Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
89

Fedora 39: FEDORA-2024-40ee18b2e7 Moderate: librsvg2 Denial of Service

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-40ee18b2e7 2024-06-02 03:36:56.060441 -------------------------------------------------------------------------------- Name : librsvg2 Product : Fedora 39 Version : 2.57.1 Release : 2.fc39 URL : https://wiki.gnome.org/Projects/LibRsvg Summary : An SVG library based on cairo Description : An SVG library based on cairo. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Fri May 24 2024 Fabio Valentini - 2.57.1-2 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-40ee18b2e7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . The librsvg2 enhancement improves integration with Rust and resolves minor security issues for applications running on Fedora 39.. Rust Applications Update,Fedora 39 Security,Software Fixes,Library Updates. . LinuxSecurity.com Team

Calendar%202 Jun 02, 2024 Fedora
217

Oracle Linux 9 ELSA-2023-5081 Moderate: Librsvg2 Security Patch

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-5081 https://linux.oracle.com/errata/ELSA-2023-5081.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: librsvg2-2.50.7-1.el9_2.1.i686.rpm librsvg2-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-devel-2.50.7-1.el9_2.1.i686.rpm librsvg2-devel-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-tools-2.50.7-1.el9_2.1.x86_64.rpm aarch64: librsvg2-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-devel-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-tools-2.50.7-1.el9_2.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//librsvg2-2.50.7-1.el9_2.1.src.rpm Related CVEs: CVE-2023-38633 Description of changes: [2.50.7-1.el9_2.1] - Fix CVE-2023-38633 (#2224947) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Advisory ELSA-2023-5081 addresses a moderate security issue in Librsvg2. Fix the identified risk now!. linux, updated, oracle, unbreakable, network. . LinuxSecurity.com Team

