Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 11 articles for you...
172

Ubuntu 24.04 LTS USN-6790-1 Critical Amavisd-New Bypass Issue

amavisd-new could be made to bypass security measures.. ========================================================================== Ubuntu Security Notice USN-6790-1 May 28, 2024 amavisd-new vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: amavisd-new could be made to bypass security measures. Software Description: - amavisd-new: Interface between MTA and virus scanner/content filters Details: It was discovered that amavisd-new incorrectly handled certain MIME email messages with multiple boundary parameters. A remote attacker could possibly use this issue to bypass checks for banned files or malware. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS amavisd-new 1:2.13.0-3ubuntu2 Ubuntu 23.10 amavisd-new 1:2.13.0-3ubuntu1.1 Ubuntu 22.04 LTS amavisd-new 1:2.12.2-1ubuntu1.1 Ubuntu 20.04 LTS amavisd-new 1:2.11.0-6.1ubuntu1.1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6790-1 CVE-2024-28054 Package Information: https://launchpad.net/ubuntu/+source/amavisd-new/1:2.13.0-3ubuntu2 https://launchpad.net/ubuntu/+source/amavisd-new/1:2.13.0-3ubuntu1.1 https://launchpad.net/ubuntu/+source/amavisd-new/1:2.12.2-1ubuntu1.1 https://launchpad.net/ubuntu/+source/amavisd-new/1:2.11.0-6.1ubuntu1.1 . Critical flaw in Amavisd-new lets users evade malware scans on Ubuntu systems. Swift update necessary to bolster security protocols.. Ubuntu Security Notice, Amavisd-New Update, Email Security Threat, Linux Update Process. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 28, 2024 Critical Ubuntu
100

