Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
203

Mageia 7: 2019-0299 Critical Bind Security Advisory for TCP Issues

Updated bind packages fix security vulnerabilities Limiting simultaneous TCP clients is ineffective (CVE-2018-5743) Race condition when discarding malformed packets can cause bind to . MGASA-2019-0299 - Updated bind packages fix security vulnerabilities Publication date: 23 Oct 2019 URL: https://advisories.mageia.org/MGASA-2019-0299.html Type: security Affected Mageia releases: 7 CVE: CVE-2018-5743, CVE-2019-6471 Updated bind packages fix security vulnerabilities Limiting simultaneous TCP clients is ineffective (CVE-2018-5743) Race condition when discarding malformed packets can cause bind to exit with assertion failure (CVE-2019-6471) In addition to those two security issues, this package releases also fixes two additional issues: - a missing conflict tag between old bind and bnew ind-utils subpackages, preventing upgrade due to a file conflict - missing root.key file, despite this one being refered in default configuration References: - https://bugs.mageia.org/show_bug.cgi?id=24422 - https://access.redhat.com/errata/RHSA-2019:1294 - https://access.redhat.com/errata/RHSA-2019:1714 - https://www.cve.org/CVERecord?id=CVE-2018-5743 - https://www.cve.org/CVERecord?id=CVE-2019-6471 SRPMS: - 7/core/bind-9.11.6-1.1.mga7 . Improved Bind Modules for Address Vulnerabilities in Mageia 7 and Bolstered Network Consistency with Essential Updates.. bind security update, Mageia network security, TCP client vulnerability, security patch management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 23, 2019 Critical Mageia
89

Fedora 24: 2017-edce28f24b Critical BIND Security Update

Security fix for CVE-2017-3136, CVE-2017-3137 and CVE-2017-3138. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-edce28f24b 2017-05-06 17:08:23.402094 --------------------------------------------------------------------------------Name : bind99 Product : Fedora 24 Version : 9.9.9 Release : 4.P8.fc24 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-3136, CVE-2017-3137 and CVE-2017-3138 --------------------------------------------------------------------------------References: [ 1 ] Bug #1441125 - CVE-2017-3136 bind: Incorrect error handling causes assertion failure when using DNS64 with "break-dnssec yes;" https://bugzilla.redhat.com/show_bug.cgi?id=1441125 [ 2 ] Bug #1441133 - CVE-2017-3137 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver https://bugzilla.redhat.com/show_bug.cgi?id=1441133 [ 3 ] Bug #1441137 - CVE-2017-3138 bind: REQUIRE assertion failure when null command string on control channel is received https://bugzilla.redhat.com/show_bug.cgi?id=1441137 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Tackling BIND security vulnerabilities in Fedora 24 through essential patches targeting assertion faults and DNS weaknesses.. Fedora BIND Security Fix,DNS Issue Resolution,Assertion Failure Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 06, 2017 Critical Fedora
89

Fedora 26: 2017-a354efc764 Critical: bind99 DoS and Assertion Problems

Security fix for CVE-2017-3136, CVE-2017-3137 and CVE-2017-3138. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-a354efc764 2017-04-19 16:59:44.108374 --------------------------------------------------------------------------------Name : bind99 Product : Fedora 26 Version : 9.9.9 Release : 5.P8.fc26 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-3136, CVE-2017-3137 and CVE-2017-3138 --------------------------------------------------------------------------------References: [ 1 ] Bug #1441125 - CVE-2017-3136 bind: Incorrect error handling causes assertion failure when using DNS64 with "break-dnssec yes;" https://bugzilla.redhat.com/show_bug.cgi?id=1441125 [ 2 ] Bug #1441133 - CVE-2017-3137 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver https://bugzilla.redhat.com/show_bug.cgi?id=1441133 [ 3 ] Bug #1441137 - CVE-2017-3138 bind: REQUIRE assertion failure when null command string on control channel is received https://bugzilla.redhat.com/show_bug.cgi?id=1441137 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Important patch for bind99 resolving various vulnerabilities in data handling that could lead to system failures.. Fedora bind99 security fix, DNS DoS risk, assertion failure issue, BIND library update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 19, 2017 Critical Fedora
89

