This update for gsl fixes the following issues: CVE-2020-35357: Fixed a stack out of bounds read in gsl_stats_quantile_from_sorted_data(). (bsc#1214681). # Security update for gsl Announcement ID: SUSE-SU-2023:3527-1 Rating: moderate References: * #1214681 Cross-References: * CVE-2020-35357 CVSS scores: * CVE-2020-35357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2020-35357 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Workstation Extension 15 SP4 * SUSE Linux Enterprise Workstation Extension 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gsl fixes the following issues: * CVE-2020-35357: Fixed a stack out of bounds read in gsl_stats_quantile_from_sorted_data(). (bsc#1214681) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-WE-15-SP4-2023-3527=1 * SUSE Linux Enterprise Workstation Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-WE-15-SP5-2023-3527=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3527=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3527=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP4 (x86_64) * libgsl23-debuginfo-2.4-150100.9.4.1 * gsl-debuginfo-2.4-150100.9.4.1 * libgsl23-2.4-150100.9.4.1 * gsl-debugsource-2.4-150100.9.4.1 * SUSELinux Enterprise Workstation Extension 15 SP5 (x86_64) * libgsl23-debuginfo-2.4-150100.9.4.1 * gsl-debuginfo-2.4-150100.9.4.1 * libgsl23-2.4-150100.9.4.1 * gsl-debugsource-2.4-150100.9.4.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * gsl_2_4-gnu-hpc-debuginfo-2.4-150100.9.4.1 * libgslcblas_2_4-gnu-hpc-debuginfo-2.4-150100.9.4.1 * libgsl_2_4-gnu-hpc-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-doc-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-debugsource-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-devel-2.4-150100.9.4.1 * libgslcblas_2_4-gnu-hpc-2.4-150100.9.4.1 * libgsl23-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-2.4-150100.9.4.1 * libgsl23-debuginfo-2.4-150100.9.4.1 * libgsl_2_4-gnu-hpc-debuginfo-2.4-150100.9.4.1 * openSUSE Leap 15.4 (noarch) * gsl_2_4-gnu-hpc-examples-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-module-2.4-150100.9.4.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * gsl_2_4-gnu-hpc-debuginfo-2.4-150100.9.4.1 * libgslcblas_2_4-gnu-hpc-debuginfo-2.4-150100.9.4.1 * libgsl_2_4-gnu-hpc-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-doc-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-debugsource-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-devel-2.4-150100.9.4.1 * libgslcblas_2_4-gnu-hpc-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-2.4-150100.9.4.1 * libgsl_2_4-gnu-hpc-debuginfo-2.4-150100.9.4.1 * openSUSE Leap 15.5 (noarch) * gsl_2_4-gnu-hpc-examples-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-module-2.4-150100.9.4.1 ## References: * https://www.suse.com/security/cve/CVE-2020-35357.html * https://bugzilla.suse.com/show_bug.cgi?id=1214681 . This patch resolves a vulnerability in GSL, correcting stack overflow incidents and improving overall system stability.. gsl security advisory, openSUSE update, stack overflow fix, system integrity update. . LinuxSecurity.com Team
An update that fixes 12 vulnerabilities is now available. . openSUSE Security Update: Security update for transfig ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1458-1 Rating: important References: #1189325 #1189343 #1189345 #1189346 #1190607 #1190611 #1190612 #1190615 #1190616 #1190617 #1190618 #1192019 Cross-References: CVE-2020-21529 CVE-2020-21530 CVE-2020-21531 CVE-2020-21532 CVE-2020-21533 CVE-2020-21534 CVE-2020-21535 CVE-2020-21680 CVE-2020-21681 CVE-2020-21682 CVE-2020-21683 CVE-2021-32280 CVSS scores: CVE-2020-21529 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2020-21530 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2020-21531 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2020-21532 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2020-21533 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2020-21534 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2020-21535 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2020-21680 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-21681 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-21682 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-21683 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-32280 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes 12 vulnerabilities is nowavailable. Description: This update for transfig fixes the following issues: Update to fig2dev version 3.2.8 Patchlevel 8b (Aug 2021) - bsc#1190618, CVE-2020-21529: stack buffer overflow in the bezier_spline function in genepic.c. - bsc#1190615, CVE-2020-21530: segmentation fault in the read_objects function in read.c. - bsc#1190617, CVE-2020-21531: global buffer overflow in the conv_pattern_index function in gencgm.c. - bsc#1190616, CVE-2020-21532: global buffer overflow in the setfigfont function in genepic.c. - bsc#1190612, CVE-2020-21533: stack buffer overflow