An update that solves one vulnerability can now be installed.. # Security update for openjpeg2 Announcement ID: SUSE-SU-2026:20422-1 Release Date: 2026-02-11T19:15:23Z Rating: low References: * bsc#1227412 Cross-References: * CVE-2023-39327 CVSS scores: * CVE-2023-39327 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2023-39327 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-39327 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for openjpeg2 fixes the following issues: * CVE-2023-39327: Fixed malicious files can cause a large loop that continuously prints warning messages on the terminal (bsc#1227412). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-257=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-257=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libopenjp2-7-2.5.3-160000.3.1 * libopenjp2-7-debuginfo-2.5.3-160000.3.1 * openjpeg2-debuginfo-2.5.3-160000.3.1 * openjpeg2-debugsource-2.5.3-160000.3.1 * openjpeg2-2.5.3-160000.3.1 * openjpeg2-devel-2.5.3-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * openjpeg2-devel-doc-2.5.3-160000.3.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libopenjp2-7-x86-64-v3-2.5.3-160000.3.1 * libopenjp2-7-x86-64-v3-debuginfo-2.5.3-160000.3.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * libopenjp2-7-2.5.3-160000.3.1 *libopenjp2-7-debuginfo-2.5.3-160000.3.1 * openjpeg2-debuginfo-2.5.3-160000.3.1 * openjpeg2-debugsource-2.5.3-160000.3.1 * openjpeg2-2.5.3-160000.3.1 * openjpeg2-devel-2.5.3-160000.3.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (x86_64) * libopenjp2-7-x86-64-v3-2.5.3-160000.3.1 * libopenjp2-7-x86-64-v3-debuginfo-2.5.3-160000.3.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (noarch) * openjpeg2-devel-doc-2.5.3-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-39327.html * https://bugzilla.suse.com/show_bug.cgi?id=1227412 . Update resolves a low severity issue in openjpeg2 for SUSE, addressing a loop attack vulnerability.. openjpeg2 security update SUSE patch low severity. . Severity: Low. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for openjpeg2 Announcement ID: SUSE-SU-2026:0330-1 Release Date: 2026-01-28T16:27:19Z Rating: low References: * bsc#1227412 Cross-References: * CVE-2023-39327 CVSS scores: * CVE-2023-39327 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2023-39327 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-39327 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for openjpeg2 fixes the following issues: * CVE-2023-39327: Fixed malicious files can cause a large loop that continuously prints warning messages on the terminal (bsc#1227412). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-330=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-330=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-330=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * openjpeg2-debugsource-2.3.0-150000.3.24.1 * openjpeg2-devel-2.3.0-150000.3.24.1 * libopenjp2-7-debuginfo-2.3.0-150000.3.24.1 * libopenjp2-7-2.3.0-150000.3.24.1 * openjpeg2-2.3.0-150000.3.24.1 * openjpeg2-debuginfo-2.3.0-150000.3.24.1 * openSUSE Leap 15.6 (x86_64) * libopenjp2-7-32bit-debuginfo-2.3.0-150000.3.24.1 *libopenjp2-7-32bit-2.3.0-150000.3.24.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openjpeg2-debugsource-2.3.0-150000.3.24.1 * openjpeg2-devel-2.3.0-150000.3.24.1 * libopenjp2-7-debuginfo-2.3.0-150000.3.24.1 * libopenjp2-7-2.3.0-150000.3.24.1 * openjpeg2-2.3.0-150000.3.24.1 * openjpeg2-debuginfo-2.3.0-150000.3.24.1 * SUSE Package Hub 15 15-SP7 (x86_64) * libopenjp2-7-32bit-debuginfo-2.3.0-150000.3.24.1 * libopenjp2-7-32bit-2.3.0-150000.3.24.1 ## References: * https://www.suse.com/security/cve/CVE-2023-39327.html * https://bugzilla.suse.com/show_bug.cgi?id=1227412 . Update for openjpeg2 addresses a low-severity security issue in SUSE, preventing malicious loop threats on terminal.. openjpeg2 security update, openSUSE patch, SUSE vulnerability fix. . Severity: Low. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for openjpeg2 Announcement ID: SUSE-SU-2026:0330-1 Release Date: 2026-01-28T16:27:19Z Rating: low References: * bsc#1227412 Cross-References: * CVE-2023-39327 CVSS scores: * CVE-2023-39327 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2023-39327 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-39327 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for openjpeg2 fixes the following issues: * CVE-2023-39327: Fixed malicious files can cause a large loop that continuously prints warning messages on the terminal (bsc#1227412). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-330=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-330=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-330=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * openjpeg2-debugsource-2.3.0-150000.3.24.1 * openjpeg2-devel-2.3.0-150000.3.24.1 * libopenjp2-7-debuginfo-2.3.0-150000.3.24.1 * libopenjp2-7-2.3.0-150000.3.24.1 * openjpeg2-2.3.0-150000.3.24.1 * openjpeg2-debuginfo-2.3.0-150000.3.24.1 * openSUSE Leap 15.6 (x86_64) * libopenjp2-7-32bit-debuginfo-2.3.0-150000.3.24.1 *libopenjp2-7-32bit-2.3.0-150000.3.24.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openjpeg2-debugsource-2.3.0-150000.3.24.1 * openjpeg2-devel-2.3.0-150000.3.24.1 * libopenjp2-7-debuginfo-2.3.0-150000.3.24.1 * libopenjp2-7-2.3.0-150000.3.24.1 * openjpeg2-2.3.0-150000.3.24.1 * openjpeg2-debuginfo-2.3.0-150000.3.24.1 * SUSE Package Hub 15 15-SP7 (x86_64) * libopenjp2-7-32bit-debuginfo-2.3.0-150000.3.24.1 * libopenjp2-7-32bit-2.3.0-150000.3.24.1 ## References: * https://www.suse.com/security/cve/CVE-2023-39327.html * https://bugzilla.suse.com/show_bug.cgi?id=1227412 . Update for openjpeg2 on openSUSE fixes a low-severity issue with malicious files causing system disruptions.. openjpeg2 security fix, SUSE openSUSE updates, low severity security advisory. . Severity: Low. LinuxSecurity.com Team
Backport fix for CVE-2023-39327.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-3ecdf562bf 2024-09-22 00:14:59.037950 -------------------------------------------------------------------------------- Name : openjpeg Product : Fedora 41 Version : 2.5.2 Release : 4.fc41 URL : https://github.com/uclouvain/openjpeg Summary : C-Library for JPEG 2000 Description : The OpenJPEG library is an open-source JPEG 2000 library developed in order to promote the use of JPEG 2000. This package contains * JPEG 2000 codec compliant with the Part 1 of the standard (Class-1 Profile-1 compliance). * JP2 (JPEG 2000 standard Part 2 - Handling of JP2 boxes and extended multiple component transforms for multispectral and hyperspectral imagery) -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2023-39327. -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 6 2024 Sandro Mani - 2.5.2-4 - Backport patch for CVE-2023-39327 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2295814 - CVE-2023-39327 openjpeg: Malicious files can cause the program to enter a large loop [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2295814 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-3ecdf562bf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744). References: - https://bugs.mageia.org/show_bug.cgi?id=25403 . MGASA-2019-0378 - Updated kdelibs4 packages fix security vulnerability Publication date: 13 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0378.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744). References: - https://bugs.mageia.org/show_bug.cgi?id=25403 - https://kde.org/info/security/advisory-20190807-1.txt - https://access.redhat.com/errata/RHSA-2019:2606 - https://www.cve.org/CVERecord?id=CVE-2019-14744 SRPMS: - 7/core/kdelibs4-4.14.38-7.1.mga7 . Mageia releases kdelibs4 update to address a security vulnerability that permits limited user interaction for executing code. Read on for more information.. kdelibs Security Advisory, Mageia Update, Malicious Files Execution, Desktop Application Vulnerability. . LinuxSecurity.com Team
