Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 512
Alerts This Week
Warning Icon 1 512

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 30 articles for you...
217

Oracle Linux 8: transfig Moderate ELSA-2026-0756 CVE-2025-46397 Fix

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-0756 http://linux.oracle.com/errata/ELSA-2026-0756.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: transfig-3.2.6a-5.el8_10.x86_64.rpm aarch64: transfig-3.2.6a-5.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/transfig-3.2.6a-5.el8_10.src.rpm Related CVEs: CVE-2025-46397 Description of changes: [1:3.2.6a-5] - Detect nan in spline control values - Fix for CVE-2025-46397 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Updated rpms for Oracle Linux 8 include a moderate fix for transfig addressing a critical issue. Details inside.. Oracle Linux, transfig, Moderate Advisory, information security. . LinuxSecurity.com Team

Calendar%202 Jan 21, 2026 Oracle
217

Oracle Linux 9 ELSA-2026-0700 Transfig Moderate CVE-2025-46397

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-0700 http://linux.oracle.com/errata/ELSA-2026-0700.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: transfig-3.2.7b-11.el9_7.x86_64.rpm aarch64: transfig-3.2.7b-11.el9_7.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/transfig-3.2.7b-11.el9_7.src.rpm Related CVEs: CVE-2025-46397 Description of changes: [1:3.2.7b-11] - Detect nan in spline control values - CVE-2025-46397 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 announced a moderate security update for transfig addressing CVE-2025-46397. Update recommended.. Oracle Linux, transfig, security advisory, CVE-2025-46397, update recommendation. . LinuxSecurity.com Team

Calendar%202 Jan 15, 2026 Oracle
203

Mageia 9: Transfig Important CVE-2025-46397 Segfault Risks MGASA-2025-0253

MGASA-2025-0253 - Updated transfig packages fix security vulnerabilities. MGASA-2025-0253 - Updated transfig packages fix security vulnerabilities Publication date: 31 Oct 2025 URL: https://advisories.mageia.org/MGASA-2025-0253.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-46397, CVE-2025-46398, CVE-2025-46399, CVE-2025-46400 Description: fig2dev stack-overflow. (CVE-2025-46397) fig2dev stack-overflow via read_objects. (CVE-2025-46398) fig2dev segmentation fault vulnerability. (CVE-2025-46399) fig2dev segmentation fault in read_arcobject. (CVE-2025-46400) References: - https://bugs.mageia.org/show_bug.cgi?id=34309 - - https://www.cve.org/CVERecord?id=CVE-2025-46397 - https://www.cve.org/CVERecord?id=CVE-2025-46398 - https://www.cve.org/CVERecord?id=CVE-2025-46399 - https://www.cve.org/CVERecord?id=CVE-2025-46400 SRPMS: - 9/core/transfig-3.2.9a-1.1.mga9 . Updated transfig packages in Mageia address multiple security threats, including stack overflow and segfault vulnerabilities.. Mageia Transfig Security, Stack Overflow Fix, Segmentation Fault Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 01, 2025 Important Mageia
89

Fedora 41: Transfig Security Advisory Addresses Major Seg Fault Issues

Update to latest upstream snapshot ee3f4d841d1ba7d5b1b57544c5068822ca92b1af. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-465f43da19 2025-07-23 01:14:06.280613+00:00 -------------------------------------------------------------------------------- Name : transfig Product : Fedora 41 Version : 3.2.9a^20250619.ee3f4d8 Release : 1.fc41 URL : https://sourceforge.net/projects/mcj/ Summary : Utility for converting FIG files (made by xfig) to other formats Description : The transfig utility creates a makefile which translates FIG (created by xfig) or PIC figures into a specified LaTeX graphics language (for example, PostScript(TM)). Transfig is used to create TeX documents which are portable (i.e., they can be printed in a wide variety of environments). Install transfig if you need a utility for translating FIG or PIC figures into certain graphics languages. -------------------------------------------------------------------------------- Update Information: Update to latest upstream snapshot ee3f4d841d1ba7d5b1b57544c5068822ca92b1af -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 19 2025 Marian Koncek - 1:3.2.9a^20250619.ee3f4d8-1 - Update to latest upstream snapshot ee3f4d841d1ba7d5b1b57544c5068822ca92b1af -------------------------------------------------------------------------------- References: [ 1 ] Bug #2373186 - CVE-2025-46399 transfig: Fig2dev Segmentation Fault Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2373186 [ 2 ] Bug #2373192 - CVE-2025-46400 transfig: fig2dev segmentation fault in read_arcobject [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2373192 [ 3 ] Bug #2373195 - CVE-2025-46398 transfig: fig2dev stack-overflow via read_objects [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2373195 [ 4 ] Bug #2373197 - CVE-2025-46397transfig: fig2dev stack-overflow [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2373197 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-465f43da19' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Explore the key enhancements in transfig for Fedora 41, focusing on resolving crucial segmentation fault problems that have been impacting users.. Fedora 41, transfig Update, segmentation fault, security patches, software improvements. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 23, 2025 Important Fedora
89