in the read_textobject function in read.c. - bsc#1190611, CVE-2020-21534: global buffer overflow in the get_line function in read.c. - bsc#1190607, CVE-2020-21535: segmentation fault in the gencgm_start function in gencgm.c. - bsc#1192019, CVE-2021-32280: NULL pointer dereference in compute_closed_spline() in trans_spline.c This update was imported from the SUSE:SLE-15:Update update project. This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-1458=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x): transfig-3.2.8b-bp152.3.6.2 References: https://www.suse.com/security/cve/CVE-2020-21529.html https://www.suse.com/security/cve/CVE-2020-21530.html https://www.suse.com/security/cve/CVE-2020-21531.html https://www.suse.com/security/cve/CVE-2020-21532.html https://www.suse.com/security/cve/CVE-2020-21533.html https://www.suse.com/security/cve/CVE-2020-21534.html https://www.suse.com/security/cve/CVE-2020-21535.html https://www.suse.com/security/cve/CVE-2020-21680.html https://www.suse.com/security/cve/CVE-2020-21681.html https://www.suse.com/security/cve/CVE-2020-21682.html https://www.suse.com/security/cve/CVE-2020-21683.html https://www.suse.com/security/cve/CVE-2021-32280.html https://bugzilla.suse.com/1189325 https://bugzilla.suse.com/1189343 https://bugzilla.suse.com/1189345 https://bugzilla.suse.com/1189346 https://bugzilla.suse.com/1190607 https://bugzilla.suse.com/1190611 https://bugzilla.suse.com/1190612 https://bugzilla.suse.com/1190615 https://bugzilla.suse.com/1190616 https://bugzilla.suse.com/1190617 https://bugzilla.suse.com/1190618 https://bugzilla.suse.com/1192019 . A significant software patch for transfig tackles 12 major vulnerabilities, improving overall security and operational reliability.. openSUSE Security, transfig Update, important Patch. . Severity: Important. LinuxSecurity.com Team
Fix for CVE-2021-25217. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-8ca8263bde 2021-06-05 01:14:13.536814 --------------------------------------------------------------------------------Name : dhcp Product : Fedora 33 Version : 4.4.2 Release : 9.b1.fc33 URL : https://www.isc.org/dhcp/ Summary : Dynamic host configuration protocol software Description : DHCP (Dynamic Host Configuration Protocol) --------------------------------------------------------------------------------Update Information: Fix for CVE-2021-25217 --------------------------------------------------------------------------------ChangeLog: * Thu May 27 2021 Pavel Zhukov - 12:4.4.2-9.b1 - Fix for CVE-2021-25217 --------------------------------------------------------------------------------References: [ 1 ] Bug #1963258 - CVE-2021-25217 dhcp: stack-based buffer overflow when parsing statements with colon-separated hex digits in config or lease files in dhcpd and dhclient https://bugzilla.redhat.com/show_bug.cgi?id=1963258 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-8ca8263bde' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with the buggy. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-27e7b92407 2019-04-22 05:09:02.624501 --------------------------------------------------------------------------------Name : elementary-code Product : Fedora 29 Version : 3.1.1 Release : 2.fc29 URL : https://github.com/elementary/code Summary : Code editor from elementary Description : Code editor from elementary. --------------------------------------------------------------------------------Update Information: This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with the buggy Meson, excepting packages for updates were already pending (in those cases, those updates have been edited instead). --------------------------------------------------------------------------------ChangeLog: * Tue Apr 16 2019 Adam Williamson - 3.1.1-2 - Rebuild with Meson fix for #1699099 * Sun Mar 17 2019 Fabio Valentini - 3.1.1-1 - Update to version 3.1.1. * Thu Mar 7 2019 Fabio Valentini - 3.1.0-1 - Update to version 3.1.0. * Mon Jan 7 2019 Fabio Valentini - 3.0.2-1 - Update to version 3.0.2. * Tue Dec 18 2018 Fabio Valentini - 3.0.1-1 - Update to version 3.0.1. * Thu Oct 18 2018 Fabio Valentini - 3.0-1 - Update to version3.0. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-27e7b92407' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for ghostscript-library ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1369-1 Rating: moderate References: #1090099 Cross-References: CVE-2016-9601 CVE-2018-10194 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for ghostscript-library fixes the following issues: - CVE-2018-10194: Fixed a stack-based buffer overflow in gdevpdts.c (bsc#1090099) - Fixed a crash in the fix for CVE-2016-9601. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-ghostscript-library-13617=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-ghostscript-library-13617=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-ghostscript-library-13617=1 Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): ghostscript-devel-8.62-32.47.10.1 ghostscript-ijs-devel-8.62-32.47.10.1 libgimpprint-devel-4.2.7-32.47.10.