Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-40ee18b2e7 2024-06-02 03:36:56.060441 -------------------------------------------------------------------------------- Name : librsvg2 Product : Fedora 39 Version : 2.57.1 Release : 2.fc39 URL : https://wiki.gnome.org/Projects/LibRsvg Summary : An SVG library based on cairo Description : An SVG library based on cairo. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Fri May 24 2024 Fabio Valentini - 2.57.1-2 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-40ee18b2e7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-5081 https://linux.oracle.com/errata/ELSA-2023-5081.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: librsvg2-2.50.7-1.el9_2.1.i686.rpm librsvg2-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-devel-2.50.7-1.el9_2.1.i686.rpm librsvg2-devel-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-tools-2.50.7-1.el9_2.1.x86_64.rpm aarch64: librsvg2-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-devel-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-tools-2.50.7-1.el9_2.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//librsvg2-2.50.7-1.el9_2.1.src.rpm Related CVEs: CVE-2023-38633 Description of changes: [2.50.7-1.el9_2.1] - Fix CVE-2023-38633 (#2224947) _______________________________________________ El-errata mailing list
An update for librsvg2 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: librsvg2 security update Advisory ID: RHSA-2023:5081-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5081 Issue date: 2023-09-12 CVE Names: CVE-2023-38633 ===================================================================== 1. Summary: An update for librsvg2 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The librsvg2 packages provide a Scalable Vector Graphics (SVG) library based on the libart library. Security Fix(es): * librsvg: Arbitrary file read when xinclude href has special characters (CVE-2023-38633) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2224945 - CVE-2023-38633 librsvg: Arbitrary file read when xinclude href has special characters 6. Package List: Red Hat Enterprise LinuxAppStream (v. 9): Source: librsvg2-2.50.7-1.el9_2.1.src.rpm aarch64: librsvg2-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-debuginfo-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-debugsource-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-devel-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-tools-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_2.1.aarch64.rpm ppc64le: librsvg2-2.50.7-1.el9_2.1.ppc64le.rpm librsvg2-debuginfo-2.50.7-1.el9_2.1.ppc64le.rpm librsvg2-debugsource-2.50.7-1.el9_2.1.ppc64le.rpm librsvg2-devel-2.50.7-1.el9_2.1.ppc64le.rpm librsvg2-tools-2.50.7-1.el9_2.1.ppc64le.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_2.1.ppc64le.rpm s390x: librsvg2-2.50.7-1.el9_2.1.s390x.rpm librsvg2-debuginfo-2.50.7-1.el9_2.1.s390x.rpm librsvg2-debugsource-2.50.7-1.el9_2.1.s390x.rpm librsvg2-devel-2.50.7-1.el9_2.1.s390x.rpm librsvg2-tools-2.50.7-1.el9_2.1.s390x.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_2.1.s390x.rpm x86_64: librsvg2-2.50.7-1.el9_2.1.i686.rpm librsvg2-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-debuginfo-2.50.7-1.el9_2.1.i686.rpm librsvg2-debuginfo-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-debugsource-2.50.7-1.el9_2.1.i686.rpm librsvg2-debugsource-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-devel-2.50.7-1.el9_2.1.i686.rpm librsvg2-devel-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-tools-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_2.1.i686.