Fedora 42 Update: Important Segfault Problems in transfig and Testing

Add smoke tests. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-ea5c403b3e 2025-07-23 00:57:56.630601+00:00 -------------------------------------------------------------------------------- Name : transfig Product : Fedora 42 Version : 3.2.9a^20250619.ee3f4d8 Release : 2.fc42 URL : https://sourceforge.net/projects/mcj/ Summary : Utility for converting FIG files (made by xfig) to other formats Description : The transfig utility creates a makefile which translates FIG (created by xfig) or PIC figures into a specified LaTeX graphics language (for example, PostScript(TM)). Transfig is used to create TeX documents which are portable (i.e., they can be printed in a wide variety of environments). Install transfig if you need a utility for translating FIG or PIC figures into certain graphics languages. -------------------------------------------------------------------------------- Update Information: Add smoke tests -------------------------------------------------------------------------------- ChangeLog: * Mon Jul 14 2025 Marian Koncek - 1:3.2.9a^20250619.ee3f4d8-2 - Add smoke tests * Thu Jun 19 2025 Marian Koncek - 1:3.2.9a^20250619.ee3f4d8-1 - Update to latest upstream snapshot ee3f4d841d1ba7d5b1b57544c5068822ca92b1af -------------------------------------------------------------------------------- References: [ 1 ] Bug #2373187 - CVE-2025-46399 transfig: Fig2dev Segmentation Fault Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373187 [ 2 ] Bug #2373193 - CVE-2025-46400 transfig: fig2dev segmentation fault in read_arcobject [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373193 [ 3 ] Bug #2373196 - CVE-2025-46398 transfig: fig2dev stack-overflow via read_objects [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373196 [ 4 ] Bug #2373198 - CVE-2025-46397 transfig: fig2dev stack-overflow[fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373198 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ea5c403b3e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . The latest Fedora 42 release introduces a transfigure revision that boosts reliability, implementing smoke tests to resolve significant segmentation faults.. Fedora Update, transfig, segmentation fault, security advisory, important update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 23, 2025 Important Fedora
100

SUSE 12 SP5: 2025:01890-1 moderate: transfig buffer overflow

* bsc#1243260 * bsc#1243261 * bsc#1243262 * bsc#1243263 . # Security update for transfig Announcement ID: SUSE-SU-2025:01890-1 Release Date: 2025-06-11T05:43:47Z Rating: moderate References: * bsc#1243260 * bsc#1243261 * bsc#1243262 * bsc#1243263 Cross-References: * CVE-2025-46397 * CVE-2025-46398 * CVE-2025-46399 * CVE-2025-46400 CVSS scores: * CVE-2025-46397 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46397 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46398 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46398 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46399 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46399 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46400 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46400 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for transfig fixes the following issues: Update to fig2dev version 3.2.9a * CVE-2025-46397: Fixed a stack buffer overflow in fig2dev in bezier_spline function (bsc#1243260). * CVE-2025-46398: Fixed a stack buffer overflow in fig2dev in read_objects function (bsc#1243262). * CVE-2025-46399: Fixed a segmentation fault in fig2dev in genge_itp_spline function (bsc#1243263). * CVE-2025-46400: Fixed a segmentation fault in fig2dev in read_arcobject function (bsc#1243261). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1890=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * transfig-debuginfo-3.2.8b-2.26.1 * transfig-debugsource-3.2.8b-2.26.1 * transfig-3.2.8b-2.26.1 ## References: * https://www.suse.com/security/cve/CVE-2025-46397.html * https://www.suse.com/security/cve/CVE-2025-46398.html * https://www.suse.com/security/cve/CVE-2025-46399.html * https://www.suse.com/security/cve/CVE-2025-46400.html * https://bugzilla.suse.com/show_bug.cgi?id=1243260 * https://bugzilla.suse.com/show_bug.cgi?id=1243261 * https://bugzilla.suse.com/show_bug.cgi?id=1243262 * https://bugzilla.suse.com/show_bug.cgi?id=1243263 . SUSE's latest Transfig security enhancements mitigate various vulnerabilities, notably address space misalignments and memory corruption issues.. SUSE Transfig security updates, buffer overflow fix, segmentation fault remediation, SUSE Enterprise support. . LinuxSecurity.com Team

