Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 34 Moderate Advisory: Qt5-Qtsvg Out Of Bounds Read A95A40B78B

An out of bounds read in function QRadialFetchSimd from crafted svg file may lead to information disclosure or other potential consequences. This update includes the backported upstream fix and should resolve the security issue.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-a95a40b78b 2021-03-25 00:15:39.359217 --------------------------------------------------------------------------------Name : qt5-qtsvg Product : Fedora 34 Version : 5.15.2 Release : 4.fc34 URL : https://www.qt.io/ Summary : Qt5 - Support for rendering and displaying SVG Description : Scalable Vector Graphics (SVG) is an XML-based language for describing two-dimensional vector graphics. Qt provides classes for rendering and displaying SVG drawings in widgets and on other paint devices. --------------------------------------------------------------------------------Update Information: An out of bounds read in function QRadialFetchSimd from crafted svg file may lead to information disclosure or other potential consequences. This update includes the backported upstream fix and should resolve the security issue. --------------------------------------------------------------------------------ChangeLog: * Tue Mar 9 2021 Than Ngo - 5.15.2-4 - Resolves: #1931447, Out of bounds read in function QRadialFetchSimd from crafted svg file --------------------------------------------------------------------------------References: [ 1 ] Bug #1931444 - qt: Out of bounds read in function QRadialFetchSimd from crafted svg file https://bugzilla.redhat.com/show_bug.cgi?id=1931444 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-a95a40b78b' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . A boundary violation in the qt5-qtsvg module of Qt5 could lead to potential information leaks. This patch addresses the vulnerability with official corrections.. Qt5 Qtsvg Update, Fedora Security Fix, Information Disclosure Resolution. . LinuxSecurity.com Team

Calendar 2 Mar 24, 2021 Fedora
89

Fedora 22: FEDORA-2016-12345 Critical Update for Batik XML Parsing Issue

Security fix for CVE-2015-0250. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-8783 2015-05-25 20:39:36 -------------------------------------------------------------------------------- Name : batik Product : Fedora 21 Version : 1.8 Release : 0.18.svn1230816.fc21 URL : https://xmlgraphics.apache.org/batik/ Summary : Scalable Vector Graphics for Java Description : Batik is a Java(tm) technology based toolkit for applications that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-0250 -------------------------------------------------------------------------------- ChangeLog: * Thu May 21 2015 Michal Srb - 1.8-0.18.svn1230816 - Disable external xml entities - Resolves: CVE-2015-0250 * Mon Jan 12 2015 Alexander Kurtakov 1.8-0.17.svn1230816 - Add obsoletes in batik-css to ease updates. * Mon Dec 8 2014 Alexander Kurtakov 1.8-0.16.svn1230816 - Split css in subpackage. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update batik' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . A crucial security update for Batik on Fedora 21 addresses CVE-2015-0250. Users should promptly apply this patch for system safety. Follow the installationsteps provided.. Batik Security Update,Fedora 21,Security Fix,SVG Toolkit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 04, 2015 Critical Fedora
91

Gentoo: GLSA 200510-06 Normal: Dia SVG Import Code Execution

Improperly sanitised data in Dia allows remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200510-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Dia: Arbitrary code execution through SVG import Date: October 06, 2005 Bugs: #107916 ID: 200510-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Improperly sanitised data in Dia allows remote attackers to execute arbitrary code. Background ========= Dia is a gtk+ based diagram creation program released under the GPL license. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-office/dia < 0.94-r3 > = 0.94-r3 Description ========== Joxean Koret discovered that the SVG import plugin in Dia fails to properly sanitise data read from an SVG file. Impact ===== An attacker could create a specially crafted SVG file, which, when imported into Dia, could lead to the execution of arbitrary code. Workaround ========= There is no known workaround at this time. Resolution ========= All Dia users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-office/dia-0.94-r3" References ========= [ 1 ] CAN-2005-2966 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200510-06 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our usersmachines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Gentoo Security Advisory GLSA 202310-04 reveals a vulnerability in GIMP; all users are advised to update immediately.. Dia Security Advisory, Gentoo GLSA, Code Execution, SVG Risk. . LinuxSecurity.com Team

Calendar 2 Oct 06, 2005 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here