Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 21 articles for you...
89

Fedora 43 podofo Important Denial Of Service CVE-2026-44348 2026-19873e3fac

Update to podof-1.0.4.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-19873e3fac 2026-05-29 01:26:24.644290+00:00 -------------------------------------------------------------------------------- Name : podofo Product : Fedora 43 Version : 1.0.4 Release : 1.fc43 URL : https://github.com/podofo/podofo Summary : Tools and libraries to work with the PDF file format Description : PoDoFo is a library to work with the PDF file format. The name comes from the first letter of PDF (Portable Document Format). A few tools to work with PDF files are already included in the PoDoFo package. The PoDoFo library is a free, portable C++ library which includes classes to parse PDF files and modify their contents into memory. The changes can be written back to disk easily. The parser can also be used to extract information from a PDF file (for example the parser could be used in a PDF viewer). Besides parsing PoDoFo includes also very simple classes to create your own PDF files. All classes are documented so it is easy to start writing your own application using PoDoFo. -------------------------------------------------------------------------------- Update Information: Update to podof-1.0.4. -------------------------------------------------------------------------------- ChangeLog: * Wed May 20 2026 Sandro Mani - 1.0.4-1 - Update to 1.0.4 * Sat Jan 17 2026 Fedora Release Engineering - 1.0.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Mon Dec 8 2025 Sandro Mani - 1.0.3-2 - Rebuild (libtiff) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2477832 - CVE-2026-44348 podofo0.10: PoDoFo: Denial of service due to double-free vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2477832 [ 2 ] Bug #2477835 - CVE-2026-44348 podofo: PoDoFo: Denial of service due todouble-free vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2477835 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-19873e3fac' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 43 podofo update addresses critical denial of service risk due to double-free vulnerability in software.. Fedora Podof Denial Of Service Update Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 29, 2026 Important Fedora
89

Fedora 44 Podofo Critical Denial of Service Update 2026-5c81faa7bf

Update to podof-1.0.4.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5c81faa7bf 2026-05-29 01:10:57.991179+00:00 -------------------------------------------------------------------------------- Name : podofo Product : Fedora 44 Version : 1.0.4 Release : 1.fc44 URL : https://github.com/podofo/podofo Summary : Tools and libraries to work with the PDF file format Description : PoDoFo is a library to work with the PDF file format. The name comes from the first letter of PDF (Portable Document Format). A few tools to work with PDF files are already included in the PoDoFo package. The PoDoFo library is a free, portable C++ library which includes classes to parse PDF files and modify their contents into memory. The changes can be written back to disk easily. The parser can also be used to extract information from a PDF file (for example the parser could be used in a PDF viewer). Besides parsing PoDoFo includes also very simple classes to create your own PDF files. All classes are documented so it is easy to start writing your own application using PoDoFo. -------------------------------------------------------------------------------- Update Information: Update to podof-1.0.4. -------------------------------------------------------------------------------- ChangeLog: * Wed May 20 2026 Sandro Mani - 1.0.4-1 - Update to 1.0.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2477832 - CVE-2026-44348 podofo0.10: PoDoFo: Denial of service due to double-free vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2477832 [ 2 ] Bug #2477835 - CVE-2026-44348 podofo: PoDoFo: Denial of service due to double-free vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2477835 -------------------------------------------------------------------------------- This updatecan be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5c81faa7bf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Install podofo 1.0.4 to address important DoS issues in Fedora 44. Ensure system security with this latest update.. Fedora 44 podofo update, security patch, DoS vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 29, 2026 Important Fedora
100

SUSE: Podofo Moderate Fix Available for Use in 2025:03533-1

* bsc#1231058 * bsc#1249105 Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 . # Security update for podofo Announcement ID: SUSE-SU-2025:03533-1 Release Date: 2025-10-10T15:14:06Z Rating: moderate References: * bsc#1231058 * bsc#1249105 Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that has two security fixes can now be installed. ## Description: This update for podofo fixes the following issues: * fixed a free-after-use in PdfTokenizer (bsc#1249105) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-3533=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libpodofo-devel-1.0.2-150700.3.3.1 * podofo-debugsource-1.0.2-150700.3.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1231058 * https://bugzilla.suse.com/show_bug.cgi?id=1249105 . Moderate security update for Podofo in SUSE Linux Enterprise fixing a free-after-use issue with updates required.. SUSE Linux Enterprise,podofo security update,moderate updates,SUSE Package Hub. . LinuxSecurity.com Team

