Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
100

SUSE 15 SP6: 2024:4084-1 important: WebKit2GTK3 address spoofing

* bsc#1231039 * bsc#1232747 Cross-References: * CVE-2024-40866 . # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2024:4084-1 Release Date: 2024-11-27T14:36:51Z Rating: important References: * bsc#1231039 * bsc#1232747 Cross-References: * CVE-2024-40866 * CVE-2024-44185 * CVE-2024-44187 * CVE-2024-44244 * CVE-2024-44296 CVSS scores: * CVE-2024-40866 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2024-40866 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2024-44185 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-44185 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-44185 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-44185 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-44187 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2024-44187 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2024-44244 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-44244 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-44244 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2024-44296 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-44296 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-44296 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-44296 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP6 * Desktop Applications Module 15-SP6 * Development Tools Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves five vulnerabilities can now be installed. ##Description: This update for webkit2gtk3 fixes the following issues: Update to version 2.46.3 (bsc#1232747): * CVE-2024-44244: Processing maliciously crafted web content may lead to an unexpected process crash. * CVE-2024-44296: Processing maliciously crafted web content may prevent Content Security Policy from being enforced. * CVE-2024-40866: Visiting a malicious website may lead to address bar spoofing. New references to version 2.46.0 (boo#1231039): * CVE-2024-44187: A cross- origin issue existed with “iframe” elements. This was addressed with improved tracking of security origins. * CVE-2024-44185: Processing maliciously crafted web content may lead to an unexpected process crash. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-4084=1 openSUSE-SLE-15.6-2024-4084=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-4084=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2024-4084=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2024-4084=1 ## Package List: * openSUSE Leap 15.6 (noarch) * WebKitGTK-4.1-lang-2.46.3-150600.12.16.1 * WebKitGTK-6.0-lang-2.46.3-150600.12.16.1 * WebKitGTK-4.0-lang-2.46.3-150600.12.16.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libwebkitgtk-6_0-4-2.46.3-150600.12.16.1 * webkit2gtk3-soup2-debugsource-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_0-18-2.46.3-150600.12.16.1 * webkit2gtk4-devel-2.46.3-150600.12.16.1 * webkit-jsc-4.1-2.46.3-150600.12.16.1 * webkit2gtk3-soup2-minibrowser-debuginfo-2.46.3-150600.12.16.1 * libwebkit2gtk-4_1-0-2.46.3-150600.12.16.1 *webkitgtk-6_0-injected-bundles-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_1-0-2.46.3-150600.12.16.1 * webkit2gtk4-minibrowser-2.46.3-150600.12.16.1 * webkit2gtk-4_1-injected-bundles-2.46.3-150600.12.16.1 * typelib-1_0-JavaScriptCore-4_1-2.46.3-150600.12.16.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.46.3-150600.12.16.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.3-150600.12.16.1 * typelib-1_0-WebKit2WebExtension-4_0-2.46.3-150600.12.16.1 * typelib-1_0-WebKit2WebExtension-4_1-2.46.3-150600.12.16.1 * webkit-jsc-4-2.46.3-150600.12.16.1 * webkit2gtk-4_0-injected-bundles-2.46.3-150600.12.16.1 * typelib-1_0-JavaScriptCore-4_0-2.46.3-150600.12.16.1 * webkit-jsc-4.1-debuginfo-2.46.3-150600.12.16.1 * webkit2gtk3-soup2-devel-2.46.3-150600.12.16.1 * webkit2gtk3-minibrowser-2.46.3-150600.12.16.1 * webkit2gtk4-minibrowser-debuginfo-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.46.3-150600.12.16.1 * libwebkitgtk-6_0-4-debuginfo-2.46.3-150600.12.16.1 * webkit-jsc-4-debuginfo-2.46.3-150600.12.16.1 * webkit2gtk3-soup2-minibrowser-2.46.3-150600.12.16.1 * typelib-1_0-JavaScriptCore-6_0-2.46.3-150600.12.16.1 * libwebkit2gtk-4_1-0-debuginfo-2.46.3-150600.12.16.1 * typelib-1_0-WebKit2-4_1-2.46.3-150600.12.16.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.46.3-150600.12.16.1 * webkit2gtk3-debugsource-2.46.3-150600.12.16.1 * webkit-jsc-6.0-debuginfo-2.46.3-150600.12.16.