Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 41: 2025-a1d884e467 moderate: libiniparser heap overflow

Patched libiniparser to fix CVE-2025-0633. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a1d884e467 2025-03-01 01:22:54.667783+00:00 -------------------------------------------------------------------------------- Name : iniparser Product : Fedora 41 Version : 4.2.4 Release : 3.fc41 URL : https://github.com/ndevilla/iniparser Summary : C library for parsing "INI-style" files Description : iniParser is an ANSI C library to parse "INI-style" files, often used to hold application configuration information. -------------------------------------------------------------------------------- Update Information: Patched libiniparser to fix CVE-2025-0633 -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 25 2025 David Cantrell - 4.2.4-3 - Patch for CVE-2025-0633 - Heap Overflow in iniparser.c (#2346474) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2346474 - CVE-2025-0633 iniparser: Heap Overflow in iniparser.c https://bugzilla.redhat.com/show_bug.cgi?id=2346474 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a1d884e467' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Updated libiniparser in Fedora 41 to fix memory corruption vulnerability, bolstering application security.. Heap Overflow, Fedora Update, libiniparser Patch. . LinuxSecurity.com Team

Calendar 2 Mar 01, 2025 Fedora
98

Red Hat Enterprise Linux 3 End Of Life Notification: RHSA-2009:1526-02

This is the 1-year notification of the End Of Life plans for Red Hat Enterprise Linux 3.. ==================================================================== Red Hat Security Advisory Synopsis: Low: Red Hat Enterprise Linux 3 - 1-Year End Of Life Notice Advisory ID: RHSA-2009:1526-02 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:1526.html Issue date: 2009-11-09 ==================================================================== 1. Summary: This is the 1-year notification of the End Of Life plans for Red Hat Enterprise Linux 3. 2. Relevant releases/architectures: Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Description: In accordance with the Red Hat Enterprise Linux Errata Support Policy, the regular 7 year life-cycle of Red Hat Enterprise Linux 3 will end on October 31, 2010. After this date, Red Hat will discontinue the regular subscription services for Red Hat Enterprise Linux 3. Therefore, new bug fix, enhancement, and security errata updates, as well as technical support services will no longer be available for the following products: * Red Hat Enterprise Linux AS 3 * Red Hat Enterprise Linux ES 3 * Red Hat Enterprise Linux WS 3 * Red Hat Enterprise Linux Extras 3 * Red Hat Desktop 3 * Red Hat Global File System 3 * Red Hat Cluster Suite 3 Customers still running production workloads on Red Hat Enterprise Linux 3 are advised to begin planning the upgrade to Red Hat Enterprise Linux 5. Active subscribers of Red Hat Enterprise Linux already have access to all currently maintained versions of Red Hat Enterprise Linux, as part of their subscription without additional fees. For customers who are unable to migrate off Red Hat Enterprise Linux 3 before its end-of-life date, Red Hat may offer a limited,optional extension program. For more information, contact your Red Hat sales representative or channel partner. Details of the Red Hat Enterprise Linux life-cycle can be found on the Red Hat website: https://access.redhat.com/support/policy/updates/errata 4. Solution: This errata contains an updated redhat-release package, that adds a new file to "/usr/share/doc/", which contains this end of life notice. 5. Bugs fixed (http://bugzilla.redhat.com/): 531220 - Send Out RHEL 3 1-Year EOL Notice 6. Package List: Red Hat Enterprise Linux AS version 3: Source: i386: redhat-release-3AS-13.9.7.i386.rpm redhat-release-debuginfo-3AS-13.9.7.i386.rpm ia64: redhat-release-3AS-13.9.7.ia64.rpm redhat-release-debuginfo-3AS-13.9.7.ia64.rpm ppc: redhat-release-3AS-13.9.7.ppc.rpm redhat-release-debuginfo-3AS-13.9.7.ppc.rpm s390: redhat-release-3AS-13.9.7.s390.rpm redhat-release-debuginfo-3AS-13.9.7.s390.rpm s390x: redhat-release-3AS-13.9.7.s390x.rpm redhat-release-debuginfo-3AS-13.9.7.s390x.rpm x86_64: redhat-release-3AS-13.9.7.x86_64.rpm redhat-release-debuginfo-3AS-13.9.7.x86_64.rpm Red Hat Desktop version 3: Source: i386: redhat-release-3Desktop-13.9.7.i386.rpm redhat-release-debuginfo-3Desktop-13.9.7.i386.rpm x86_64: redhat-release-3Desktop-13.9.7.x86_64.rpm redhat-release-debuginfo-3Desktop-13.9.7.x86_64.rpm Red Hat Enterprise Linux ES version 3: Source: i386: redhat-release-3ES-13.9.7.i386.rpm redhat-release-debuginfo-3ES-13.9.7.i386.rpm ia64: redhat-release-3ES-13.9.7.ia64.rpm redhat-release-debuginfo-3ES-13.9.7.ia64.rpm x86_64: redhat-release-3ES-13.9.7.x86_64.rpm redhat-release-debuginfo-3ES-13.9.7.x86_64.rpm Red Hat Enterprise Linux WS version 3: Source: i386: redhat-release-3WS-13.9.7.i386.rpm redhat-release-debuginfo-3WS-13.9.7.i386.rpm ia64: redhat-release-3WS-13.9.7.ia64.rpm redhat-release-debuginfo-3WS-13.9.7.ia64.rpm x86_64: redhat-release-3WS-13.9.7.x86_64.rpm redhat-release-debuginfo-3WS-13.9.7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details onhow to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/updates/classification#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2009 Red Hat, Inc. . Red Hat's Announcement Regarding the 1-Year End Of Life for Enterprise Linux 3: Crucial information for users and support resources.. End Of Life Notice, Red Hat Advisory, Enterprise Linux Support. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Nov 09, 2009 Low Red Hat
99

Slackware: 2005-135-02 False Alarm On NcFTP Security Advisory

Hey folks, An advisory recently went out on NcFTP, but it appears that the issue in question was fixed long ago in version 3.1.5, released on 2002-10-13. I received an email at security@slackware.com from a well-meaning user . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] (FALSE ALARM ON) ncftp (SSA:2005-135-02) Hey folks, An advisory recently went out on NcFTP, but it appears that the issue in question was fixed long ago in version 3.1.5, released on 2002-10-13. I received an email at security@slackware.com from a well-meaning user informing me that 3.1.9 had a security issue that was going unpatched: > I just noticed that there is a new security update (version 3.1.9) for > NcFTP client available, but the current Slacware Package Browser lists > version ncftp-3.1.8-i486-1. I then went to www.ncftp.com to verify this, and managed to misread the site, thinking that an old security advisory pertained to 3.1.9. I imagine that's the same thing that happened to the person who wrote to me. Anyway, just to let you all know that if you already have 3.1.5 or newer that there aren't any security issues affecting you that I'd consider worth an advisory. My apologies if this has been an inconvenience to any Slackware users, or if the fine people at NcFTP or other distributions have had to answer any questions about this. I'll try to read more carefully next time. :-) Take care, Pat +-----+ . Debian notice DSA:2005-134-03 indicates that the reported vulnerabilities in GnuPG were based on obsolete data and are not of concern.. Slackware Advisory,NcFTP Update,Security Alert,False Alarm. . LinuxSecurity.com Team

Calendar 2 May 16, 2005 Slackware
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here