Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
100

SUSE 15 SP6: 2024:4291-1 critical: python312 unbounded memory

* bsc#1231795 * bsc#1234290 Cross-References: * CVE-2024-12254 . # Security update for python312 Announcement ID: SUSE-SU-2024:4291-1 Release Date: 2024-12-11T11:24:51Z Rating: important References: * bsc#1231795 * bsc#1234290 Cross-References: * CVE-2024-12254 CVSS scores: * CVE-2024-12254 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-12254 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-12254 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for python312 fixes the following issues: * CVE-2024-12254: Fixed unbounded memory buffering in SelectorSocketTransport.writelines() (bsc#1234290) Other fixes: \- Updated to version 3.12.8 \- Remove -IVendor/ from python-config (bsc#1231795) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-4291=1 openSUSE-SLE-15.6-2024-4291=1 * Python 3 Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Python3-15-SP6-2024-4291=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * python312-doc-devhelp-3.12.8-150600.3.12.1 * python312-tools-3.12.8-150600.3.12.1 * libpython3_12-1_0-debuginfo-3.12.8-150600.3.12.1 *python312-dbm-debuginfo-3.12.8-150600.3.12.1 * python312-tk-3.12.8-150600.3.12.1 * python312-idle-3.12.8-150600.3.12.1 * python312-base-3.12.8-150600.3.12.1 * python312-curses-3.12.8-150600.3.12.1 * python312-testsuite-debuginfo-3.12.8-150600.3.12.1 * python312-debugsource-3.12.8-150600.3.12.1 * libpython3_12-1_0-3.12.8-150600.3.12.1 * python312-tk-debuginfo-3.12.8-150600.3.12.1 * python312-testsuite-3.12.8-150600.3.12.1 * python312-3.12.8-150600.3.12.1 * python312-curses-debuginfo-3.12.8-150600.3.12.1 * python312-doc-3.12.8-150600.3.12.1 * python312-base-debuginfo-3.12.8-150600.3.12.1 * python312-dbm-3.12.8-150600.3.12.1 * python312-debuginfo-3.12.8-150600.3.12.1 * python312-devel-3.12.8-150600.3.12.1 * python312-core-debugsource-3.12.8-150600.3.12.1 * openSUSE Leap 15.6 (x86_64) * python312-32bit-3.12.8-150600.3.12.1 * libpython3_12-1_0-32bit-debuginfo-3.12.8-150600.3.12.1 * libpython3_12-1_0-32bit-3.12.8-150600.3.12.1 * python312-base-32bit-debuginfo-3.12.8-150600.3.12.1 * python312-32bit-debuginfo-3.12.8-150600.3.12.1 * python312-base-32bit-3.12.8-150600.3.12.1 * openSUSE Leap 15.6 (aarch64_ilp32) * python312-64bit-debuginfo-3.12.8-150600.3.12.1 * libpython3_12-1_0-64bit-debuginfo-3.12.8-150600.3.12.1 * python312-64bit-3.12.8-150600.3.12.1 * python312-base-64bit-3.12.8-150600.3.12.1 * python312-base-64bit-debuginfo-3.12.8-150600.3.12.1 * libpython3_12-1_0-64bit-3.12.8-150600.3.12.1 * Python 3 Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python312-dbm-debuginfo-3.12.8-150600.3.12.1 * python312-tk-debuginfo-3.12.8-150600.3.12.1 * python312-3.12.8-150600.3.12.1 * python312-curses-debuginfo-3.12.8-150600.3.12.1 * python312-debugsource-3.12.8-150600.3.12.1 * python312-tools-3.12.8-150600.3.12.1 * python312-tk-3.12.8-150600.3.12.1 * python312-devel-3.12.8-150600.3.12.1 * python312-curses-3.12.8-150600.3.12.1 *python312-base-debuginfo-3.12.8-150600.3.12.1 * libpython3_12-1_0-3.12.8-150600.3.12.1 * python312-idle-3.12.8-150600.3.12.1 * python312-dbm-3.12.8-150600.3.12.1 * python312-debuginfo-3.12.8-150600.3.12.1 * python312-core-debugsource-3.12.8-150600.3.12.1 * python312-base-3.12.8-150600.3.12.1 * libpython3_12-1_0-debuginfo-3.12.8-150600.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12254.html * https://bugzilla.suse.com/show_bug.cgi?id=1231795 * https://bugzilla.suse.com/show_bug.cgi?id=1234290 . The recent security notice for python312 underscores significant vulnerabilities and enhancements for SUSE offerings, taking effect on December 11, 2024.. python312 security update,SUSE advisory,buffering issue fix,SUSE Linux application. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 11, 2024 Critical SuSE
89

