An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Security update for python-nltk ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0098-1 Rating: important References: #1260066 #1260067 #1260068 Cross-References: CVE-2026-33230 CVE-2026-33231 CVE-2026-33236 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for python-nltk fixes the following issues: - CVE-2026-33230: reflected cross-site scripting issue in the `lookup_...` route (boo#1260066) - CVE-2026-33231: unauthenticated remote shutdown of the local WordNet Browser HTTP server when it is started in its default mode (boo#1260067) - CVE-2026-33236: Attackers can control a remote XML index server to provide malicious values containing path traversal sequences (boo#1260068) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-98=1 Package List: - openSUSE Backports SLE-15-SP7 (noarch): python3-nltk-3.7-bp157.3.9.1 References: https://www.suse.com/security/cve/CVE-2026-33230.html https://www.suse.com/security/cve/CVE-2026-33231.html https://www.suse.com/security/cve/CVE-2026-33236.html https://bugzilla.suse.com/1260066 https://bugzilla.suse.com/1260067 https://bugzilla.suse.com/1260068 . This update resolves critical issues in python-nltk affecting openSUSE Backports SLE-15-SP7 with important risk levels.. openSUSE updates, python-nltk security, important vulnerabilities. . Severity: Important.LinuxSecurity.com Team
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for openvpn ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1642-1 Rating: important References: #1044947 Cross-References: CVE-2017-7508 Affected Products: SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openvpn fixes the following issues: - It was possible to trigger an assertion by sending a malformed IPv6 packet. That issue could have been abused to remotely shutdown an openvpn server or client, if IPv6 and --mssfix were enabled and if the IPv6 networks used inside the VPN were known. [bsc#1044947, CVE-2017-7508] Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-openvpn-13166=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-openvpn-13166=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-openvpn-13166=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-openvpn-13166=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-openvpn-13166=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390xx86_64): openvpn-2.0.9-143.46.1 openvpn-auth-pam-plugin-2.0.9-143.46.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): openvpn-2.0.9-143.46.1 openvpn-auth-pam-plugin-2.0.9-143.46.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): openvpn-2.0.9-143.46.1 openvpn-auth-pam-plugin-2.0.9-143.46.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): openvpn-debuginfo-2.0.9-143.46.1 openvpn-debugsource-2.0.9-143.46.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): openvpn-debuginfo-2.0.9-143.46.1 openvpn-debugsource-2.0.9-143.46.1 References: https://www.suse.com/security/cve/CVE-2017-7508.html https://bugzilla.suse.com/1044947 . Essential patch released for OpenVPN to tackle significant vulnerabilities on SUSE Linux Enterprise platforms.. SUSE Linux Enterprise, openvpn security, remote shutdown risk, SUSE update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.