Fedora 25: 2017-f44f2f5a48 Moderate: Bind99 Assertion Fixes

Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-f44f2f5a48 2017-01-14 00:22:37.172566 -------------------------------------------------------------------------------- Name : bind99 Product : Fedora 25 Version : 9.9.9 Release : 4.P5.fc25 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1411348 - CVE-2016-9131 bind: assertion failure while processing response to an ANY query https://bugzilla.redhat.com/show_bug.cgi?id=1411348 [ 2 ] Bug #1411367 - CVE-2016-9147 bind: assertion failure while handling a query response containing inconsistent DNSSEC information https://bugzilla.redhat.com/show_bug.cgi?id=1411367 [ 3 ] Bug #1411377 - CVE-2016-9444 bind: assertion failure while handling an unusually-formed DS record response https://bugzilla.redhat.com/show_bug.cgi?id=1411377 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Essential security patches for bind99 on Fedora 25 rectifying various assertion vulnerabilities to enhance overall system robustness.. Bind DNS Update, Fedora Security Patch, Assertion Failures Bind, Security Fix Fedora 25. . LinuxSecurity.com Team

Calendar 2 Jan 14, 2017 Fedora
89

Fedora 23: Critical Fix for bind-dyndb-ldap Assertion Errors

security fix. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-09bf9e06ea 2015-12-19 14:50:40.381406 -------------------------------------------------------------------------------- Name : bind-dyndb-ldap Product : Fedora 23 Version : 8.0 Release : 4.fc23 URL : https://pagure.io/bind-dyndb-ldap Summary : LDAP back-end plug-in for BIND Description : This package provides an LDAP back-end plug-in for BIND. It features support for dynamic updates and internal caching, to lift the load off of your LDAP server. -------------------------------------------------------------------------------- Update Information: security fix -------------------------------------------------------------------------------- References: [ 1 ] Bug #1291176 - CVE-2015-8000 bind: responses with a malformed class attribute can trigger an assertion failure in db.c https://bugzilla.redhat.com/show_bug.cgi?id=1291176 [ 2 ] Bug #1291186 - CVE-2015-8461 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c https://bugzilla.redhat.com/show_bug.cgi?id=1291186 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update bind-dyndb-ldap' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . This alert outlines the resolution for bind-dyndb-ldap weaknesses impacting Fedora 23, with significantconsequences.. bind dyn db ldap security, fedora update, assertion errors. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 19, 2015 Critical Fedora
87