Calendar%202 Sep 14, 2023 Oracle
98

Red Hat: RHSA-2023:5081-01 Moderate: librsvg2 Arbitrary File Read

An update for librsvg2 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: librsvg2 security update Advisory ID: RHSA-2023:5081-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5081 Issue date: 2023-09-12 CVE Names: CVE-2023-38633 ===================================================================== 1. Summary: An update for librsvg2 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The librsvg2 packages provide a Scalable Vector Graphics (SVG) library based on the libart library. Security Fix(es): * librsvg: Arbitrary file read when xinclude href has special characters (CVE-2023-38633) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2224945 - CVE-2023-38633 librsvg: Arbitrary file read when xinclude href has special characters 6. Package List: Red Hat Enterprise LinuxAppStream (v. 9): Source: librsvg2-2.50.7-1.el9_2.1.src.rpm aarch64: librsvg2-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-debuginfo-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-debugsource-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-devel-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-tools-2.50.7-1.el9_2.1.aarch64.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_2.1.aarch64.rpm ppc64le: librsvg2-2.50.7-1.el9_2.1.ppc64le.rpm librsvg2-debuginfo-2.50.7-1.el9_2.1.ppc64le.rpm librsvg2-debugsource-2.50.7-1.el9_2.1.ppc64le.rpm librsvg2-devel-2.50.7-1.el9_2.1.ppc64le.rpm librsvg2-tools-2.50.7-1.el9_2.1.ppc64le.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_2.1.ppc64le.rpm s390x: librsvg2-2.50.7-1.el9_2.1.s390x.rpm librsvg2-debuginfo-2.50.7-1.el9_2.1.s390x.rpm librsvg2-debugsource-2.50.7-1.el9_2.1.s390x.rpm librsvg2-devel-2.50.7-1.el9_2.1.s390x.rpm librsvg2-tools-2.50.7-1.el9_2.1.s390x.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_2.1.s390x.rpm x86_64: librsvg2-2.50.7-1.el9_2.1.i686.rpm librsvg2-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-debuginfo-2.50.7-1.el9_2.1.i686.rpm librsvg2-debuginfo-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-debugsource-2.50.7-1.el9_2.1.i686.rpm librsvg2-debugsource-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-devel-2.50.7-1.el9_2.1.i686.rpm librsvg2-devel-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-tools-2.50.7-1.el9_2.1.x86_64.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_2.1.i686.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_2.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-38633 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlAINkAAoJENzjgjWX9erEmkgP/0vJfSsohnRgUIB7UneTgOQq ksqb1fvDRc8CeDpZZeqIOL/q+F7tZzxlb8GFT6Q5P/RJn5wG1ESA2fQ8jkTr7CVs 983vvdl3fSSx3urMQM5jqVFhHfeogGiGEAqLnLUqNpC1MTvoGEH7iqLlWqKYiNJc T3eHbMcYAmFNdFqPaPeifzb6GfU4lv2LSNU3CLMOLBftFcEJ7pEcl6i8m0EVgVoX clT39XoMKZ+TAEOOxCTbM6LN08PvlTdotVDDH2XcTzdCMVmA0aT8zNF4CPfLlah9 Tct7OU8FWijKKNAWNZ1+ONtjUmZMgGX+/Yv2Yj2dNTiClFbq29KlZ3zFERb/mOUP EHa9T6HuXtahdDPcuHbJeK91u4w3gpCfGxBkj2Vw7omMQWfj4NeXb/iOdrsiVhtE HSx41yeNenmhvfLPF6tmQDzmeqFZje/+Vt+lP+N/terWuKJwoH8UeTb+twFTgNj/ XDAg0kCjizZG5420wh33ZKhY9n3S6t4F8C2Y+RUP3gNttwWCYsctPq2U9OAhvBcw Ig6nI4PV3bjv9wXKyKMeP0DY6Br2UQ0vJpnIhZFUQPrWU4WQgq3UhAGccNtpSKVL tz2Sqf9otYPFBiQ3l6PIKN2owZzN2Ht+fjeMqukMY2tI6jwe+NnGBHxR6SO+vSLJ A6bsmvUGhaPMXXG5jzJJ =pDni -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu released a critical patch for libxml2 fixing potential information disclosures categorized as high risk. Immediate intervention recommended.. Red Hat Security, librsvg2 Update, Linux Security Advisory, Moderate Severity Update, Enterprise Linux Fix. . LinuxSecurity.com Team

