An update that solves one vulnerability can now be installed.. # liblxc-devel-7.0.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:10678-1 Rating: moderate Cross-References: * CVE-2026-39402 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the liblxc-devel-7.0.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * liblxc-devel 7.0.0-1.1 * liblxc1 7.0.0-1.1 * lxc 7.0.0-1.1 * lxc-bash-completion 7.0.0-1.1 * lxc-ja-doc 7.0.0-1.1 * lxc-ko-doc 7.0.0-1.1 * pam_cgfs 7.0.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39402.html . This update for openSUSE Tumbleweed delivers a moderate security fix for a vulnerability in liblxc-devel package.. openSUSE Tumbleweed security liblxc-devel update. . Severity: Medium. LinuxSecurity.com Team
* bsc#1234414 * bsc#1234417 * bsc#1234421 * bsc#1234424 * bsc#1234425 . # Security update for gstreamer-plugins-good Announcement ID: SUSE-SU-2025:0064-1 Release Date: 2025-01-10T13:48:33Z Rating: important References: * bsc#1234414 * bsc#1234417 * bsc#1234421 * bsc#1234424 * bsc#1234425 * bsc#1234426 * bsc#1234427 * bsc#1234428 * bsc#1234432 * bsc#1234433 * bsc#1234434 * bsc#1234435 * bsc#1234436 * bsc#1234439 * bsc#1234440 * bsc#1234446 * bsc#1234447 * bsc#1234449 * bsc#1234462 * bsc#1234473 * bsc#1234476 * bsc#1234477 Cross-References: * CVE-2024-47530 * CVE-2024-47537 * CVE-2024-47539 * CVE-2024-47543 * CVE-2024-47544 * CVE-2024-47545 * CVE-2024-47546 * CVE-2024-47596 * CVE-2024-47597 * CVE-2024-47598 * CVE-2024-47599 * CVE-2024-47601 * CVE-2024-47602 * CVE-2024-47603 * CVE-2024-47606 * CVE-2024-47613 * CVE-2024-47774 * CVE-2024-47775 * CVE-2024-47776 * CVE-2024-47777 * CVE-2024-47778 * CVE-2024-47834 CVSS scores: * CVE-2024-47530 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-47530 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-47537 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47537 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47537 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47539 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47539 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47539 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47543 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-47543 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47543 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47544 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47544 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47544 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47545 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47545 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47546 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47546 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47546 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47596 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47596 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47597 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47597( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-47598 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47598 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47598 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-47599 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47599 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47599 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47601 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47601 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47601 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47602 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47602 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47603 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47603 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47603 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47606 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47606 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47606 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47613 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47613 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47613 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47774 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47774 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47774 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-47775 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47775 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47775 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-47776 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47776 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47776 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-47777 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47777 