDXF, removed extra src/in_dxfb.c. * Fixed encoding of added r2000 AUXHEADER address. * Fixed EED encoding from dwgrewrite. * Add several checks against [CVE-2020-6609, boo#1160520], [CVE-2020-6610, boo#1160522], [CVE-2020-6611, boo#1160523], [CVE-2020-6612, boo#1160524], [CVE-2020-6613, boo#1160525], [CVE-2020-6614, boo#1160526], [CVE-2020-6615, boo#1160527] Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-96=1 Package List: - openSUSELeap 15.1 (x86_64): libredwg-debuginfo-0.10-lp151.2.6.1 libredwg-debugsource-0.10-lp151.2.6.1 libredwg-devel-0.10-lp151.2.6.1 libredwg-tools-0.10-lp151.2.6.1 libredwg-tools-debuginfo-0.10-lp151.2.6.1 libredwg0-0.10-lp151.2.6.1 libredwg0-debuginfo-0.10-lp151.2.6.1 References: https://www.suse.com/security/cve/CVE-2020-6609.html https://www.suse.com/security/cve/CVE-2020-6610.html https://www.suse.com/security/cve/CVE-2020-6611.html https://www.suse.com/security/cve/CVE-2020-6612.html https://www.suse.com/security/cve/CVE-2020-6613.html https://www.suse.com/security/cve/CVE-2020-6614.html https://www.suse.com/security/cve/CVE-2020-6615.html https://bugzilla.suse.com/1160520 https://bugzilla.suse.com/1160522 https://bugzilla.suse.com/1160523 https://bugzilla.suse.com/1160524 https://bugzilla.suse.com/1160525 https://bugzilla.suse.com/1160526 https://bugzilla.suse.com/1160527 -- . openSUSE released a security advisory for vulnerabilities in libredwg, highlighting risks to system integrity and urging users to apply updates for better protection.. openSUSE Update, libredwg Security, Moderate Threat, Patch Instructions. . LinuxSecurity.com Team
An update that solves 17 vulnerabilities and has one errata is now available.. openSUSE Security Update: Security update for libredwg ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0095-1 Rating: moderate References: #1129868 #1129869 #1129870 #1129873 #1129874 #1129875 #1129876 #1129878 #1129879 #1129881 #1154080 #1159824 #1159825 #1159826 #1159827 #1159828 #1159831 #1159832 Cross-References: CVE-2019-20009 CVE-2019-20010 CVE-2019-20011 CVE-2019-20012 CVE-2019-20013 CVE-2019-20014 CVE-2019-20015 CVE-2019-9770 CVE-2019-9771 CVE-2019-9772 CVE-2019-9773 CVE-2019-9774 CVE-2019-9775 CVE-2019-9776 CVE-2019-9777 CVE-2019-9778 CVE-2019-9779 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that solves 17 vulnerabilities and has one errata is now available. Description: This update for libredwg fixes the following issues: libredwg was updated to release 0.9.3: * Added the -x,--extnames option to dwglayers for r13-r14 DWGs. * Fixed some leaks: SORTENTSTABLE, PROXY_ENTITY.ownerhandle for r13. * Add DICTIONARY.itemhandles[] for r13 and r14. * Fixed some dwglayers null pointer derefs, and flush its output for each layer. * Added several overflow checks from fuzzing [CVE-2019-20010, boo#1159825], [CVE-2019-20011, boo#1159826], [CVE-2019-20012, boo#1159827], [CVE-2019-20013, boo#1159828], [CVE-2019-20014, boo#1159831], [CVE-2019-20015, boo#1159832] * Disallow illegal SPLINE scenarios [CVE-2019-20009, boo#1159824] Update to release 0.9.1: * Fixed more null pointer dereferences, overflows, hangs and memory leaks for fuzzed (i.e. illegal) DWGs. Update to release 0.9 [boo#1154080]: * Added theDXF importer, using the new dynapi and the r2000 encoder. Only for r2000 DXFs. * Added utf8text conversion functions to the dynapi. * Added 3DSOLID encoder. * Added APIs to find handles for names, searching in tables and dicts. * API breaking changes - see NEWS file in package. * Fixed null pointer dereferences, and memory leaks (except DXF importer) [boo#1129868, CVE-2019-9779] [boo#1129869, CVE-2019-9778] [boo#1129870, CVE-2019-9777] [boo#1129873, CVE-2019-9776] [boo#1129874, CVE-2019-9773] [boo#1129875, CVE-2019-9772] [boo#1129876, CVE-2019-9771] [boo#1129878, CVE-2019-9775] [boo#1129879, CVE-2019-9774] [boo#1129881, CVE-2019-9770] Update to 0.8: * add a new dynamic API, read and write all header and object fields by name * API breaking changes * Fix many errors in DXF output * Fix JSON output * Many more bug fixes to handle specific object types This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-95=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): libredwg-devel-0.9.3-bp151.2.3.1 libredwg-tools-0.9.3-bp151.2.3.1 libredwg0-0.9.3-bp151.2.3.1 References: https://www.suse.com/security/cve/CVE-2019-20009.html https://www.suse.com/security/cve/CVE-2019-20010.html https://www.suse.com/security/cve/CVE-2019-20011.html https://www.suse.com/security/cve/CVE-2019-20012.html https://www.suse.com/security/cve/CVE-2019-20013.html https://www.suse.com/security/cve/CVE-2019-20014.html https://www.suse.com/security/cve/CVE-2019-20015.html https://www.suse.com/security/cve/CVE-2019-9770.html https://www.suse.com/security/cve/CVE-2019-9771.html https://www.suse.com/security/cve/CVE-2019-9772.html https://www.suse.com/security/cve/CVE-2019-9773.html https://www.suse.com/security/cve/CVE-2019-9774.html https://www.suse.com/security/cve/CVE-2019-9775.html https://www.suse.com/security/cve/CVE-2019-9776.html https://www.suse.com/security/cve/CVE-2019-9777.html https://www.suse.com/security/cve/CVE-2019-9778.html https://www.suse.com/security/cve/CVE-2019-9779.html https://bugzilla.suse.com/1129868 https://bugzilla.suse.com/1129869 https://bugzilla.suse.com/1129870 https://bugzilla.suse.com/1129873 https://bugzilla.suse.com/1129874 https://bugzilla.suse.com/1129875 https://bugzilla.suse.com/1129876 https://bugzilla.suse.com/1129878 https://bugzilla.suse.com/1129879 https://bugzilla.suse.com/1129881 https://bugzilla.suse.com/1154080 https://bugzilla.suse.com/1159824 https://bugzilla.suse.com/1159825 https://bugzilla.suse.com/1159826 https://bugzilla.suse.com/1159827 https://bugzilla.suse.com/1159828 https://bugzilla.suse.com/1159831 https://bugzilla.suse.com/1159832 -- . The latest openSUSE release resolves 17 security vulnerabilities concerning libredwg, improving overall system integrity and safeguarding against threats.. openSUSE Update, libredwg Security Fix, Moderate Threat Patch, SLE-15-SP1 Update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.