Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # python311-oauthlib-3.2.2-5.4 on GA media Announcement ID: openSUSE-SU-2025:15100-1 Rating: moderate Cross-References: * CVE-2022-36087 CVSS scores: * CVE-2022-36087 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the python311-oauthlib-3.2.2-5.4 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * python311-oauthlib 3.2.2-5.4 * python312-oauthlib 3.2.2-5.4 * python313-oauthlib 3.2.2-5.4 ## References: * https://www.suse.com/security/cve/CVE-2022-36087.html . Security notice for openSUSE highlighting a moderate threat in python311-oauthlib linked to CVE-2022-36087. Find specifics below.. openSUSE security, python library updates, supply chain security. . LinuxSecurity.com Team
Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-cd87acc644 2025-04-21 16:44:59.680841+00:00 -------------------------------------------------------------------------------- Name : python-pydantic-core Product : Fedora 41 Version : 2.27.2 Release : 5.fc41 URL : https://github.com/pydantic/pydantic-core Summary : Core validation logic for pydantic written in rust Description : The pydantic-core project provides the core validation logic for pydantic written in Rust. -------------------------------------------------------------------------------- Update Information: Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9. Update rust-zip to 2.6.1, fixing GHSA-94vh-gphv-8pm8. -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 11 2025 Benjamin A. Beasley - 2.27.2-5 - Rebuilt with idna 1.x; no longer allow older idna versions * Fri Apr 11 2025 Benjamin A. Beasley - 2.27.2-4 - Expect maturin to handle license files * Sat Jan 18 2025 Fedora Release Engineering - 2.27.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Thu Dec 26 2024 Benjamin A. Beasley - 2.27.2-2 - Omit snapshot tests on EPEL10 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2277901 - rust-adblock-0.9.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2277901 [ 2 ] Bug #2291175 - rust-idna-1.0.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2291175 [ 3 ] Bug #2323618 - rust-url-2.5.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2323618 [ 4 ] Bug #2324926 - rust-cookie_store-0.21.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2324926 [ 5 ] Bug #2352783 - rust-zip-2.6.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2352783 [ 6 ] Bug #2358015 - Review Request: rust-write16 - UTF-16 analog of the Write trait https://bugzilla.redhat.com/show_bug.cgi?id=2358015 [ 7 ] Bug #2358018 - Review Request: rust-utf16_iter - Iterator by char over potentially-invalid UTF-16 in &[u16] https://bugzilla.redhat.com/show_bug.cgi?id=2358018 [ 8 ] Bug #2358020 - Review Request: rust-icu_locid - API for managing Unicode Language and Locale Identifiers https://bugzilla.redhat.com/show_bug.cgi?id=2358020 [ 9 ] Bug #2358105 - Review Request: rust-icu_provider_macros - Proc macros for ICU data providers https://bugzilla.redhat.com/show_bug.cgi?id=2358105 [ 10 ] Bug #2358290 - Review Request: rust-icu_provider - Trait and struct definitions for the ICU data provider https://bugzilla.redhat.com/show_bug.cgi?id=2358290 [ 11 ] Bug #2358292 - Review Request: rust-icu_locid_transform_data - Data for the icu_locid_transform crate https://bugzilla.redhat.com/show_bug.cgi?id=2358292 [ 12 ] Bug #2358507 - Review Request: rust-icu_locid_transform - API for Unicode Language and Locale Identifiers canonicalization https://bugzilla.redhat.com/show_bug.cgi?id=2358507 [ 13 ] Bug #2358521 - Review Request: rust-icu_properties_data - Data for the icu_properties crate https://bugzilla.redhat.com/show_bug.cgi?id=2358521 [ 14 ] Bug #2358522 - Review Request: rust-icu_normalizer_data - Data for the icu_normalizer crate https://bugzilla.redhat.com/show_bug.cgi?id=2358522 [ 15 ] Bug #2358527 - Review Request: rust-icu_properties - Definitions for Unicode properties https://bugzilla.redhat.com/show_bug.cgi?id=2358527 [ 16 ] Bug #2358606 - Review Request: rust-icu_normalizer - API for normalizing text into Unicode Normalization Forms https://bugzilla.redhat.com/show_bug.cgi?id=2358606 [ 17 ] Bug #2358642 - Review Request: rust-idna_adapter - Back end adapter for idna https://bugzilla.redhat.com/show_bug.cgi?id=2358642 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-cd87acc644' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
update to version 2.25.1, CVE-2025-27154. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-fba1b24e4b 2025-03-08 01:23:45.593648+00:00 -------------------------------------------------------------------------------- Name : python-spotipy Product : Fedora 41 Version : 2.25.1 Release : 1.fc41 URL : https://github.com/spotipy-dev/spotipy Summary : A light weight Python library for the Spotify Web API Description : A light weight Python library for the Spotify Web API -------------------------------------------------------------------------------- Update Information: update to version 2.25.1, CVE-2025-27154 -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 27 2025 Bill Pemberton - 2.25.1-1 - update to version 2.25.1 * Sat Jan 18 2025 Fedora Release Engineering - 2.25.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2348684 - python-spotipy-2.25.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2348684 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-fba1b24e4b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Multiple security issues were discovered in Pillow, a Python imaging library, which could result in denial of service or the execution of arbitrary code if malformed images are processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5704-1