NLTK could be made to overwrite files.. =========================================================================Ubuntu Security Notice USN-4106-1 August 20, 2019 NLTK vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.04 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: NLTK could be made to overwrite files. Software Description: - nltk: Python libraries for natural language processing Details: Mike Salvatore discovered that NLTK mishandled crafted ZIP archives during extraction. A remote attacker could use this vulnerability to write arbitrary files to the filesystem Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: python-nltk 3.4-1ubuntu0.1 python3-nltk 3.4-1ubuntu0.1 Ubuntu 18.04 LTS: python-nltk 3.2.5-1ubuntu0.1 python3-nltk 3.2.5-1ubuntu0.1 Ubuntu 16.04 LTS: python-nltk 3.1-1ubuntu0.1 python3-nltk 3.1-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4106-1 CVE-2019-14751 Package Information: https://launchpad.net/ubuntu/+source/nltk/3.4-1ubuntu0.1 https://launchpad.net/ubuntu/+source/nltk/3.2.5-1ubuntu0.1 https://launchpad.net/ubuntu/+source/nltk/3.1-1ubuntu0.1 . Ubuntu Security Notice USN-4106-1 addresses a NLTK flaw that could lead to file overwrites; users are advised to upgrade to ensure safety.. NLTK Vulnerability, Ubuntu Security Notice, File Overwrite Exploit, Software Update Instructions. . Severity: Important. LinuxSecurity.com Team
This update fixes **CVE-2019-14744 (kconfig arbitrary shell code execution)** in the KDE 3 compatibility version of kdelibs used by legacy KDE 3 applications. The full list of fixes in this `kdelibs3` build: * fixes **CVE-2019-14744** - `kconfig`: malicious `.desktop` files (and others) would execute code. KConfig had a well-meaning feature that allowed configuration files to execute arbitrary. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-f9f78895c3 2019-08-19 01:01:06.548912 --------------------------------------------------------------------------------Name : kdelibs3 Product : Fedora 30 Version : 3.5.10 Release : 101.fc30 URL : https://kde.org/ Summary : KDE 3 Libraries Description : Libraries for KDE 3: KDE Libraries included: kdecore (KDE core library), kdeui (user interface), kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking), kspell (spelling checker), jscript (javascript), kab (addressbook), kimgio (image manipulation). --------------------------------------------------------------------------------Update Information: This update fixes **CVE-2019-14744 (kconfig arbitrary shell code execution)** in the KDE 3 compatibility version of kdelibs used by legacy KDE 3 applications. The full list of fixes in this `kdelibs3` build: * fixes **CVE-2019-14744** -`kconfig`: malicious `.desktop` files (and others) would execute code. KConfig had a well-meaning feature that allowed configuration files to execute arbitrary shell commands. Unfortunately, this could be abused by untrusted `.desktop` files to execute arbitrary code as the target user, without the user even running the `.desktop` file. Therefore, this update removes that ill-fated feature. (Backported by Kevin Kofler from upstream: `kf5-kconfig` fix by David Faure, `kdelibs` 4 backport by Kai Uwe Broulik.) * adds native support for **xdg-user-dirs** for *Desktop* and *Documents*, without shelling outto `xdg-user-dir` from the config file. This