An update that solves one vulnerability can now be installed.. # Security update for opencc Announcement ID: SUSE-SU-2026:21553-1 Release Date: 2026-05-05T15:14:33Z Rating: moderate References: * bsc#1256930 Cross-References: * CVE-2025-15536 CVSS scores: * CVE-2025-15536 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-15536 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-15536 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15536 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2025-15536 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for opencc fixes the following issues: Update to version 1.2.0. Security issues fixed: * CVE-2025-15536: specifically crafted string can lead to out-of-bounds read (bsc#1256930). Other updates and bugfixes: * Version 1.2.0: * Fix the crash issue when reading configuration files. * Add type definitions (Typing). * Fix two out-of-bounds reading issues when handling truncated UTF-8 input. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-686=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-686=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libopencc1_2-1.2.0-160000.1.1 * libopencc1_2-debuginfo-1.2.0-160000.1.1 *opencc-data-1.2.0-160000.1.1 * opencc-debuginfo-1.2.0-160000.1.1 * opencc-debugsource-1.2.0-160000.1.1 * opencc-devel-1.2.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libopencc1_2-1.2.0-160000.1.1 * libopencc1_2-debuginfo-1.2.0-160000.1.1 * opencc-data-1.2.0-160000.1.1 * opencc-debuginfo-1.2.0-160000.1.1 * opencc-debugsource-1.2.0-160000.1.1 * opencc-devel-1.2.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15536.html * https://bugzilla.suse.com/show_bug.cgi?id=1256930 . An update for opencc addresses a critical out-of-bounds issue in SUSE systems. Install the patch now to secure your environment.. SUSE Linux, opencc, out-of-bounds read, security update, patch instructions. . LinuxSecurity.com Team
Fix CVE-2025-15536. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5829e53bd7 2026-02-01 01:02:12.727896+00:00 -------------------------------------------------------------------------------- Name : opencc Product : Fedora 42 Version : 1.1.9 Release : 2.fc42 URL : https://github.com/BYVoid/OpenCC Summary : Libraries for Simplified-Traditional Chinese Conversion Description : OpenCC is a library for converting characters and phrases between Traditional Chinese and Simplified Chinese. -------------------------------------------------------------------------------- Update Information: Fix CVE-2025-15536 -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 22 2026 Peng Wu - 1.1.9-2 - Add opencc-fixes-CVE.patch - Resolves: RHBZ#2430838 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2430838 - CVE-2025-15536 opencc: BYVoid OpenCC MaxMatchSegmentation.cpp MaxMatchSegmentation heap-based overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2430838 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5829e53bd7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fix CVE-2025-15536. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b627cd8944 2026-02-01 00:49:17.189373+00:00 -------------------------------------------------------------------------------- Name : opencc Product : Fedora 43 Version : 1.1.9 Release : 5.fc43 URL : https://github.com/BYVoid/OpenCC Summary : Libraries for Simplified-Traditional Chinese Conversion Description : OpenCC is a library for converting characters and phrases between Traditional Chinese and Simplified Chinese. -------------------------------------------------------------------------------- Update Information: Fix CVE-2025-15536 -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 22 2026 Peng Wu - 1.1.9-5 - Add opencc-fixes-CVE.patch - Resolves: RHBZ#2430839 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2430839 - CVE-2025-15536 opencc: BYVoid OpenCC MaxMatchSegmentation.cpp MaxMatchSegmentation heap-based overflow [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2430839 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b627cd8944' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
OpenCC could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7972-1 January 21, 2026 opencc vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: OpenCC could be made to crash if it received specially crafted input. Software Description: - opencc: simplified-traditional Chinese conversion library Details: It was discovered that OpenCC incorrectly handled truncated UTF-8 input. An attacker could possibly use this issue to cause OpenCC to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libopencc1.1 1.1.9+ds1-2ubuntu0.1 opencc 1.1.9+ds1-2ubuntu0.1 Ubuntu 24.04 LTS libopencc1.1 1.1.7+ds1-1ubuntu0.1 opencc 1.1.7+ds1-1ubuntu0.1 Ubuntu 22.04 LTS libopencc1.1 1.1.3+ds1-3ubuntu3.1 opencc 1.1.3+ds1-3ubuntu3.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7972-1 CVE-2025-15536 Package Information: https://launchpad.net/ubuntu/+source/opencc/1.1.9+ds1-2ubuntu0.1 . OpenCC issue could crash the application, leading to denial of service on Ubuntu systems. Immediate updates recommended.. OpenCC Denial of Service, Ubuntu Security Notice, OpenCC Vulnerability, Security Update Instructions. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for opencc ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4288-1 Rating: low References: #1108310 Cross-References: CVE-2018-16982 CVSS scores: CVE-2018-16982 (NVD) : 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2018-16982 (SUSE): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for opencc fixes the following issues: - CVE-2018-16982: Fixed out-of-bounds keyOffset and valueOffset values in BinaryDict.cpp. (bsc#1108310) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-4288=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-4288=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): opencc-debuginfo-1.0.3-5.3.1 opencc-devel-1.0.3-5.3.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libopencc2-1.0.3-5.3.1 opencc-1.0.3-5.3.1 opencc-data-1.0.3-5.3.1 opencc-debuginfo-1.0.3-5.3.1 References: https://www.suse.com/security/cve/CVE-2018-16982.html https://bugzilla.suse.com/1108310 . SUSE Security Patch for opencc addresses a minorvulnerability. Follow suggested procedures to protect your systems effectively.. SUSE Linux Enterprise, Opencc Security, Low Severity Patch, Software Development Kit. . Severity: Low. LinuxSecurity.com Team
It was discovered that opencc contained an out of bounds pointer in BinaryDict.cpp which could lead to segment fault and a Denial of Service (CVE-2018-16982). References: . MGASA-2018-0443 - Updated opencc packages fix security vulnerability Publication date: 11 Nov 2018 URL: https://advisories.mageia.org/MGASA-2018-0443.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-16982 It was discovered that opencc contained an out of bounds pointer in BinaryDict.cpp which could lead to segment fault and a Denial of Service (CVE-2018-16982). References: - https://bugs.mageia.org/show_bug.cgi?id=23764 - https://lists.fedoraproject.org/archives/list/
Security fix for CVE-2018-16982. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-6bf5d4c292 2018-10-30 17:13:37.321247 --------------------------------------------------------------------------------Name : opencc Product : Fedora 29 Version : 1.0.5 Release : 3.fc29 URL : https://github.com/BYVoid/OpenCC Summary : Libraries for Simplified-Traditional Chinese Conversion Description : OpenCC is a library for converting characters and phrases between Traditional Chinese and Simplified Chinese. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-16982 --------------------------------------------------------------------------------ChangeLog: * Wed Oct 17 2018 Peng Wu - 1.0.5-3 - Security fix for CVE-2018-16982 --------------------------------------------------------------------------------References: [ 1 ] Bug #1629956 - CVE-2018-16982 opencc: out-of-bounds keyOffset and valueOffset values in BinaryDict::NewFromFile in BinaryDict.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1629956 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-6bf5d4c292' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.