Calendar 2 Oct 10, 2025 SuSE
100

SUSE: 2024:3550-1 moderate: podofo application crash fixes

* bsc#1023072 * bsc#1023190 * bsc#1027776 * bsc#1027779 * bsc#1027785 . # Security update for podofo Announcement ID: SUSE-SU-2024:3550-1 Release Date: 2024-10-08T14:08:01Z Rating: moderate References: * bsc#1023072 * bsc#1023190 * bsc#1027776 * bsc#1027779 * bsc#1027785 * bsc#1027786 * bsc#1027787 * bsc#1037000 * bsc#1075322 * bsc#1084894 Cross-References: * CVE-2015-8981 * CVE-2017-6840 * CVE-2017-6841 * CVE-2017-6842 * CVE-2017-6845 * CVE-2017-6849 * CVE-2017-8378 * CVE-2018-5309 * CVE-2018-8001 CVSS scores: * CVE-2017-6840 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2017-6841 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2017-6842 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2017-6845 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2017-6849 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2017-6849 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2017-8378 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2017-8378 ( NVD ): 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2018-5309 ( SUSE ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2018-5309 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-8001 ( SUSE ): 5.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2018-8001 ( NVD ): 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAPApplications 15 SP6 * SUSE Package Hub 15 15-SP5 * SUSE Package Hub 15 15-SP6 An update that solves nine vulnerabilities and has one security fix can now be installed. ## Description: This update for podofo fixes the following issues: * CVE-2015-8981: Fixed heap overflow in the function ReadXRefSubsection (bsc#1023190) * CVE-2017-6840: Fixed invalid memory read in ColorChanger::GetColorFromStack (colorchanger.cpp) (bsc#1027787) * CVE-2017-6841: Fixed NULL pointer dereference in GraphicsStack::TGraphicsStackElement::~TGraphicsStackElement (graphicsstack.h) (bsc#1027786) * CVE-2017-6842: Fixed NULL pointer dereference in ColorChanger::GetColorFromStack (colorchanger.cpp) (bsc#1027785) * CVE-2017-6845: Fixed NULL pointer dereference in GraphicsStack::TGraphicsStackElement::SetNonStrokingColorSpace (graphicsstack.h) (bsc#1027779) * CVE-2017-6849: Fixed NULL pointer dereference in PoDoFo::PdfColorGray::~PdfColorGray (PdfColor.cpp) (bsc#1027776) * CVE-2017-8378: Fixed denial of service (application crash) vectors related to m_offsets.size (PdfParser::ReadObjects func in base/PdfParser.cpp) (bsc#1037000) * Fixed NULL pointer dereference in PdfInfo::GuessFormat (pdfinfo.cpp) (bsc#1023072) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-3550=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3550=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3550=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-3550=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-3550=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) *podofo-debugsource-0.9.6-150300.3.15.1 * libpodofo0_9_6-0.9.6-150300.3.15.1 * podofo-debuginfo-0.9.6-150300.3.15.1 * libpodofo0_9_6-debuginfo-0.9.6-150300.3.15.1 * podofo-0.9.6-150300.3.15.1 * libpodofo-devel-0.9.6-150300.3.15.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * podofo-debugsource-0.9.6-150300.3.15.1 * libpodofo0_9_6-0.9.6-150300.3.15.1 * podofo-debuginfo-0.9.6-150300.3.15.1 * libpodofo0_9_6-debuginfo-0.9.6-150300.3.15.1 * podofo-0.9.6-150300.3.15.1 * libpodofo-devel-0.9.6-150300.3.15.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * podofo-debugsource-0.9.6-150300.3.15.1 * libpodofo0_9_6-0.9.6-150300.3.15.1 * podofo-debuginfo-0.9.6-150300.3.15.1 * libpodofo0_9_6-debuginfo-0.9.6-150300.3.15.1 * podofo-0.9.6-150300.3.15.1 * libpodofo-devel-0.9.6-150300.3.15.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * podofo-debugsource-0.9.6-150300.3.15.1 * libpodofo0_9_6-0.9.6-150300.3.15.1 * podofo-debuginfo-0.9.6-150300.3.15.1 * libpodofo0_9_6-debuginfo-0.9.6-150300.3.15.1 * podofo-0.9.6-150300.3.15.1 * libpodofo-devel-0.9.6-150300.3.15.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * podofo-debugsource-0.9.6-150300.3.15.1 * libpodofo0_9_6-0.9.6-150300.3.15.1 * podofo-debuginfo-0.9.6-150300.3.15.1 * libpodofo0_9_6-debuginfo-0.9.6-150300.3.15.1 * podofo-0.9.6-150300.3.15.1 * libpodofo-devel-0.9.6-150300.3.15.1 ## References: * https://www.suse.com/security/cve/CVE-2015-8981.html * https://www.suse.com/security/cve/CVE-2017-6840.html * https://www.suse.com/security/cve/CVE-2017-6841.html * https://www.suse.com/security/cve/CVE-2017-6842.html * https://www.suse.com/security/cve/CVE-2017-6845.html * https://www.suse.com/security/cve/CVE-2017-6849.html * https://www.suse.com/security/cve/CVE-2017-8378.html * https://www.suse.com/security/cve/CVE-2018-5309.html * https://www.suse.com/security/cve/CVE-2018-8001.html *https://bugzilla.suse.com/show_bug.cgi?id=1023072 * https://bugzilla.suse.com/show_bug.cgi?id=1023190 * https://bugzilla.suse.com/show_bug.cgi?id=1027776 * https://bugzilla.suse.com/show_bug.cgi?id=1027779 * https://bugzilla.suse.com/show_bug.cgi?id=1027785 * https://bugzilla.suse.com/show_bug.cgi?id=1027786 * https://bugzilla.suse.com/show_bug.cgi?id=1027787 * https://bugzilla.suse.com/show_bug.cgi?id=1037000 * https://bugzilla.suse.com/show_bug.cgi?id=1075322 * https://bugzilla.suse.com/show_bug.cgi?id=1084894 . Essential patches for podofo fix various bugs, addressing app failures and avoiding service interruptions. Keep your system safe.. SUSE Security Updates, podofo vulnerabilities, SUSE patch instructions. . LinuxSecurity.com Team