Debian Woody 2.4.6-2woody11 Critical: Squid Denial Of Service Fix

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 809-3 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze November 7th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : squid Vulnerability : assertion error Problem type : remote Debian-specific: no CVE ID : CAN-2005-2794 Debian Bug : 320035 Kosa Attila discovered that the security update DSA 809-2 contained a regression in the packages for the old stable distribution (woody). The orginal advisory text follows: Certain aborted requests that trigger an assertion in squid, the popular WWW proxy cache, may allow remote attackers to cause a denial of service. This update also fixes a regression caused by DSA 751. For the oldstable distribution (woody) this problem has been fixed in version 2.4.6-2woody11. We recommend that you upgrade your squid package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 614 341d5ba1daa6d5b4c997096a4116c782 Size/MD5 checksum: 257997 65e0a384bde2fdb61d215b86b421b1be Size/MD5 checksum: 1081920 59ce2c58da189626d77e27b9702ca228 Alpha architecture: Size/MD5 checksum: 817194 c9b35cf30db2598f1fe8c5a4b5d842dd Size/MD5 checksum: 76148f9310bc22c747405959b1a548765f48e Size/MD5 checksum: 60940 a3032f47551bfc3a53623631f2fda3f1 ARM architecture: Size/MD5 checksum: 727402 3cb96a5aa6b00203ea2f8ca447ff21ae Size/MD5 checksum: 73928 2dc73eb6c00e423056ea6fccf7ef0855 Size/MD5 checksum: 59250 6d4a9adeffca56d10026dd775ea1766c Intel IA-32 architecture: Size/MD5 checksum: 685502 0ac74ef690c17e054f7c1d9a0319d7de Size/MD5 checksum: 74448 873b78ff72c7bf4dd6497228a50fe3f5 Size/MD5 checksum: 58946 fcd7e84899b7e0cc7b5290899f9b95ec Intel IA-64 architecture: Size/MD5 checksum: 955144 956ca54bbec7ee77f4e53f62f5078bd0 Size/MD5 checksum: 79996 6bba69eaedc04ccacc73191750eb65bc Size/MD5 checksum: 63612 12d098851265c912a45c20fb66528bf6 HP Precision architecture: Size/MD5 checksum: 780488 8eae73112548261c5d9cb52c39468c73 Size/MD5 checksum: 75376 6a9c3c90ab04d5594387c07f1086f3f6 Size/MD5 checksum: 60400 7b0c999f8016a93fa2c804003e8997ba Motorola 680x0 architecture: Size/MD5 checksum: 667508 37917b970bd277c5e33d44aa7193d4e1 Size/MD5 checksum: 73258 9de2cd08019e7fdd6ab5ed9e4fd191b0 Size/MD5 checksum: 58474 020cf4dc54f33b326c7a3b8b17b11ae5 Big endian MIPS architecture: Size/MD5 checksum: 766382 01a6964d987a57eb7066f8d2fc7d9f60 Size/MD5 checksum: 74874 1c7e8a86b012880d7995cd9f14f86815 Size/MD5 checksum: 59544 82025d0826276e2e439fcec45490c5d7 Little endian MIPS architecture: Size/MD5 checksum: 767106 306855c183e3b34c0d329c020c1afceb Size/MD5 checksum: 74960 8261559dc2ac4aa803711db4ecf08657 Size/MD5 checksum: 59616 5d49f5eb3b7686d58e1cdc7f5cc783e9 PowerPC architecture: Size/MD5 checksum: 724312 060818b003b05f21bec0411b14b8f629 Size/MD5 checksum: 73928 f2801b6161fc1709ec3198a0d68c6560 Size/MD5checksum: 59136 3d87426bb6d775aeef02cfc0f782f4cf IBM S/390 architecture: Size/MD5 checksum: 713394 17e4f9e7c223ad452d770925643f1e8c Size/MD5 checksum: 74254 290cf064e45db12f456ffc18d7de0edf Size/MD5 checksum: 59680 19221bca088e9ce1d68bb4c65db9ca00 Sun Sparc architecture: Size/MD5 checksum: 725552 cde8744e9e40f33aa8b9f6b8942c314a Size/MD5 checksum: 76542 e2ed6f1f3612fbdc5c203195e060c68d Size/MD5 checksum: 61558 56204ea6db0a0342920f8381e07df3ae - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance squid software version to rectify assertion fault leading to service interruption issues in Debian. Advisory for individuals operating on development builds.. Squid Update, Denial Of Service, Debian GNU/Linux. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 07, 2005 Critical Debian
87