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.3-150600.12.16.1 * libjavascriptcoregtk-6_0-1-2.46.3-150600.12.16.1 * webkit2gtk3-minibrowser-debuginfo-2.46.3-150600.12.16.1 * typelib-1_0-WebKit-6_0-2.46.3-150600.12.16.1 * webkit2gtk4-debugsource-2.46.3-150600.12.16.1 * webkit2gtk3-devel-2.46.3-150600.12.16.1 * typelib-1_0-WebKit2-4_0-2.46.3-150600.12.16.1 * webkit-jsc-6.0-2.46.3-150600.12.16.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.46.3-150600.12.16.1 * libwebkit2gtk-4_0-37-2.46.3-150600.12.16.1 *typelib-1_0-WebKitWebProcessExtension-6_0-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.46.3-150600.12.16.1 * openSUSE Leap 15.6 (x86_64) * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.46.3-150600.12.16.1 * libwebkit2gtk-4_1-0-32bit-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_0-18-32bit-2.46.3-150600.12.16.1 * libwebkit2gtk-4_0-37-32bit-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_1-0-32bit-2.46.3-150600.12.16.1 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.46.3-150600.12.16.1 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.46.3-150600.12.16.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_1-0-64bit-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.46.3-150600.12.16.1 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_0-18-64bit-2.46.3-150600.12.16.1 * libwebkit2gtk-4_0-37-64bit-2.46.3-150600.12.16.1 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.46.3-150600.12.16.1 * libwebkit2gtk-4_1-0-64bit-2.46.3-150600.12.16.1 * Basesystem Module 15-SP6 (noarch) * WebKitGTK-6.0-lang-2.46.3-150600.12.16.1 * WebKitGTK-4.0-lang-2.46.3-150600.12.16.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libjavascriptcoregtk-4_0-18-debuginfo-2.46.3-150600.12.16.1 * libwebkitgtk-6_0-4-2.46.3-150600.12.16.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.3-150600.12.16.1 * webkit2gtk3-soup2-debugsource-2.46.3-150600.12.16.1 * libwebkitgtk-6_0-4-debuginfo-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_0-18-2.46.3-150600.12.16.1 * libjavascriptcoregtk-6_0-1-2.46.3-150600.12.16.1 * webkit2gtk4-debugsource-2.46.3-150600.12.16.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.46.3-150600.12.16.1 * typelib-1_0-WebKit2-4_0-2.46.3-150600.12.16.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.3-150600.12.16.1 *typelib-1_0-WebKit2WebExtension-4_0-2.46.3-150600.12.16.1 * webkit2gtk-4_0-injected-bundles-2.46.3-150600.12.16.1 * libwebkit2gtk-4_0-37-2.46.3-150600.12.16.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.46.3-150600.12.16.1 * typelib-1_0-JavaScriptCore-4_0-2.46.3-150600.12.16.1 * webkit2gtk3-soup2-devel-2.46.3-150600.12.16.1 * webkitgtk-6_0-injected-bundles-2.46.3-150600.12.16.1 * Desktop Applications Module 15-SP6 (noarch) * WebKitGTK-4.1-lang-2.46.3-150600.12.16.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * webkit2gtk3-debugsource-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_1-0-2.46.3-150600.12.16.1 * webkit2gtk-4_1-injected-bundles-2.46.3-150600.12.16.1 * typelib-1_0-JavaScriptCore-4_1-2.46.3-150600.12.16.1 * libwebkit2gtk-4_1-0-debuginfo-2.46.3-150600.12.16.1 * libwebkit2gtk-4_1-0-2.46.3-150600.12.16.1 * webkit2gtk3-devel-2.46.3-150600.12.16.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.46.3-150600.12.16.1 * typelib-1_0-WebKit2-4_1-2.46.3-150600.12.16.1 * typelib-1_0-WebKit2WebExtension-4_1-2.46.3-150600.12.16.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.46.3-150600.12.16.1 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * webkit2gtk4-debugsource-2.46.3-150600.12.16.1 * typelib-1_0-JavaScriptCore-6_0-2.46.3-150600.12.16.1 * typelib-1_0-WebKit-6_0-2.46.3-150600.12.16.1 * webkit2gtk4-devel-2.46.3-150600.12.16.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.46.3-150600.12.16.1 ## References: * https://www.suse.com/security/cve/CVE-2024-40866.html * https://www.suse.com/security/cve/CVE-2024-44185.html * https://www.suse.com/security/cve/CVE-2024-44187.html * https://www.suse.com/security/cve/CVE-2024-44244.html * https://www.suse.com/security/cve/CVE-2024-44296.html * https://bugzilla.suse.com/show_bug.cgi?id=1231039 * https://bugzilla.suse.com/show_bug.cgi?id=1232747 . Urgent security notice released for webkit2gtk3 within SUSE, targeting numerousvulnerabilities linked to phishing and system crashes.. SUSE updates, webkit2gtk3 fixes, security vulnerabilities, important patches, SUSE Linux. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 27, 2024 Important SuSE
87