Calendar%202 Jun 11, 2025 SuSE
202

openSUSE: 2025:01835-1 moderate: transfig buffer overflow fixes

An update that solves seven vulnerabilities and has two security fixes can now be installed.. # Security update for transfig Announcement ID: SUSE-SU-2025:01835-1 Release Date: 2025-06-09T13:24:47Z Rating: moderate References: * bsc#1225947 * bsc#1230427 * bsc#1240379 * bsc#1240380 * bsc#1240381 * bsc#1243260 * bsc#1243261 * bsc#1243262 * bsc#1243263 Cross-References: * CVE-2025-31162 * CVE-2025-31163 * CVE-2025-31164 * CVE-2025-46397 * CVE-2025-46398 * CVE-2025-46399 * CVE-2025-46400 CVSS scores: * CVE-2025-31162 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31162 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31163 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31163 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31164 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31164 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-46397 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46397 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46398 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46398 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46399 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46399 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46400 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46400 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves seven vulnerabilities and has two securityfixes can now be installed. ## Description: This update for transfig fixes the following issues: Update to fig2dev version 3.2.9a * CVE-2025-31162: Fixed a floating point exception in fig2dev in get_slope function (bsc#1240380). * CVE-2025-31163: Fixed a segmentation fault in fig2dev in put_patternarc function (bsc#1240381). * CVE-2025-31164: Fixed a heap buffer overflow in fig2dev in create_line_with_spline function (bsc#1240379). * CVE-2025-46397: Fixed a stack buffer overflow in fig2dev in bezier_spline function (bsc#1243260). * CVE-2025-46398: Fixed a stack buffer overflow in fig2dev in read_objects function (bsc#1243262). * CVE-2025-46399: Fixed a segmentation fault in fig2dev in genge_itp_spline function (bsc#1243263). * CVE-2025-46400: Fixed a segmentation fault in fig2dev in read_arcobject function (bsc#1243261). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1835=1 SUSE-2025-1835=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1835=1 * SUSE Linux Enterprise Workstation Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-1835=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * transfig-3.2.9a-150600.3.5.1 * transfig-debugsource-3.2.9a-150600.3.5.1 * transfig-debuginfo-3.2.9a-150600.3.5.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x) * transfig-3.2.9a-150600.3.5.1 * transfig-debugsource-3.2.9a-150600.3.5.1 * transfig-debuginfo-3.2.9a-150600.3.5.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64) * transfig-3.2.9a-150600.3.5.1 * transfig-debugsource-3.2.9a-150600.3.5.1 * transfig-debuginfo-3.2.9a-150600.3.5.1 ## References: *https://www.suse.com/security/cve/CVE-2025-31162.html * https://www.suse.com/security/cve/CVE-2025-31163.html * https://www.suse.com/security/cve/CVE-2025-31164.html * https://www.suse.com/security/cve/CVE-2025-46397.html * https://www.suse.com/security/cve/CVE-2025-46398.html * https://www.suse.com/security/cve/CVE-2025-46399.html * https://www.suse.com/security/cve/CVE-2025-46400.html * https://bugzilla.suse.com/show_bug.cgi?id=1225947 * https://bugzilla.suse.com/show_bug.cgi?id=1230427 * https://bugzilla.suse.com/show_bug.cgi?id=1240379 * https://bugzilla.suse.com/show_bug.cgi?id=1240380 * https://bugzilla.suse.com/show_bug.cgi?id=1240381 * https://bugzilla.suse.com/show_bug.cgi?id=1243260 * https://bugzilla.suse.com/show_bug.cgi?id=1243261 * https://bugzilla.suse.com/show_bug.cgi?id=1243262 * https://bugzilla.suse.com/show_bug.cgi?id=1243263 . A recent patch for Fedora resolves seven vulnerabilities within httpd, implementing various improvements and bolstering system integrity.. openSUSE updates, transfig security, software vulnerabilities, Linux patch management. . LinuxSecurity.com Team

