v7.2.0 New features Add new argument order to sort multiple inclusions. v7.1.8 Bug fixes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-cb26113de5 2025-11-25 01:34:32.166769+00:00 -------------------------------------------------------------------------------- Name : python-mkdocs-include-markdown-plugin Product : Fedora 42 Version : 7.2.0 Release : 1.fc42 URL : https://github.com/mondeja/mkdocs-include-markdown-plugin Summary : Mkdocs Markdown includer plugin Description : This package provides an Mkdocs Markdown includer plugin. -------------------------------------------------------------------------------- Update Information: v7.2.0 New features Add new argument order to sort multiple inclusions. v7.1.8 Bug fixes Escape substitution placeholders to prevent malformed output in edge cases. (CVE-2025-59940) -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 24 2025 Michel Lind - 7.2.0-1 - Update to 7.2.0 - Resolves: rhbz#2344045 - 7.1.8 fixes CVE-2025-59940; Resolves: rhbz#2400521 * Fri Sep 19 2025 Python Maint - 7.1.2-6 - Rebuilt for Python 3.14.0rc3 bytecode * Fri Aug 15 2025 Python Maint - 7.1.2-5 - Rebuilt for Python 3.14.0rc2 bytecode * Fri Jul 25 2025 Fedora Release Engineering - 7.1.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Tue Jun 3 2025 Python Maint - 7.1.2-3 - Rebuilt for Python 3.14 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2400372 - CVE-2025-59940 mkdocs-include-markdown-plugin: mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders https://bugzilla.redhat.com/show_bug.cgi?id=2400372 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su-c 'dnf upgrade --advisory FEDORA-2025-cb26113de5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
v7.2.0 New features Add new argument order to sort multiple inclusions. v7.1.8 Bug fixes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1b1bb708af 2025-11-25 01:06:48.342007+00:00 -------------------------------------------------------------------------------- Name : python-mkdocs-include-markdown-plugin Product : Fedora 43 Version : 7.2.0 Release : 1.fc43 URL : https://github.com/mondeja/mkdocs-include-markdown-plugin Summary : Mkdocs Markdown includer plugin Description : This package provides an Mkdocs Markdown includer plugin. -------------------------------------------------------------------------------- Update Information: v7.2.0 New features Add new argument order to sort multiple inclusions. v7.1.8 Bug fixes Escape substitution placeholders to prevent malformed output in edge cases. (CVE-2025-59940) -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 24 2025 Michel Lind - 7.2.0-1 - Update to 7.2.0 - Resolves: rhbz#2344045 - 7.1.8 fixes CVE-2025-59940; Resolves: rhbz#2400521 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2400372 - CVE-2025-59940 mkdocs-include-markdown-plugin: mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders https://bugzilla.redhat.com/show_bug.cgi?id=2400372 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1b1bb708af' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1241691 Cross-References: * CVE-2025-2761 . # Security update for gimp Announcement ID: SUSE-SU-2025:1571-1 Release Date: 2025-05-16T13:49:04Z Rating: moderate References: * bsc#1241691 Cross-References: * CVE-2025-2761 CVSS scores: * CVE-2025-2761 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2025-2761 ( NVD ): 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for gimp fixes the following issues: * CVE-2025-2761: unvalidated user input in FLI file parsing may lead to an out-of-bounds write (bsc#1241691). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1571=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1571=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1571=1 * SUSE Linux Enterprise Workstation Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-1571=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libgimpui-2_0-0-2.10.30-150400.3.14.1 * gimp-devel-2.10.30-150400.3.14.1 * gimp-2.10.30-150400.3.14.1 * libgimp-2_0-0-2.10.30-150400.3.14.1 * gimp-plugin-aa-2.10.30-150400.3.14.1 * gimp-plugin-aa-debuginfo-2.10.30-150400.3.14.