SUSE: 2024:1444-1 Moderate: Fix for PHP7 Bypass Vulnerability Issues

* bsc#1222857 * bsc#1222858 Cross-References: * CVE-2024-2756 . # Security update for php7 Announcement ID: SUSE-SU-2024:1444-1 Rating: moderate References: * bsc#1222857 * bsc#1222858 Cross-References: * CVE-2024-2756 * CVE-2024-3096 CVSS scores: * CVE-2024-2756 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2024-3096 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * Legacy Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Package Hub 15 15-SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for php7 fixes the following issues: * CVE-2024-2756: Fixed bypass of security fix applied for CVE-2022-31629 that lead PHP to consider not secure cookies as secure (bsc#1222857) * CVE-2024-3096: Fixed bypass on null byte leading passwords checked via password_verify (bsc#1222858) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-1444=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-1444=1 * Legacy Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP5-2024-1444=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-1444=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * apache2-mod_php7-debugsource-7.4.33-150400.4.34.1 * php7-gmp-7.4.33-150400.4.34.1 * php7-gettext-7.4.33-150400.4.34.1 * php7-sodium-7.4.33-150400.4.34.1 * php7-embed-debugsource-7.4.33-150400.4.34.1 * php7-posix-debuginfo-7.4.33-150400.4.34.1 * php7-soap-7.4.33-150400.4.34.1 * php7-zip-debuginfo-7.4.33-150400.4.34.1 * php7-xmlreader-7.4.33-150400.4.34.1 * php7-tidy-debuginfo-7.4.33-150400.4.34.1 * php7-dba-debuginfo-7.4.33-150400.4.34.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.34.1 * php7-intl-debuginfo-7.4.33-150400.4.34.1 * php7-cli-debuginfo-7.4.33-150400.4.34.1 * php7-shmop-7.4.33-150400.4.34.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.34.1 * php7-zlib-7.4.33-150400.4.34.1 * php7-7.4.33-150400.4.34.1 * php7-xsl-debuginfo-7.4.33-150400.4.34.1 * php7-bz2-debuginfo-7.4.33-150400.4.34.1 * php7-fastcgi-7.4.33-150400.4.34.1 * php7-curl-debuginfo-7.4.33-150400.4.34.1 * php7-opcache-debuginfo-7.4.33-150400.4.34.1 * php7-iconv-7.4.33-150400.4.34.1 * php7-calendar-7.4.33-150400.4.34.1 * php7-calendar-debuginfo-7.4.33-150400.4.34.1 * php7-exif-7.4.33-150400.4.34.1 * php7-fileinfo-7.4.33-150400.4.34.1 * php7-mbstring-7.4.33-150400.4.34.1 * php7-debuginfo-7.4.33-150400.4.34.1 * php7-bz2-7.4.33-150400.4.34.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.34.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.34.1 * php7-gettext-debuginfo-7.4.33-150400.4.34.1 * php7-iconv-debuginfo-7.4.33-150400.4.34.1 * php7-ftp-debuginfo-7.4.33-150400.4.34.1 * php7-soap-debuginfo-7.4.33-150400.4.34.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.34.1 * php7-readline-debuginfo-7.4.33-150400.4.34.1 * php7-dom-7.4.33-150400.4.34.1 * php7-gd-7.4.33-150400.4.34.1 * php7-ctype-7.4.33-150400.4.34.1 * php7-sqlite-debuginfo-7.4.33-150400.4.34.1 * php7-ftp-7.4.33-150400.4.34.1 * php7-fastcgi-debugsource-7.4.33-150400.4.34.1 * php7-shmop-debuginfo-7.4.33-150400.4.34.1 * php7-phar-debuginfo-7.4.33-150400.4.34.1 * php7-pgsql-7.4.33-150400.4.34.1 * php7-odbc-7.4.33-150400.4.34.1 * php7-zip-7.4.33-150400.4.34.1 *php7-gmp-debuginfo-7.4.33-150400.4.34.1 * php7-zlib-debuginfo-7.4.33-150400.4.34.1 * php7-dba-7.4.33-150400.4.34.1 * php7-exif-debuginfo-7.4.33-150400.4.34.1 * php7-sysvsem-7.4.33-150400.4.34.1 * php7-snmp-debuginfo-7.4.33-150400.4.34.1 * php7-cli-7.4.33-150400.4.34.1 * php7-odbc-debuginfo-7.4.33-150400.4.34.1 * php7-pdo-debuginfo-7.4.33-150400.4.34.1 * php7-devel-7.4.33-150400.4.34.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.34.1 * php7-bcmath-7.4.33-150400.4.34.1 * php7-pcntl-7.4.33-150400.4.34.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.34.1 * php7-snmp-7.4.33-150400.4.34.1 * php7-bcmath-debuginfo-7.4.33-150400.4.34.1 * php7-intl-7.4.33-150400.4.34.1 * php7-embed-debuginfo-7.4.33-150400.4.34.1 * php7-sysvshm-7.4.33-150400.4.34.1 * php7-dom-debuginfo-7.4.33-150400.4.34.1 * php7-mysql-7.4.33-150400.4.34.1 * php7-sockets-7.4.33-150400.4.34.1 * php7-ctype-debuginfo-7.4.33-150400.4.34.1 * php7-pcntl-debuginfo-7.4.33-150400.4.34.1 * php7-fpm-debugsource-7.4.33-150400.4.34.1 * php7-pgsql-debuginfo-7.4.33-150400.4.34.1 * php7-sodium-debuginfo-7.4.33-150400.4.34.1 * php7-embed-7.4.33-150400.4.34.1 * php7-curl-7.4.33-150400.4.34.1 * php7-sockets-debuginfo-7.4.33-150400.4.34.1 * php7-posix-7.4.33-150400.4.34.1 * php7-ldap-7.4.33-150400.4.34.1 * php7-enchant-7.4.33-150400.4.34.1 * php7-mysql-debuginfo-7.4.33-150400.4.34.1 * php7-tokenizer-7.4.33-150400.4.34.1 * php7-enchant-debuginfo-7.4.33-150400.4.34.1 * php7-json-debuginfo-7.4.33-150400.4.34.1 * php7-phar-7.4.33-150400.4.34.1 * php7-xmlrpc-7.4.33-150400.4.34.1 * php7-openssl-debuginfo-7.4.33-150400.4.34.1 * php7-fpm-debuginfo-7.4.33-150400.4.34.1 * apache2-mod_php7-7.4.33-150400.4.34.1 * php7-ldap-debuginfo-7.4.33-150400.4.34.1 * php7-sqlite-7.4.33-150400.4.34.1 * php7-debugsource-7.4.33-150400.4.34.1 * php7-sysvmsg-7.4.33-150400.4.34.1 * php7-tidy-7.4.33-150400.4.34.1 *php7-tokenizer-debuginfo-7.4.33-150400.4.34.1 * php7-xmlwriter-7.4.33-150400.4.34.1 * php7-gd-debuginfo-7.4.33-150400.4.34.1 * php7-fpm-7.4.33-150400.4.34.1 * php7-openssl-7.4.33-150400.4.34.