Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
100

SUSE: 2020:4371-1 Critical: Linux Kernel Live Patch Security Fix

An update that fixes 5 vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 0 for SLE 12 SP4) ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:3252-1 Rating: important References: #1153108 #1156320 #1156321 #1156331 #1156334 Cross-References: CVE-2018-16871 CVE-2018-20856 CVE-2019-10220 CVE-2019-13272 CVE-2019-15917 Affected Products: SUSE Linux Enterprise Live Patching 12-SP4 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for the Linux Kernel 4.12.14-94_41 fixes several issues. The following security issues were fixed: - CVE-2019-15917: Fixed a use-after-free when hci_uart_register_dev() fails in hci_uart_set_proto() (bsc#1156334). - CVE-2018-20856: Fixed a use-after-free in block/blk-core.c due to improper error handling (bsc#1156331). - CVE-2019-13272: Fixed a privilege escalation from user to root due to improper handling of credentials by leveraging certain scenarios with a parent-child process relationship (bsc#1156321). - CVE-2018-16871: Fixed an issue where an attacker, who could mount an exported NFS filesystem, was able to trigger a null pointer dereference by using an invalid NFS sequence leading to kernel panic and deny of access to the NFS server (bsc#1156320). - CVE-2019-10220: Fixed an issue where samba servers could inject relative paths in directory entry lists (bsc#1153108). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12-SP4: zypper in -t patch SUSE-SLE-Live-Patching-12-SP4-2019-3252=1SUSE-SLE-Live-Patching-12-SP4-2019-3253=1 Package List: - SUSE Linux Enterprise Live Patching 12-SP4 (ppc64le x86_64): kgraft-patch-4_12_14-94_41-default-9-2.25.1 kgraft-patch-4_12_14-94_41-default-debuginfo-9-2.25.1 kgraft-patch-4_12_14-95_3-default-8-2.5 kgraft-patch-SLE12-SP4_Update_0-debugsource-9-2.25.1 References: https://www.suse.com/security/cve/CVE-2018-16871.html https://www.suse.com/security/cve/CVE-2018-20856.html https://www.suse.com/security/cve/CVE-2019-10220.html https://www.suse.com/security/cve/CVE-2019-13272.html https://www.suse.com/security/cve/CVE-2019-15917.html https://bugzilla.suse.com/1153108 https://bugzilla.suse.com/1156320 https://bugzilla.suse.com/1156321 https://bugzilla.suse.com/1156331 https://bugzilla.suse.com/1156334 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . Crucial SUSE Security Patch addressing multiple vulnerabilities in Linux Kernel Live Patch 0 for SLE 12 SP4 deployment.. SUSE Security Update, Linux Kernel Patch, Privilege Escalation, Live Patching. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 11, 2019 Important SuSE
200

Scientific Linux: Critical Update For Firefox Security Flaws

Critical: firefox security update. Date: Fri, 10 Dec 2010 16:14:21 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Critical: firefox on SL4.x, SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Critical: firefox security update Issue date: 2010-12-09 CVE Names: CVE-2010-3766 CVE-2010-3767 CVE-2010-3768 CVE-2010-3770 CVE-2010-3771 CVE-2010-3772 CVE-2010-3773 CVE-2010-3774 CVE-2010-3775 CVE-2010-3776 CVE-2010-3777 Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2010-3766, CVE-2010-3767, CVE-2010-3772, CVE-2010-3776, CVE-2010-3777) A flaw was found in the way Firefox handled malformed JavaScript. A website with an object containing malicious JavaScript could cause Firefox to execute that JavaScript with the privileges of the user running Firefox. (CVE-2010-3771) This update adds support for the Sanitiser for OpenType (OTS) library to Firefox. This library helps prevent potential exploits in malformed OpenType fonts by verifying the font file prior to use. (CVE-2010-3768) A flaw was found in the way Firefox loaded Java LiveConnect scripts. Malicious web content could load a Java LiveConnect script in a way that would result in the plug-in object having elevated privileges, allowing it to execute Java code with the privileges of the user running Firefox. (CVE-2010-3775) It was found that the fix for CVE-2010-0179 was incomplete when the Firebug add-on was used. If a user visited a website containing malicious JavaScript while the Firebug add-on was enabled, it could cause Firefox to execute arbitrary JavaScript with the privileges of the user running Firefox. (CVE-2010-3773) A flaw was found in the way Firefox presented the location bar to users. A malicious website could trick a user into thinking they are visiting thesite reported by the location bar, when the page is actually content controlled by an attacker. (CVE-2010-3774) A cross-site scripting (XSS) flaw was found in the Firefox x-mac-arabic, x-mac-farsi, and x-mac-hebrew character encodings. Certain characters were converted to angle brackets when displayed. If server-side script filtering missed these cases, it could result in Firefox executing JavaScript code with the permissions of a different website. (CVE-2010-3770) After installing the update, Firefox must be restarted for the changes to take effect. SL 4.x SRPMS: firefox-3.6.13-3.el4.src.rpm i386: firefox-3.6.13-3.el4.i386.rpm x86_64: firefox-3.6.13-3.el4.i386.rpm firefox-3.6.13-3.el4.x86_64.rpm SL 5.x SRPMS: firefox-3.6.13-2.el5.src.rpm xulrunner-1.9.2.13-3.el5.src.rpm i386: firefox-3.6.13-2.el5.i386.rpm xulrunner-1.9.2.13-3.el5.i386.rpm xulrunner-devel-1.9.2.13-3.el5.i386.rpm x86_64: firefox-3.6.13-2.el5.i386.rpm firefox-3.6.13-2.el5.x86_64.rpm xulrunner-1.9.2.13-3.el5.i386.rpm xulrunner-1.9.2.13-3.el5.x86_64.rpm xulrunner-devel-1.9.2.13-3.el5.i386.rpm xulrunner-devel-1.9.2.13-3.el5.x86_64.rpm -Connie Sieh -Troy Dawson . Crucial Firefox patch resolves major vulnerabilities that allow code execution and access restrictions in CentOS.. firefox security, Scientific Linux, critical updates, access denial issues, code execution vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 10, 2010 Critical Scientific Linux
200

