Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
202

openSUSE: Advisory for Moderate Buffer Logic Error CVE-2025-13654

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for duc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0496-1 Rating: moderate References: #1254566 Cross-References: CVE-2025-13654 CVSS scores: CVE-2025-13654 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for duc fixes the following issues: Update to 1.4.6: * new: added LICENCE to 'make release' target * fix: fixed logic error in buffer_get() (boo#1254566, CVE-2025-13654) * cha: updated tests Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-496=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): duc-1.4.6-bp156.3.3.1 References: https://www.suse.com/security/cve/CVE-2025-13654.html https://bugzilla.suse.com/1254566 . Moderate security advisory for openSUSE fixing buffer error in duc. Install patch promptly to mitigate risks.. openSUSE Security Update, duc application, buffer overflow fix. . LinuxSecurity.com Team

Calendar%202 Dec 31, 2025 OpenSUSE
202

openSUSE: duc Moderate Buffer Logic Error Patch CVE-2025-13654

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for duc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0487-1 Rating: moderate References: #1254566 Cross-References: CVE-2025-13654 CVSS scores: CVE-2025-13654 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for duc fixes the following issues: Update to 1.4.6: * new: added LICENCE to 'make release' target * fix: fixed logic error in buffer_get() (boo#1254566, CVE-2025-13654) * cha: updated tests Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2025-487=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): duc-1.4.6-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2025-13654.html https://bugzilla.suse.com/1254566 . Update available for duc with moderate severity fixing a buffer logic error in openSUSE Backports SLE-15-SP7.. duc security update, openSUSE moderate patch, buffer logic error, openSUSE Backports, software update. . LinuxSecurity.com Team

Calendar%202 Dec 26, 2025 OpenSUSE
202

openSUSE: 2020:0784-1 Moderate Fix for Xawtv Buffer Overflow Issue

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for xawtv ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0784-1 Rating: moderate References: #1171655 Cross-References: CVE-2020-13696 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for xawtv fixes the following issues: - CVE-2020-13696: Fixed an issue in setuid-root program that which could have allowed arbitrary file existence tests and open() with O_RDWR (boo#1171655). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-784=1 Package List: - openSUSE Leap 15.1 (x86_64): alevtd-3.103-lp151.3.3.1 alevtd-debuginfo-3.103-lp151.3.3.1 motv-3.103-lp151.3.3.1 motv-debuginfo-3.103-lp151.3.3.1 pia-3.103-lp151.3.3.1 pia-debuginfo-3.103-lp151.3.3.1 tv-common-3.103-lp151.3.3.1 tv-common-debuginfo-3.103-lp151.3.3.1 v4l-conf-3.103-lp151.3.3.1 v4l-conf-debuginfo-3.103-lp151.3.3.1 v4l-tools-3.103-lp151.3.3.1 v4l-tools-debuginfo-3.103-lp151.3.3.1 xawtv-3.103-lp151.3.3.1 xawtv-debuginfo-3.103-lp151.3.3.1 xawtv-debugsource-3.103-lp151.3.3.1 References: https://www.suse.com/security/cve/CVE-2020-13696.html https://bugzilla.suse.com/1171655 -- . openSUSE Security Patch resolves xawtv vulnerabilities. Moderate severity related to CVE-2020-13696 impacting openSUSE Leap 15.1.. OpenSUSE Update, Xawtv Fix, Security Patch. . LinuxSecurity.com Team

Calendar%202 Jun 08, 2020 OpenSUSE
98

Red Hat Enterprise Linux: RHSA-2019-2196-01 Low: zziplib Memory Leak

An update for zziplib is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: zziplib security update Advisory ID: RHSA-2019:2196-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:2196 Issue date: 2019-08-06 CVE Names: CVE-2018-6541 CVE-2018-16548 ==================================================================== 1. Summary: An update for zziplib is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The zziplib is a lightweight library to easily extract data from zip files. Security Fix(es): * zziplib: Bus error caused by loading of a misaligned address inzzip/zip.c (CVE-2018-6541) * zziplib: Memory leak triggered in the function __zzip_parse_root_directory in zip.c (CVE-2018-16548) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and otherrelated information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1598244 - CVE-2018-6541 zziplib: Bus error caused by loading of a misaligned address inzzip/zip.c 1626200 - CVE-2018-16548 zziplib: Memory leak triggered in the function __zzip_parse_root_directory in zip.c 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: zziplib-0.13.62-11.el7.src.rpm x86_64: zziplib-0.13.62-11.el7.i686.rpm zziplib-0.13.62-11.el7.x86_64.rpm zziplib-debuginfo-0.13.62-11.el7.i686.rpm zziplib-debuginfo-0.13.62-11.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: zziplib-debuginfo-0.13.62-11.el7.i686.rpm zziplib-debuginfo-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62-11.el7.i686.rpm zziplib-devel-0.13.62-11.el7.x86_64.rpm zziplib-utils-0.13.62-11.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): Source: zziplib-0.13.62-11.el7.src.rpm x86_64: zziplib-0.13.62-11.el7.i686.rpm zziplib-0.13.62-11.el7.x86_64.rpm zziplib-debuginfo-0.13.62-11.el7.i686.rpm zziplib-debuginfo-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62-11.el7.i686.rpm zziplib-devel-0.13.62-11.el7.x86_64.rpm zziplib-utils-0.13.62-11.el7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: zziplib-0.13.62-11.el7.src.rpm ppc64: zziplib-0.13.62-11.el7.ppc.rpm zziplib-0.13.62-11.el7.ppc64.rpm zziplib-debuginfo-0.13.62-11.el7.ppc.rpm zziplib-debuginfo-0.13.62-11.el7.ppc64.rpm ppc64le: zziplib-0.13.62-11.el7.ppc64le.rpm zziplib-debuginfo-0.13.62-11.el7.ppc64le.rpm s390x: zziplib-0.13.62-11.el7.s390.rpm zziplib-0.13.62-11.el7.s390x.rpm zziplib-debuginfo-0.13.62-11.el7.s390.rpm zziplib-debuginfo-0.13.62-11.el7.s390x.rpm x86_64: zziplib-0.13.62-11.el7.i686.rpm zziplib-0.13.62-11.el7.x86_64.rpm zziplib-debuginfo-0.13.62-11.el7.i686.rpm zziplib-debuginfo-0.13.62-11.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64: zziplib-debuginfo-0.13.62-11.el7.ppc.rpm zziplib-debuginfo-0.13.62-11.el7.ppc64.rpm zziplib-devel-0.13.62-11.el7.ppc.rpm zziplib-devel-0.13.62-11.el7.ppc64.rpm zziplib-utils-0.13.62-11.el7.ppc64.rpm ppc64le: zziplib-debuginfo-0.13.62-11.el7.ppc64le.rpm zziplib-devel-0.13.62-11.el7.ppc64le.rpm zziplib-utils-0.13.62-11.el7.ppc64le.rpm s390x: zziplib-debuginfo-0.13.62-11.el7.s390.rpm zziplib-debuginfo-0.13.62-11.el7.s390x.rpm zziplib-devel-0.13.62-11.el7.s390.rpm zziplib-devel-0.13.62-11.el7.s390x.rpm zziplib-utils-0.13.62-11.el7.s390x.rpm x86_64: zziplib-debuginfo-0.13.62-11.el7.i686.rpm zziplib-debuginfo-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62-11.el7.i686.rpm zziplib-devel-0.13.62-11.el7.x86_64.rpm zziplib-utils-0.13.62-11.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: zziplib-0.13.62-11.el7.src.rpm x86_64: zziplib-0.13.62-11.el7.i686.rpm zziplib-0.13.62-11.el7.x86_64.rpm zziplib-debuginfo-0.13.62-11.el7.i686.rpm zziplib-debuginfo-0.13.62-11.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: zziplib-debuginfo-0.13.62-11.el7.i686.rpm zziplib-debuginfo-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62-11.el7.i686.rpm zziplib-devel-0.13.62-11.el7.x86_64.rpm zziplib-utils-0.13.62-11.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signatureare available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-6541 https://access.redhat.com/security/cve/CVE-2018-16548 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.7_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXUl3FNzjgjWX9erEAQgVmg/+JynnJaPR/txFrs8465aBCCgNClnVGzIr uSBcteZg76uMI+QPu8UhZ1ig+tCmIhXDCoStyExkGTp/KQXceHhELCEMgWPpHT/I XnV6NXz1IyHJFa3r8eT3GTzXuPfCsT56DgKg/UCj/EYY+k+DgsbFPXxvcQ0DJugM 6a/vWSN8S7RxcxZEnsN1dyiewAxSYIh7lyUzSMKoR8R96KYF2NLgTbEqZIjvsmjp J6MLDt9JUeYczy4s/T6c1fqFM+r0mQoMGmq2jmDAMb6YAWP1kXbqo6zayUhhs2U4 NN/t6fUD1nCAygL7ncffRlqx3aw7fY619jyTYfe4HGJ5i8GEWaNS1Y8oRUlHkKnW woysHAvL3hZKIVhFthFbMNNnvNWgN3+JuZwNLvi4yCRmuPS5MjFBztvtPlK50CtS oP7fzVJxp/0xd0EjZW13XPC1HCcdEDcFizz1n8NU63LiX/BoVTYqNlrSrY/fK8+V H68YNnlhBseY1PwT6KptBHuqHfdYXms5QcQz3DjruYzjAXYSddmRrnrO/xzmyDFs sYEBcxlSDgpdKkbXKOclvbdGeKFI+SEp++KR5XEBjL8QfeWPfc9jAvDEEO1zNKO5 1QyiOZL8JQG8JX5RCPwbqsZVzTaruz8XZjMSUu95E0uo+/KwJ+yNrKYYlGyGjv73 OAnZLaaMoUw=2Rya -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian enhances libdb for its Stable release with minor patches addressing performance concerns related to data handling and resource allocation.. zziplib security update, Red Hat advisory, Linux 7 security, memory leak fix, buffer error. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Aug 06, 2019 Low Red Hat
197

Debian Jessie: DLA-1730-4 Critical: libssh2 Buffer Error Fix

Several more boundary checks have been backported to libssh2's src/sftp.c. Furthermore, all boundary checks in src/sftp.c now result in an LIBSSH2_ERROR_BUFFER_TOO_SMALL error code, rather than a . Package : libssh2 Version : 1.4.3-4.1+deb8u5 CVE ID : CVE-2019-3860 Several more boundary checks have been backported to libssh2's src/sftp.c. Furthermore, all boundary checks in src/sftp.c now result in an LIBSSH2_ERROR_BUFFER_TOO_SMALL error code, rather than a LIBSSH2_ERROR_ OUT_OF_BOUNDARY error code. As a side note, it was discovered that libssh2's SFTP implementation from Debian jessie only works well against OpenSSH SFTP servers from Debian wheezy, tests against newer OpenSSH versions (such as available in Debian jessie and beyond) interim-fail with SFTP protocol error "Error opening remote file". Operation might continue after this error, this depends on application implementations. For Debian 8 "Jessie", this problem has been fixed in version 1.4.3-4.1+deb8u5. We recommend that you upgrade your libssh2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail: This email address is being protected from spambots. You need JavaScript enabled to view it., https://sunweavers.net/ . Enhance your Debian 8 security by updating the libssh2 package to fix CVE-2019-3860 buffer errors. Follow the provided steps to upgrade safely. libssh2 Update,debian security advisory,SFTP Fix,buffer overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 30, 2019 Critical Debian LTS
100