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47777 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-47778 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47778 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47778 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47834 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47834 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for gstreamer-plugins-good fixes the following issues: * CVE-2024-47530: Fixed an uninitialized stack memory in Matroska/WebM demuxer. (boo#1234421) * CVE-2024-47537: Fixed an out-of-bounds write in isomp4/qtdemux.c. (boo#1234414) * CVE-2024-47539: Fixed an out-of-bounds write in convert_to_s334_1a. (boo#1234417) * CVE-2024-47543: Fixed an out-of-bounds write in qtdemux_parse_container. (boo#1234462) * CVE-2024-47544: Fixed a NULL-pointer dereferences in MP4/MOV demuxer CENC handling. (boo#1234473) * CVE-2024-47545: Fixed an integer underflow in FOURCC_strf parsing leading to out-of-bounds read. (boo#1234476) * CVE-2024-47546: Fixed an integer underflow in extract_cc_from_data leading to out-of-bounds read. (boo#1234477) * CVE-2024-47596: Fixed an integer underflow in MP4/MOV demuxer that can lead to out-of-bounds reads. (boo#1234424) * CVE-2024-47597: Fixed an out-of-bounds reads in MP4/MOV demuxer sample table parser (boo#1234425) * CVE-2024-47598: Fixed MP4/MOV sample table parser out-of-bounds read. (boo#1234426) * CVE-2024-47599: Fixed insufficient error handling in JPEG decoder that can lead to NULL-pointer dereferences. (boo#1234427) * CVE-2024-47601: Fixed a NULL-pointer dereference in Matroska/WebM demuxer. (boo#1234428) * CVE-2024-47602: Fixed a NULL-pointer dereferences and out-of-bounds reads in Matroska/WebM demuxer. (boo#1234432) * CVE-2024-47603: Fixed a NULL-pointer dereference in Matroska/WebM demuxer. (boo#1234433) * CVE-2024-47606: Avoid integer overflow when allocating sysmem. (bsc#1234449) * CVE-2024-47606: Fixed an integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writes. (boo#1234449) * CVE-2024-47613: Fixed a NULL-pointer dereference in gdk-pixbuf decoder. (boo#1234447) * CVE-2024-47774: Fixed an integer overflow in AVI subtitle parser that leads to out-of-bounds reads. (boo#1234446) * CVE-2024-47775: Fixed various out-of-bounds reads in WAV parser. (boo#1234434) * CVE-2024-47776: Fixed various out-of-bounds reads in WAV parser. (boo#1234435) * CVE-2024-47777: Fixed various out-of-bounds reads in WAV parser. (boo#1234436) * CVE-2024-47778: Fixed various out-of-bounds reads in WAV parser. (boo#1234439) * CVE-2024-47834: Fixed a use-after-free in the Matroska demuxer that can cause crashes for certain input files. (boo#1234440) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-64=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -tpatch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-64=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-64=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-64=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-64=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * gstreamer-plugins-good-1.22.0-150500.4.6.1 * gstreamer-plugins-good-extra-1.22.0-150500.4.6.1 * gstreamer-plugins-good-gtk-1.22.0-150500.4.6.1 * gstreamer-plugins-good-qtqml-1.22.0-150500.4.6.1 * gstreamer-plugins-good-jack-debuginfo-1.22.0-150500.4.6.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.6.1 * gstreamer-plugins-good-extra-debuginfo-1.22.0-150500.4.6.1 * gstreamer-plugins-good-debugsource-1.22.0-150500.4.6.1 * gstreamer-plugins-good-gtk-debuginfo-1.22.0-150500.4.6.1 * gstreamer-plugins-good-jack-1.22.0-150500.4.6.1 * gstreamer-plugins-good-qtqml-debuginfo-1.22.0-150500.4.6.1 * openSUSE Leap 15.5 (x86_64) * gstreamer-plugins-good-extra-32bit-debuginfo-1.22.0-150500.4.6.1 * gstreamer-plugins-good-jack-32bit-debuginfo-1.22.0-150500.4.6.1 * gstreamer-plugins-good-32bit-1.22.0-150500.4.6.1 * gstreamer-plugins-good-jack-32bit-1.22.0-150500.4.6.1 * gstreamer-plugins-good-extra-32bit-1.22.0-150500.4.6.1 * gstreamer-plugins-good-32bit-debuginfo-1.22.0-150500.4.6.1 * openSUSE Leap 15.5 (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.6.1 * openSUSE Leap 15.5 (aarch64_ilp32) * gstreamer-plugins-good-jack-64bit-1.22.0-150500.4.6.1 * gstreamer-plugins-good-extra-64bit-1.22.0-150500.4.6.1 * gstreamer-plugins-good-extra-64bit-debuginfo-1.22.0-150500.4.6.1 * gstreamer-plugins-good-jack-64bit-debuginfo-1.22.0-150500.4.6.1 * gstreamer-plugins-good-64bit-debuginfo-1.22.0-150500.4.6.1 *gstreamer-plugins-good-64bit-1.22.0-150500.4.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * gstreamer-plugins-good-1.22.0-150500.4.6.1 * gstreamer-plugins-good-debugsource-1.22.0-150500.4.6.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * gstreamer-plugins-good-1.22.0-150500.4.6.1 * gstreamer-plugins-good-debugsource-1.22.0-150500.4.6.