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_2.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-38633 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlAINkAAoJENzjgjWX9erEmkgP/0vJfSsohnRgUIB7UneTgOQq ksqb1fvDRc8CeDpZZeqIOL/q+F7tZzxlb8GFT6Q5P/RJn5wG1ESA2fQ8jkTr7CVs 983vvdl3fSSx3urMQM5jqVFhHfeogGiGEAqLnLUqNpC1MTvoGEH7iqLlWqKYiNJc T3eHbMcYAmFNdFqPaPeifzb6GfU4lv2LSNU3CLMOLBftFcEJ7pEcl6i8m0EVgVoX clT39XoMKZ+TAEOOxCTbM6LN08PvlTdotVDDH2XcTzdCMVmA0aT8zNF4CPfLlah9 Tct7OU8FWijKKNAWNZ1+ONtjUmZMgGX+/Yv2Yj2dNTiClFbq29KlZ3zFERb/mOUP EHa9T6HuXtahdDPcuHbJeK91u4w3gpCfGxBkj2Vw7omMQWfj4NeXb/iOdrsiVhtE HSx41yeNenmhvfLPF6tmQDzmeqFZje/+Vt+lP+N/terWuKJwoH8UeTb+twFTgNj/ XDAg0kCjizZG5420wh33ZKhY9n3S6t4F8C2Y+RUP3gNttwWCYsctPq2U9OAhvBcw Ig6nI4PV3bjv9wXKyKMeP0DY6Br2UQ0vJpnIhZFUQPrWU4WQgq3UhAGccNtpSKVL tz2Sqf9otYPFBiQ3l6PIKN2owZzN2Ht+fjeMqukMY2tI6jwe+NnGBHxR6SO+vSLJ A6bsmvUGhaPMXXG5jzJJ =pDni -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for librsvg2 is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: librsvg2 security update Advisory ID: RHSA-2023:4809-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4809 Issue date: 2023-08-29 CVE Names: CVE-2023-38633 ===================================================================== 1. Summary: An update for librsvg2 is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.9.0) - aarch64, ppc64le, s390x, x86_64 3. Description: The librsvg2 packages provide a Scalable Vector Graphics (SVG) library based on the libart library. Security Fix(es): * librsvg: Arbitrary file read when xinclude href has special characters (CVE-2023-38633) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2224945 - CVE-2023-38633 librsvg: Arbitrary file read when xinclude href has special characters 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.9.0): Source: librsvg2-2.50.7-1.el9_0.1.src.rpm aarch64: librsvg2-2.50.7-1.el9_0.1.aarch64.rpm librsvg2-debuginfo-2.50.7-1.el9_0.1.aarch64.rpm librsvg2-debugsource-2.50.7-1.el9_0.1.aarch64.rpm librsvg2-devel-2.50.7-1.el9_0.1.aarch64.rpm librsvg2-tools-2.50.7-1.el9_0.1.aarch64.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_0.1.aarch64.rpm ppc64le: librsvg2-2.50.7-1.el9_0.1.ppc64le.rpm librsvg2-debuginfo-2.50.7-1.el9_0.1.ppc64le.rpm librsvg2-debugsource-2.50.7-1.el9_0.1.ppc64le.rpm librsvg2-devel-2.50.7-1.el9_0.1.ppc64le.rpm librsvg2-tools-2.50.7-1.el9_0.1.ppc64le.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_0.1.ppc64le.rpm s390x: librsvg2-2.50.7-1.el9_0.1.s390x.rpm librsvg2-debuginfo-2.50.7-1.el9_0.1.s390x.rpm librsvg2-debugsource-2.50.7-1.el9_0.1.s390x.rpm librsvg2-devel-2.50.7-1.el9_0.1.s390x.rpm librsvg2-tools-2.50.7-1.el9_0.1.s390x.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_0.1.s390x.rpm x86_64: librsvg2-2.50.7-1.el9_0.1.i686.rpm librsvg2-2.50.7-1.el9_0.1.x86_64.rpm librsvg2-debuginfo-2.50.7-1.el9_0.1.i686.rpm librsvg2-debuginfo-2.50.7-1.el9_0.1.x86_64.rpm librsvg2-debugsource-2.50.7-1.el9_0.1.i686.rpm librsvg2-debugsource-2.50.7-1.el9_0.1.x86_64.rpm librsvg2-devel-2.50.7-1.el9_0.1.i686.rpm librsvg2-devel-2.50.7-1.el9_0.1.x86_64.rpm librsvg2-tools-2.50.7-1.el9_0.1.x86_64.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_0.1.i686.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_0.