Scientific Linux: SL5.x Low Severity Selinux Policy Bug Fix Update

Low: selinux-policy bug fix update. Date: Wed, 14 Oct 2009 16:15:51 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Low: selinux-policy on SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Low: selinux-policy bug fix update Issue date: 2009-09-02 These updated packages resolve several bugs in Security-Enhanced Linux (SELinux) policy as shipped with Scientific Linux 5. The majority of these bugs resulted in SELinux denying legitimate access. The most prominent error came when tzdata was updated. SL 5.x SRPMS: selinux-policy-2.4.6-255.el5_4.1.src.rpm i386: libselinux-1.33.4-5.5.el5.i386.rpm libselinux-devel-1.33.4-5.5.el5.i386.rpm libselinux-python-1.33.4-5.5.el5.i386.rpm libselinux-ruby-1.33.4-5.5.el5.i386.rpm libselinux-utils-1.33.4-5.5.el5.i386.rpm libsemanage-1.9.1-4.4.el5.i386.rpm libsemanage-devel-1.9.1-4.4.el5.i386.rpm libsepol-1.15.2-2.el5.i386.rpm libsepol-devel-1.15.2-2.el5.i386.rpm policycoreutils-1.33.12-14.6.el5.i386.rpm policycoreutils-gui-1.33.12-14.6.el5.i386.rpm policycoreutils-newrole-1.33.12-14.6.el5.i386.rpm selinux-policy-2.4.6-255.el5_4.1.noarch.rpm selinux-policy-devel-2.4.6-255.el5_4.1.noarch.rpm selinux-policy-minimum-2.4.6-255.el5_4.1.noarch.rpm selinux-policy-mls-2.4.6-255.el5_4.1.noarch.rpm selinux-policy-strict-2.4.6-255.el5_4.1.noarch.rpm selinux-policy-targeted-2.4.6-255.el5_4.1.noarch.rpm x86_64: libselinux-1.33.4-5.5.el5.i386.rpm libselinux-1.33.4-5.5.el5.x86_64.rpm libselinux-devel-1.33.4-5.5.el5.i386.rpm libselinux-devel-1.33.4-5.5.el5.x86_64.rpm libselinux-python-1.33.4-5.5.el5.x86_64.rpm libselinux-ruby-1.33.4-5.5.el5.x86_64.rpm libselinux-utils-1.33.4-5.5.el5.x86_64.rpm libsemanage-1.9.1-4.4.el5.x86_64.rpm libsemanage-devel-1.9.1-4.4.el5.i386.rpm libsemanage-devel-1.9.1-4.4.el5.x86_64.rpm libsepol-1.15.2-2.el5.i386.rpm libsepol-1.15.2-2.el5.x86_64.rpm libsepol-devel-1.15.2-2.el5.i386.rpm libsepol-devel-1.15.2-2.el5.x86_64.rpm policycoreutils-1.33.12-14.6.el5.x86_64.rpm policycoreutils-gui-1.33.12-14.6.el5.x86_64.rpm policycoreutils-newrole-1.33.12-14.6.el5.x86_64.rpm selinux-policy-2.4.6-255.el5_4.1.noarch.rpm selinux-policy-devel-2.4.6-255.el5_4.1.noarch.rpm selinux-policy-minimum-2.4.6-255.el5_4.1.noarch.rpm selinux-policy-mls-2.4.6-255.el5_4.1.noarch.rpm selinux-policy-strict-2.4.6-255.el5_4.1.noarch.rpm selinux-policy-targeted-2.4.6-255.el5_4.1.noarch.rpm -Connie Sieh -Troy Dawson . Kernel security enhancement patch for CentOS addresses permission conflicts. Essential information for execution enclosed.. selinux-policy, bug fix update, Scientific Linux errata, access control. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Oct 14, 2009 Low Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here