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-good-1.22.0-150500.4.6.1 * gstreamer-plugins-good-debugsource-1.22.0-150500.4.6.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * gstreamer-plugins-good-1.22.0-150500.4.6.1 * gstreamer-plugins-good-debugsource-1.22.0-150500.4.6.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2024-47530.html * https://www.suse.com/security/cve/CVE-2024-47537.html * https://www.suse.com/security/cve/CVE-2024-47539.html * https://www.suse.com/security/cve/CVE-2024-47543.html * https://www.suse.com/security/cve/CVE-2024-47544.html * https://www.suse.com/security/cve/CVE-2024-47545.html * https://www.suse.com/security/cve/CVE-2024-47546.html * https://www.suse.com/security/cve/CVE-2024-47596.html *https://www.suse.com/security/cve/CVE-2024-47597.html * https://www.suse.com/security/cve/CVE-2024-47598.html * https://www.suse.com/security/cve/CVE-2024-47599.html * https://www.suse.com/security/cve/CVE-2024-47601.html * https://www.suse.com/security/cve/CVE-2024-47602.html * https://www.suse.com/security/cve/CVE-2024-47603.html * https://www.suse.com/security/cve/CVE-2024-47606.html * https://www.suse.com/security/cve/CVE-2024-47613.html * https://www.suse.com/security/cve/CVE-2024-47774.html * https://www.suse.com/security/cve/CVE-2024-47775.html * https://www.suse.com/security/cve/CVE-2024-47776.html * https://www.suse.com/security/cve/CVE-2024-47777.html * https://www.suse.com/security/cve/CVE-2024-47778.html * https://www.suse.com/security/cve/CVE-2024-47834.html * https://bugzilla.suse.com/show_bug.cgi?id=1234414 * https://bugzilla.suse.com/show_bug.cgi?id=1234417 * https://bugzilla.suse.com/show_bug.cgi?id=1234421 * https://bugzilla.suse.com/show_bug.cgi?id=1234424 * https://bugzilla.suse.com/show_bug.cgi?id=1234425 * https://bugzilla.suse.com/show_bug.cgi?id=1234426 * https://bugzilla.suse.com/show_bug.cgi?id=1234427 * https://bugzilla.suse.com/show_bug.cgi?id=1234428 * https://bugzilla.suse.com/show_bug.cgi?id=1234432 * https://bugzilla.suse.com/show_bug.cgi?id=1234433 * https://bugzilla.suse.com/show_bug.cgi?id=1234434 * https://bugzilla.suse.com/show_bug.cgi?id=1234435 * https://bugzilla.suse.com/show_bug.cgi?id=1234436 * https://bugzilla.suse.com/show_bug.cgi?id=1234439 * https://bugzilla.suse.com/show_bug.cgi?id=1234440 * https://bugzilla.suse.com/show_bug.cgi?id=1234446 * https://bugzilla.suse.com/show_bug.cgi?id=1234447 * https://bugzilla.suse.com/show_bug.cgi?id=1234449 * https://bugzilla.suse.com/show_bug.cgi?id=1234462 * https://bugzilla.suse.com/show_bug.cgi?id=1234473 * https://bugzilla.suse.com/show_bug.cgi?id=1234476 * https://bugzilla.suse.com/show_bug.cgi?id=1234477 . A significant patch for gstreamer-plugins-goodon SUSE platforms, targeting critical security flaws and providing necessary remedies.. gstreamer-plugins-good update, SUSE Linux security, software vulnerabilities, security update announcement. . Severity: Important. LinuxSecurity.com Team
Update to new upstream version (closes rhbz#2303131). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-5aad2fda6a 2024-09-26 02:43:43.727628 -------------------------------------------------------------------------------- Name : chisel Product : Fedora 40 Version : 1.10.0 Release : 1.fc40 URL : https://github.com/jpillora/chisel Summary : TCP tunnel over HTTP Description : A fast TCP tunnel over HTTP. -------------------------------------------------------------------------------- Update Information: Update to new upstream version (closes rhbz#2303131) -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 17 2024 Fabian Affolter - 1.10.0-1 - Update to new upstream version (closes rhbz#2303131) - Set version (closes rhbz#2265825) - Fix CVE-2024-43798 (closes rhbz#2308435, closes rhbz#2308436) * Wed Jul 17 2024 Fedora Release Engineering - 1.9.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2265825 - Version is 0.0.0-src https://bugzilla.redhat.com/show_bug.cgi?id=2265825 [ 2 ] Bug #2303131 - chisel-1.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2303131 [ 3 ] Bug #2308435 - CVE-2024-43798 chisel: From NVD collector [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2308435 [ 4 ] Bug #2308436 - CVE-2024-43798 chisel: From NVD collector [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2308436 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-5aad2fda6a' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves two vulnerabilities and has two fixes is now available. . SUSE Security Update: Security update for python3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0529-1 Rating: moderate References: #1176262 #1179756 #1180686 #1181126 Cross-References: CVE-2019-20916 CVE-2021-3177 CVSS scores: CVE-2019-20916 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2019-20916 (SUSE): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N CVE-2021-3177 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-3177 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Module for Development Tools 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that solves two vulnerabilities and has two fixes is now available. Description: This update for python3 fixes the following issues: - CVE-2021-3177: Fixed buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution (bsc#1181126). - Provide the newest setuptools wheel (bsc#1176262, CVE-2019-20916) in their correct form (bsc#1180686). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Development Tools 15-SP2: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP2-2021-529=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-529=1 Package List: - SUSE Linux Enterprise Module for Development Tools 15-SP2 (aarch64 ppc64le s390x x86_64): python3-tools-3.6.12-3.75.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): libpython3_6m1_0-3.6.12-3.75.1 libpython3_6m1_0-debuginfo-3.6.12-3.75.1 python3-3.6.12-3.75.1 python3-base-3.6.12-3.75.1 python3-curses-3.6.12-3.75.1 python3-curses-debuginfo-3.6.12-3.75.1 python3-dbm-3.6.12-3.75.1 python3-dbm-debuginfo-3.6.12-3.75.1 python3-debuginfo-3.6.12-3.75.1 python3-debugsource-3.6.12-3.75.1 python3-devel-3.6.12-3.75.1 python3-devel-debuginfo-3.6.12-3.75.1 python3-idle-3.6.12-3.75.1 python3-tk-3.6.12-3.75.1 python3-tk-debuginfo-3.6.12-3.75.1 References: https://www.suse.com/security/cve/CVE-2019-20916.html https://www.suse.com/security/cve/CVE-2021-3177.html https://bugzilla.suse.com/1176262 https://bugzilla.suse.com/1179756 https://bugzilla.suse.com/1180686 https://bugzilla.suse.com/1181126 . New python3 patch released on SUSE to remedy multiple vulnerabilities, focusing on mitigating security threats and improving overall system reliability.. SUSE Security Update, Python3 Fix, System Vulnerability, Software Integrity. . LinuxSecurity.com Team
An update for dnsmasq is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: dnsmasq security update Advisory ID: RHSA-2021:0245-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:0245 Issue date: 2021-01-25 CVE Names: CVE-2020-25684 CVE-2020-25685 CVE-2020-25686 ==================================================================== 1. Summary: An update for dnsmasq is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.3) - x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.3) - x86_64 3. Description: The dnsmasq packages contain Dnsmasq, a lightweight DNS (Domain Name Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server. Security Fix(es): * dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker (CVE-2020-25684) * dnsmasq: loose query name check in reply_query() makes forging replies easier for an off-path attacker (CVE-2020-25685) * dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker (CVE-2020-25686) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in theReferences section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1889686 - CVE-2020-25684 dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker 1889688 - CVE-2020-25685 dnsmasq: loose query name check in reply_query() makes forging replies easier for an off-path attacker 1890125 - CVE-2020-25686 dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.3): Source: dnsmasq-2.66-21.el7_3.3.src.rpm x86_64: dnsmasq-2.66-21.el7_3.3.x86_64.rpm dnsmasq-debuginfo-2.66-21.el7_3.3.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.3): x86_64: dnsmasq-debuginfo-2.66-21.el7_3.3.x86_64.rpm dnsmasq-utils-2.66-21.el7_3.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-25684 https://access.redhat.com/security/cve/CVE-2020-25685 https://access.redhat.com/security/cve/CVE-2020-25686 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2021-001 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYA7f0tzjgjWX9erEAQhkVw//TiQCCQm8LxTdmLfbxkLw/vUMz27NlHGS iTAjLLCeXb4R8KEDNk8jsOJuNMwyxc4xZufGM/9IppuEzp7+kashJ3PUKcD4T/V6 RhEijXJd158qy5JbTRZOANjs7bU5D1C47vI09vKNVQm3rq0sR2QVYWgYKfjab5oJ /MxqYbnKaJG01xhbWPURLSxHqWVyOdadvyZBO6a0yY/i4b9RjDQ4Y7hNYSK7SHOK kxkxFiAaqCIIt1MYE12PUVJZ7vXNLBoanYUkT5tEIFh6gh1piOp4dPVAGsAB+wlF whbqchwD575RuTTiB1vOZBYWnXU8iAlLfqTHFQtPzX0cyFBFgyZE3QpQVnxbVO2L 2JxnBp+KTn1Ztw1wsW+QhW+5XfalC8mwsNkw7//fW++r345CVczl7vBxyNof/tt6 btSu8tI+Nuc7RZhlNYt8SLysgarr8ai7zPgv/Xp2nCf0JF3tGRxPbDlr+MONLrv4 DngN6BaAcbKiieO3DL1tEhhTmyxZ31G2e32C8PRrcqgQPvTncvJhRIV5jHXpOhLG j80OMEdgJtXers7TQRKIdvC/bn119KpfA1cu+yWuS4Xiz1bYFmtWU+k38TCRYnFE 9MRVWSBxIWoS4sDX62E+3mtZtU12BtxWtPBU84U9uC+mD1CiCdIRsw9Z6STKWkYG wFdDuJ0J6QU=56a7 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Updated ImageMagick packages that fix several security issues . Date: Thu, 24 Aug 2006 15:50:16 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for "ImageMagick" on SL 40,41,42,43 i386,x86_64 now available Comments: To:
Get the latest Linux and open source security news straight to your inbox.