is needed due to the above security fix. (This feature was previously implemented in the Fedora `kde-settings` by shelling out to `xdg-user-dir` from the config file using the KConfig feature removed above.) (Backported by Kevin Kofler from Trinity Desktop / Timothy Pearson.) * fixes a **KJS double-free** that could crash legacy KDE 3 applications such as Quanta Plus when trying to execute JavaScript. (Backported by OpenSUSE / Wolfgang Bauer from Trinity Desktop / Timothy Pearson.) --------------------------------------------------------------------------------ChangeLog: * Sat Aug 10 2019 Kevin Kofler - 3.5.10-101 - Backport CVE-2019-14744 fix by David Faure and Kai Uwe Broulik from kdelibs 4 - Backport native xdg-user-dirs support by Timothy Pearson from Trinity (needed to fix the regression that would otherwise result from the above security fix) - Backport KJS double-free fix by Timothy Pearson (backport by wbauer/OpenSUSE) * Thu Jul 25 2019 Fedora Release Engineering - 3.5.10-100 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Thu Apr 11 2019 Richard Shaw - 3.5.10-99 - Rebuild for OpenEXR 2.3.0. --------------------------------------------------------------------------------References: [ 1 ] Bug #1740138 - CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction https://bugzilla.redhat.com/show_bug.cgi?id=1740138 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-f9f78895c3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update for patch is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: patch security update Advisory ID: RHSA-2018:2092-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2018:2092 Issue date: 2018-06-27 CVE Names: CVE-2018-1000156 ==================================================================== 1. Summary: An update for patch is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.3) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.3) - ppc64, ppc64le, s390x, x86_64 3. Description: The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file (patching the file). Security Fix(es): * patch: Malicious patch files cause ed to execute arbitrary commands (CVE-2018-1000156) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1564326 - CVE-2018-1000156 patch: Malicious patch files cause ed to execute arbitrary commands 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.3): Source: patch-2.7.1-10.el7_3.src.rpm x86_64: patch-2.7.1-10.el7_3.x86_64.rpm patch-debuginfo-2.7.1-10.el7_3.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.3): Source: patch-2.7.1-10.el7_3.src.rpm ppc64: patch-2.7.1-10.el7_3.ppc64.rpm patch-debuginfo-2.7.1-10.el7_3.ppc64.rpm ppc64le: patch-2.7.1-10.el7_3.ppc64le.rpm patch-debuginfo-2.7.1-10.el7_3.ppc64le.rpm s390x: patch-2.7.1-10.el7_3.s390x.rpm patch-debuginfo-2.7.1-10.el7_3.s390x.rpm x86_64: patch-2.7.1-10.el7_3.x86_64.rpm patch-debuginfo-2.7.1-10.el7_3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-1000156 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBWzPhS9zjgjWX9erEAQg3dhAAlJX3W5Gr0qWH9I5ewXNiqYeDrsAFYpKf UkCtmV/CwkC3Q3rY46UUhw9wVPFbi/7C4L7G5cyKP8J13+WiQkTOzT/P7ZUUSKD6 1dGmLtKVjKjFx/WcSK/8xyaMRocdT28DKfsiu3hL664sJ7GvJJbrAW996rSWFgt4 AiOy++3sp/DeSz8ayvgvFo05JX6OWv0Op+VOMQtL3dOn4xscQWL/lJRr+X+rEm9+ 8iwfvJcsZRogZUdJ2AA7Ma7j+rtrWwkln5Bjj7y7gDI+vtwmP8+Z3VnT9xhQBhpc usNHNGHbnWrJfG49d3Giw9hepFwjyv2p6bxp/c981ep2kKIp471A+DXttV7ptAHx /17idwkek6CQWbuZPIv42PLCDA6+nLNrWrKxqSNEXfRaJBW7Xstjda0Uq0oATisY upd3Bfb2KFqjVpbp+Z+3xGV7QwuMDDkDM4Oyu1jjBHUj1NrYqzNPqc8I8iX5/VGP tIlEaN15mluLh1j2kbJ8BRjlBw9quPjeKH7bIOM397BLR55cFJIckXSBhu2uDQSk sAxWdaIejIGhsChfsqu9vExTVuQsd82YGqGodeggGB+u+P9NLwff6EaJejlnQTXx vXKMcVqmFTEeeDA+UvaQ+mFyhct0ALREaseIuT/90GU6F5CM85T9SuSi5TIN9IE5 FNpMTsOvj1k=r2Jx -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.