Calendar%202 Jun 09, 2025 OpenSUSE
100

SUSE: 2025:01835-1 moderate: transfig buffer overflow fixes and more

* bsc#1225947 * bsc#1230427 * bsc#1240379 * bsc#1240380 * bsc#1240381 . # Security update for transfig Announcement ID: SUSE-SU-2025:01835-1 Release Date: 2025-06-09T13:24:47Z Rating: moderate References: * bsc#1225947 * bsc#1230427 * bsc#1240379 * bsc#1240380 * bsc#1240381 * bsc#1243260 * bsc#1243261 * bsc#1243262 * bsc#1243263 Cross-References: * CVE-2025-31162 * CVE-2025-31163 * CVE-2025-31164 * CVE-2025-46397 * CVE-2025-46398 * CVE-2025-46399 * CVE-2025-46400 CVSS scores: * CVE-2025-31162 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31162 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31163 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31163 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31164 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-31164 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-46397 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46397 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46398 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46398 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46399 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46399 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46400 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-46400 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves seven vulnerabilities and has two security fixes can now beinstalled. ## Description: This update for transfig fixes the following issues: Update to fig2dev version 3.2.9a * CVE-2025-31162: Fixed a floating point exception in fig2dev in get_slope function (bsc#1240380). * CVE-2025-31163: Fixed a segmentation fault in fig2dev in put_patternarc function (bsc#1240381). * CVE-2025-31164: Fixed a heap buffer overflow in fig2dev in create_line_with_spline function (bsc#1240379). * CVE-2025-46397: Fixed a stack buffer overflow in fig2dev in bezier_spline function (bsc#1243260). * CVE-2025-46398: Fixed a stack buffer overflow in fig2dev in read_objects function (bsc#1243262). * CVE-2025-46399: Fixed a segmentation fault in fig2dev in genge_itp_spline function (bsc#1243263). * CVE-2025-46400: Fixed a segmentation fault in fig2dev in read_arcobject function (bsc#1243261). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1835=1 SUSE-2025-1835=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1835=1 * SUSE Linux Enterprise Workstation Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-1835=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * transfig-3.2.9a-150600.3.5.1 * transfig-debugsource-3.2.9a-150600.3.5.1 * transfig-debuginfo-3.2.9a-150600.3.5.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x) * transfig-3.2.9a-150600.3.5.1 * transfig-debugsource-3.2.9a-150600.3.5.1 * transfig-debuginfo-3.2.9a-150600.3.5.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64) * transfig-3.2.9a-150600.3.5.1 * transfig-debugsource-3.2.9a-150600.3.5.1 * transfig-debuginfo-3.2.9a-150600.3.5.1 ## References: *https://www.suse.com/security/cve/CVE-2025-31162.html * https://www.suse.com/security/cve/CVE-2025-31163.html * https://www.suse.com/security/cve/CVE-2025-31164.html * https://www.suse.com/security/cve/CVE-2025-46397.html * https://www.suse.com/security/cve/CVE-2025-46398.html * https://www.suse.com/security/cve/CVE-2025-46399.html * https://www.suse.com/security/cve/CVE-2025-46400.html * https://bugzilla.suse.com/show_bug.cgi?id=1225947 * https://bugzilla.suse.com/show_bug.cgi?id=1230427 * https://bugzilla.suse.com/show_bug.cgi?id=1240379 * https://bugzilla.suse.com/show_bug.cgi?id=1240380 * https://bugzilla.suse.com/show_bug.cgi?id=1240381 * https://bugzilla.suse.com/show_bug.cgi?id=1243260 * https://bugzilla.suse.com/show_bug.cgi?id=1243261 * https://bugzilla.suse.com/show_bug.cgi?id=1243262 * https://bugzilla.suse.com/show_bug.cgi?id=1243263 . A crucial enhancement for transfig in SUSE addresses problems such as segmentation errors and buffer overflows. Please respond promptly.. SUSE Security Patch, transfig Update, Linux Security Fix, SUSE Linux Open Source. . LinuxSecurity.com Team

Calendar%202 Jun 09, 2025 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200