Calendar 2 Oct 08, 2024 SuSE
100

SUSE: 2024:2287-1 Low: Podofo Security Update for Multiple Products

* bsc#1213720 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 . # Security update for podofo Announcement ID: SUSE-SU-2024:2287-1 Rating: low References: * bsc#1213720 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 An update that has one security fix can now be installed. ## Description: This update for podofo fixes the following issues: * PdfEncrypt: Validate more encrypt dictionary parameters (bsc#1213720) * PdfXRefStreamParserObject: Fixed handling of invalid XRef stream entries (bsc#1213720) * Drop unused backup sources to clean up the compile env (bsc#1213720) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-2287=1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 zypper in -t patch SUSE-SLE-WE-12-SP5-2024-2287=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * podofo-debuginfo-0.9.2-3.18.1 * podofo-debugsource-0.9.2-3.18.1 * libpodofo-devel-0.9.2-3.18.1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (x86_64) * libpodofo0_9_2-debuginfo-0.9.2-3.18.1 * podofo-debuginfo-0.9.2-3.18.1 * libpodofo0_9_2-0.9.2-3.18.1 * podofo-debugsource-0.9.2-3.18.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1213720 . Red Hat issued a minor severity notice regarding gdk-pixbuf, outlining enhancements for multiple impacted Enterprise Linux offerings.. SUSE Linux Enterprise, Podofo Fix,Low Severity Advisory. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Jul 03, 2024 Low SuSE
100