Calendar%202 Sep 12, 2023 Red Hat
98

Red Hat Enterprise Linux 9 RHSA-2023-4809: Librsvg2 File Read Vulnerability

An update for librsvg2 is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: librsvg2 security update Advisory ID: RHSA-2023:4809-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4809 Issue date: 2023-08-29 CVE Names: CVE-2023-38633 ===================================================================== 1. Summary: An update for librsvg2 is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.9.0) - aarch64, ppc64le, s390x, x86_64 3. Description: The librsvg2 packages provide a Scalable Vector Graphics (SVG) library based on the libart library. Security Fix(es): * librsvg: Arbitrary file read when xinclude href has special characters (CVE-2023-38633) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2224945 - CVE-2023-38633 librsvg: Arbitrary file read when xinclude href has special characters 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.9.0): Source: librsvg2-2.50.7-1.el9_0.1.src.rpm aarch64: librsvg2-2.50.7-1.el9_0.1.aarch64.rpm librsvg2-debuginfo-2.50.7-1.el9_0.1.aarch64.rpm librsvg2-debugsource-2.50.7-1.el9_0.1.aarch64.rpm librsvg2-devel-2.50.7-1.el9_0.1.aarch64.rpm librsvg2-tools-2.50.7-1.el9_0.1.aarch64.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_0.1.aarch64.rpm ppc64le: librsvg2-2.50.7-1.el9_0.1.ppc64le.rpm librsvg2-debuginfo-2.50.7-1.el9_0.1.ppc64le.rpm librsvg2-debugsource-2.50.7-1.el9_0.1.ppc64le.rpm librsvg2-devel-2.50.7-1.el9_0.1.ppc64le.rpm librsvg2-tools-2.50.7-1.el9_0.1.ppc64le.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_0.1.ppc64le.rpm s390x: librsvg2-2.50.7-1.el9_0.1.s390x.rpm librsvg2-debuginfo-2.50.7-1.el9_0.1.s390x.rpm librsvg2-debugsource-2.50.7-1.el9_0.1.s390x.rpm librsvg2-devel-2.50.7-1.el9_0.1.s390x.rpm librsvg2-tools-2.50.7-1.el9_0.1.s390x.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_0.1.s390x.rpm x86_64: librsvg2-2.50.7-1.el9_0.1.i686.rpm librsvg2-2.50.7-1.el9_0.1.x86_64.rpm librsvg2-debuginfo-2.50.7-1.el9_0.1.i686.rpm librsvg2-debuginfo-2.50.7-1.el9_0.1.x86_64.rpm librsvg2-debugsource-2.50.7-1.el9_0.1.i686.rpm librsvg2-debugsource-2.50.7-1.el9_0.1.x86_64.rpm librsvg2-devel-2.50.7-1.el9_0.1.i686.rpm librsvg2-devel-2.50.7-1.el9_0.1.x86_64.rpm librsvg2-tools-2.50.7-1.el9_0.1.x86_64.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_0.1.i686.rpm librsvg2-tools-debuginfo-2.50.7-1.el9_0.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-38633 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJk7gXmAAoJENzjgjWX9erEsuAP/3JsqjZLcYlnCCj8LFj12VF1 szOqxtD0x+s6/0OoSh1ry7x+ReJ4Hl3bE3XMDiNV+KQOZIbi7rgXPk/V44LA1+Su g+1h3xasJluKb2TdjGJL6E3bTj1M8jRV2HERzZbQ5xAROZ1Opiv9LeCyljxYUBf2 jTH+WIpkw8n3kk0YEluQCvXl64PJNZbJKBFdWrvtaQ1r78NDF1nSe8D/b28FPx9c C+QHAiFmHNpiY/9Wq3fRocJwuClbKPKzFDs0V40+R54YosRSZfVGf/4N4Ndi7do2 BnohX13NMZmX6GuyQE2dZVpCkUaHipj83m2WNOsWH4siT5OjcC02CibQ+lAcrJm2 rps6AWTtLoO5509dHM8EHGGU1LCndJD5DZUkg6mu3hyuClcRK5nWXLrSYAQVez4y YGbraHyc/1TzSN6XsWXCbr0q+8u5nhu908WSLpvxyzehZkcypAu4+mEFIcfd1nIy k0WrQ7uZOEpcVNZUw9vh8Dc8fzm4KHlpOqE6s3C0Zzr53kX7bQ3LcCCqs9ourwbL oiiHXf6L7O/rqqJ4HaTwkVJtZQjCJRfBQ9g66fSYR9YbXOZiIXovR65MZKVl2kqK JQR51S7JIkwcSjLtVkU89PNrHmvPIGIpJInFO7E3NoO/tYxsE3vsFtUwiqQVnzb+ JGYUfd0wZA8/0AQ4BwYc =CYlx -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A significant update for librsvg2 has been released, categorized as moderate risk, which mitigates an issue related to arbitrary file reading.. librsvg2 Update, Red Hat Enterprise, Security Advisory. . LinuxSecurity.com Team

Calendar%202 Aug 29, 2023 Red Hat
89

Fedora 37: FEDORA-2023-0873c38acd Critical: librsvg2 File Read Threat

librsvg 2.54.6 release, fixing CVE-2023-38633: - Fix arbitrary file read when href has special characters.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-0873c38acd 2023-08-17 00:33:38.714810 -------------------------------------------------------------------------------- Name : librsvg2 Product : Fedora 37 Version : 2.54.6 Release : 1.fc37 URL : https://wiki.gnome.org/Projects/LibRsvg Summary : An SVG library based on cairo Description : An SVG library based on cairo. -------------------------------------------------------------------------------- Update Information: librsvg 2.54.6 release, fixing CVE-2023-38633: - Fix arbitrary file read when href has special characters. -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 1 2023 Kalev Lember - 2.54.6-1 - Update to 2.54.6 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0873c38acd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not replyto spam, report it: . Update for librsvg2 mitigating security vulnerabilities in Fedora 37 while enhancing file processing functionalities.. librsvg2,Fedora 37,arbitrary file read,security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 17, 2023 Critical Fedora
98

