Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20963-1

Опубликовано: 12 июн. 2026
Источник: suse-cvrf

Описание

Security update for neonmodem

This update for neonmodem fixes the following issues:

Changes in neonmodem:

  • Update golang.org/x/net dependency to v0.55.0 due to bsc#1267193

  • Update golang.org/x/image dependency to v0.38.0 due to bsc#1260727

  • Update golang.org/x/term dependency to v0.42.0 due to bsc#1260727

  • Update to version 1.0.7+git0.346d1d3:

    • Update dependencies, remove debug output
    • Update GitHub actions
    • discourse: APi fixes
    • Bump golang.org/x/net from 0.36.0 to 0.38.0
    • Bump golang.org/x/net from 0.34.0 to 0.36.0
    • Update dependencies
    • Change chat button
  • Add build option for position-independent executables

Список пакетов

openSUSE Leap 16.0
neonmodem-1.0.7+git0.346d1d3-bp160.1.1

Описание

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.


Затронутые продукты
openSUSE Leap 16.0:neonmodem-1.0.7+git0.346d1d3-bp160.1.1

Ссылки

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.


Затронутые продукты
openSUSE Leap 16.0:neonmodem-1.0.7+git0.346d1d3-bp160.1.1

Ссылки

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.


Затронутые продукты
openSUSE Leap 16.0:neonmodem-1.0.7+git0.346d1d3-bp160.1.1

Ссылки

Описание

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.


Затронутые продукты
openSUSE Leap 16.0:neonmodem-1.0.7+git0.346d1d3-bp160.1.1

Ссылки

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.


Затронутые продукты
openSUSE Leap 16.0:neonmodem-1.0.7+git0.346d1d3-bp160.1.1

Ссылки

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.


Затронутые продукты
openSUSE Leap 16.0:neonmodem-1.0.7+git0.346d1d3-bp160.1.1

Ссылки