Fedora 37: FEDORA-2022-08fdc4138a Critical: WebKitGTK Software Update

* Fix scrolling issues in some sites having fixed background. * Fix prolonged buffering during progressive live playback. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-42799, CVE-2022-42823, CVE-2022-42824. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-08fdc4138a 2022-11-09 00:09:40.867638 --------------------------------------------------------------------------------Name : webkitgtk Product : Fedora 37 Version : 2.38.2 Release : 1.fc37 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. --------------------------------------------------------------------------------Update Information: * Fix scrolling issues in some sites having fixed background. * Fix prolonged buffering during progressive live playback. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-42799, CVE-2022-42823, CVE-2022-42824 --------------------------------------------------------------------------------ChangeLog: * Fri Nov 4 2022 Michael Catanzaro 2.38.2-1 - Update to 2.38.2 --------------------------------------------------------------------------------References: [ 1 ] Bug #2140194 - Freeze exception for WebKitGTK 2.38.2 https://bugzilla.redhat.com/show_bug.cgi?id=2140194 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-08fdc4138a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Improvements in Fedora 37's webkitgtk 2.38.2 address scrolling, buffering challenges, and bolster security measures, leading to better overall performance.. webkitgtk updates, Fedora 37 security, software fixes, performance improvements. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 08, 2022 Critical Fedora
89

Fedora 33: 2021-09272cf059 Moderate: OpenJDK Buffering Issues Fix

# New in release OpenJDK 8u282 (2021-01-19) Live versions of these release notes can be found at: * https://mail.openjdk.org/pipermail/jdk8u-dev/2021-January/013337.html * https://builds.shipilev.net/backports-monitor/release-notes-openjdk8u282.txt ## Security fixes * JDK-8247619: Improve Direct Buffering of Characters ## Other changes * [JDK-8230839](https://bugs.openjdk.org/browse/JDK-8230839):. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-09272cf059 2021-02-11 01:42:27.185532 --------------------------------------------------------------------------------Name : java-1.8.0-openjdk Product : Fedora 33 Version : 1.8.0.282.b08 Release : 0.fc33 URL : https://openjdk.org/ Summary : OpenJDK 8 Runtime Environment Description : The OpenJDK 8 runtime environment. --------------------------------------------------------------------------------Update Information: # New in release OpenJDK 8u282 (2021-01-19) Live versions of these release notes can be found at: * https://mail.openjdk.org/pipermail/jdk8u-dev/2021-January/013337.html * https://builds.shipilev.net/backports-monitor/release-notes-openjdk8u282.txt ## Security fixes * JDK-8247619: Improve Direct Buffering of Characters ## Other changes * [JDK-8230839](https://bugs.openjdk.org/browse/JDK-8230839): Updated XML Signature Implementation to Apache Santuario 2.1.3, adding support for embedding elliptic curve public keys in the KeyValue element * Default to RSA when using keytool, as DSA is only supported by the LEGACY crypto policy. * Make java-1.8.0-openjdk-demo own its directories as well as its files --------------------------------------------------------------------------------ChangeLog: * Sat Jan 30 2021 Andrew Hughes - 1:1.8.0.282.b08-0 - Update to aarch64-shenandoah-jdk8u282-b08 (GA) - Update release notes for 8u282. - Remove PR3601, covered upstream by JDK-8062808. - Remove upstreamed JDK-8197981/PR3548,JDK-8062808/PR3548 & JDK-8254177. - Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 - Adapt JDK-8143245 patch, following JDK-8254166 - Remove upstreamed patch PR3519 - Use RSA as default for keytool, as DSA is disabled in all crypto policies except LEGACY - Add directories to files directive for demo package. - Include a test in the RPM to check the build has the correct vendor information. - Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value. - Cleanup package descriptions and version number placement. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-09272cf059' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . OpenJDK 8u292 is now available featuring important security enhancements and essential patches for Fedora 34 users. Discover more details here.. OpenJDK 8u282, Fedora Update, Java Runtime. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 10, 2021 Important Fedora
203

