Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file. (CVE-2024-22641) References: . MGASA-2024-0361 - Updated php-tcpdf packages fix security vulnerability Publication date: 12 Nov 2024 URL: https://advisories.mageia.org/MGASA-2024-0361.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-22641 TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file. (CVE-2024-22641) References: - https://bugs.mageia.org/show_bug.cgi?id=33731 - https://lists.fedoraproject.org/archives/list/
* bsc#1229596 * bsc#1229704 * bsc#1230227 Cross-References: . # Security update for python39 Announcement ID: SUSE-SU-2024:3411-1 Rating: important References: * bsc#1229596 * bsc#1229704 * bsc#1230227 Cross-References: * CVE-2024-6232 * CVE-2024-7592 * CVE-2024-8088 CVSS scores: * CVE-2024-6232 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2024-6232 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-6232 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7592 ( SUSE ): 2.6 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-7592 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8088 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-8088 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Legacy Module 15-SP5 * openSUSE Leap 15.3 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for python39 fixes the following issues: * Update to 3.9.20: * CVE-2024-6232: excessive backtracking when parsing tarfile headers leads to ReDoS. (bsc#1230227) * CVE-2024-7592: quadratic algorithm used when parsing cookies leads to excessive resource consumption. (bsc#1229596) * CVE-2024-8088: lack of name validation when extracting a zip archive leads to infinite loops. (bsc#1229704) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methodslike YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-3411=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3411=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3411=1 * Legacy Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP5-2024-3411=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-3411=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-3411=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-3411=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-3411=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * python39-doc-devhelp-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-testsuite-debuginfo-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-testsuite-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-idle-3.9.20-150300.4.52.1 * python39-doc-3.9.20-150300.4.52.1 * openSUSE Leap 15.3 (x86_64) * python39-32bit-3.9.20-150300.4.52.1 *libpython3_9-1_0-32bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-32bit-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-32bit-3.9.20-150300.4.52.1 * python39-32bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-32bit-3.9.20-150300.4.52.1 * openSUSE Leap 15.3 (aarch64_ilp32) * python39-64bit-3.9.20-150300.4.52.1 * libpython3_9-1_0-64bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-64bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-64bit-3.9.20-150300.4.52.1 * libpython3_9-1_0-64bit-3.9.20-150300.4.52.1 * python39-64bit-debuginfo-3.9.20-150300.4.52.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * python39-doc-devhelp-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-testsuite-debuginfo-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-testsuite-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-idle-3.9.20-150300.4.52.1 * python39-doc-3.9.20-150300.4.52.1 * openSUSE Leap 15.5 (x86_64) * python39-32bit-3.9.20-150300.4.52.1 * libpython3_9-1_0-32bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-32bit-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-32bit-3.9.20-150300.4.52.1 * python39-32bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-32bit-3.9.20-150300.4.52.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) *python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * python39-doc-devhelp-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-testsuite-debuginfo-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-testsuite-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-idle-3.9.20-150300.4.52.1 * python39-doc-3.9.20-150300.4.52.1 * openSUSE Leap 15.6 (x86_64) * python39-32bit-3.9.20-150300.4.52.1 * libpython3_9-1_0-32bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-32bit-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-32bit-3.9.20-150300.4.52.1 * python39-32bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-32bit-3.9.20-150300.4.52.1 * Legacy Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python39-curses-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 *python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * python39-idle-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 * python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * python39-idle-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 * python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 *python39-idle-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 * python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * python39-idle-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 ## References: * https://www.suse.com/security/cve/CVE-2024-6232.html * https://www.suse.com/security/cve/CVE-2024-7592.html * https://www.suse.com/security/cve/CVE-2024-8088.html * https://bugzilla.suse.com/show_bug.cgi?id=1229596 * https://bugzilla.suse.com/show_bug.cgi?id=1229704 * https://bugzilla.suse.com/show_bug.cgi?id=1230227 . Bolster your platform's protection using SUSE's Python39 security patch that tackles urgent vulnerabilities throughout multiple components.. Python39 Security Update, SUSE Security Advisory, Linux Fixes. . Severity: Important. LinuxSecurity.com Team
