The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-6713 http://linux.oracle.com/errata/ELSA-2026-6713.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: ImageMagick-6.9.10.68-7.0.9.el7_9.i686.rpm ImageMagick-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-c++-6.9.10.68-7.0.9.el7_9.i686.rpm ImageMagick-c++-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-c++-devel-6.9.10.68-7.0.9.el7_9.i686.rpm ImageMagick-c++-devel-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-devel-6.9.10.68-7.0.9.el7_9.i686.rpm ImageMagick-devel-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-doc-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-perl-6.9.10.68-7.0.9.el7_9.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/ImageMagick-6.9.10.68-7.0.9.el7_9.src.rpm Related CVEs: CVE-2026-28691 CVE-2026-28693 Description of changes: [6.9.10.68-7.0.9] - Fix CVE-2026-28691 and CVE-2026-28693 [Orabug: 39174244] [6.9.10.68-7.0.7] - Fixes Local File Disclosure via Path Traversal (CVE-2026-25965) [Orabug: 39118995] - Fixes Memory allocation with excessive without limits in the internal SVG decoder (CVE-2026-25985) [6.9.10.68-7.0.5] - Fix CVE-2025-62171 and CVE-2026-23876 [Orabug: 38997140] [6.9.10.68-7.0.3] - Security update CVE-2025-57803 [Orabug: 38455460] [6.9.10.68-7.0.1] - Fix for CVE-2025-55154 [Orabug: 38417011] _______________________________________________ El-errata mailing list
An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for GraphicsMagick ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1619-1 Rating: moderate References: #1138425 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.1 openSUSE Leap 15.0 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for GraphicsMagick fixes the following issues: - disable indirect reads that disclosed file contents from the local system (boo#1138425) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2019-1619=1 - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-1619=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1619=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): GraphicsMagick-1.3.25-144.1 GraphicsMagick-debuginfo-1.3.25-144.1 GraphicsMagick-debugsource-1.3.25-144.1 GraphicsMagick-devel-1.3.25-144.1 libGraphicsMagick++-Q16-12-1.3.25-144.1 libGraphicsMagick++-Q16-12-debuginfo-1.3.25-144.1 libGraphicsMagick++-devel-1.3.25-144.1 libGraphicsMagick-Q16-3-1.3.25-144.1 libGraphicsMagick-Q16-3-debuginfo-1.3.25-144.1 libGraphicsMagick3-config-1.3.25-144.1 libGraphicsMagickWand-Q16-2-1.3.25-144.1 libGraphicsMagickWand-Q16-2-debuginfo-1.3.25-144.1 perl-GraphicsMagick-1.3.25-144.1 perl-GraphicsMagick-debuginfo-1.3.25-144.1 - openSUSE Leap 15.1 (x86_64): GraphicsMagick-1.3.29-lp151.4.6.1 GraphicsMagick-debuginfo-1.3.29-lp151.4.6.1 GraphicsMagick-debugsource-1.3.29-lp151.4.6.1 GraphicsMagick-devel-1.3.29-lp151.4.6.1 libGraphicsMagick++-Q16-12-1.3.29-lp151.4.6.1 libGraphicsMagick++-Q16-12-debuginfo-1.3.29-lp151.4.6.1 libGraphicsMagick++-devel-1.3.29-lp151.4.6.1 libGraphicsMagick-Q16-3-1.3.29-lp151.4.6.1 libGraphicsMagick-Q16-3-debuginfo-1.3.29-lp151.4.6.1 libGraphicsMagick3-config-1.3.29-lp151.4.6.1 libGraphicsMagickWand-Q16-2-1.3.29-lp151.4.6.1 libGraphicsMagickWand-Q16-2-debuginfo-1.3.29-lp151.4.6.1 perl-GraphicsMagick-1.3.29-lp151.4.6.1 perl-GraphicsMagick-debuginfo-1.3.29-lp151.4.6.1 - openSUSE Leap 15.0 (x86_64): GraphicsMagick-1.3.29-lp150.3.34.1 GraphicsMagick-debuginfo-1.3.29-lp150.3.34.1 GraphicsMagick-debugsource-1.3.29-lp150.3.34.1 GraphicsMagick-devel-1.3.29-lp150.3.34.1 libGraphicsMagick++-Q16-12-1.3.29-lp150.3.34.1 libGraphicsMagick++-Q16-12-debuginfo-1.3.29-lp150.3.34.1 libGraphicsMagick++-devel-1.3.29-lp150.3.34.1 libGraphicsMagick-Q16-3-1.3.29-lp150.3.34.1 libGraphicsMagick-Q16-3-debuginfo-1.3.29-lp150.3.34.1 libGraphicsMagick3-config-1.3.29-lp150.3.34.1 libGraphicsMagickWand-Q16-2-1.3.29-lp150.3.34.1 libGraphicsMagickWand-Q16-2-debuginfo-1.3.29-lp150.3.34.1 perl-GraphicsMagick-1.3.29-lp150.3.34.1 perl-GraphicsMagick-debuginfo-1.3.29-lp150.3.34.1 References: https://bugzilla.suse.com/1138425 -- . GraphicsMagick security patch deployed for openSUSE users tackling local file exposure vulnerabilities.. openSUSE security update, GraphicsMagick patch, local file exposure fix. . LinuxSecurity.com Team
It was discovered that there were two vulnerabilities libphp-phpmailer, an email library for the PHP programming language: * CVE-2017-5223: Local file disclosure vulnerability via relative path . Package : libphp-phpmailer Version : 5.2.9+dfsg-2+deb8u4 CVE IDs : CVE-2017-5223 CVE-2018-19296 It was discovered that there were two vulnerabilities libphp-phpmailer, an email library for the PHP programming language: * CVE-2017-5223: Local file disclosure vulnerability via relative path HTML transformations. * CVE-2018-19296: Object injection attack. For Debian 8 "Jessie", this issue has been fixed in libphp-phpmailer version 5.2.9+dfsg-2+deb8u4. We recommend that you upgrade your libphp-phpmailer packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Critical: seamonkey security update. Date: Fri, 4 Jul 2008 10:06:15 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for seamonkey on SL3.x, SL4.x i386/x86_64 Comments: To: "
An updated squirrelmail package that fixes a local file . Date: Wed, 5 Jul 2006 12:12:57 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for "squirrelmail" on SL 40,41,42,43 i386,x86_64 now available Comments: To:
An updated squirrelmail package that fixes a local file . Date: Wed, 5 Jul 2006 12:06:22 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for "squirrelmail" on SL 301,302,303,304,305,307 i386,x86_64 now available Comments: To:
Get the latest Linux and open source security news straight to your inbox.