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.34.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.34.1 * php7-test-7.4.33-150400.4.34.1 * php7-pdo-7.4.33-150400.4.34.1 * php7-readline-7.4.33-150400.4.34.1 * php7-json-7.4.33-150400.4.34.1 * php7-mbstring-debuginfo-7.4.33-150400.4.34.1 * php7-opcache-7.4.33-150400.4.34.1 * php7-xsl-7.4.33-150400.4.34.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * apache2-mod_php7-debugsource-7.4.33-150400.4.34.1 * php7-gmp-7.4.33-150400.4.34.1 * php7-gettext-7.4.33-150400.4.34.1 * php7-sodium-7.4.33-150400.4.34.1 * php7-embed-debugsource-7.4.33-150400.4.34.1 * php7-posix-debuginfo-7.4.33-150400.4.34.1 * php7-soap-7.4.33-150400.4.34.1 * php7-zip-debuginfo-7.4.33-150400.4.34.1 * php7-xmlreader-7.4.33-150400.4.34.1 * php7-tidy-debuginfo-7.4.33-150400.4.34.1 * php7-dba-debuginfo-7.4.33-150400.4.34.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.34.1 * php7-intl-debuginfo-7.4.33-150400.4.34.1 * php7-cli-debuginfo-7.4.33-150400.4.34.1 * php7-shmop-7.4.33-150400.4.34.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.34.1 * php7-zlib-7.4.33-150400.4.34.1 * php7-7.4.33-150400.4.34.1 * php7-xsl-debuginfo-7.4.33-150400.4.34.1 * php7-bz2-debuginfo-7.4.33-150400.4.34.1 * php7-fastcgi-7.4.33-150400.4.34.1 * php7-curl-debuginfo-7.4.33-150400.4.34.1 * php7-opcache-debuginfo-7.4.33-150400.4.34.1 * php7-iconv-7.4.33-150400.4.34.1 * php7-calendar-7.4.33-150400.4.34.1 * php7-calendar-debuginfo-7.4.33-150400.4.34.1 * php7-exif-7.4.33-150400.4.34.1 * php7-fileinfo-7.4.33-150400.4.34.1 * php7-mbstring-7.4.33-150400.4.34.1 * php7-debuginfo-7.4.33-150400.4.34.1 * php7-bz2-7.4.33-150400.4.34.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.34.1 *php7-sysvshm-debuginfo-7.4.33-150400.4.34.1 * php7-gettext-debuginfo-7.4.33-150400.4.34.1 * php7-iconv-debuginfo-7.4.33-150400.4.34.1 * php7-ftp-debuginfo-7.4.33-150400.4.34.1 * php7-soap-debuginfo-7.4.33-150400.4.34.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.34.1 * php7-readline-debuginfo-7.4.33-150400.4.34.1 * php7-dom-7.4.33-150400.4.34.1 * php7-gd-7.4.33-150400.4.34.1 * php7-ctype-7.4.33-150400.4.34.1 * php7-sqlite-debuginfo-7.4.33-150400.4.34.1 * php7-ftp-7.4.33-150400.4.34.1 * php7-fastcgi-debugsource-7.4.33-150400.4.34.1 * php7-shmop-debuginfo-7.4.33-150400.4.34.1 * php7-phar-debuginfo-7.4.33-150400.4.34.1 * php7-pgsql-7.4.33-150400.4.34.1 * php7-odbc-7.4.33-150400.4.34.1 * php7-zip-7.4.33-150400.4.34.1 * php7-gmp-debuginfo-7.4.33-150400.4.34.1 * php7-zlib-debuginfo-7.4.33-150400.4.34.1 * php7-dba-7.4.33-150400.4.34.1 * php7-exif-debuginfo-7.4.33-150400.4.34.1 * php7-sysvsem-7.4.33-150400.4.34.1 * php7-snmp-debuginfo-7.4.33-150400.4.34.1 * php7-cli-7.4.33-150400.4.34.1 * php7-odbc-debuginfo-7.4.33-150400.4.34.1 * php7-pdo-debuginfo-7.4.33-150400.4.34.1 * php7-devel-7.4.33-150400.4.34.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.34.1 * php7-bcmath-7.4.33-150400.4.34.1 * php7-pcntl-7.4.33-150400.4.34.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.34.1 * php7-snmp-7.4.33-150400.4.34.1 * php7-bcmath-debuginfo-7.4.33-150400.4.34.1 * php7-intl-7.4.33-150400.4.34.1 * php7-embed-debuginfo-7.4.33-150400.4.34.1 * php7-sysvshm-7.4.33-150400.4.34.1 * php7-dom-debuginfo-7.4.33-150400.4.34.1 * php7-mysql-7.4.33-150400.4.34.1 * php7-sockets-7.4.33-150400.4.34.1 * php7-ctype-debuginfo-7.4.33-150400.4.34.1 * php7-pcntl-debuginfo-7.4.33-150400.4.34.1 * php7-fpm-debugsource-7.4.33-150400.4.34.1 * php7-pgsql-debuginfo-7.4.33-150400.4.34.1 * php7-sodium-debuginfo-7.4.33-150400.4.34.1 * php7-embed-7.4.33-150400.4.34.1 * php7-curl-7.4.33-150400.4.34.1 * php7-sockets-debuginfo-7.4.33-150400.4.34.1 * php7-posix-7.4.33-150400.4.34.1 * php7-ldap-7.4.33-150400.4.34.1 * php7-enchant-7.4.33-150400.4.34.1 * php7-mysql-debuginfo-7.4.33-150400.4.34.1 * php7-tokenizer-7.4.33-150400.4.34.1 * php7-enchant-debuginfo-7.4.33-150400.4.34.1 * php7-json-debuginfo-7.4.33-150400.4.34.1 * php7-phar-7.4.33-150400.4.34.1 * php7-xmlrpc-7.4.33-150400.4.34.1 * php7-openssl-debuginfo-7.4.33-150400.4.34.1 * php7-fpm-debuginfo-7.4.33-150400.4.34.1 * apache2-mod_php7-7.4.33-150400.4.34.1 * php7-ldap-debuginfo-7.4.33-150400.4.34.1 * php7-sqlite-7.4.33-150400.4.34.1 * php7-debugsource-7.4.33-150400.4.34.1 * php7-sysvmsg-7.4.33-150400.4.34.1 * php7-tidy-7.4.33-150400.4.34.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.34.1 * php7-xmlwriter-7.4.33-150400.4.34.1 * php7-fpm-7.4.33-150400.4.34.1 * php7-gd-debuginfo-7.4.33-150400.4.34.1 * php7-openssl-7.4.33-150400.4.34.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.34.