PlantUML could be made to crash or run programs as your login if it opened a specially crafted UML file.. ========================================================================== Ubuntu Security Notice USN-7353-1 March 17, 2025 plantuml vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: PlantUML could be made to crash or run programs as your login if it opened a specially crafted UML file. Software Description: - plantuml: text-to-UML converter Details: Tobias S. Fink discovered that PlantUML was susceptible to cross-site scripting attacks (XSS) in instances where SVG images were rendered. An attacker could possibly use this issue to cause PlantUML to crash, resulting in a denial of service, or the execution of arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 plantuml 1:1.2020.2+ds-5ubuntu0.1 Ubuntu 24.04 LTS plantuml 1:1.2020.2+ds-3ubuntu1.1 Ubuntu 22.04 LTS plantuml 1:1.2020.2+ds-1ubuntu0.1 Ubuntu 20.04 LTS plantuml 1:1.2018.13+ds-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS plantuml 1:1.2017.15-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS plantuml 8024-2ubuntu0.1~esm1 Available with Ubuntu Pro Ingeneral, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7353-1 CVE-2022-1231 Package Information: https://launchpad.net/ubuntu/+source/plantuml/1:1.2020.2+ds-5ubuntu0.1 https://launchpad.net/ubuntu/+source/plantuml/1:1.2020.2+ds-3ubuntu1.1 https://launchpad.net/ubuntu/+source/plantuml/1:1.2020.2+ds-1ubuntu0.1 . PlantUML is vulnerable to XSS attacks, possibly causing DoS or code execution. Update Ubuntu systems for security.. plantuml, crash, programs, login, opened, specially, crafted. . Severity: Important. LinuxSecurity.com Team
Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : plantuml Product : Fedora 40 Version : 1.2024.3 Release : 3.fc40 URL : https://plantuml.com/ Summary : Program to generate UML diagram from a text description Description : PlantUML is a program allowing to draw UML diagrams, using a simple and human readable text description. It is extremely useful for code documenting, sketching project architecture during team conversations and so on. PlantUML supports the following diagram types - sequence diagram - use case diagram - class diagram - activity diagram - component diagram - state diagram -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri - 1:1.2024.3-3 - Rebuilt for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build withjava-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update plantuml to the latest version v1.2023.11. This update also includes fixes for CVE-2023-3431 and CVE-2023-3432.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-731133ab8e 2023-10-01 03:37:03.210259 -------------------------------------------------------------------------------- Name : plantuml Product : Fedora 39 Version : 1.2023.11 Release : 1.fc39 URL : https://plantuml.com/ Summary : Program to generate UML diagram from a text description Description : PlantUML is a program allowing to draw UML diagrams, using a simple and human readable text description. It is extremely useful for code documenting, sketching project architecture during team conversations and so on. PlantUML supports the following diagram types - sequence diagram - use case diagram - class diagram - activity diagram - component diagram - state diagram -------------------------------------------------------------------------------- Update Information: Update plantuml to the latest version v1.2023.11. This update also includes fixes for CVE-2023-3431 and CVE-2023-3432. -------------------------------------------------------------------------------- ChangeLog: * Sat Sep 23 2023 blinxen - 1:1.2023.11-1 - Update to version 1.2023.11 (rhbz#2232105) * Fri Sep 22 2023 blinxen - 1:1.2023.7-4 - Migrate license specification to SPDX -------------------------------------------------------------------------------- References: [ 1 ] Bug #2218063 - CVE-2023-3432 plantuml: URL Restriction Bypass in plantuml/plantuml https://bugzilla.redhat.com/show_bug.cgi?id=2218063 [ 2 ] Bug #2218066 - CVE-2023-3431 plantuml: Local file read through %load_json in plantuml/plantuml https://bugzilla.redhat.com/show_bug.cgi?id=2218066 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2023-731133ab8e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2022-1379. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e6c09a89eb 2022-05-25 01:03:47.532320 --------------------------------------------------------------------------------Name : plantuml Product : Fedora 36 Version : 1.2022.5 Release : 1.fc36 URL : https://plantuml.com/ Summary : Program to generate UML diagram from a text description Description : PlantUML is a program allowing to draw UML diagrams, using a simple and human readable text description. It is extremely useful for code documenting, sketching project architecture during team conversations and so on. PlantUML supports the following diagram types - sequence diagram - use case diagram - class diagram - activity diagram - component diagram - state diagram --------------------------------------------------------------------------------Update Information: Security fix for CVE-2022-1379 --------------------------------------------------------------------------------ChangeLog: * Mon May 16 2022 Sandipan Roy - 1:1.2022.5-1 - Updated version to 1.2022.5 - Added fix for rhbz#2086392 --------------------------------------------------------------------------------References: [ 1 ] Bug #2086391 - CVE-2022-1379 plantuml: URL Restriction Bypass https://bugzilla.redhat.com/show_bug.cgi?id=2086391 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-e6c09a89eb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.