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): ghostscript-fonts-other-8.62-32.47.10.1 ghostscript-fonts-rus-8.62-32.47.10.1 ghostscript-fonts-std-8.62-32.47.10.1 ghostscript-library-8.62-32.47.10.1 ghostscript-omni-8.62-32.47.10.1 ghostscript-x11-8.62-32.47.10.1 libgimpprint-4.2.7-32.47.10.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): ghostscript-library-debuginfo-8.62-32.47.10.1 ghostscript-library-debugsource-8.62-32.47.10.1 References: https://www.suse.com/security/cve/CVE-2016-9601.html https://www.suse.com/security/cve/CVE-2018-10194.html https://bugzilla.suse.com/1090099 . SUSE Security Patch Resolves Moderate Vulnerabilities in Ghostscript-Library Across Various Offerings.. ghostscript library update, SUSE vulnerability fix, Software Development Kit security, SUSE Server patch. . LinuxSecurity.com Team
Security fix for [CVE-2018-10194](https://access.redhat.com/security/cve/cve-2018-10194).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-226dac231f 2018-04-29 21:22:26.242949 --------------------------------------------------------------------------------Name : ghostscript Product : Fedora 26 Version : 9.20 Release : 11.fc26 URL : https://www.ghostscript.com/ Summary : A PostScript interpreter and renderer Description : Ghostscript is a set of software that provides a PostScript interpreter, a set of C procedures (the Ghostscript library, which implements the graphics capabilities in the PostScript language) and an interpreter for Portable Document Format (PDF) files. Ghostscript translates PostScript code into many common, bitmapped formats, like those understood by your printer or screen. Ghostscript is normally used to display PostScript files and to print PostScript files to non-PostScript printers. If you need to display PostScript files or print them to non-PostScript printers, you should install ghostscript. If you install ghostscript, you also need to install the ghostscript-fonts package. --------------------------------------------------------------------------------Update Information: Security fix for [CVE-2018-10194](https://access.redhat.com/security/cve/cve-2018-10194). --------------------------------------------------------------------------------ChangeLog: * Mon Apr 23 2018 David Kaspar [Dee'Kej] - 9.20-11 - Fix for CVE-2018-10194 added (bug #1569821) --------------------------------------------------------------------------------References: [ 1 ] Bug #1569108 - CVE-2018-10194 ghostscript: Stack-based out-of-bounds write in pdf_set_text_matrix function in gdevpdts.c https://bugzilla.redhat.com/show_bug.cgi?id=1569108 --------------------------------------------------------------------------------This update can be installed with the "dnf"update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-226dac231f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for Linux Kernel Live Patch 15 for SLE 12 SP1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1943-1 Rating: important References: #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for the Linux Kernel 3.12.74-60_64_40 fixes one issue. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1209=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1209=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kgraft-patch-3_12_74-60_64_40-default-2-3.1 kgraft-patch-3_12_74-60_64_40-xen-2-3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): kgraft-patch-3_12_74-60_64_40-default-2-3.1 kgraft-patch-3_12_74-60_64_40-xen-2-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1039496 . A recent security patch resolves asignificant stack capacity vulnerability in the Linux Kernel Live Patch 15 targeting SUSE 12 SP1 platforms.. Linux Kernel, Security Patch, SUSE SLE, Important Update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is now available. now available.. SUSE Security Update: Security update for Linux Kernel Live Patch 4 for SLE 12 SP2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1923-1 Rating: important References: #1019079 #1025013 #1025254 #1030575 #1031481 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Live Patching 12 ______________________________________________________________________________ An update that solves one vulnerability and has 6 fixes is now available. Description: This update for the Linux Kernel 4.4.38-93 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2017-1197=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Live Patching 12 (x86_64): kgraft-patch-4_4_38-93-default-6-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1019079 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1025254 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 . SUSE Security Enhancement tackles a severe buffer overflow issue with KernelLive Patch 5 for SLE 15 SP3.. SUSE Linux Kernel, Live Patch, Security Update, Stack Issue, Kernel Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.