Red Hat Enterprise Linux 8: RHSA-2020-4709 Notice on librsvg2 Resource Loss

An update for librsvg2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: librsvg2 security update Advisory ID: RHSA-2020:4709-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4709 Issue date: 2020-11-03 CVE Names: CVE-2019-20446 ==================================================================== 1. Summary: An update for librsvg2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The librsvg2 packages provide a Scalable Vector Graphics (SVG) library based on the libart library. Security Fix(es): * librsvg: Resource exhaustion via crafted SVG file with nested patterns (CVE-2019-20446) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 1797608 - CVE-2019-20446 librsvg: Resource exhaustion via crafted SVG file with nested patterns 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: librsvg2-2.42.7-4.el8.src.rpm aarch64: librsvg2-2.42.7-4.el8.aarch64.rpm librsvg2-debuginfo-2.42.7-4.el8.aarch64.rpm librsvg2-debugsource-2.42.7-4.el8.aarch64.rpm librsvg2-devel-2.42.7-4.el8.aarch64.rpm librsvg2-tools-2.42.7-4.el8.aarch64.rpm librsvg2-tools-debuginfo-2.42.7-4.el8.aarch64.rpm ppc64le: librsvg2-2.42.7-4.el8.ppc64le.rpm librsvg2-debuginfo-2.42.7-4.el8.ppc64le.rpm librsvg2-debugsource-2.42.7-4.el8.ppc64le.rpm librsvg2-devel-2.42.7-4.el8.ppc64le.rpm librsvg2-tools-2.42.7-4.el8.ppc64le.rpm librsvg2-tools-debuginfo-2.42.7-4.el8.ppc64le.rpm s390x: librsvg2-2.42.7-4.el8.s390x.rpm librsvg2-debuginfo-2.42.7-4.el8.s390x.rpm librsvg2-debugsource-2.42.7-4.el8.s390x.rpm librsvg2-devel-2.42.7-4.el8.s390x.rpm librsvg2-tools-2.42.7-4.el8.s390x.rpm librsvg2-tools-debuginfo-2.42.7-4.el8.s390x.rpm x86_64: librsvg2-2.42.7-4.el8.i686.rpm librsvg2-2.42.7-4.el8.x86_64.rpm librsvg2-debuginfo-2.42.7-4.el8.i686.rpm librsvg2-debuginfo-2.42.7-4.el8.x86_64.rpm librsvg2-debugsource-2.42.7-4.el8.i686.rpm librsvg2-debugsource-2.42.7-4.el8.x86_64.rpm librsvg2-devel-2.42.7-4.el8.i686.rpm librsvg2-devel-2.42.7-4.el8.x86_64.rpm librsvg2-tools-2.42.7-4.el8.x86_64.rpm librsvg2-tools-debuginfo-2.42.7-4.el8.i686.rpm librsvg2-tools-debuginfo-2.42.7-4.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-20446 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGPSIGNATURE----- Version: GnuPG v1 iQIVAwUBX6I459zjgjWX9erEAQjKdg//edLSxuHdabfPxe1TZHKEDZKW3U2si5jC 0zbcaN3SYWX24zl7S0/Oo2oefS6H/TzUZ1bT9/xFYOE7/SHV1b+MFR4UrPiBpwCd D49pInShXrNiCd9I+J6SOaRPXlIBtx5sFt4nuSts8GrXRGwQVDwB6tD9KvQKTpl5 E467DEjvQmHBhYUoF3Z9ybevj8jLqNYZN4vFsa/SesOZsUNDbbr90UuxDJs4NpYu BZ9/9lIAq5h0lg5RjRGSgcjXtzW2GUicdbYqN429TiZNKuY7lMwbVs7AUcu57G0h BtSUq5YWiU+9bfdgc6m0YoBjTUmee0sqc8TnPd+ztnkstg6CEPVZpFjEaTLu29lu BtDxMYZpqSbFvtgpFYBkP/UX9yoL21+3MOYF2Nn7lGMeg8TjlKxEAXivnw/Hde0d l8/H/rwF2J2KEbtzQt+coGk1p0pEisGSZ0MEXmdBa6cWmqImMddGav4BB3/w5gyy mfGx2Ysf+B3afeOxu37LekOZl/wl5ITQVxNQ6/4WlSMSwlnE+/e6CaSemu4SI5s1 najTH8xKSsg4/Ak0Ald7DrdHqmZeGsWVSQYbpeQd/EEV5SH4mZ1xv+ZevKOxc0r1 CCmBQPbjAQjhejnHFxzWVLQaGpgalm13yShWcBLFZhJGW+CpKGdDSV0QczOKZNsO AJl/ISGiBI0=MLy/ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A security update for librsvg2 in Red Hat Enterprise Linux 8 has been released. It's crucial to implement the fix without delay.. librsvg2 Update, Red Hat Security Advisory, resource exhaustion fix, Linux security updates. . LinuxSecurity.com Team