Debian 3.0 DSA-809-2 Moderate: Squid Assertion Error Denial Of Service

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 809-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze September 30th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : squid Vulnerability : assertion error Problem type : remote Debian-specific: no CVE ID : CAN-2005-2794 Debian Bug : 320035 Certain aborted requests that trigger an assertion in squid, the popular WWW proxy cache, may allow remote attackers to cause a denial of service. This update also fixes a regression caused by DSA 751. For the oldstable distribution (woody) this problem has been fixed in version 2.4.6-2woody10. For the stable distribution (sarge) this problem has been fixed in version 2.5.9-10sarge1. For the unstable distribution (sid) this problem has been fixed in version 2.5.10-5. We recommend that you upgrade your squid package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 614 72838788cad08e14db248125795fef03 Size/MD5 checksum: 257792 036373fa29b3f0ef0f13f1ce2b7e9506 Size/MD5 checksum: 1081920 59ce2c58da189626d77e27b9702ca228 Alpha architecture: Size/MD5 checksum: 817042 b0318ebf7e5450af40b441af0c50b229 Size/MD5 checksum: 75990a0b663697addfd7ddbb88720c0b9e68e Size/MD5 checksum: 60788 65e29fc78534c678777e894cd26eec7f ARM architecture: Size/MD5 checksum: 727164 d19d26c7184a23612fdc6bdb005e11b9 Size/MD5 checksum: 73770 4fa3a5c95b1afa8842b8a340ec702860 Size/MD5 checksum: 59082 2e1de11f65b713e3db221e1ea8bbef34 Intel IA-32 architecture: Size/MD5 checksum: 685324 d228802c15397d498ca395a79b6d56bc Size/MD5 checksum: 74282 fd8888249ca4080be1ba62e9cdd5b3ba Size/MD5 checksum: 58774 8ba44f4a2da57814f0813d21e23b5f95 Intel IA-64 architecture: Size/MD5 checksum: 954974 feeefd11d6f446fbf70cc5954b9273df Size/MD5 checksum: 79824 ca19bb8416b7648195cc7b1c9768ceab Size/MD5 checksum: 63464 d9b3f5e4b4e690dee6bff6a720112d08 HP Precision architecture: Size/MD5 checksum: 780254 31bcfe48aa1774e2f29a9fc3fcb028f0 Size/MD5 checksum: 75208 ab2f18b11bea0362cf27cab265324e10 Size/MD5 checksum: 60236 c11448e476cc4aecc2f8fbd8f35873aa Motorola 680x0 architecture: Size/MD5 checksum: 667886 9c1c6c63caca8e2ba13723060cb0038a Size/MD5 checksum: 73110 5c5bb1288209366cc195afb92ada5c88 Size/MD5 checksum: 58332 8dd16ceb8fca5fbc29e2e051d21a1c02 Big endian MIPS architecture: Size/MD5 checksum: 766336 aa28ffd592af2bf9fd57aae55e4c4c42 Size/MD5 checksum: 74746 c037664fd063e6b938131b67290471ee Size/MD5 checksum: 59382 dc652da2e206ca66180c2b8038a2d531 Little endian MIPS architecture: Size/MD5 checksum: 766916 842c270e8d8aac9c8cafd710e7a80056 Size/MD5 checksum: 74798 883335e9cbc0bab9dcf6f8d341ef65f4 Size/MD5 checksum: 59462 462a5a45363182d594099aa0c8fd9aed PowerPC architecture: Size/MD5 checksum: 724132 156c01c65ee7cf2fed18fee9efb9a041 Size/MD5 checksum: 73768 5b595aa01f81366cd5a8c2a0c2e910eb Size/MD5checksum: 58980 b15773fde173ecf67c0491a29b4db6d6 IBM S/390 architecture: Size/MD5 checksum: 713198 8e578e68b934256633d79da244add1af Size/MD5 checksum: 74096 ff166996af8bc0443447014a6b614648 Size/MD5 checksum: 59528 8bb8826cfdb59c54ffa7e14b19840795 Sun Sparc architecture: Size/MD5 checksum: 725476 7653876e85019972267725ec16038326 Size/MD5 checksum: 76372 64ae6d6fe2317785a8d537bb4664106e Size/MD5 checksum: 61404 33d487f77d9912900e14c033b4a3a306 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A remote access vulnerability has been identified in the nginx package for Ubuntu - update your installation immediately to shield your environment from external threats.. Debian Security,Squid Denial of Service,Package Upgrade. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 30, 2005 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here