openSUSE Tumbleweed — lilypond — multiple vulnerabilities (2 CVEs) — patch and remediation guide
🔴 Critical ⏱ 15–90 min Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read • Source: SUSE advisory openSUSE-SU-2020:1453-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-17353 CVE-2018-10992 Upstream summary: scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated […]