Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
203

Mageia: 2022-0241 Moderate: chromium-browser-stable Security Issues

The chromium-browser-stable package has been updated to the 103.0.5060.53 branch, fixing many bugs and 14 CVE. Some of them are listed below: Use after free in Base. (CVE-2022-2156) Use after free in Interest groups. (CVE-2022-2157) . MGASA-2022-0241 - Updated chromium-browser-stable packages fix security vulnerability Publication date: 24 Jun 2022 URL: https://advisories.mageia.org/MGASA-2022-0241.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-2156, CVE-2022-2157, CVE-2022-2158, CVE-2022-2160, CVE-2022-2161, CVE-2022-2162, CVE-2022-2163, CVE-2022-2164, CVE-2022-2165 The chromium-browser-stable package has been updated to the 103.0.5060.53 branch, fixing many bugs and 14 CVE. Some of them are listed below: Use after free in Base. (CVE-2022-2156) Use after free in Interest groups. (CVE-2022-2157) Type Confusion in V8. (CVE-2022-2158) Insufficient policy enforcement in DevTools. (CVE-2022-2160) Use after free in WebApp Provider. (CVE-2022-2161) Insufficient policy enforcement in File System API. (CVE-2022-2162) Use after free in Cast UI and Toolbar. (CVE-2022-2163) Inappropriate implementation in Extensions API. (CVE-2022-2164) Insufficient data validation in URL formatting. (CVE-2022-2165) Various fixes from internal audits, fuzzing and other initiatives References: - https://bugs.mageia.org/show_bug.cgi?id=30575 - https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html - https://blog.chromium.org/2022/05/chrome-103-beta-early-navigation-hints.html - https://www.cve.org/CVERecord?id=CVE-2022-2156 - https://www.cve.org/CVERecord?id=CVE-2022-2157 - https://www.cve.org/CVERecord?id=CVE-2022-2158 - https://www.cve.org/CVERecord?id=CVE-2022-2160 - https://www.cve.org/CVERecord?id=CVE-2022-2161 - https://www.cve.org/CVERecord?id=CVE-2022-2162 - https://www.cve.org/CVERecord?id=CVE-2022-2163 - https://www.cve.org/CVERecord?id=CVE-2022-2164 - https://www.cve.org/CVERecord?id=CVE-2022-2165 SRPMS: -8/core/chromium-browser-stable-103.0.5060.53-1.mga8 . The latest release of the chromium-browser-stable package resolves several vulnerabilities to improve overall user protection.. chromium-browser-stable security, Mageia updates, browser flaws. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 24, 2022 Important Mageia
87

Debian: DSA-2883-1 Critical: Chromium Browser Flaws Security Update

Several vulnerabilities have been discovered in the chromium web browser. CVE-2013-6653 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2883-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Michael Gilbert March 23, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : chromium-browser CVE ID : CVE-2013-6653 CVE-2013-6654 CVE-2013-6655 CVE-2013-6656 CVE-2013-6657 CVE-2013-6658 CVE-2013-6659 CVE-2013-6660 CVE-2013-6661 CVE-2013-6663 CVE-2013-6664 CVE-2013-6665 CVE-2013-6666 CVE-2013-6667 CVE-2013-6668 CVE-2014-1700 CVE-2014-1701 CVE-2014-1702 CVE-2014-1703 CVE-2014-1704 CVE-2014-1705 CVE-2014-1713 CVE-2014-1715 Several vulnerabilities have been discovered in the chromium web browser. CVE-2013-6653 Khalil Zhani discovered a use-after-free issue in chromium's web contents color chooser. CVE-2013-6654 TheShow3511 discovered an issue in SVG handling. CVE-2013-6655 cloudfuzzer discovered a use-after-free issue in dom event handling. CVE-2013-6656 NeexEmil discovered an information leak in the XSS auditor. CVE-2013-6657 NeexEmil discovered a way to bypass the Same Origin policy in the XSS auditor. CVE-2013-6658 cloudfuzzer discovered multiple use-after-free issues surrounding the updateWidgetPositions function. CVE-2013-6659 Antoine Delignat-Lavaud and Karthikeyan Bhargavan discovered that it was possible to trigger an unexpected certificate chain during TLS renegotiation. CVE-2013-6660 bishopjeffreys discovered an information leak in the drag and drop implementation. CVE-2013-6661 The Google Chrome team discovered and fixed multiple issues in version 33.0.1750.117. CVE-2013-6663 Atte Kettunen discovered a use-after-free issuein SVG handling. CVE-2013-6664 Khalil Zhani discovered a use-after-free issue in the speech recognition feature. CVE-2013-6665 cloudfuzzer discovered a buffer overflow issue in the software renderer. CVE-2013-6666 netfuzzer discovered a restriction bypass in the Pepper Flash plugin. CVE-2013-6667 The Google Chrome team discovered and fixed multiple issues in version 33.0.1750.146. CVE-2013-6668 Multiple vulnerabilities were fixed in version 3.24.35.10 of the V8 javascript library. CVE-2014-1700 Chamal de Silva discovered a use-after-free issue in speech synthesis. CVE-2014-1701 aidanhs discovered a cross-site scripting issue in event handling. CVE-2014-1702 Colin Payne discovered a use-after-free issue in the web database implementation. CVE-2014-1703 VUPEN discovered a use-after-free issue in web sockets that could lead to a sandbox escape. CVE-2014-1704 Multiple vulnerabilities were fixed in version 3.23.17.18 of the V8 javascript library. CVE-2014-1705 A memory corruption issue was discovered in the V8 javascript library. CVE-2014-1713 A use-after-free issue was discovered in the AttributeSetter function. CVE-2014-1715 A directory traversal issue was found and fixed. For the stable distribution (wheezy), these problems have been fixed in version 33.0.1750.152-1~deb7u1. For the testing distribution (jessie), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 33.0.1750.152-1. We recommend that you upgrade your chromium-browser packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical patches released for the webkit-browser addressing several vulnerabilities needing prompt action.. Debian Chromium Security Flaws, BrowserVulnerability Update, Web Browser Patches. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 24, 2014 Critical Debian
172