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.34.1 * php7-test-7.4.33-150400.4.34.1 * php7-pdo-7.4.33-150400.4.34.1 * php7-readline-7.4.33-150400.4.34.1 * php7-json-7.4.33-150400.4.34.1 * php7-mbstring-debuginfo-7.4.33-150400.4.34.1 * php7-opcache-7.4.33-150400.4.34.1 * php7-xsl-7.4.33-150400.4.34.1 * Legacy Module 15-SP5 (aarch64 ppc64le s390x x86_64) * apache2-mod_php7-debugsource-7.4.33-150400.4.34.1 * php7-gmp-7.4.33-150400.4.34.1 * php7-gettext-7.4.33-150400.4.34.1 * php7-sodium-7.4.33-150400.4.34.1 * php7-posix-debuginfo-7.4.33-150400.4.34.1 * php7-soap-7.4.33-150400.4.34.1 * php7-zip-debuginfo-7.4.33-150400.4.34.1 * php7-xmlreader-7.4.33-150400.4.34.1 * php7-tidy-debuginfo-7.4.33-150400.4.34.1 * php7-dba-debuginfo-7.4.33-150400.4.34.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.34.1 * php7-intl-debuginfo-7.4.33-150400.4.34.1 * php7-cli-debuginfo-7.4.33-150400.4.34.1 * php7-shmop-7.4.33-150400.4.34.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.34.1 * php7-zlib-7.4.33-150400.4.34.1 * php7-7.4.33-150400.4.34.1 * php7-xsl-debuginfo-7.4.33-150400.4.34.1 * php7-bz2-debuginfo-7.4.33-150400.4.34.1 * php7-fastcgi-7.4.33-150400.4.34.1 * php7-curl-debuginfo-7.4.33-150400.4.34.1 * php7-opcache-debuginfo-7.4.33-150400.4.34.1 * php7-iconv-7.4.33-150400.4.34.1 * php7-calendar-7.4.33-150400.4.34.1 * php7-calendar-debuginfo-7.4.33-150400.4.34.1 * php7-exif-7.4.33-150400.4.34.1 * php7-fileinfo-7.4.33-150400.4.34.1 * php7-mbstring-7.4.33-150400.4.34.1 * php7-debuginfo-7.4.33-150400.4.34.1 * php7-bz2-7.4.33-150400.4.34.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.34.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.34.1 * php7-gettext-debuginfo-7.4.33-150400.4.34.1 * php7-iconv-debuginfo-7.4.33-150400.4.34.1 * php7-ftp-debuginfo-7.4.33-150400.4.34.1 * php7-soap-debuginfo-7.4.33-150400.4.34.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.34.1 * php7-readline-debuginfo-7.4.33-150400.4.34.1 * php7-dom-7.4.33-150400.4.34.1 * php7-gd-7.4.33-150400.4.34.1 * php7-ctype-7.4.33-150400.4.34.1 * php7-sqlite-debuginfo-7.4.33-150400.4.34.1 * php7-ftp-7.4.33-150400.4.34.1 * php7-fastcgi-debugsource-7.4.33-150400.4.34.1 * php7-shmop-debuginfo-7.4.33-150400.4.34.1 * php7-phar-debuginfo-7.4.33-150400.4.34.1 * php7-pgsql-7.4.33-150400.4.34.1 * php7-odbc-7.4.33-150400.4.34.1 * php7-zip-7.4.33-150400.4.34.1 * php7-gmp-debuginfo-7.4.33-150400.4.34.1 * php7-zlib-debuginfo-7.4.33-150400.4.34.1 * php7-dba-7.4.33-150400.4.34.1 * php7-exif-debuginfo-7.4.33-150400.4.34.1 * php7-sysvsem-7.4.33-150400.4.34.1 * php7-snmp-debuginfo-7.4.33-150400.4.34.1 * php7-cli-7.4.33-150400.4.34.1 * php7-odbc-debuginfo-7.4.33-150400.4.34.1 * php7-pdo-debuginfo-7.4.33-150400.4.34.1 * php7-devel-7.4.33-150400.4.34.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.34.1 * php7-bcmath-7.4.33-150400.4.34.1 *php7-pcntl-7.4.33-150400.4.34.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.34.1 * php7-snmp-7.4.33-150400.4.34.1 * php7-bcmath-debuginfo-7.4.33-150400.4.34.1 * php7-intl-7.4.33-150400.4.34.1 * php7-sysvshm-7.4.33-150400.4.34.1 * php7-dom-debuginfo-7.4.33-150400.4.34.1 * php7-mysql-7.4.33-150400.4.34.1 * php7-sockets-7.4.33-150400.4.34.1 * php7-ctype-debuginfo-7.4.33-150400.4.34.1 * php7-pcntl-debuginfo-7.4.33-150400.4.34.1 * php7-fpm-debugsource-7.4.33-150400.4.34.1 * php7-pgsql-debuginfo-7.4.33-150400.4.34.1 * php7-sodium-debuginfo-7.4.33-150400.4.34.1 * php7-curl-7.4.33-150400.4.34.1 * php7-sockets-debuginfo-7.4.33-150400.4.34.1 * php7-posix-7.4.33-150400.4.34.1 * php7-ldap-7.4.33-150400.4.34.1 * php7-enchant-7.4.33-150400.4.34.1 * php7-mysql-debuginfo-7.4.33-150400.4.34.1 * php7-tokenizer-7.4.33-150400.4.34.1 * php7-enchant-debuginfo-7.4.33-150400.4.34.1 * php7-json-debuginfo-7.4.33-150400.4.34.1 * php7-phar-7.4.33-150400.4.34.1 * php7-xmlrpc-7.4.33-150400.4.34.1 * php7-openssl-debuginfo-7.4.33-150400.4.34.1 * php7-fpm-debuginfo-7.4.33-150400.4.34.1 * apache2-mod_php7-7.4.33-150400.4.34.1 * php7-ldap-debuginfo-7.4.33-150400.4.34.1 * php7-sqlite-7.4.33-150400.4.34.1 * php7-debugsource-7.4.33-150400.4.34.1 * php7-sysvmsg-7.4.33-150400.4.34.1 * php7-tidy-7.4.33-150400.4.34.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.34.1 * php7-xmlwriter-7.4.33-150400.4.34.1 * php7-fpm-7.4.33-150400.4.34.1 * php7-gd-debuginfo-7.4.33-150400.4.34.1 * php7-openssl-7.4.33-150400.4.34.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.34.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.34.1 * php7-pdo-7.4.33-150400.4.34.1 * php7-readline-7.4.33-150400.4.34.1 * php7-json-7.4.33-150400.4.34.1 * php7-mbstring-debuginfo-7.4.33-150400.4.34.1 * php7-opcache-7.4.33-150400.4.34.1 * php7-xsl-7.4.33-150400.4.34.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * php7-embed-debugsource-7.4.33-150400.4.34.1 * php7-embed-7.4.33-150400.4.34.1 * php7-embed-debuginfo-7.4.33-150400.4.34.1 ## References: * https://www.suse.com/security/cve/CVE-2024-2756.html * https://www.suse.com/security/cve/CVE-2024-3096.html * https://bugzilla.suse.com/show_bug.cgi?id=1222857 * https://bugzilla.suse.com/show_bug.cgi?id=1222858 . SUSE releases critical security patches for php8 addressing several vulnerabilities of moderate importance. Ensure you update promptly to safeguard systems.. php7 security update,SUSE Linux security,vulnerability patch,software update,linux security advisory. . LinuxSecurity.com Team

Calendar 2 Apr 26, 2024 SuSE
203

Mageia 9 MGASA-2024-0058 Critical: Open-VM-Tools Bypass Issues

The updated packages fix security vulnerabilities: Authentication bypass vulnerability in the vgauth module. (CVE-2023-20867) SAML token signature bypass. (CVE-2023-34058) File descriptor hijack vulnerability in the vmware-user-suid-wrapper. . MGASA-2024-0058 - Updated open-vm-tools packages fix security vulnerabilities Publication date: 14 Mar 2024 URL: https://advisories.mageia.org/MGASA-2024-0058.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-34058, CVE-2023-34059 The updated packages fix security vulnerabilities: Authentication bypass vulnerability in the vgauth module. (CVE-2023-20867) SAML token signature bypass. (CVE-2023-34058) File descriptor hijack vulnerability in the vmware-user-suid-wrapper. (CVE-2023-34059) References: - https://bugs.mageia.org/show_bug.cgi?id=32454 - https://access.redhat.com/errata/RHSA-2023:3948 - https://www.openwall.com/lists/oss-security/2023/10/27/1 - https://www.openwall.com/lists/oss-security/2023/10/27/2 - https://github.com/vmware/open-vm-tools/releases/tag/stable-12.3.5 - https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23678 - https://www.cve.org/CVERecord?id=CVE-2023-34058 - https://www.cve.org/CVERecord?id=CVE-2023-34059 SRPMS: - 9/core/open-vm-tools-12.3.5-2.mga9 . The latest version of Mageia's open-vm-tools packages fixes severe security vulnerabilities that could leave users open to threats.. open-vm-tools security fix,Mageia packages update,authentication flaws,security vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 14, 2024 Critical Mageia
89

Fedora 2024-633dc7e183: Critical Grub2 Bypass Vulnerability Detected

Combined update for several fixes as well as security fix for CVE-2023-4001 ``` Mon Jan 15 2024 Nicolas Frayer - 2.06-114 grub- core/commands: add flag to only search root dev Resolves: #2223437 Resolves: #2224951 Resolves: #2258096 Resolves: CVE-2023-4001 Sat Jan 13 2024 Hector Martin - 2.06-113 Switch memdisk compression to lzop . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-633dc7e183 2024-02-05 01:45:31.502538 -------------------------------------------------------------------------------- Name : grub2 Product : Fedora 38 Version : 2.06 Release : 114.fc38 URL : Summary : Bootloader with support for Linux, Multiboot and more Description : The GRand Unified Bootloader (GRUB) is a highly configurable and customizable bootloader with modular architecture. It supports a rich variety of kernel formats, file systems, computer architectures and hardware devices. -------------------------------------------------------------------------------- Update Information: Combined update for several fixes as well as security fix for CVE-2023-4001 ``` Mon Jan 15 2024 Nicolas Frayer - 2.06-114 grub- core/commands: add flag to only search root dev Resolves: #2223437 Resolves: #2224951 Resolves: #2258096 Resolves: CVE-2023-4001 Sat Jan 13 2024 Hector Martin - 2.06-113 Switch memdisk compression to lzop Thu Jan 11 2024 Daan De Meyer - 2.06-112 Don't obsolete the tools package with minimal Mon Jan 8 2024 Nicolas Frayer - 2.06-111 xfs: some bios systems with /boot partition created with xfsprog < 6.5.0 can't boot with one of the xfs upstream patches Resolves: #2254370 Tue Dec 19 2023 Nicolas Frayer - 2.06-110 normal: fix prefix when loading modules Resolves: #2209435 Resolves: #2173015 Tue Dec 12 2023 leo sandoval - 2.06-109 chainloader: remove device path debug message``` -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 15 2024 Nicolas Frayer - 2.06-114 - grub-core/commands: add flag to only search root dev - Resolves: #2223437 - Resolves: #2224951 - Resolves: #2258096 - Resolves: CVE-2023-4001 * Sat Jan 13 2024 Hector Martin - 2.06-113 - Switch memdisk compression to lzop * Thu Jan 11 2024 Daan De Meyer - 2.06-112 - Don't obsolete the tools package with minimal * Mon Jan 8 2024 Nicolas Frayer - 2.06-111 - xfs: some bios systems with /boot partition created with xfsprog < 6.5.0 can't boot with one of the xfs upstream patches - Resolves: #2254370 * Tue Dec 19 2023 Nicolas Frayer - 2.06-110 - normal: fix prefix when loading modules - Resolves: #2209435 - Resolves: #2173015 * Tue Dec 12 2023 leo sandoval - 2.06-109 - chainloader: remove device path debug message -------------------------------------------------------------------------------- References: [ 1 ] Bug #2224951 - CVE-2023-4001 grub2: bypass the GRUB password protection feature https://bugzilla.redhat.com/show_bug.cgi?id=2224951 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-633dc7e183' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ ListGuidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora's latest update tackles serious grub2 vulnerabilities, specifically the CVE-2023-4001 bypass. Follow the commands to update, reinstall grub2, and regenerate the config.. Fedora Updates, Grub2 Security Fix, Fedora Bootloader Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 05, 2024 Critical Fedora
100

SUSE Linux Enterprise Curl Moderate: 2023:4713-1 Cookie Bypass

* bsc#1217573 Cross-References: * CVE-2023-46218 . # Security update for curl Announcement ID: SUSE-SU-2023:4713-1 Rating: moderate References: * bsc#1217573 Cross-References: * CVE-2023-46218 CVSS scores: * CVE-2023-46218 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4713=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4713=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2023-4713=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * curl-debugsource-7.66.0-150200.4.63.1 * curl-7.66.0-150200.4.63.1 * libcurl4-7.66.0-150200.4.63.1 * curl-debuginfo-7.66.0-150200.4.63.1 * libcurl4-debuginfo-7.66.0-150200.4.63.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * curl-debugsource-7.66.0-150200.4.63.1 * curl-7.66.0-150200.4.63.1 * libcurl4-7.66.0-150200.4.63.1 * curl-debuginfo-7.66.0-150200.4.63.1 * libcurl4-debuginfo-7.66.0-150200.4.63.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * curl-debugsource-7.66.0-150200.4.63.1 * curl-7.66.0-150200.4.63.1 * libcurl4-7.66.0-150200.4.63.1 * curl-debuginfo-7.66.0-150200.4.63.1 * libcurl4-debuginfo-7.66.0-150200.4.63.1 ## References: *https://www.suse.com/security/cve/CVE-2023-46218.html * https://bugzilla.suse.com/show_bug.cgi?id=1217573 . SUSE has released a patch for a curl flaw that allows for a potential cookie bypass, raising concerns over secure information management and unauthorized access.. SUSE Patch Update,curl Security Advisory,Cookie Bypass Fix,Moderate Security Update. . LinuxSecurity.com Team

Calendar 2 Dec 11, 2023 SuSE
89

Fedora 37 Kubernetes 1.25.11 Critical: Seccomp Bypass Risk

Patch update to Kubernetes 1.25 for Fedora 37. Primarily a security fix for CVE-2023-2431: Bypass of seccomp profile enforcement.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-a1d7a29fe5 2023-07-01 00:37:09.086560 --------------------------------------------------------------------------------Name : kubernetes Product : Fedora 37 Version : 1.25.11 Release : 1.fc37 URL : https://kubernetes.io/docs/home/ Summary : Container cluster management Description : Container cluster management --------------------------------------------------------------------------------Update Information: Patch update to Kubernetes 1.25 for Fedora 37. Primarily a security fix for CVE-2023-2431: Bypass of seccomp profile enforcement. --------------------------------------------------------------------------------ChangeLog: * Thu Jun 22 2023 Bradley G Smith - 1.25.11-1 - Update To Kubernetes 1.25.11 --------------------------------------------------------------------------------References: [ 1 ] Bug #2215555 - TRIAGE-CVE-2023-2431 kubernetes: Bypass of seccomp profile enforcement https://bugzilla.redhat.com/show_bug.cgi?id=2215555 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a1d7a29fe5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code ofConduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Kubernetes 1.25 receives a security update: Fedora 37 provides a patch that resolves the issue related to seccomp profile bypass, explained in detail here.. Kubernetes Fedora Patch Bypass Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 01, 2023 Critical Fedora
98