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for python-Pillow ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0125-1 Rating: important References: #1219048 Cross-References: CVE-2023-50447 CVSS scores: CVE-2023-50447 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2023-50447 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-Pillow fixes the following issues: - CVE-2023-50447: Fixed arbitrary code execution via the environment parameter (boo#1219048) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-125=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): python3-Pillow-8.4.0-bp155.3.3.1 python3-Pillow-tk-8.4.0-bp155.3.3.1 References: https://www.suse.com/security/cve/CVE-2023-50447.html https://bugzilla.suse.com/1219048 . openSUSE Security Notice: Security patch available for python-Pillow Notification ID: openSUSE-SU-2024:0451-2. Python Pillow Update, openSUSE Security Fix, Code Execution Risk. . Severity: Important. LinuxSecurity.com Team
Security fix for CVE-2023-45139. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-6d1d9f70d2 2024-01-25 00:38:48.210927 -------------------------------------------------------------------------------- Name : fonttools Product : Fedora 39 Version : 4.43.1 Release : 1.fc39 URL : https://github.com/fonttools/fonttools/ Summary : Tools to manipulate font files Description : fontTools is a library for manipulating fonts, written in Python. The project includes the TTX tool, that can convert TrueType and OpenType fonts to and from an XML text format, which is also called TTX. It supports TrueType, OpenType, AFM and to an extent Type 1 and some Mac-specific formats. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-45139 -------------------------------------------------------------------------------- ChangeLog: * Sun Oct 8 2023 Parag Nemade - 4.43.1-1 - Update to 4.43.1 version (#2241574) * Tue Aug 22 2023 Parag Nemade - 4.42.1-1 - Update to 4.42.1 version (#2232931) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2257808 - CVE-2023-45139 fonttools: XML External Entity Injection (XXE) Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2257808 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-6d1d9f70d2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 2022.12.7, fixes CVE-2022-23491.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-7ed04fe4a7 2023-03-30 01:14:14.931077 --------------------------------------------------------------------------------Name : mingw-python-certifi Product : Fedora 36 Version : 2022.12.7 Release : 1.fc36 URL : https://certifi.io/ Summary : MinGW Windows Python certifi library Description : MinGW Windows Python certifi. --------------------------------------------------------------------------------Update Information: Update to 2022.12.7, fixes CVE-2022-23491. --------------------------------------------------------------------------------ChangeLog: * Tue Mar 21 2023 Sandro Mani - 2022.12.7-1 - Update to 2022.12.7 * Thu Jul 21 2022 Fedora Release Engineering - 2021.10.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Mon Feb 14 2022 Sandro Mani - 2021.10.8-1 - Update to 2021.10.8 --------------------------------------------------------------------------------References: [ 1 ] Bug #2180096 - CVE-2022-23491 mingw-python-certifi: python-certifi: untrusted root certificates [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2180096 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-7ed04fe4a7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
urllib3 could be made to stop responding if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-5812-1 January 19, 2023 python-urllib3 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: urllib3 could be made to stop responding if it received specially crafted network traffic. Software Description: - python-urllib3: HTTP library with thread-safe connection pooling Details: It was discovered that urllib3 incorrectly handled certain characters in URLs. A remote attacker could possibly use this issue to cause urllib3 to consume resources, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: python3-urllib3 1.25.8-2ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5812-1 CVE-2021-33503 Package Information: https://launchpad.net/ubuntu/+source/python-urllib3/1.25.8-2ubuntu0.2 . USN-5820-1 security alert addresses a python-requests denial of service flaw affecting Ubuntu platforms. python urllib3, Ubuntu security, denial of service, network traffic issues. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.