Debian DSA-5792-1: CVE-2024-40866 Moderate Threat in WebKitGTK

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-40866 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5792-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Alberto Garcia October 14, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : webkit2gtk CVE ID : CVE-2024-40866 CVE-2024-44187 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-40866 Hafiizh and YoKo Kho discovered that visiting a malicious website may lead to address bar spoofing. CVE-2024-44187 Narendra Bhati discovered that a malicious website may exfiltrate data cross-origin. For the stable distribution (bookworm), these problems have been fixed in version 2.46.0-2~deb12u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/webkit2gtk Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Immediate patches released for webkit2gtk addressing severe security vulnerabilities. Update without delay to prevent unauthorized data access.. Debian Security, WebKitGTK, Security Updates. . LinuxSecurity.com Team

Calendar%202 Oct 14, 2024 Debian
200

SL7 Thunderbird: SLSA-2022:6169-1 Important Fixes for Address Spoofing

This update upgrades Thunderbird to version 91.13.0. * Mozilla: Address bar spoofing via XSLT error handling (CVE-2022-38472) * Mozilla: Cross-origin XSLT Documents would have inherited the parent's permissions (CVE-2022-38473) * Mozilla: Memory safety bugs fixed in Firefox 104 and Firefox ESR 102.2 (CVE-2022-38477) * Mozilla: Memory safety bugs fixed in Firefox 104, Firefox ESR 102.2, and F [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2022:6169-1 Issue Date: 2022-08-25 CVE Numbers: CVE-2022-38472 CVE-2022-38473 CVE-2022-38476 CVE-2022-38477 CVE-2022-38478 -- This update upgrades Thunderbird to version 91.13.0. Security Fix(es): * Mozilla: Address bar spoofing via XSLT error handling (CVE-2022-38472) * Mozilla: Cross-origin XSLT Documents would have inherited the parent's permissions (CVE-2022-38473) * Mozilla: Memory safety bugs fixed in Firefox 104 and Firefox ESR 102.2 (CVE-2022-38477) * Mozilla: Memory safety bugs fixed in Firefox 104, Firefox ESR 102.2, and Firefox ESR 91.13 (CVE-2022-38478) * Mozilla: Data race and potential use-after-free in PK11_ChangePW (CVE-2022-38476) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 thunderbird-91.13.0-1.el7_9.x86_64.rpm thunderbird-debuginfo-91.13.0-1.el7_9.x86_64.rpm - Scientific Linux Development Team . Crucial Firefox security patch addressing vulnerabilities in email spoofing and memory stability concerns. Advisory Number: SLSA-2023:8174-2. thunderbird update,Mozilla fixes,Scientific Linux,memory safety issues,address spoofing. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 25, 2022 Important Scientific Linux
89

