Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
PDF signature forgery with adbe.pkcs7.sha1 SubFilter. (CVE-2025-2866) References: - https://bugs.mageia.org/show_bug.cgi?id=34234 - https://lists.debian.org/debian-security-announce/2025/msg00070.html . MGASA-2025-0154 - Updated libreoffice packages fix security vulnerability Publication date: 11 May 2025 URL: https://advisories.mageia.org/MGASA-2025-0154.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-2866 PDF signature forgery with adbe.pkcs7.sha1 SubFilter. (CVE-2025-2866) References: - https://bugs.mageia.org/show_bug.cgi?id=34234 - https://lists.debian.org/debian-security-announce/2025/msg00070.html - - https://www.cve.org/CVERecord?id=CVE-2025-2866 SRPMS: - 9/core/libreoffice-24.2.7.2-1.3.mga9 . Recent LibreOffice updates for Mageia address a PDF signature tampering vulnerability, highlighting the critical need for strong cybersecurity protocols.. libreoffice security, Mageia update, PDF forgery fix, Mageia CVE advisory. . LinuxSecurity.com Team
* bsc#1241620 Cross-References: * CVE-2025-43903 . # Security update for poppler Announcement ID: SUSE-SU-2025:1434-1 Release Date: 2025-05-02T10:37:11Z Rating: moderate References: * bsc#1241620 Cross-References: * CVE-2025-43903 CVSS scores: * CVE-2025-43903 ( SUSE ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-43903 ( NVD ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for poppler fixes the following issues: * CVE-2025-43903: improper verification of adbe.pkcs7.sha1 signatures allows for signature forgeries. (bsc#1241620) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1434=1 openSUSE-SLE-15.6-2025-1434=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1434=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1434=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * poppler-tools-24.03.0-150600.3.13.1 * poppler-tools-debuginfo-24.03.0-150600.3.13.1 * libpoppler135-24.03.0-150600.3.13.1 * libpoppler135-debuginfo-24.03.0-150600.3.13.1 * libpoppler-glib8-debuginfo-24.03.0-150600.3.13.1 * poppler-qt6-debugsource-24.03.0-150600.3.13.1 * typelib-1_0-Poppler-0_18-24.03.0-150600.3.13.1 * poppler-debugsource-24.03.0-150600.3.13.1 * libpoppler-qt6-3-24.03.0-150600.3.13.1 *libpoppler-cpp0-24.03.0-150600.3.13.1 * libpoppler-qt5-devel-24.03.0-150600.3.13.1 * libpoppler-devel-24.03.0-150600.3.13.1 * libpoppler-cpp0-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt5-1-24.03.0-150600.3.13.1 * libpoppler-qt6-devel-24.03.0-150600.3.13.1 * poppler-qt5-debugsource-24.03.0-150600.3.13.1 * libpoppler-qt5-1-debuginfo-24.03.0-150600.3.13.1 * libpoppler-glib8-24.03.0-150600.3.13.1 * libpoppler-qt6-3-debuginfo-24.03.0-150600.3.13.1 * libpoppler-glib-devel-24.03.0-150600.3.13.1 * openSUSE Leap 15.6 (x86_64) * libpoppler135-32bit-24.03.0-150600.3.13.1 * libpoppler-glib8-32bit-24.03.0-150600.3.13.1 * libpoppler-cpp0-32bit-24.03.0-150600.3.13.1 * libpoppler-glib8-32bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt5-1-32bit-24.03.0-150600.3.13.1 * libpoppler135-32bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt5-1-32bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler-cpp0-32bit-debuginfo-24.03.0-150600.3.13.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libpoppler-cpp0-64bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt5-1-64bit-24.03.0-150600.3.13.1 * libpoppler-glib8-64bit-24.03.0-150600.3.13.1 * libpoppler-cpp0-64bit-24.03.0-150600.3.13.1 * libpoppler-glib8-64bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt5-1-64bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler135-64bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler135-64bit-24.03.0-150600.3.13.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * poppler-tools-24.03.0-150600.3.13.1 * poppler-tools-debuginfo-24.03.0-150600.3.13.1 * libpoppler135-24.03.0-150600.3.13.1 * libpoppler135-debuginfo-24.03.0-150600.3.13.1 * libpoppler-glib8-debuginfo-24.03.0-150600.3.13.1 * typelib-1_0-Poppler-0_18-24.03.0-150600.3.13.1 * poppler-debugsource-24.03.0-150600.3.13.1 * libpoppler-cpp0-24.03.0-150600.3.13.1 * libpoppler-devel-24.03.0-150600.3.13.1 * libpoppler-cpp0-debuginfo-24.03.0-150600.3.13.1 *libpoppler-glib8-24.03.0-150600.3.13.1 * libpoppler-glib-devel-24.03.0-150600.3.13.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * poppler-qt6-debugsource-24.03.0-150600.3.13.1 * libpoppler-qt6-3-24.03.0-150600.3.13.1 * poppler-debugsource-24.03.0-150600.3.13.1 * libpoppler-cpp0-24.03.0-150600.3.13.1 * libpoppler-qt5-devel-24.03.0-150600.3.13.1 * libpoppler-devel-24.03.0-150600.3.13.1 * libpoppler-cpp0-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt5-1-24.03.0-150600.3.13.1 * libpoppler-qt6-devel-24.03.0-150600.3.13.1 * poppler-qt5-debugsource-24.03.0-150600.3.13.1 * libpoppler-qt5-1-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt6-3-debuginfo-24.03.0-150600.3.13.1 * SUSE Package Hub 15 15-SP6 (x86_64) * libpoppler135-32bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler-glib8-32bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler135-32bit-24.03.0-150600.3.13.1 * libpoppler-glib8-32bit-24.03.0-150600.3.13.1 ## References: * https://www.suse.com/security/cve/CVE-2025-43903.html * https://bugzilla.suse.com/show_bug.cgi?id=1241620 . SUSE has rolled out a crucial update to tackle a security flaw in poppler. This patch is essential for safeguarding systems against potential signature forgery threats.. SUSE Security Update, Poppler Update, Signature Forgery Fix. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for poppler Announcement ID: SUSE-SU-2025:1434-1 Release Date: 2025-05-02T10:37:11Z Rating: moderate References: * bsc#1241620 Cross-References: * CVE-2025-43903 CVSS scores: * CVE-2025-43903 ( SUSE ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-43903 ( NVD ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for poppler fixes the following issues: * CVE-2025-43903: improper verification of adbe.pkcs7.sha1 signatures allows for signature forgeries. (bsc#1241620) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1434=1 openSUSE-SLE-15.6-2025-1434=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1434=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1434=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * poppler-tools-24.03.0-150600.3.13.1 * poppler-tools-debuginfo-24.03.0-150600.3.13.1 * libpoppler135-24.03.0-150600.3.13.1 * libpoppler135-debuginfo-24.03.0-150600.3.13.1 * libpoppler-glib8-debuginfo-24.03.0-150600.3.13.1 * poppler-qt6-debugsource-24.03.0-150600.3.13.1 * typelib-1_0-Poppler-0_18-24.03.0-150600.3.13.1 * poppler-debugsource-24.03.0-150600.3.13.1 * libpoppler-qt6-3-24.03.0-150600.3.13.1 *libpoppler-cpp0-24.03.0-150600.3.13.1 * libpoppler-qt5-devel-24.03.0-150600.3.13.1 * libpoppler-devel-24.03.0-150600.3.13.1 * libpoppler-cpp0-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt5-1-24.03.0-150600.3.13.1 * libpoppler-qt6-devel-24.03.0-150600.3.13.1 * poppler-qt5-debugsource-24.03.0-150600.3.13.1 * libpoppler-qt5-1-debuginfo-24.03.0-150600.3.13.1 * libpoppler-glib8-24.03.0-150600.3.13.1 * libpoppler-qt6-3-debuginfo-24.03.0-150600.3.13.1 * libpoppler-glib-devel-24.03.0-150600.3.13.1 * openSUSE Leap 15.6 (x86_64) * libpoppler135-32bit-24.03.0-150600.3.13.1 * libpoppler-glib8-32bit-24.03.0-150600.3.13.1 * libpoppler-cpp0-32bit-24.03.0-150600.3.13.1 * libpoppler-glib8-32bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt5-1-32bit-24.03.0-150600.3.13.1 * libpoppler135-32bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt5-1-32bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler-cpp0-32bit-debuginfo-24.03.0-150600.3.13.