Red Hat 8.1: RHSA-2023:3936-01 Important: python3 Bypass Issue

An update for python3 is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: python3 security update Advisory ID: RHSA-2023:3936-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3936 Issue date: 2023-06-29 CVE Names: CVE-2023-24329 ==================================================================== 1. Summary: An update for python3 is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.1) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS E4S (v. 8.1) - aarch64, ppc64le, s390x, x86_64 3. Description: Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: urllib.parse url blocklisting bypass (CVE-2023-24329) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2173917 - CVE-2023-24329 python: urllib.parse url blocklisting bypass 6. Package List: Red Hat Enterprise Linux AppStream E4S (v. 8.1): aarch64: platform-python-debug-3.6.8-15.1.el8_1.1.aarch64.rpm platform-python-devel-3.6.8-15.1.el8_1.1.aarch64.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.aarch64.rpm python3-debugsource-3.6.8-15.1.el8_1.1.aarch64.rpm python3-idle-3.6.8-15.1.el8_1.1.aarch64.rpm python3-tkinter-3.6.8-15.1.el8_1.1.aarch64.rpm ppc64le: platform-python-debug-3.6.8-15.1.el8_1.1.ppc64le.rpm platform-python-devel-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-debugsource-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-idle-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-tkinter-3.6.8-15.1.el8_1.1.ppc64le.rpm s390x: platform-python-debug-3.6.8-15.1.el8_1.1.s390x.rpm platform-python-devel-3.6.8-15.1.el8_1.1.s390x.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.s390x.rpm python3-debugsource-3.6.8-15.1.el8_1.1.s390x.rpm python3-idle-3.6.8-15.1.el8_1.1.s390x.rpm python3-tkinter-3.6.8-15.1.el8_1.1.s390x.rpm x86_64: platform-python-3.6.8-15.1.el8_1.1.i686.rpm platform-python-debug-3.6.8-15.1.el8_1.1.i686.rpm platform-python-debug-3.6.8-15.1.el8_1.1.x86_64.rpm platform-python-devel-3.6.8-15.1.el8_1.1.i686.rpm platform-python-devel-3.6.8-15.1.el8_1.1.x86_64.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.i686.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.x86_64.rpm python3-debugsource-3.6.8-15.1.el8_1.1.i686.rpm python3-debugsource-3.6.8-15.1.el8_1.1.x86_64.rpm python3-idle-3.6.8-15.1.el8_1.1.i686.rpm python3-idle-3.6.8-15.1.el8_1.1.x86_64.rpm python3-test-3.6.8-15.1.el8_1.1.i686.rpm python3-tkinter-3.6.8-15.1.el8_1.1.i686.rpm python3-tkinter-3.6.8-15.1.el8_1.1.x86_64.rpm Red Hat Enterprise Linux BaseOS E4S (v.8.1): Source: python3-3.6.8-15.1.el8_1.1.src.rpm aarch64: platform-python-3.6.8-15.1.el8_1.1.aarch64.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.aarch64.rpm python3-debugsource-3.6.8-15.1.el8_1.1.aarch64.rpm python3-libs-3.6.8-15.1.el8_1.1.aarch64.rpm python3-test-3.6.8-15.1.el8_1.1.aarch64.rpm ppc64le: platform-python-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-debugsource-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-libs-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-test-3.6.8-15.1.el8_1.1.ppc64le.rpm s390x: platform-python-3.6.8-15.1.el8_1.1.s390x.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.s390x.rpm python3-debugsource-3.6.8-15.1.el8_1.1.s390x.rpm python3-libs-3.6.8-15.1.el8_1.1.s390x.rpm python3-test-3.6.8-15.1.el8_1.1.s390x.rpm x86_64: platform-python-3.6.8-15.1.el8_1.1.x86_64.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.i686.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.x86_64.rpm python3-debugsource-3.6.8-15.1.el8_1.1.i686.rpm python3-debugsource-3.6.8-15.1.el8_1.1.x86_64.rpm python3-libs-3.6.8-15.1.el8_1.1.i686.rpm python3-libs-3.6.8-15.1.el8_1.1.x86_64.rpm python3-test-3.6.8-15.1.el8_1.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZJ2or9zjgjWX9erEAQgEGQ/+NF29rUsWpqKyPuuOWMqF0KJRjfd3sv1w 6pp2p/7xR1rNrkJeMv2vU0Mv9n9xR7nVGnVEfkcxwDaUsrja0h/97yie8Z4FcXWI haTj5Oe83lKLxy4XomSiBIXRgp8svHCH5cPxe6p9Ezx9+xSg4QKW8Wz2T+Q7U13u ZeVaOeg/EIbJGa2+gQ1tUBb28xcnXavbGKbHNRUGLsgIPHF8tmXufTcPCM1GMPCr 07NMfSJuwFt9CjlZXZIsfn2C1ADL+aRVMejvV/CY5Cn4cc6IJqX9nM2DpkiUgZjf +zjUrTXH/LGR7NOcyUyyWErJQJg9SoaJxWdyoUm9Pbs7YkF8QzN7UU0+2VIkdT5e dujPuFr435gaacj05xCWRgxAvck1Y6aYXaC8YJNM+KUyzZYcQyfGQB0RK9xHPorC eZjiqfii7qDEBJaDglX6fOHVwrQGrQ9sHSMToEBurlc+E6Wjvpsh45NcuLYOZubg TmShSgcEoLCN/K6NkAuo9L4SpWgmAU/IZW23nNpurWGrAI3Ht8FxRAgAQuieR4ic CW7OsFxx4/T/ZXKp/uXghRJBZHeP8nvY/0ymh11/DwQQ1lGGhxEVEx4jUjV1dbJO Alul8f5VjR7+eXYQsPWHZnx0dowuW/2NtBzzNxX83LgREzaf5U2HHY7AUy0jGe4X 8U64p6Xx3FU=muR1 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical python3 security patch has been released for Red Hat Enterprise Linux 8.1, mitigating serious security flaws.. python3 Security Update, Red Hat Advisory, Enterprise Linux Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 29, 2023 Important Red Hat
98