SUSE: 2015:0371-1 Important Samba CVE-2015-0240 Buffer Error

An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes is now available. is now available.. SUSE Security Update: Security update for Samba ______________________________________________________________________________ Announcement ID: SUSE-SU-2015:0371-1 Rating: important References: #872912 #898031 #899558 #913001 #917376 Cross-References: CVE-2015-0240 Affected Products: SUSE Linux Enterprise Software Development Kit 11 SP3 SUSE Linux Enterprise Server 11 SP3 for VMware SUSE Linux Enterprise Server 11 SP3 SUSE Linux Enterprise Desktop 11 SP3 ______________________________________________________________________________ An update that solves one vulnerability and has four fixes is now available. Description: Samba has been updated to fix one security issue: * CVE-2015-0240: Don't call talloc_free on an uninitialized pointer (bnc#917376). Additionally, these non-security issues have been fixed: * Realign the winbind request structure following require_membership_of field expansion (bnc#913001). * Reuse connections derived from DFS referrals (bso#10123, fate#316512). * Set domain/workgroup based on authentication callback value (bso#11059). * Fix spoolss error response marshalling (bso#10984). * Fix spoolss EnumJobs and GetJob responses (bso#10905, bnc#898031). * Fix handling of bad EnumJobs levels (bso#10898). * Fix small memory-leak in the background print process; (bnc#899558). * Prune idle or hung connections older than "winbind request timeout" (bso#3204, bnc#872912). Security Issues: * CVE-2015-0240 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the commandlisted for your product: - SUSE Linux Enterprise Software Development Kit 11 SP3: zypper in -t patch sdksp3-samba-20150217=10321 - SUSE Linux Enterprise Server 11 SP3 for VMware: zypper in -t patch slessp3-samba-20150217=10321 - SUSE Linux Enterprise Server 11 SP3: zypper in -t patch slessp3-samba-20150217=10321 - SUSE Linux Enterprise Desktop 11 SP3: zypper in -t patch sledsp3-samba-20150217=10321 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11 SP3 (i586 ia64 ppc64 s390x x86_64): libldb-devel-3.6.3-0.56.1 libnetapi-devel-3.6.3-0.56.1 libnetapi0-3.6.3-0.56.1 libsmbclient-devel-3.6.3-0.56.1 libsmbsharemodes-devel-3.6.3-0.56.1 libsmbsharemodes0-3.6.3-0.56.1 libtalloc-devel-3.6.3-0.56.1 libtdb-devel-3.6.3-0.56.1 libtevent-devel-3.6.3-0.56.1 libwbclient-devel-3.6.3-0.56.1 samba-devel-3.6.3-0.56.1 - SUSE Linux Enterprise Server 11 SP3 for VMware (i586 x86_64): ldapsmb-1.34b-12.56.1 libldb1-3.6.3-0.56.1 libsmbclient0-3.6.3-0.56.1 libtalloc2-3.6.3-0.56.1 libtdb1-3.6.3-0.56.1 libtevent0-3.6.3-0.56.1 libwbclient0-3.6.3-0.56.1 samba-3.6.3-0.56.1 samba-client-3.6.3-0.56.1 samba-krb-printing-3.6.3-0.56.1 samba-winbind-3.6.3-0.56.1 - SUSE Linux Enterprise Server 11 SP3 for VMware (x86_64): libsmbclient0-32bit-3.6.3-0.56.1 libtalloc2-32bit-3.6.3-0.56.1 libtdb1-32bit-3.6.3-0.56.1 libtevent0-32bit-3.6.3-0.56.1 libwbclient0-32bit-3.6.3-0.56.1 samba-32bit-3.6.3-0.56.1 samba-client-32bit-3.6.3-0.56.1 samba-winbind-32bit-3.6.3-0.56.1 - SUSE Linux Enterprise Server 11 SP3 for VMware (noarch): samba-doc-3.6.3-0.56.1 - SUSE Linux Enterprise Server 11 SP3 (i586 ia64 ppc64 s390x x86_64): ldapsmb-1.34b-12.56.1 libldb1-3.6.3-0.56.1 libsmbclient0-3.6.3-0.56.1 libtalloc2-3.6.3-0.56.1 libtdb1-3.6.3-0.56.1 libtevent0-3.6.3-0.56.1 libwbclient0-3.6.3-0.56.1 samba-3.6.3-0.56.1 samba-client-3.6.3-0.56.1 samba-krb-printing-3.6.3-0.56.1 samba-winbind-3.6.3-0.56.1 - SUSE Linux Enterprise Server 11 SP3 (ppc64 s390x x86_64): libsmbclient0-32bit-3.6.3-0.56.1 libtalloc2-32bit-3.6.3-0.56.1 libtdb1-32bit-3.6.3-0.56.1 libtevent0-32bit-3.6.3-0.56.1 libwbclient0-32bit-3.6.3-0.56.1 samba-32bit-3.6.3-0.56.1 samba-client-32bit-3.6.3-0.56.1 samba-winbind-32bit-3.6.3-0.56.1 - SUSE Linux Enterprise Server 11 SP3 (noarch): samba-doc-3.6.3-0.56.1 - SUSE Linux Enterprise Server 11 SP3 (ia64): libsmbclient0-x86-3.6.3-0.56.1 libtalloc2-x86-3.6.3-0.56.1 libtdb1-x86-3.6.3-0.56.1 libwbclient0-x86-3.6.3-0.56.1 samba-client-x86-3.6.3-0.56.1 samba-winbind-x86-3.6.3-0.56.1 samba-x86-3.6.3-0.56.1 - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64): libldb1-3.6.3-0.56.1 libsmbclient0-3.6.3-0.56.1 libtalloc2-3.6.3-0.56.1 libtdb1-3.6.3-0.56.1 libtevent0-3.6.3-0.56.1 libwbclient0-3.6.3-0.56.1 samba-3.6.3-0.56.1 samba-client-3.6.3-0.56.1 samba-krb-printing-3.6.3-0.56.1 samba-winbind-3.6.3-0.56.1 - SUSE Linux Enterprise Desktop 11 SP3 (x86_64): libldb1-32bit-3.6.3-0.56.1 libsmbclient0-32bit-3.6.3-0.56.1 libtalloc2-32bit-3.6.3-0.56.1 libtdb1-32bit-3.6.3-0.56.1 libtevent0-32bit-3.6.3-0.56.1 libwbclient0-32bit-3.6.3-0.56.1 samba-32bit-3.6.3-0.56.1 samba-client-32bit-3.6.3-0.56.1 samba-winbind-32bit-3.6.3-0.56.1 - SUSE Linux Enterprise Desktop 11 SP3 (noarch): samba-doc-3.6.3-0.56.1 References: https://www.suse.com/security/cve/CVE-2015-0240.html https://bugzilla.suse.com/show_bug.cgi?id=872912 https://bugzilla.suse.com/show_bug.cgi?id=898031 https://bugzilla.suse.com/show_bug.cgi?id=899558 https://bugzilla.suse.com/show_bug.cgi?id=913001 https://bugzilla.suse.com/show_bug.cgi?id=917376 https://scc.suse.com:443/patches/ . SUSE Security Update for OpenSSL corrects CVE-2016-2107, along with solutions for general bugs and guidelines for setup.. Samba Security Update, SUSE Advisory, Samba CVE, Software Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 25, 2015 Important SuSE
100

SUSE Linux 11 SP2: 2013:0434-1 Critical: Java Remote Execution

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.. SUSE Security Update: Security update for Java ______________________________________________________________________________ Announcement ID: SUSE-SU-2013:0434-1 Rating: critical References: #807487 Cross-References: CVE-2013-0809 CVE-2013-1493 Affected Products: SUSE Linux Enterprise Desktop 11 SP2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This release of Icedtea6-1.12.4 fixes the following two issues that allowed a remote attacker to execute arbitrary code remotely by providing crafted images to the affected code. * CVE-2013-0809: CVSS v2 Base Score: 6.8 (critical) (AV:N/AC:M/Au:N/C:P/I:P/A:P): Insufficient Information (CWE-noinfo) * CVE-2013-1493: CVSS v2 Base Score: 6.8 (critical) (AV:N/AC:M/Au:N/C:P/I:P/A:P): Buffer Errors (CWE-119) Security Issue references: * CVE-2013-0809 * CVE-2013-1493 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Desktop 11 SP2: zypper in -t patch sledsp2-java-1_6_0-openjdk-7457 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64): java-1_6_0-openjdk-1.6.0.0_b27.1.12.4-0.2.1 java-1_6_0-openjdk-demo-1.6.0.0_b27.1.12.4-0.2.1 java-1_6_0-openjdk-devel-1.6.0.0_b27.1.12.4-0.2.1 References: https://www.suse.com/security/cve/CVE-2013-0809.html https://www.suse.com/security/cve/CVE-2013-1493.html . SUSE Security Patch addresses severe flaws in Java impacting SUSE Linux systems. Information regarding execution and memory overflow vulnerabilities..SUSE Linux Java Patch, Remote Code Execution, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 12, 2013 Critical SuSE
100