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libpoppler-cpp0-64bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt5-1-64bit-24.03.0-150600.3.13.1 * libpoppler-glib8-64bit-24.03.0-150600.3.13.1 * libpoppler-cpp0-64bit-24.03.0-150600.3.13.1 * libpoppler-glib8-64bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt5-1-64bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler135-64bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler135-64bit-24.03.0-150600.3.13.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * poppler-tools-24.03.0-150600.3.13.1 * poppler-tools-debuginfo-24.03.0-150600.3.13.1 * libpoppler135-24.03.0-150600.3.13.1 * libpoppler135-debuginfo-24.03.0-150600.3.13.1 * libpoppler-glib8-debuginfo-24.03.0-150600.3.13.1 * typelib-1_0-Poppler-0_18-24.03.0-150600.3.13.1 * poppler-debugsource-24.03.0-150600.3.13.1 * libpoppler-cpp0-24.03.0-150600.3.13.1 * libpoppler-devel-24.03.0-150600.3.13.1 * libpoppler-cpp0-debuginfo-24.03.0-150600.3.13.1 *libpoppler-glib8-24.03.0-150600.3.13.1 * libpoppler-glib-devel-24.03.0-150600.3.13.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * poppler-qt6-debugsource-24.03.0-150600.3.13.1 * libpoppler-qt6-3-24.03.0-150600.3.13.1 * poppler-debugsource-24.03.0-150600.3.13.1 * libpoppler-cpp0-24.03.0-150600.3.13.1 * libpoppler-qt5-devel-24.03.0-150600.3.13.1 * libpoppler-devel-24.03.0-150600.3.13.1 * libpoppler-cpp0-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt5-1-24.03.0-150600.3.13.1 * libpoppler-qt6-devel-24.03.0-150600.3.13.1 * poppler-qt5-debugsource-24.03.0-150600.3.13.1 * libpoppler-qt5-1-debuginfo-24.03.0-150600.3.13.1 * libpoppler-qt6-3-debuginfo-24.03.0-150600.3.13.1 * SUSE Package Hub 15 15-SP6 (x86_64) * libpoppler135-32bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler-glib8-32bit-debuginfo-24.03.0-150600.3.13.1 * libpoppler135-32bit-24.03.0-150600.3.13.1 * libpoppler-glib8-32bit-24.03.0-150600.3.13.1 ## References: * https://www.suse.com/security/cve/CVE-2025-43903.html * https://bugzilla.suse.com/show_bug.cgi?id=1241620 . A medium-level security notice has been issued for openSUSE users concerning vulnerabilities in poppler that could impact various systems. Users are advised to follow the update guidelines.. openSUSE security, poppler update, moderate vulnerability, system patch. . LinuxSecurity.com Team
browserify-sign could allow unintended access if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-6800-1 May 30, 2024 node-browserify-sign vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: browserify-sign could allow unintended access if it opened a specially crafted file. Software Description: - node-browserify-sign: createSign and createVerify in your browser Details: It was discovered that browserify-sign incorrectly handled an upper bound check in signature verification. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to perform a signature forgery attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10 node-browserify-sign 4.2.1-3ubuntu0.1 Ubuntu 22.04 LTS node-browserify-sign 4.2.1-2ubuntu0.1 Ubuntu 20.04 LTS node-browserify-sign 4.0.4-2ubuntu0.20.04.1 Ubuntu 18.04 LTS node-browserify-sign 4.0.4-2ubuntu0.18.04.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6800-1 CVE-2023-46234 Package Information: https://launchpad.net/ubuntu/+source/node-browserify-sign/4.2.1-3ubuntu0.1 https://launchpad.net/ubuntu/+source/node-browserify-sign/4.2.1-2ubuntu0.1 https://launchpad.net/ubuntu/+source/node-browserify-sign/4.0.4-2ubuntu0.20.04.1 . A critical vulnerability in the browserify-sign package affects Ubuntu 20.04, 21.10, and 22.04, needing immediate updates to ensure system security.browserify-sign, Node-Browserify-Sign, access control, signature forgery. . LinuxSecurity.com Team
