Multiple vulnerabilities have been found in LibreOffice, the worst of which could result in user-assisted code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202506-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: LibreOffice: Multiple Vulnerabilities Date: June 12, 2025 Bugs: #948825 ID: 202506-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been found in LibreOffice, the worst of which could result in user-assisted code execution. Background ========== LibreOffice is a powerful office suite; its clean interface and powerful tools let you unleash your creativity and grow your productivity. Affected packages ================= Package Vulnerable Unaffected -------------------------- ------------- -------------- app-office/libreoffice < 24.2.7.2-r1 > = 24.2.7.2-r1 app-office/libreoffice-bin < 24.8.4 > = 24.8.4 Description =========== Multiple vulnerabilities have been discovered in LibreOffice. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All LibreOffice binary users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-office/libreoffice-bin-24.8.4" All LibreOffice users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-office/libreoffice-24.2.7.2-r1" References ========== [ 1 ] CVE-2024-12425 https://nvd.nist.gov/vuln/detail/CVE-2024-12425 [ 2 ] CVE-2024-12426 https://nvd.nist.gov/vuln/detail/CVE-2024-12426 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202506-03 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in Redis, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202008-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Redis: Multiple vulnerabilities Date: August 27, 2020 Bugs: #633824, #724776 ID: 202008-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Redis, the worst of which could result in the arbitrary execution of code. Background ========= Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache and message broker. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-db/redis < 5.0.9 > = 5.0.9 Description ========== Multiple vulnerabilities have been discovered in Redis. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Redis users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-db/redis-5.0.9" References ========= [ 1 ] CVE-2017-15047 https://nvd.nist.gov/vuln/detail/CVE-2017-15047 [ 2 ] CVE-2020-14147 https://nvd.nist.gov/vuln/detail/CVE-2020-14147 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202008-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in xkbcommon, the worst of which may lead to a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201810-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: xkbcommon: Multiple vulnerabilities Date: October 30, 2018 Bugs: #665702 ID: 201810-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in xkbcommon, the worst of which may lead to a Denial of Service condition. Background ========= xkbcommon is a library to handle keyboard descriptions, including loading them from disk, parsing them and handling their state. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 x11-libs/libxkbcommon < 0.8.2 > = 0.8.2 Description ========== Multiple vulnerabilities have been discovered in libxkbcommon. Please review the CVE identifiers referenced below for details. Impact ===== A local attacker could supply a specially crafted keymap file possibly resulting in a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All libxkbcommon users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-libs/libxkbcommon-0.8.2" References ========= [ 1 ] CVE-2018-15853 https://nvd.nist.gov/vuln/detail/CVE-2018-15853 [ 2 ] CVE-2018-15854 https://nvd.nist.gov/vuln/detail/CVE-2018-15854 [ 3 ] CVE-2018-15855 https://nvd.nist.gov/vuln/detail/CVE-2018-15855 [ 4 ] CVE-2018-15856 https://nvd.nist.gov/vuln/detail/CVE-2018-15856 [ 5 ] CVE-2018-15857 https://nvd.nist.gov/vuln/detail/CVE-2018-15857 [ 6 ] CVE-2018-15858 https://nvd.nist.gov/vuln/detail/CVE-2018-15858 [ 7 ] CVE-2018-15859 https://nvd.nist.gov/vuln/detail/CVE-2018-15859 [ 8 ] CVE-2018-15861 https://nvd.nist.gov/vuln/detail/CVE-2018-15861 [ 9 ] CVE-2018-15862 https://nvd.nist.gov/vuln/detail/CVE-2018-15862 [ 10 ] CVE-2018-15863 https://nvd.nist.gov/vuln/detail/CVE-2018-15863 [ 11 ] CVE-2018-15864 https://nvd.nist.gov/vuln/detail/CVE-2018-15864 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201810-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in cups-filters, the worst of which could lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201510-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: cups-filters: Multiple vulnerabilities Date: October 31, 2015 Bugs: #553644, #553836 ID: 201510-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in cups-filters, the worst of which could lead to arbitrary code execution. Background ========= cups-filters is an OpenPrinting CUPS Filters. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-print/cups-filters < 1.0.71 > = 1.0.71 Description ========== Multiple vulnerabilities have been discovered in cups-filters. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could entice a user to open a specially crafted print job using cups-filters, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All cups-filters users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-print/cups-filters-1.0.71" References ========= [ 1 ] CVE-2015-3258 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3258 [ 2 ] CVE-2015-3279 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3279 Availability =========== ThisGLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201510-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been discovered in Mozilla Firefox and Mozilla Seamonkey.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200712-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Mozilla Firefox, SeaMonkey: Multiple vulnerabilities Date: December 29, 2007 Bugs: #198965, #200909 ID: 200712-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in Mozilla Firefox and Mozilla Seamonkey. Background ========= Mozilla Firefox is a cross-platform web browser from Mozilla. SeaMonkey is a free, cross-platform Internet suite. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-client/mozilla-firefox < 2.0.0.11 > = 2.0.0.11 2 www-client/mozilla-firefox-bin < 2.0.0.11 > = 2.0.0.11 3 www-client/seamonkey < 1.1.7 > = 1.1.7 4 www-client/seamonkey-bin < 1.1.7 > = 1.1.7 ------------------------------------------------------------------- 4 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Jesse Ruderman and Petko D. Petkov reported that the jar protocol handler in Mozilla Firefox and Seamonkey does not properly check MIME types (CVE-2007-5947). Gregory Fleischer reported that the window.location property can be used to generate a fake HTTP Referer (CVE-2007-5960). Multiple memory errors have also beenreported (CVE-2007-5959). Impact ===== A remote attacker could possibly exploit these vulnerabilities to execute arbitrary code in the context of the browser and conduct Cross-Site-Scripting or Cross-Site Request Forgery attacks. Workaround ========= There is no known workaround at this time. Resolution ========= All Mozilla Firefox users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-client/mozilla-firefox-2.0.0.11" All Mozilla Firefox binary users should upgrade to the latest version: # emerge --sync # emerge --ask -1 -v "> =www-client/mozilla-firefox-bin-2.0.0.11" All SeaMonkey users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-client/seamonkey-1.1.7" All SeaMonkey binary users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-client/seamonkey-bin-1.1.7" References ========= [ 1 ] CVE-2007-5947 https://www.cve.org/CVERecord?id=CVE-2007-5947 [ 2 ] CVE-2007-5959 https://www.cve.org/CVERecord?id=CVE-2007-5959 [ 3 ] CVE-2007-5960 https://www.cve.org/CVERecord?id=CVE-2007-5960 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200712-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.