Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
100

SUSE: Poppler Important CVE-2025-43718 Buffer Issues 2025:3910-1

* bsc#1250908 * bsc#1251940 Cross-References: * CVE-2025-43718 . # Security update for poppler Announcement ID: SUSE-SU-2025:3910-1 Release Date: 2025-11-02T12:18:24Z Rating: important References: * bsc#1250908 * bsc#1251940 Cross-References: * CVE-2025-43718 * CVE-2025-52885 CVSS scores: * CVE-2025-43718 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-43718 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2025-43718 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-43718 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-52885 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-52885 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2025-52885 ( NVD ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 LTS * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Retail Branch Server 4.3 LTS * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 LTS An update that solves two vulnerabilities can now be installed. ## Description: This update for poppler fixes the following issues: * CVE-2025-43718: fixed uncontrolled recursion in the regex-based metadata parser when processing specially crafted PDF files (bsc#1250908) * CVE-2025-52885: improved pointer handling that could have led to dangling pointers when the vector is resized (bsc#1251940) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Proxy 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-3910=1 * SUSE Manager Retail Branch Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-LTS-2025-3910=1 * SUSE Manager Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-3910=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-3910=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-3910=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3910=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patchSUSE-SLE-Product-HPC-15-SP3-LTSS-2025-3910=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3910=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3910=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-3910=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-3910=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-3910=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3910=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3910=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-3910=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3910=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-3910=1 ## Package List: * SUSE Manager Proxy 4.3 LTS (x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * SUSE Manager Retail Branch Server 4.3 LTS (x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * SUSE Manager Server 4.3 LTS (ppc64le s390x x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * typelib-1_0-Poppler-0_18-0.79.0-150200.3.46.1 *libpoppler-glib8-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * libpoppler-devel-0.79.0-150200.3.46.1 * libpoppler-cpp0-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler-glib-devel-0.79.0-150200.3.46.1 * poppler-tools-0.79.0-150200.3.46.1 * libpoppler-cpp0-debuginfo-0.79.0-150200.3.46.1 * libpoppler-glib8-debuginfo-0.79.0-150200.3.46.1 * poppler-tools-debuginfo-0.79.0-150200.3.46.1 * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * typelib-1_0-Poppler-0_18-0.79.0-150200.3.46.1 * libpoppler-glib8-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * libpoppler-devel-0.79.0-150200.3.46.1 * libpoppler-cpp0-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler-glib-devel-0.79.0-150200.3.46.1 * poppler-tools-0.79.0-150200.3.46.1 * libpoppler-cpp0-debuginfo-0.79.0-150200.3.46.1 * libpoppler-glib8-debuginfo-0.79.0-150200.3.46.1 * poppler-tools-debuginfo-0.79.0-150200.3.46.1 * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * SUSE Linux Enterprise High PerformanceComputing ESPOS 15 SP5 (aarch64 x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * typelib-1_0-Poppler-0_18-0.79.0-150200.3.46.1 * libpoppler-glib8-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * libpoppler-devel-0.79.0-150200.3.46.1 * libpoppler-cpp0-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler-glib-devel-0.79.0-150200.3.46.1 * poppler-tools-0.79.0-150200.3.46.1 * libpoppler-cpp0-debuginfo-0.79.0-150200.3.46.1 * libpoppler-glib8-debuginfo-0.79.0-150200.3.46.1 * poppler-tools-debuginfo-0.79.0-150200.3.46.1 * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * typelib-1_0-Poppler-0_18-0.79.0-150200.3.46.1 * libpoppler-glib8-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * libpoppler-devel-0.79.0-150200.3.46.1 * libpoppler-cpp0-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler-glib-devel-0.79.0-150200.3.46.1 * poppler-tools-0.79.0-150200.3.46.1 * libpoppler-cpp0-debuginfo-0.79.0-150200.3.46.1 * libpoppler-glib8-debuginfo-0.79.0-150200.3.46.1 *poppler-tools-debuginfo-0.79.0-150200.3.46.1 * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.46.1 * poppler-debugsource-0.79.0-150200.3.46.1 * libpoppler89-0.79.0-150200.3.46.1 ## References: * https://www.suse.com/security/cve/CVE-2025-43718.html * https://www.suse.com/security/cve/CVE-2025-52885.html * https://bugzilla.suse.com/show_bug.cgi?id=1250908 * https://bugzilla.suse.com/show_bug.cgi?id=1251940 . Important SUSE security advisory for Poppler addresses critical issues in PDF processing and pointer handling.. SUSE Poppler Security Update Important Vulnerability Warning. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 03, 2025 Important SuSE
172