Calendar%202 Nov 04, 2020 Red Hat
89

Fedora 28 FEDORA-2019-d7ef743ef0 high: librsvg2 DoS issue

librsvg 2.42.7 release. - Fix a denial-of-service condition from exponential explosion of rendered elements, through nested use of SVG "use" elements in malicious SVGs. This is similar to the XML "billion laughs attack" but for SVG instancing.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-d7ef743ef0 2019-03-27 03:26:43.386615 --------------------------------------------------------------------------------Name : librsvg2 Product : Fedora 28 Version : 2.42.7 Release : 2.fc28 URL : https://wiki.gnome.org/Projects/LibRsvg Summary : An SVG library based on cairo Description : An SVG library based on cairo. --------------------------------------------------------------------------------Update Information: librsvg 2.42.7 release. - Fix a denial-of-service condition from exponential explosion of rendered elements, through nested use of SVG "use" elements in malicious SVGs. This is similar to the XML "billion laughs attack" but for SVG instancing. --------------------------------------------------------------------------------ChangeLog: * Mon Feb 18 2019 Kalev Lember - 2.42.7-2 - Rebuild * Tue Sep 4 2018 Kalev Lember - 2.42.7-1 - Update to 2.42.7 * Wed Aug 8 2018 Kalev Lember - 2.42.6-1 - Update to 2.42.6 - Use bundled rust deps --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-d7ef743ef0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announcemailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Mitigate possible denial-of-service vulnerabilities in librsvg2 by applying the security updates from Fedora 28 released on 2019-03-27, enhancing system reliability and performance. librsvg, denial of service, Fedora security update. . LinuxSecurity.com Team

Calendar%202 Mar 26, 2019 Fedora
89

Fedora 25: Important DoS Vulnerability in Librsvg2 Resolved Successfully

librsvg 2.40.18 release, fixing CVE-2017-11464 (division-by-zero in the Gaussian blur code). For details, see https://mail.gnome.org/archives/ftp-release-list/2017-July/msg00078.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-cf1a42722d 2017-07-24 17:29:46.085997 --------------------------------------------------------------------------------Name : librsvg2 Product : Fedora 25 Version : 2.40.18 Release : 1.fc25 URL : https://wiki.gnome.org/Projects/LibRsvg Summary : An SVG library based on cairo Description : An SVG library based on cairo. --------------------------------------------------------------------------------Update Information: librsvg 2.40.18 release, fixing CVE-2017-11464 (division-by-zero in the Gaussian blur code). For details, see https://mail.gnome.org/archives/ftp-release-list/2017-July/msg00078.html --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade librsvg2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent security patch for Librsvg2 resolves a critical division-by-zero vulnerability in its Gaussian blur implementation, thereby maintaining system stability on Fedora 25.. Librsvg2 Security, Fedora 25 Update, Gaussian Blur Fix, DoS Mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 25, 2017 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200