openSUSE: 2024:2281-1 Low Severity: podofo Security Update

* bsc#1213720 Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.5 . # Security update for podofo Announcement ID: SUSE-SU-2024:2281-1 Rating: low References: * bsc#1213720 Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP5 * SUSE Package Hub 15 15-SP6 An update that has one security fix can now be installed. ## Description: This update for podofo fixes the following issues: * PdfEncrypt: Validate more encrypt dictionary parameters (bsc#1213720) * PdfXRefStreamParserObject: Fixed handling of invalid XRef stream entries (bsc#1213720) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-2281=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-2281=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-2281=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-2281=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-2281=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * podofo-debugsource-0.9.6-150300.3.12.1 * libpodofo0_9_6-0.9.6-150300.3.12.1 * podofo-debuginfo-0.9.6-150300.3.12.1 * libpodofo0_9_6-debuginfo-0.9.6-150300.3.12.1 *libpodofo-devel-0.9.6-150300.3.12.1 * podofo-0.9.6-150300.3.12.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * podofo-debugsource-0.9.6-150300.3.12.1 * libpodofo0_9_6-0.9.6-150300.3.12.1 * podofo-debuginfo-0.9.6-150300.3.12.1 * libpodofo0_9_6-debuginfo-0.9.6-150300.3.12.1 * libpodofo-devel-0.9.6-150300.3.12.1 * podofo-0.9.6-150300.3.12.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * podofo-debugsource-0.9.6-150300.3.12.1 * libpodofo0_9_6-0.9.6-150300.3.12.1 * podofo-debuginfo-0.9.6-150300.3.12.1 * libpodofo0_9_6-debuginfo-0.9.6-150300.3.12.1 * libpodofo-devel-0.9.6-150300.3.12.1 * podofo-0.9.6-150300.3.12.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * podofo-debugsource-0.9.6-150300.3.12.1 * libpodofo0_9_6-0.9.6-150300.3.12.1 * podofo-debuginfo-0.9.6-150300.3.12.1 * libpodofo0_9_6-debuginfo-0.9.6-150300.3.12.1 * libpodofo-devel-0.9.6-150300.3.12.1 * podofo-0.9.6-150300.3.12.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * podofo-debugsource-0.9.6-150300.3.12.1 * libpodofo0_9_6-0.9.6-150300.3.12.1 * podofo-debuginfo-0.9.6-150300.3.12.1 * libpodofo0_9_6-debuginfo-0.9.6-150300.3.12.1 * libpodofo-devel-0.9.6-150300.3.12.1 * podofo-0.9.6-150300.3.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1213720 . Announcements regarding the recent security advisory SUSE-SU-2024:2281-1 for podofo, focusing on essential security enhancements and their implications.. openSUSE Security Advisory, podofo Update, SUSE Patch. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Jul 02, 2024 Low SuSE
100

