Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
202

openSUSE Leap 15.0 openSUSE-SU-2018:2231-1 Moderate: ZNC Admin Issue

An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for znc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2231-1 Rating: moderate References: #1101280 #1101281 Cross-References: CVE-2018-14055 CVE-2018-14056 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for znc fixes the following issues: - Update to version 1.7.1 * CVE-2018-14055: non-admin user could gain admin privileges and shell access by injecting values into znc.conf (bnc#1101281) * CVE-2018-14056: path traversal in HTTP handler via ../ in a web skin name. (bnc#1101280) - Update to version 1.7.0 * Make ZNC UI translateable to different languages * Configs written before ZNC 0.206 can't be read anymore * Implement IRCv3.2 capabilities away-notify, account-notify, extended-join * Implement IRCv3.2 capabilities echo-message, cap-notify on the "client side" * Update capability names as they are named in IRCv3.2: znc.in/server-time-iso?server-time, znc.in/batch?batch. Old names will continue working for a while, then will be removed in some future version. * Make ZNC request server-time from server when available * Add "AuthOnlyViaModule" global/user setting * Stop defaulting real name to "Got ZNC?" * Add SNI SSL client support * Add support for CIDR notation in allowed hosts list and in trusted proxy list * Add network-specific config for cert validation in addition to user-supplied fingerprints: TrustAllCerts, defaults to false, and TrustPKI, defaults to true. * Add /attach command for symmetry with /detach. Unlike /join it allows wildcards. - Update to version 1.6.6: * Fix use-after-free in znc --makepem. It was broken for a long time, but started segfaulting only now. This is a useability fix, not a security fix, because self-signed (or signed by a CA) certificates can be created without using --makepem, and then combined into znc.pem. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-819=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-819=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): znc-1.7.1-20.3.1 znc-debuginfo-1.7.1-20.3.1 znc-debugsource-1.7.1-20.3.1 znc-devel-1.7.1-20.3.1 znc-perl-1.7.1-20.3.1 znc-perl-debuginfo-1.7.1-20.3.1 znc-python3-1.7.1-20.3.1 znc-python3-debuginfo-1.7.1-20.3.1 znc-tcl-1.7.1-20.3.1 znc-tcl-debuginfo-1.7.1-20.3.1 - openSUSE Leap 42.3 (noarch): znc-lang-1.7.1-20.3.1 - openSUSE Leap 15.0 (x86_64): znc-1.7.1-lp150.2.6.1 znc-debuginfo-1.7.1-lp150.2.6.1 znc-debugsource-1.7.1-lp150.2.6.1 znc-devel-1.7.1-lp150.2.6.1 znc-perl-1.7.1-lp150.2.6.1 znc-perl-debuginfo-1.7.1-lp150.2.6.1 znc-python3-1.7.1-lp150.2.6.1 znc-python3-debuginfo-1.7.1-lp150.2.6.1 znc-tcl-1.7.1-lp150.2.6.1 znc-tcl-debuginfo-1.7.1-lp150.2.6.1 - openSUSE Leap 15.0 (noarch): znc-lang-1.7.1-lp150.2.6.1 References: https://www.suse.com/security/cve/CVE-2018-14055.html https://www.suse.com/security/cve/CVE-2018-14056.html https://bugzilla.suse.com/1101280 https://bugzilla.suse.com/1101281 -- . This Fedora patch resolves various vulnerabilities in nginx, enhancing reliability and user management overall.. openSUSE Security, ZNC Admin Issue, Security Update, Software Vulnerability. . LinuxSecurity.com Team

Calendar 2 Aug 07, 2018 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here