Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
100

SUSE Linux 15: 2021:0423-1 Critical: Apache Security Flaw

An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two fixes is now available. fixes is now available.. SUSE Security Update: Security update for bind ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:0113-1 Rating: important References: #1018699 #1018700 #1018701 #1018702 #965748 Cross-References: CVE-2016-9131 CVE-2016-9147 CVE-2016-9444 Affected Products: SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that solves three vulnerabilities and has two fixes is now available. Description: This update for bind fixes the following issues: - Fix a potential assertion failure that could have been triggered by a malformed response to an ANY query, thereby facilitating a denial-of-service attack. [CVE-2016-9131, bsc#1018700, bsc#1018699] - Fix a potential assertion failure that could have been triggered by responding to a query with inconsistent DNSSEC information, thereby facilitating a denial-of-service attack. [CVE-2016-9147, bsc#1018701, bsc#1018699] - Fix potential assertion failure that could have been triggered by DNS responses that contain unusually-formed DS resource records, facilitating a denial-of-service attack. [CVE-2016-9444, bsc#1018702, bsc#1018699] - Fixed ldapdump to use a temporary pseudo nameserver that conforms to BIND's expected syntax. Prior versions would not work correctly with an LDAP backed DNS server. [bsc#965748] Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-52=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-52=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12 (x86_64): bind-9.9.9P1-28.26.1 bind-chrootenv-9.9.9P1-28.26.1 bind-debuginfo-9.9.9P1-28.26.1 bind-debugsource-9.9.9P1-28.26.1 bind-libs-32bit-9.9.9P1-28.26.1 bind-libs-9.9.9P1-28.26.1 bind-libs-debuginfo-32bit-9.9.9P1-28.26.1 bind-libs-debuginfo-9.9.9P1-28.26.1 bind-utils-9.9.9P1-28.26.1 bind-utils-debuginfo-9.9.9P1-28.26.1 - SUSE Linux Enterprise Server for SAP 12 (noarch): bind-doc-9.9.9P1-28.26.1 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): bind-9.9.9P1-28.26.1 bind-chrootenv-9.9.9P1-28.26.1 bind-debuginfo-9.9.9P1-28.26.1 bind-debugsource-9.9.9P1-28.26.1 bind-libs-9.9.9P1-28.26.1 bind-libs-debuginfo-9.9.9P1-28.26.1 bind-utils-9.9.9P1-28.26.1 bind-utils-debuginfo-9.9.9P1-28.26.1 - SUSE Linux Enterprise Server 12-LTSS (s390x x86_64): bind-libs-32bit-9.9.9P1-28.26.1 bind-libs-debuginfo-32bit-9.9.9P1-28.26.1 - SUSE Linux Enterprise Server 12-LTSS (noarch): bind-doc-9.9.9P1-28.26.1 References: https://www.suse.com/security/cve/CVE-2016-9131.html https://www.suse.com/security/cve/CVE-2016-9147.html https://www.suse.com/security/cve/CVE-2016-9444.html https://bugzilla.suse.com/1018699 https://bugzilla.suse.com/1018700 https://bugzilla.suse.com/1018701 https://bugzilla.suse.com/1018702 https://bugzilla.suse.com/965748 . Revisions on allocation settings addressing three critical aspects, promoting overall system integrity and safeguarding with essential enhancements.. SUSE Linux, bind service, system update, security fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 12, 2017 Important SuSE
198

Arch Linux: ASA-201507-6 High Severity: Bind Denial Of Service

The package bind before version 9.10.2.P2-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201507-6 ======================================== Severity: High Date : 2015-07-07 CVE-ID : CVE-2015-4620 Package : bind Type : denial of service Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package bind before version 9.10.2.P2-1 is vulnerable to denial of service. Resolution ========= Upgrade to 9.10.2.P2-1. # pacman -Syu "bind> =9.10.2.P2-1" The problem has been fixed upstream in version 9.10.2.P2. Workaround ========= Disabling DNSSEC validation prevents exploitation of this defect but is not generally recommended. The recommended solution is to upgrade to a patched version. DNSSEC validation can be disabled by setting dnssec-validation no; in the "options" section of /etc/named.conf Description ========== A very uncommon combination of zone data has been found that triggers a bug in BIND, with the result that named will exit with a "REQUIRE" failure in name.c when validating the data returned in answer to a recursive query. This means that a recursive resolver that is performing DNSSEC validation can be deliberately stopped by an attacker who can cause the resolver to perform a query against a maliciously-constructed zone. Impact ===== A remote attacker can crash a bind resolver performing DNSSEC validation by querying it for a specially crafted zone. References ========= https://kb.isc.org/docs/aa-01267 https://www.cve.org/CVERecord?id=CVE-2015-4620 . The CentOS Security Notice CESA-2023-009 highlights a critical vulnerability affecting the httpd package that necessitates an urgent patch.. Arch Linux, Bind Service, Denial of Service, Security Update. . LinuxSecurity.com Team

Calendar 2 Jul 07, 2015 ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here