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-38633 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJk7gXmAAoJENzjgjWX9erEsuAP/3JsqjZLcYlnCCj8LFj12VF1 szOqxtD0x+s6/0OoSh1ry7x+ReJ4Hl3bE3XMDiNV+KQOZIbi7rgXPk/V44LA1+Su g+1h3xasJluKb2TdjGJL6E3bTj1M8jRV2HERzZbQ5xAROZ1Opiv9LeCyljxYUBf2 jTH+WIpkw8n3kk0YEluQCvXl64PJNZbJKBFdWrvtaQ1r78NDF1nSe8D/b28FPx9c C+QHAiFmHNpiY/9Wq3fRocJwuClbKPKzFDs0V40+R54YosRSZfVGf/4N4Ndi7do2 BnohX13NMZmX6GuyQE2dZVpCkUaHipj83m2WNOsWH4siT5OjcC02CibQ+lAcrJm2 rps6AWTtLoO5509dHM8EHGGU1LCndJD5DZUkg6mu3hyuClcRK5nWXLrSYAQVez4y YGbraHyc/1TzSN6XsWXCbr0q+8u5nhu908WSLpvxyzehZkcypAu4+mEFIcfd1nIy k0WrQ7uZOEpcVNZUw9vh8Dc8fzm4KHlpOqE6s3C0Zzr53kX7bQ3LcCCqs9ourwbL oiiHXf6L7O/rqqJ4HaTwkVJtZQjCJRfBQ9g66fSYR9YbXOZiIXovR65MZKVl2kqK JQR51S7JIkwcSjLtVkU89PNrHmvPIGIpJInFO7E3NoO/tYxsE3vsFtUwiqQVnzb+ JGYUfd0wZA8/0AQ4BwYc =CYlx -----END PGP SIGNATURE----- -- RHSA-announce mailing list
librsvg 2.54.6 release, fixing CVE-2023-38633: - Fix arbitrary file read when href has special characters.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-0873c38acd 2023-08-17 00:33:38.714810 -------------------------------------------------------------------------------- Name : librsvg2 Product : Fedora 37 Version : 2.54.6 Release : 1.fc37 URL : https://wiki.gnome.org/Projects/LibRsvg Summary : An SVG library based on cairo Description : An SVG library based on cairo. -------------------------------------------------------------------------------- Update Information: librsvg 2.54.6 release, fixing CVE-2023-38633: - Fix arbitrary file read when href has special characters. -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 1 2023 Kalev Lember - 2.54.6-1 - Update to 2.54.6 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0873c38acd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
An update for librsvg2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: librsvg2 security update Advisory ID: RHSA-2020:4709-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4709 Issue date: 2020-11-03 CVE Names: CVE-2019-20446 ==================================================================== 1. Summary: An update for librsvg2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The librsvg2 packages provide a Scalable Vector Graphics (SVG) library based on the libart library. Security Fix(es): * librsvg: Resource exhaustion via crafted SVG file with nested patterns (CVE-2019-20446) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 1797608 - CVE-2019-20446 librsvg: Resource exhaustion via crafted SVG file with nested patterns 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: librsvg2-2.42.7-4.el8.src.rpm aarch64: librsvg2-2.42.7-4.el8.aarch64.rpm librsvg2-debuginfo-2.42.7-4.el8.aarch64.rpm librsvg2-debugsource-2.42.7-4.el8.aarch64.rpm librsvg2-devel-2.42.7-4.el8.aarch64.rpm librsvg2-tools-2.42.7-4.el8.aarch64.rpm librsvg2-tools-debuginfo-2.42.7-4.el8.aarch64.rpm ppc64le: librsvg2-2.42.7-4.el8.ppc64le.rpm librsvg2-debuginfo-2.42.7-4.el8.ppc64le.rpm librsvg2-debugsource-2.42.7-4.el8.ppc64le.rpm librsvg2-devel-2.42.7-4.el8.ppc64le.rpm librsvg2-tools-2.42.7-4.el8.ppc64le.rpm librsvg2-tools-debuginfo-2.42.7-4.el8.ppc64le.rpm s390x: librsvg2-2.42.7-4.el8.s390x.rpm librsvg2-debuginfo-2.42.7-4.el8.s390x.rpm librsvg2-debugsource-2.42.7-4.el8.s390x.rpm librsvg2-devel-2.42.7-4.el8.s390x.rpm librsvg2-tools-2.42.7-4.el8.s390x.rpm librsvg2-tools-debuginfo-2.42.7-4.el8.s390x.rpm x86_64: librsvg2-2.42.7-4.el8.i686.rpm librsvg2-2.42.7-4.el8.x86_64.rpm librsvg2-debuginfo-2.42.7-4.el8.i686.rpm librsvg2-debuginfo-2.42.7-4.el8.x86_64.rpm librsvg2-debugsource-2.42.7-4.el8.i686.rpm librsvg2-debugsource-2.42.7-4.el8.x86_64.rpm librsvg2-devel-2.42.7-4.el8.i686.rpm librsvg2-devel-2.42.7-4.el8.x86_64.rpm librsvg2-tools-2.42.7-4.el8.x86_64.rpm librsvg2-tools-debuginfo-2.42.7-4.el8.i686.rpm librsvg2-tools-debuginfo-2.42.7-4.