Fedora 26: 2017:1563-1 Critical: Chromium Address Spoofing Issues

Chromium 59. Add smaller logo files. Fix lots of security bugs: Security fix for CVE-2017-5070, CVE-2017-5071, CVE-2017-5072, CVE-2017-5073, CVE-2017-5074, CVE-2017-5075, CVE-2017-5086, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078, CVE-2017-5079, CVE-2017-5080, CVE-2017-5081, CVE-2017-5082, CVE-2017-5083, CVE-2017-5085. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-c11d7ef69a 2017-06-26 19:08:28.704542 --------------------------------------------------------------------------------Name : chromium-native_client Product : Fedora 26 Version : 59.0.3071.86 Release : 1.20170607gitaac1de2.fc26 URL : https://src.chromium.org/ Summary : Google Native Client Toolchain Description : Google's "pnacl" toolchain for native client support in Chromium. Depends on their older "nacl" toolchain, packaged separately. --------------------------------------------------------------------------------Update Information: Chromium 59. Add smaller logo files. Fix lots of security bugs: Security fix for CVE-2017-5070, CVE-2017-5071, CVE-2017-5072, CVE-2017-5073, CVE-2017-5074, CVE-2017-5075, CVE-2017-5086, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078, CVE-2017-5079, CVE-2017-5080, CVE-2017-5081, CVE-2017-5082, CVE-2017-5083, CVE-2017-5085 --------------------------------------------------------------------------------References: [ 1 ] Bug #1459037 - CVE-2017-5085 chromium-browser: inappropriate javascript execution on webui pages https://bugzilla.redhat.com/show_bug.cgi?id=1459037 [ 2 ] Bug #1459036 - CVE-2017-5083 chromium-browser: ui spoofing in blink https://bugzilla.redhat.com/show_bug.cgi?id=1459036 [ 3 ] Bug #1459035 - CVE-2017-5082 chromium-browser: insufficient hardening in credit card editor https://bugzilla.redhat.com/show_bug.cgi?id=1459035 [ 4 ] Bug #1459034 - CVE-2017-5081 chromium-browser: extension verification bypass https://bugzilla.redhat.com/show_bug.cgi?id=1459034 [ 5 ] Bug #1459033 - CVE-2017-5080 chromium-browser: use after free in credit card autofill https://bugzilla.redhat.com/show_bug.cgi?id=1459033 [ 6 ] Bug #1459032 - CVE-2017-5079 chromium-browser: ui spoofing in blink https://bugzilla.redhat.com/show_bug.cgi?id=1459032 [ 7 ] Bug #1459031 - CVE-2017-5078 chromium-browser: possible command injection in mailto handling https://bugzilla.redhat.com/show_bug.cgi?id=1459031 [ 8 ] Bug #1459030 - CVE-2017-5077 chromium-browser: heap buffer overflow in skia https://bugzilla.redhat.com/show_bug.cgi?id=1459030 [ 9 ] Bug #1459029 - CVE-2017-5076 chromium-browser: address spoofing in omnibox https://bugzilla.redhat.com/show_bug.cgi?id=1459029 [ 10 ] Bug #1459028 - CVE-2017-5086 chromium-browser: address spoofing in omnibox https://bugzilla.redhat.com/show_bug.cgi?id=1459028 [ 11 ] Bug #1459027 - CVE-2017-5075 chromium-browser: information leak in csp reporting https://bugzilla.redhat.com/show_bug.cgi?id=1459027 [ 12 ] Bug #1459025 - CVE-2017-5074 chromium-browser: use after free in apps bluetooth https://bugzilla.redhat.com/show_bug.cgi?id=1459025 [ 13 ] Bug #1459024 - CVE-2017-5073 chromium-browser: use after free in print preview https://bugzilla.redhat.com/show_bug.cgi?id=1459024 [ 14 ] Bug #1459023 - CVE-2017-5072 chromium-browser: address spoofing in omnibox https://bugzilla.redhat.com/show_bug.cgi?id=1459023 [ 15 ] Bug #1459022 - CVE-2017-5071 chromium-browser: out of bounds read in v8 https://bugzilla.redhat.com/show_bug.cgi?id=1459022 [ 16 ] Bug #1459021 - CVE-2017-5070 chromium-browser: type confusion in v8 https://bugzilla.redhat.com/show_bug.cgi?id=1459021 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade chromium-native_client' at the command line. For moreinformation, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . An essential security enhancement for Fedora tackles several vulnerabilities in Chromium, accompanied by CVE resolutions. Safeguard your system accordingly.. Fedora Security Fix, Chromium Update, Address Spoofing Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 26, 2017 Critical Fedora
202