Update to 1.22.21, add fixes for CVE-2022-37599, CVE-2023-26136, CVE-2023-46234.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-5ecc250449 2024-02-28 01:40:29.293733 -------------------------------------------------------------------------------- Name : yarnpkg Product : Fedora 38 Version : 1.22.21 Release : 2.fc38 URL : https://github.com/yarnpkg/yarn Summary : Fast, reliable, and secure dependency management. Description : Fast, reliable, and secure dependency management. -------------------------------------------------------------------------------- Update Information: Update to 1.22.21, add fixes for CVE-2022-37599, CVE-2023-26136, CVE-2023-46234. -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 19 2024 Sandro Mani - 1.22.21-2 - Backport patches for CVE-2022-37599, CVE-2023-26136, CVE-2023-46234 * Fri Feb 16 2024 Sandro Mani - 1.22.21-1 - Update to 1.22.21 * Sat Jan 27 2024 Fedora Release Engineering - 1.22.19-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sat Jul 22 2023 Fedora Release Engineering - 1.22.19-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Wed May 3 2023 Sandro Mani - 1.22.19-6 - Rebuild (nodejs20) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2209317 - CVE-2022-37599 yarnpkg: loader-utils: regular expression denial of service in interpolateName.js [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2209317 [ 2 ] Bug #2220682 - CVE-2023-26136 yarnpkg: tough-cookie: prototype pollution in cookie memstore [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2220682 [ 3 ] Bug #2246633 - CVE-2023-46234 yarnpkg: browserify-sign: upper bound check issue in dsaVerify leads to a signature forgery attack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2246633 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-5ecc250449' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 1.22.21, add fixes for CVE-2022-37599, CVE-2023-26136, CVE-2023-46234.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-28fc0c2ef4 2024-02-28 01:07:06.086715 -------------------------------------------------------------------------------- Name : yarnpkg Product : Fedora 39 Version : 1.22.21 Release : 2.fc39 URL : https://github.com/yarnpkg/yarn Summary : Fast, reliable, and secure dependency management. Description : Fast, reliable, and secure dependency management. -------------------------------------------------------------------------------- Update Information: Update to 1.22.21, add fixes for CVE-2022-37599, CVE-2023-26136, CVE-2023-46234. -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 19 2024 Sandro Mani - 1.22.21-2 - Backport patches for CVE-2022-37599, CVE-2023-26136, CVE-2023-46234 * Fri Feb 16 2024 Sandro Mani - 1.22.21-1 - Update to 1.22.21 * Sat Jan 27 2024 Fedora Release Engineering - 1.22.19-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2209317 - CVE-2022-37599 yarnpkg: loader-utils: regular expression denial of service in interpolateName.js [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2209317 [ 2 ] Bug #2220682 - CVE-2023-26136 yarnpkg: tough-cookie: prototype pollution in cookie memstore [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2220682 [ 3 ] Bug #2246633 - CVE-2023-46234 yarnpkg: browserify-sign: upper bound check issue in dsaVerify leads to a signature forgery attack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2246633 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2024-28fc0c2ef4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
It was reported that incorrect bound checks in the dsaVerify function in node-browserify-sign, a Node.js library which adds crypto signing for browsers, allows an attacker to perform signature forgery attacks by constructing signatures that can be successfully verified by any . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5539-1
An upper bound check issue in `dsaVerify` function has been discovered in node-browserify-sign. This allows an attacker to construct signatures that can be successfully verified by any public key, thus leading to a signature forgery attack. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3635-1
Get the latest Linux and open source security news straight to your inbox.