Mageia: 2020-0367 Moderate: libetpan STARTTLS Data Handling Flaw

LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection". (CVE-2020-15953). . MGASA-2020-0366 - Updated libetpan packages fix a security vulnerability Publication date: 15 Sep 2020 URL: https://advisories.mageia.org/MGASA-2020-0366.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-15953 LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection". (CVE-2020-15953). References: - https://bugs.mageia.org/show_bug.cgi?id=27168 - https://lists.debian.org/debian-lts-announce/2020/08/msg00026.html - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/QFBWNA5REI5ZGW2DAOEAVHM23MOU6O5J/ - https://www.cve.org/CVERecord?id=CVE-2020-15953 SRPMS: - 7/core/libetpan-1.9.3-1.1.mga7 . Mageia announces a libetpan security patch addressing STARTTLS vulnerabilities impacting IMAP, SMTP, and POP3 services.. libetpan, security update, mageia advisory. . LinuxSecurity.com Team

Calendar 2 Sep 15, 2020 Mageia
197

Debian Jessie: DLA-2268-2 Critical: Mutt Man-In-The-Middle Attack

Two vulnerabilities have been discovered in mutt, a console email client. CVE-2020-14093 . Package : mutt Version : 1.5.23-3+deb8u3 CVE ID : CVE-2020-14093 CVE-2020-14954 Debian Bug : Two vulnerabilities have been discovered in mutt, a console email client. CVE-2020-14093 Mutt allowed an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response. CVE-2020-14954 Mutt had a STARTTLS buffering issue that affected IMAP, SMTP, and POP3. When a server had sent a "begin TLS" response, the client read additional data (e.g., from a man-in-the-middle attacker) and evaluated it in a TLS context, aka "response injection." In Debian jessie, the mutt source package builds two variants of mutt: mutt and mutt-patched. The previous package version (1.5.23-3+deb8u2, DLA-2268-1) provided fixes for the issues referenced above, but they were only applied for the mutt-patched package build, not for the (vanilla) mutt package build. For Debian 8 "Jessie", this problem has been fixed in version 1.5.23-3+deb8u3. We recommend that you upgrade your mutt packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail: This email address is being protected from spambots. You need JavaScript enabled to view it., https://sunweavers.net/ . Multiple weaknesses in the mutt mail software, compromising safety from potential eavesdropping threats. Users advised to upgrade.. Debian Mutts Security Update, Mutt Email Client Patch, Debian LTS Advisories. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 30, 2020 Critical Debian LTS
197

Debian 8: DLA-2268-1 Critical: Mutt Man-In-The-Middle Attack

Two vulnerabilities have been discovered in mutt, a console email client. CVE-2020-14093 . Package : mutt Version : 1.5.23-3+deb8u2 CVE ID : CVE-2020-14093 CVE-2020-14954 Debian Bug : 962897 Two vulnerabilities have been discovered in mutt, a console email client. CVE-2020-14093 Mutt allowed an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response. CVE-2020-14954 Mutt had a STARTTLS buffering issue that affected IMAP, SMTP, and POP3. When a server had sent a "begin TLS" response, the client read additional data (e.g., from a man-in-the-middle attacker) and evaluated it in a TLS context, aka "response injection." For Debian 8 "Jessie", these problems have been fixed in version 1.5.23-3+deb8u2. We recommend that you upgrade your mutt packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail: This email address is being protected from spambots. You need JavaScript enabled to view it., https://sunweavers.net/ . A recent Mutt security patch for Debian LTS resolves critical issues in email processing to thwart potential exploits. Users are advised to update promptly.. Mutt Package Update, Email Client Security, Debian LTS Advisory, IMAP Buffering Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 30, 2020 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here