openSUSE 13.2: Security Update for Chromium - Important Fix

An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available.. openSUSE Security Update: Security update for Chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:1209-1 Rating: important References: #977830 Cross-References: CVE-2016-1660 CVE-2016-1661 CVE-2016-1662 CVE-2016-1663 CVE-2016-1664 CVE-2016-1665 CVE-2016-1666 Affected Products: openSUSE 13.2 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: Chromium was updated to 50.0.2661.94 to fix a number of vulnerabilities (boo#977830): - CVE-2016-1660: Out-of-bounds write in Blink - CVE-2016-1661: Memory corruption in cross-process frames - CVE-2016-1662: Use-after-free in extensions - CVE-2016-1663: Use-after-free in Blink’s V8 bindings - CVE-2016-1664: Address bar spoofing - CVE-2016-1665: Information leak in V8 - CVE-2016-1666: Various fixes from internal audits, fuzzing and other initiatives Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.2: zypper in -t patch openSUSE-2016-538=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.2 (i586 x86_64): chromedriver-50.0.2661.94-97.1 chromedriver-debuginfo-50.0.2661.94-97.1 chromium-50.0.2661.94-97.1 chromium-debuginfo-50.0.2661.94-97.1 chromium-debugsource-50.0.2661.94-97.1 chromium-desktop-gnome-50.0.2661.94-97.1 chromium-desktop-kde-50.0.2661.94-97.1 chromium-ffmpegsumo-50.0.2661.94-97.1 chromium-ffmpegsumo-debuginfo-50.0.2661.94-97.1 References: https://www.suse.com/security/cve/CVE-2016-1660.html https://www.suse.com/security/cve/CVE-2016-1661.html https://www.suse.com/security/cve/CVE-2016-1662.html https://www.suse.com/security/cve/CVE-2016-1663.html https://www.suse.com/security/cve/CVE-2016-1664.html https://www.suse.com/security/cve/CVE-2016-1665.html https://www.suse.com/security/cve/CVE-2016-1666.html https://bugzilla.suse.com/977830 . The recent security patch for openSUSE 13.2 tackles several flaws in Chromium, enhancing overall system safety and performance.. openSUSE Update, Chromium Fix, Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 04, 2016 Important OpenSUSE
200