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.14.1 * gimp-debuginfo-2.10.30-150400.3.14.1 *libgimp-2_0-0-debuginfo-2.10.30-150400.3.14.1 * gimp-debugsource-2.10.30-150400.3.14.1 * gimp-devel-debuginfo-2.10.30-150400.3.14.1 * openSUSE Leap 15.4 (noarch) * gimp-lang-2.10.30-150400.3.14.1 * openSUSE Leap 15.4 (x86_64) * libgimp-2_0-0-32bit-2.10.30-150400.3.14.1 * libgimpui-2_0-0-32bit-debuginfo-2.10.30-150400.3.14.1 * libgimpui-2_0-0-32bit-2.10.30-150400.3.14.1 * libgimp-2_0-0-32bit-debuginfo-2.10.30-150400.3.14.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgimp-2_0-0-64bit-debuginfo-2.10.30-150400.3.14.1 * libgimpui-2_0-0-64bit-2.10.30-150400.3.14.1 * libgimp-2_0-0-64bit-2.10.30-150400.3.14.1 * libgimpui-2_0-0-64bit-debuginfo-2.10.30-150400.3.14.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libgimpui-2_0-0-2.10.30-150400.3.14.1 * gimp-devel-2.10.30-150400.3.14.1 * gimp-2.10.30-150400.3.14.1 * libgimp-2_0-0-2.10.30-150400.3.14.1 * gimp-plugin-aa-2.10.30-150400.3.14.1 * gimp-plugin-aa-debuginfo-2.10.30-150400.3.14.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.14.1 * gimp-debuginfo-2.10.30-150400.3.14.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.14.1 * gimp-debugsource-2.10.30-150400.3.14.1 * gimp-devel-debuginfo-2.10.30-150400.3.14.1 * openSUSE Leap 15.6 (noarch) * gimp-lang-2.10.30-150400.3.14.1 * openSUSE Leap 15.6 (x86_64) * libgimp-2_0-0-32bit-2.10.30-150400.3.14.1 * libgimpui-2_0-0-32bit-debuginfo-2.10.30-150400.3.14.1 * libgimpui-2_0-0-32bit-2.10.30-150400.3.14.1 * libgimp-2_0-0-32bit-debuginfo-2.10.30-150400.3.14.1 * SUSE Package Hub 15 15-SP6 (aarch64) * gimp-devel-2.10.30-150400.3.14.1 * gimp-2.10.30-150400.3.14.1 * gimp-plugin-aa-2.10.30-150400.3.14.1 * gimp-plugin-aa-debuginfo-2.10.30-150400.3.14.1 * gimp-devel-debuginfo-2.10.30-150400.3.14.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x) * gimp-debuginfo-2.10.30-150400.3.14.1 * libgimpui-2_0-0-2.10.30-150400.3.14.1 * libgimp-2_0-0-2.10.30-150400.3.14.1 *libgimpui-2_0-0-debuginfo-2.10.30-150400.3.14.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.14.1 * gimp-debugsource-2.10.30-150400.3.14.1 * SUSE Package Hub 15 15-SP6 (noarch) * gimp-lang-2.10.30-150400.3.14.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64) * libgimpui-2_0-0-2.10.30-150400.3.14.1 * gimp-devel-2.10.30-150400.3.14.1 * gimp-2.10.30-150400.3.14.1 * libgimp-2_0-0-2.10.30-150400.3.14.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.14.1 * gimp-debuginfo-2.10.30-150400.3.14.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.14.1 * gimp-debugsource-2.10.30-150400.3.14.1 * gimp-devel-debuginfo-2.10.30-150400.3.14.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (noarch) * gimp-lang-2.10.30-150400.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2025-2761.html * https://bugzilla.suse.com/show_bug.cgi?id=1241691 . A patch addresses the Cross-Reference vulnerability CVE-2025-2761 in gimp, fixing input validation flaws on SUSE platforms.. SUSE Update, gimp Security Fix, Cross-Reference CVE-2025-2761, SUSE Advisory. . LinuxSecurity.com Team
* bsc#1241691 Cross-References: * CVE-2025-2761 . # Security update for gimp Announcement ID: SUSE-SU-2025:1546-1 Release Date: 2025-05-13T12:37:05Z Rating: moderate References: * bsc#1241691 Cross-References: * CVE-2025-2761 CVSS scores: * CVE-2025-2761 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2025-2761 ( NVD ): 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gimp fixes the following issues: * CVE-2025-2761: unvalidated user input in FLI file parsing may lead to an out-of-bounds write (bsc#1241691). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1546=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gimp-devel-debuginfo-2.8.18-9.30.1 * gimp-devel-2.8.18-9.30.1 ## References: * https://www.suse.com/security/cve/CVE-2025-2761.html * https://bugzilla.suse.com/show_bug.cgi?id=1241691 . The latest GIMP update fixes a moderate severity vulnerability linked to unchecked user input. Check the official release notes for full details and the patch.. SUSE Update, GIMP Security Fix, Moderate Severity Risk. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.