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-20446 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGPSIGNATURE----- Version: GnuPG v1 iQIVAwUBX6I459zjgjWX9erEAQjKdg//edLSxuHdabfPxe1TZHKEDZKW3U2si5jC 0zbcaN3SYWX24zl7S0/Oo2oefS6H/TzUZ1bT9/xFYOE7/SHV1b+MFR4UrPiBpwCd D49pInShXrNiCd9I+J6SOaRPXlIBtx5sFt4nuSts8GrXRGwQVDwB6tD9KvQKTpl5 E467DEjvQmHBhYUoF3Z9ybevj8jLqNYZN4vFsa/SesOZsUNDbbr90UuxDJs4NpYu BZ9/9lIAq5h0lg5RjRGSgcjXtzW2GUicdbYqN429TiZNKuY7lMwbVs7AUcu57G0h BtSUq5YWiU+9bfdgc6m0YoBjTUmee0sqc8TnPd+ztnkstg6CEPVZpFjEaTLu29lu BtDxMYZpqSbFvtgpFYBkP/UX9yoL21+3MOYF2Nn7lGMeg8TjlKxEAXivnw/Hde0d l8/H/rwF2J2KEbtzQt+coGk1p0pEisGSZ0MEXmdBa6cWmqImMddGav4BB3/w5gyy mfGx2Ysf+B3afeOxu37LekOZl/wl5ITQVxNQ6/4WlSMSwlnE+/e6CaSemu4SI5s1 najTH8xKSsg4/Ak0Ald7DrdHqmZeGsWVSQYbpeQd/EEV5SH4mZ1xv+ZevKOxc0r1 CCmBQPbjAQjhejnHFxzWVLQaGpgalm13yShWcBLFZhJGW+CpKGdDSV0QczOKZNsO AJl/ISGiBI0=MLy/ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
librsvg 2.42.7 release. - Fix a denial-of-service condition from exponential explosion of rendered elements, through nested use of SVG "use" elements in malicious SVGs. This is similar to the XML "billion laughs attack" but for SVG instancing.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-d7ef743ef0 2019-03-27 03:26:43.386615 --------------------------------------------------------------------------------Name : librsvg2 Product : Fedora 28 Version : 2.42.7 Release : 2.fc28 URL : https://wiki.gnome.org/Projects/LibRsvg Summary : An SVG library based on cairo Description : An SVG library based on cairo. --------------------------------------------------------------------------------Update Information: librsvg 2.42.7 release. - Fix a denial-of-service condition from exponential explosion of rendered elements, through nested use of SVG "use" elements in malicious SVGs. This is similar to the XML "billion laughs attack" but for SVG instancing. --------------------------------------------------------------------------------ChangeLog: * Mon Feb 18 2019 Kalev Lember - 2.42.7-2 - Rebuild * Tue Sep 4 2018 Kalev Lember - 2.42.7-1 - Update to 2.42.7 * Wed Aug 8 2018 Kalev Lember - 2.42.6-1 - Update to 2.42.6 - Use bundled rust deps --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-d7ef743ef0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announcemailing list --
librsvg 2.40.18 release, fixing CVE-2017-11464 (division-by-zero in the Gaussian blur code). For details, see https://mail.gnome.org/archives/ftp-release-list/2017-July/msg00078.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-cf1a42722d 2017-07-24 17:29:46.085997 --------------------------------------------------------------------------------Name : librsvg2 Product : Fedora 25 Version : 2.40.18 Release : 1.fc25 URL : https://wiki.gnome.org/Projects/LibRsvg Summary : An SVG library based on cairo Description : An SVG library based on cairo. --------------------------------------------------------------------------------Update Information: librsvg 2.40.18 release, fixing CVE-2017-11464 (division-by-zero in the Gaussian blur code). For details, see https://mail.gnome.org/archives/ftp-release-list/2017-July/msg00078.html --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade librsvg2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.