Scientific Linux SL5.x, SL4.x Moderate: Kdelibs Multiple Issues

Moderate: kdelibs security update. Date: Mon, 8 Oct 2007 15:45:18 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for kdelibs on SL5.x, SL4.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Moderate: kdelibs security update Issue date: 2007-10-08 CVE Names: CVE-2007-0242 CVE-2007-0537 CVE-2007-1308 CVE-2007-1564 CVE-2007-3820 CVE-2007-4224 Two cross-site-scripting flaws were found in the way Konqueror processes certain HTML content. This could result in a malicious attacker presenting misleading content to an unsuspecting user. (CVE-2007-0242, CVE-2007-0537) A flaw was found in KDE JavaScript implementation. A web page containing malicious JavaScript code could cause Konqueror to crash. (CVE-2007-1308) A flaw was found in the way Konqueror handled certain FTP PASV commands. A malicious FTP server could use this flaw to perform a rudimentary port-scan of machines behind a user's firewall. (CVE-2007-1564) Two Konqueror address spoofing flaws have been discovered. It was possible for a malicious website to cause the Konqueror address bar to display information which could trick a user into believing they are at a different website than they actually are. (CVE-2007-3820, CVE-2007-4224) SL 4.x SRPMS: kdelibs-3.3.1-9.el4.src.rpm i386: kdelibs-3.3.1-9.el4.i386.rpm kdelibs-devel-3.3.1-9.el4.i386.rpm x86_64: kdelibs-3.3.1-9.el4.i386.rpm kdelibs-3.3.1-9.el4.x86_64.rpm kdelibs-devel-3.3.1-9.el4.x86_64.rpm SL 5.x SRPMS: kdelibs-3.5.4-13.el5.src.rpm i386: kdelibs-3.5.4-13.el5.i386.rpm kdelibs-apidocs-3.5.4-13.el5.i386.rpm kdelibs-devel-3.5.4-13.el5.i386.rpm x86_64: kdelibs-3.5.4-13.el5.i386.rpm kdelibs-3.5.4-13.el5.x86_64.rpm kdelibs-apidocs-3.5.4-13.el5.x86_64.rpm kdelibs-devel-3.5.4-13.el5.i386.rpm kdelibs-devel-3.5.4-13.el5.x86_64.rpm -Connie Sieh -Troy Dawson . Explore the specifics surrounding the recent security enhancements to kdelibs, which tackle several cross-site scripting vulnerabilities.. kdelibsSecurity Update, Scientific Linux Errata, Cross-Site Scripting, KDE JavaScript Flaw, Port-Scan Vulnerability. . LinuxSecurity.com Team

Calendar%202 Oct 08, 2007 Scientific Linux
200

Scientific Linux 5.x & 4.x Moderate: kdebase Security Issues

Moderate: kdebase security update. Date: Mon, 8 Oct 2007 15:45:17 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for kdebase on SL5.x, SL4.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Moderate: kdebase security update Issue date: 2007-10-08 CVE Names: CVE-2007-4569 CVE-2007-3820 CVE-2007-4224 Kees Huijgen found a flaw in the way KDM handled logins when autologin and "shutdown with password" were enabled. A local user would have been able to login via KDM as any user without requiring a password. (CVE-2007-4569) Two Konqueror address spoofing flaws were discovered. A malicious web site could spoof the Konqueror address bar, tricking a victim into believing the page was from a different site. (CVE-2007-3820, CVE-2007-4224) SL 4.x SRPMS: kdebase-3.3.1-6.el4.src.rpm i386: kdebase-3.3.1-6.el4.i386.rpm kdebase-devel-3.3.1-6.el4.i386.rpm x86_64: kdebase-3.3.1-6.el4.i386.rpm kdebase-3.3.1-6.el4.x86_64.rpm kdebase-devel-3.3.1-6.el4.x86_64.rpm SL 5.x SRPMS: kdebase-3.5.4-15.el5.src.rpm i386: kdebase-3.5.4-15.el5.i386.rpm kdebase-devel-3.5.4-15.el5.i386.rpm x86_64: kdebase-3.5.4-15.el5.i386.rpm kdebase-3.5.4-15.el5.x86_64.rpm kdebase-devel-3.5.4-15.el5.i386.rpm kdebase-devel-3.5.4-15.el5.x86_64.rpm -Connie Sieh -Troy Dawson . Recent developments reveal security vulnerabilities in kdebase for Scientific Linux 4.x and 5.x, prompting swift updates from the security team to address concerns and enhance protection.. kdebase security update, Scientific Linux patch, linux security updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 08, 2007 Important Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200