SUSE: 2011:001 Moderate: DoS Issues In Various Packages

To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Summary Report Announcement ID: SUSE-SR:2011:001 Date: Tue, 11 Jan 2011 10:00:00 +0000 Cross-References: CVE-2010-1455, CVE-2010-2283, CVE-2010-2284 CVE-2010-2285, CVE-2010-2286, CVE-2010-2287 CVE-2010-2761, CVE-2010-2891, CVE-2010-2992 CVE-2010-2993, CVE-2010-2994, CVE-2010-2995 CVE-2010-3445, CVE-2010-3912, CVE-2010-4180 CVE-2010-4254, CVE-2010-4300, CVE-2010-4301 CVE-2010-4528 Content of this advisory: 1) Solved Security Vulnerabilities: - finch/pidgin - libmoon-devel/moonlight-plugin - libsmi - openssl - perl-CGI-Simple - supportutils - wireshark 2) Pending Vulnerabilities, Solutions, and Work-Arounds: none 3) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Solved Security Vulnerabilities To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Security Announcements that are releasedfor more severe vulnerabilities. Fixed packages for the following incidents are already available on our FTP server and via the YaST Online Update. - finch/pidgin A NULL pointer dereference DoS has been fixed in pidgin. CVE-2010-4528 has been assigned to this issue. Affected products: openSUSE 11.2-11.3 - libmoon-devel/moonlight-plugin Untrusted Moonlight apps could bypass constraints on methods which potentially allowed attackers to execute arbitrary code (CVE-2010-4254). Affected products: SLE11-SP1 - libsmi This update fixes a buffer overflow the smiGetNode() function in libsmi. It allowed context-dependent attackers to execute arbitrary code via an Object Identifier. CVE-2010-2891: CVSS v2 Base Score: 7.5 (HIGH) (AV:N/AC:L/Au:N/C:P/I:P/A:P): Buffer Errors (CWE-119) Affected products: openSUSE 11.1-11.3 - openssl Malicious clients could downgrade a connection to a low strength cipher suite on session resumption if the server offers such ciphers (CVE-2010-4180). Affected products: openSUSE 11.1-11.3, SLE11-SP1 - perl-CGI-Simple A HTTP header injection attack was fixed in perl-CGI-Simple. CVE-2010-2761 has been assigned to this issue. Affected products: openSUSE 11.2-11.3 - supportutils the supportconfig script did not disguise passwords in the config files it collected (CVE-2010-3912). Affected products: SLE11-SP1, SLE10-SP3 - wireshark Wireshark version 1.4.2 fixes several security issues that allowed attackers to crash wireshark or potentially even execute arbitrary code (CVE-2010-1455, CVE-2010-2283, CVE-2010-2284, CVE-2010-2285, CVE-2010-2286, CVE-2010-2287, CVE-2010-2992, CVE-2010-2993, CVE-2010-2994, CVE-2010-2995, CVE-2010-3445, CVE-2010-4300, CVE-2010-4301) Affected products: openSUSE 11.1 ______________________________________________________________________________ 2) Pending Vulnerabilities, Solutions,and Work-Arounds none ______________________________________________________________________________ 3) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file containing the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and integrity of a package needs to be verified to ensure that it has not been tampered with. The internal RPM package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from This email address is being protected from spambots. You need JavaScript enabled to view it. with the key ID 9C800ACA. This key is automatically imported into the RPM database (on RPMv4-based distributions) and the gpg key ring of 'root' during installation. You can also find it on the firstinstallation CD and included at the end of this announcement. - SUSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - General Linux and SUSE security discussion. All SUSE security announcements are sent to this list. To subscribe, send an e-mail to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SUSE's announce-only mailing list. Only SUSE's security announcements are sent to this list. To subscribe, send an e-mail to . ==================================================================== SUSE's security contact is or . The public key is listed below. ==================================================================== . Stay informed about the latest CVE Security Overview with Announcement ID: SEC-CVE:2023:005, released on Wed, 15 Mar 2023 at 14:00. SUSE Security, OpenSUSE Updates, Security Summary, Vulnerability Patches. . LinuxSecurity.com Team

Calendar%202 Jan 11, 2011 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200