SUSE: 2024:2137-1 Moderate: Podofo Memory Leak and Security Update

* bsc#1127514 * bsc#1127855 * bsc#1131544 Cross-References: . # Security update for podofo Announcement ID: SUSE-SU-2024:2137-1 Rating: moderate References: * bsc#1127514 * bsc#1127855 * bsc#1131544 Cross-References: * CVE-2018-20797 * CVE-2019-10723 * CVE-2019-9199 CVSS scores: * CVE-2018-20797 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2018-20797 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2019-10723 ( SUSE ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2019-10723 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2019-9199 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2019-9199 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP5 * SUSE Package Hub 15 15-SP6 An update that solves three vulnerabilities can now be installed. ## Description: This update for podofo fixes the following issues: * CVE-2019-9199: Fixed a NULL pointer dereference in podofoimpose (bsc#1127855) * CVE-2018-20797: Fixed an excessive memory allocation in PoDoFo:podofo_calloc (bsc#1127514) * CVE-2019-10723: Fixed a memory leak in PdfPagesTreeCache (bsc#1131544) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-2137=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-2137=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-2137=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-2137=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-2137=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * libpodofo0_9_6-debuginfo-0.9.6-150300.3.9.1 * libpodofo0_9_6-0.9.6-150300.3.9.1 * libpodofo-devel-0.9.6-150300.3.9.1 * podofo-0.9.6-150300.3.9.1 * podofo-debuginfo-0.9.6-150300.3.9.1 * podofo-debugsource-0.9.6-150300.3.9.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libpodofo0_9_6-debuginfo-0.9.6-150300.3.9.1 * libpodofo0_9_6-0.9.6-150300.3.9.1 * libpodofo-devel-0.9.6-150300.3.9.1 * podofo-0.9.6-150300.3.9.1 * podofo-debuginfo-0.9.6-150300.3.9.1 * podofo-debugsource-0.9.6-150300.3.9.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libpodofo0_9_6-debuginfo-0.9.6-150300.3.9.1 * libpodofo0_9_6-0.9.6-150300.3.9.1 * libpodofo-devel-0.9.6-150300.3.9.1 * podofo-0.9.6-150300.3.9.1 * podofo-debuginfo-0.9.6-150300.3.9.1 * podofo-debugsource-0.9.6-150300.3.9.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * libpodofo0_9_6-debuginfo-0.9.6-150300.3.9.1 * libpodofo0_9_6-0.9.6-150300.3.9.1 * libpodofo-devel-0.9.6-150300.3.9.1 * podofo-0.9.6-150300.3.9.1 * podofo-debuginfo-0.9.6-150300.3.9.1 * podofo-debugsource-0.9.6-150300.3.9.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * libpodofo0_9_6-debuginfo-0.9.6-150300.3.9.1 * libpodofo0_9_6-0.9.6-150300.3.9.1 * libpodofo-devel-0.9.6-150300.3.9.1 * podofo-0.9.6-150300.3.9.1 * podofo-debuginfo-0.9.6-150300.3.9.1 * podofo-debugsource-0.9.6-150300.3.9.1 ## References: *https://www.suse.com/security/cve/CVE-2018-20797.html * https://www.suse.com/security/cve/CVE-2019-10723.html * https://www.suse.com/security/cve/CVE-2019-9199.html * https://bugzilla.suse.com/show_bug.cgi?id=1127514 * https://bugzilla.suse.com/show_bug.cgi?id=1127855 * https://bugzilla.suse.com/show_bug.cgi?id=1131544 . A new release for podofo addresses multiple concerns, outlining specifics about fixes and offering guidance for setup. Discover additional information.. SUSE Security Advisory,podofo update,security fix,software vulnerabilities,openSUSE patch. . LinuxSecurity.com Team

Calendar 2 Jun 21, 2024 SuSE
91

Gentoo: GLSA 202405-34 Critical: LibXYZ Buffer Overflow Vulnerabilities

Multiple vulnerabilities have been discovered in PoDoFo, the worst of which could lead to code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202405-33 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: PoDoFo: Multiple Vulnerabilities Date: May 12, 2024 Bugs: #906105 ID: 202405-33 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in PoDoFo, the worst of which could lead to code execution. Background ========== PoDoFo is a free portable C++ library to work with the PDF file format. Affected packages ================= Package Vulnerable Unaffected --------------- ------------ ------------ app-text/podofo < 0.10.1 > = 0.10.1 Description =========== Please review the referenced CVE identifiers for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All PoDoFo users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/podofo-0.10.1" References ========== [ 1 ] CVE-2023-31566 https://nvd.nist.gov/vuln/detail/CVE-2023-31566 [ 2 ] CVE-2023-31567 https://nvd.nist.gov/vuln/detail/CVE-2023-31567 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202405-33 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bugat https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . Gentoo Linux Security Notice GLSA 202405-44 highlights severe vulnerabilities within the OpenSSL library that require urgent attention and updates.. Gentoo Security Advisory, PoDoFo Updates, High Severity Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 12, 2024 Critical Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here