The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3798-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.9 , suse/manager/4.3/proxy-httpd:4.3.9.9.40.9 , suse/manager/4.3/proxy-httpd:latest , suse/manager/4.3/proxy-httpd:susemanager-4.3.9 , suse/manager/4.3/proxy-httpd:susemanager-4.3.9.9.40.9 Container Release : 9.40.9 Severity : moderate Type : security References : 1206667 CVE-2022-40897 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4517-1 Released: Tue Nov 21 17:30:27 2023 Summary: Security update for python3-setuptools Type: security Severity: moderate References: 1206667,CVE-2022-40897 This update for python3-setuptools fixes the following issues: - CVE-2022-40897: Fixed Regular Expression Denial of Service (ReDoS) in package_index.py (bsc#1206667). The following package changes have been done: - python3-setuptools-44.1.1-150400.9.6.1 updated . A security patch for the SUSE Container suse/manager/4.3/proxy-nginx has been released to mitigate a ReDoS vulnerability.. SUSE Manager, Container Update, Security Patches, ReDoS Threat. . LinuxSecurity.com Team
python-nltk 3.6.6 update resolves ReDoS opportunity by fixing incorrectly specified regex References: - https://bugs.mageia.org/show_bug.cgi?id=30604 . MGASA-2023-0302 - Updated python-nltk package fixes a security vulnerability Publication date: 25 Oct 2023 URL: https://advisories.mageia.org/MGASA-2023-0302.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-3828 python-nltk 3.6.6 update resolves ReDoS opportunity by fixing incorrectly specified regex References: - https://bugs.mageia.org/show_bug.cgi?id=30604 - https://www.cve.org/CVERecord?id=CVE-2021-3828 SRPMS: - 8/core/python-nltk-3.6.6-1.mga8 - 8/core/python-regex-2022.9.13-1.mga8 . MGASA-2023-0303 patch addresses a vulnerability in python-requests, mitigating an information exposure risk linked to improper SSL verification settings.. python-nltk security, mageia update, regex threat. . Severity: Critical. LinuxSecurity.com Team
Erik Krogh Kristensen and Rasmus Petersen from the GitHub Security Lab discovered a ReDoS (Regular Expression Denial of Service) vulnerability in python-mechanize, a library to automate interaction with websites modeled after the Perl module WWW::Mechanize, which could lead to . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3460-1
Upgrade to Ruby 3.1.4. * Fix ReDoS vulnerability in URI (CVE-2023-28755) * Fix ReDoS vulnerability in Time (CVE-2023-28756) Fix bundler improperly resolving archful gems in Gemfile.lock. (rhbz#2178171). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-a7be7ea1aa 2023-04-21 01:23:34.069336 --------------------------------------------------------------------------------Name : ruby Product : Fedora 36 Version : 3.1.4 Release : 175.fc36 URL : https://www.ruby-lang.org/ Summary : An interpreter of object-oriented scripting language Description : Ruby is the interpreted scripting language for quick and easy object-oriented programming. It has many features to process text files and to do system management tasks (as in Perl). It is simple, straight-forward, and extensible. --------------------------------------------------------------------------------Update Information: Upgrade to Ruby 3.1.4. * Fix ReDoS vulnerability in URI (CVE-2023-28755) * Fix ReDoS vulnerability in Time (CVE-2023-28756) Fix bundler improperly resolving archful gems in Gemfile.lock. (rhbz#2178171) --------------------------------------------------------------------------------ChangeLog: * Fri Mar 31 2023 Jarek Prokop
Two ruby-rack issues have been addressed: CVE-2023-27530 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3392-1
New ruby packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] ruby (SSA:2023-090-01) New ruby packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/ruby-3.0.6-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: ReDoS vulnerability in URI. ReDoS vulnerability in Time. For more information, see: https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/ https://www.ruby-lang.org/en/news/2023/03/30/redos-in-time-cve-2023-28756/ https://www.cve.org/CVERecord?id=CVE-2023-28755 https://www.cve.org/CVERecord?id=CVE-2023-28756 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: 22ffa16679294ddce3265d913f2fac20 ruby-3.0.6-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 0724127e313f586f6677e12e0316a070 ruby-3.0.6-x86_64-1_slack15.0.txz Slackware -current package: d39ba074e9714480e07880be54466086 d/ruby-3.2.2-i586-1.txz Slackware x86_64 -current package: 94a42ee743ed273628c09d9242ff125f d/ruby-3.2.2-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg ruby-3.0.6-i586-1_slack15.0.txz +-----+ . Recent updates to Ruby packages have been introduced in Slackware to mitigate significant security threats arising from ReDoS vulnerabilities.. ReDoSFix, Slackware 15.0, Ruby Update, Security Package. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.