Ubuntu 10.04 and 10.10 USN-998-1 Critical: Thunderbird Code Execution

Paul Nickerson, Jesse Ruderman, Olli Pettay, Igor Bukanov, Josh Soref, Gary Kwong, Martijn Wargers, Siddharth Agarwal and Michal Zalewski discovered various flaws in the browser engine. An attacker could exploit this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. (CVE-2010-3175, CVE-2010-3176) [More...]. ==========================================================Ubuntu Security Notice USN-998-1 October 20, 2010 thunderbird vulnerabilities CVE-2010-3175, CVE-2010-3176, CVE-2010-3178, CVE-2010-3179, CVE-2010-3180, CVE-2010-3182, CVE-2010-3183 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 10.04 LTS Ubuntu 10.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 10.04 LTS: thunderbird 3.0.9+build1+nobinonly-0ubuntu0.10.04.1 Ubuntu 10.10: thunderbird 3.1.5+build1+nobinonly-0ubuntu0.10.10.1 After a standard system update you need to restart Thunderbird to make all the necessary changes. Details follow: Paul Nickerson, Jesse Ruderman, Olli Pettay, Igor Bukanov, Josh Soref, Gary Kwong, Martijn Wargers, Siddharth Agarwal and Michal Zalewski discovered various flaws in the browser engine. An attacker could exploit this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. (CVE-2010-3175, CVE-2010-3176) Alexander Miller, Sergey Glazunov, and others discovered several flaws in the JavaScript engine. If JavaScript were enabled, an attacker could exploit this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. (CVE-2010-3179, CVE-2010-3180, CVE-2010-3183) Eduardo Vela Nava discovered that Thunderbird could be made to violate the same-origin policy by using modal calls with JavaScript. If JavaScriptwere enabled, an attacker could exploit this to steal information from another site. (CVE-2010-3178) Dmitri GribenkoDmitri Gribenko discovered that Thunderbird did not properly setup the LD_LIBRARY_PATH environment variable. A local attacker could exploit this to execute arbitrary code as the user invoking the program. (CVE-2010-3182) Updated packages for Ubuntu 10.04 LTS: Source archives: Size/MD5: 95097 3b820b97dccc465ea044b7a272fdc8d9 Size/MD5: 2412 387aa374c72b37d99e7e318b8e43acbf Size/MD5: 60899014 7d2be2a088f8b4206907b15c864eed52 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 64192710 d8b9db9d05a778aeec350ff7c7ea74a4 Size/MD5: 5771404 dd7e6b456234ac984e492046c5640225 Size/MD5: 149136 2bb12625422eaa66380afc63abf6705d Size/MD5: 9300 fb69d2b349444b85014ab90278fe247c Size/MD5: 11417872 a8614d1abad929d534157c00f70bbb3a i386 architecture (x86 compatible Intel/AMD): Size/MD5: 64523832 6f5f6303f3bae014e5b38ea431ce72c3 Size/MD5: 5834496 ebdaf198d5e461b79cbff7c65870ae93 Size/MD5: 148276 4b96fd44790a55884ab7d965264b3212 Size/MD5: 9290 efaad1dfc9ac1164d389406f09f374a6 Size/MD5: 10456058 43be1c1e3e25086e4194c65ee9d80f51 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 67174194 fd9e7d09bde7484758afbbf853a3d303 Size/MD5: 5240444 d9f5eab1821399e37802f2559f299f6d Size/MD5: 153468 73f3e25ed341c29828b9b37d1e8fb142 Size/MD5: 9304 6da40fbea8cdcebf9c7321001625d78e Size/MD5: 11271328 00b609e4563a886410eb81862a2c759b sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 63719158 b75221c3b7ef3a7066100877a538d5e3 Size/MD5: 5220982 d75dcceefe7a3aaa20feecdee56815a9 Size/MD5: 144390 b635c9ecfe7a71057e5e1037423055c6 Size/MD5: 9296 a3b49ba9e351f50b756c0966b738ee3f Size/MD5: 10529270f5c48a60fef599ed65b3f7b2ee155e99 Updated packages for Ubuntu 10.10: Source archives: Size/MD5: 98089 6bcacb112e75b1ea6d1f2c03e42a2655 Size/MD5: 2468 f92fc2b8b92cf814986e0b9b79019510 Size/MD5: 66546029 359e65546b29fb7e417637291393f104 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 62603474 6cb66cd9627f6b2421d213cc541098cf Size/MD5: 5006090 9a0a610fa02d7bb35aa36d5eb404d156 Size/MD5: 181308 1867a97e101e7f97f7ae6ccabc98e1b9 Size/MD5: 9384 3f0d409e02f351c6362da9ddc12f1e05 Size/MD5: 12042310 2d7a2e4ca18e79775b58ee9f03512a3a i386 architecture (x86 compatible Intel/AMD): Size/MD5: 63136006 64326c4d59ff770b9dae52e2b16d4eb2 Size/MD5: 5143614 82b15cecbe0d1602421238f034f5008f Size/MD5: 180446 9c269d8f53b3bc6e715c793717660c91 Size/MD5: 9376 9fba11d210e9364c2f8914cf4e28e23e Size/MD5: 11061068 a5d79a92d1a504caa03f5b5d3a646af7 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 65395550 60846228807534f5aafcd1f85809c51d Size/MD5: 4978992 dac3232b41d546f4bdeadcbb715e49e8 Size/MD5: 187102 ba03adced0f96c0fe84b3dc2edf59636 Size/MD5: 9382 42871e6a679dfcb0403c3d0fd73e3cf3 Size/MD5: 11745480 97c701050c6da23044085945a2bac2a6 . Explore the security notification USN-999-2 that highlights several vulnerabilities in Thunderbird, enabling the possibility of code execution.. Thunderbird Security, Ubuntu Advisory, Code Execution Flaws, Browser Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 20, 2010 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here