Ubuntu: USN-589-1 Critical: Unzip Remote Code Execution Risk

Tavis Ormandy discovered that unzip did not correctly clean up pointers. If a user or automated service was tricked into processing a specially crafted ZIP archive, a remote attacker could execute arbitrary code with user privileges. . =========================================================== Ubuntu Security Notice USN-589-1 March 20, 2008 unzip vulnerability CVE-2008-0888 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: unzip 5.52-6ubuntu4.1 Ubuntu 6.10: unzip 5.52-8ubuntu1.1 Ubuntu 7.04: unzip 5.52-9ubuntu3.1 Ubuntu 7.10: unzip 5.52-10ubuntu1.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Tavis Ormandy discovered that unzip did not correctly clean up pointers. If a user or automated service was tricked into processing a specially crafted ZIP archive, a remote attacker could execute arbitrary code with user privileges. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 12788 c944a77823f756df4f6f1352028c51ba Size/MD5: 535 05a4c713cd2bc201d7fec5dd0f1807ce Size/MD5: 1140291 9d23919999d6eac9217d1f41472034a9 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 161102 b975bb72efc3b8b8a7355011090a76d3 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 147240 7470f2fa04517e0b5b601f69db54ac84 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 165218 a6b0dc720809d80d31e809492056eee0 sparc architecture (SunSPARC/UltraSPARC): Size/MD5: 164078 552d2029d247f091442e174eae9c3a19 Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 12565 7c86995d3353555020b5072979437d32 Size/MD5: 535 942549c5fc2654810ecece441c702ed7 Size/MD5: 1140291 9d23919999d6eac9217d1f41472034a9 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 164316 1fba1ee7c30fbd2572c49d55938eac54 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 151466 20e48a45fad384a8310ce970c00903b2 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 165248 c9f333ffc8b3ea28bd5882c6f683d200 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 163544 b9cf45c1b44e808e6f4bc28a0e462ba5 Updated packages for Ubuntu 7.04: Source archives: Size/MD5: 91922 4ab4fa170cfb1009969476118e6c5ea0 Size/MD5: 619 721b61d3b81b58e01eab7e4d75ec0616 Size/MD5: 1140291 9d23919999d6eac9217d1f41472034a9 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 167272 1b0f7e30281083c3c1f7ee7ea1edbff4 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 154032 ab6718b23c1cff644082b0126a72a02e powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 169850 b3cf955d0462608841b350435a049f4d sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 166698 4a8cfaa0a4f1eb5bd54649a8a770b9fd Updated packages for Ubuntu 7.10: Source archives: Size/MD5: 92162 9cb570c2efaac04984b2a0742015ea05 Size/MD5: 621 8e761acc5aa550a4c12c32a1c233d992 Size/MD5: 1140291 9d23919999d6eac9217d1f41472034a9 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 167694 cd72a56dbb1eab868f159b9b822a22c8 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 154212 be2f160d462a22bd11bf744498e69977 powerpc architecture (AppleMacintosh G3/G4/G5): Size/MD5: 169998 630a0893db3e5fee553860240946cb21 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 166968 88ffce45be1200383a5609f09be92417 . Debian Security Bulletin highlights a severe gunzip vulnerability that allows remote code execution through pointer errors. Update available.. unzip Remote Code Execution, Ubuntu Security Notice, Critical Unzip Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 20, 2008 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here