Red Hat 8 RHSA-2023-3594-01 Important: Python3.11 Bypass Issue

An update for python3.11 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: python3.11 security update Advisory ID: RHSA-2023:3594-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3594 Issue date: 2023-06-14 CVE Names: CVE-2023-24329 ==================================================================== 1. Summary: An update for python3.11 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 Red Hat Enterprise Linux CRB (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: Python is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. Security Fix(es): * python: urllib.parse url blocklisting bypass (CVE-2023-24329) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugsfixed (https://bugzilla.redhat.com/): 2173917 - CVE-2023-24329 python: urllib.parse url blocklisting bypass 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: python3.11-3.11.2-2.el8_8.1.src.rpm aarch64: python3.11-3.11.2-2.el8_8.1.aarch64.rpm python3.11-debuginfo-3.11.2-2.el8_8.1.aarch64.rpm python3.11-debugsource-3.11.2-2.el8_8.1.aarch64.rpm python3.11-devel-3.11.2-2.el8_8.1.aarch64.rpm python3.11-libs-3.11.2-2.el8_8.1.aarch64.rpm python3.11-tkinter-3.11.2-2.el8_8.1.aarch64.rpm noarch: python3.11-rpm-macros-3.11.2-2.el8_8.1.noarch.rpm ppc64le: python3.11-3.11.2-2.el8_8.1.ppc64le.rpm python3.11-debuginfo-3.11.2-2.el8_8.1.ppc64le.rpm python3.11-debugsource-3.11.2-2.el8_8.1.ppc64le.rpm python3.11-devel-3.11.2-2.el8_8.1.ppc64le.rpm python3.11-libs-3.11.2-2.el8_8.1.ppc64le.rpm python3.11-tkinter-3.11.2-2.el8_8.1.ppc64le.rpm s390x: python3.11-3.11.2-2.el8_8.1.s390x.rpm python3.11-debuginfo-3.11.2-2.el8_8.1.s390x.rpm python3.11-debugsource-3.11.2-2.el8_8.1.s390x.rpm python3.11-devel-3.11.2-2.el8_8.1.s390x.rpm python3.11-libs-3.11.2-2.el8_8.1.s390x.rpm python3.11-tkinter-3.11.2-2.el8_8.1.s390x.rpm x86_64: python3.11-3.11.2-2.el8_8.1.x86_64.rpm python3.11-debuginfo-3.11.2-2.el8_8.1.i686.rpm python3.11-debuginfo-3.11.2-2.el8_8.1.x86_64.rpm python3.11-debugsource-3.11.2-2.el8_8.1.i686.rpm python3.11-debugsource-3.11.2-2.el8_8.1.x86_64.rpm python3.11-devel-3.11.2-2.el8_8.1.i686.rpm python3.11-devel-3.11.2-2.el8_8.1.x86_64.rpm python3.11-libs-3.11.2-2.el8_8.1.i686.rpm python3.11-libs-3.11.2-2.el8_8.1.x86_64.rpm python3.11-tkinter-3.11.2-2.el8_8.1.x86_64.rpm Red Hat Enterprise Linux CRB (v.8): aarch64: python3.11-debug-3.11.2-2.el8_8.1.aarch64.rpm python3.11-debuginfo-3.11.2-2.el8_8.1.aarch64.rpm python3.11-debugsource-3.11.2-2.el8_8.1.aarch64.rpm python3.11-idle-3.11.2-2.el8_8.1.aarch64.rpm python3.11-test-3.11.2-2.el8_8.1.aarch64.rpm ppc64le: python3.11-debug-3.11.2-2.el8_8.1.ppc64le.rpm python3.11-debuginfo-3.11.2-2.el8_8.1.ppc64le.rpm python3.11-debugsource-3.11.2-2.el8_8.1.ppc64le.rpm python3.11-idle-3.11.2-2.el8_8.1.ppc64le.rpm python3.11-test-3.11.2-2.el8_8.1.ppc64le.rpm s390x: python3.11-debug-3.11.2-2.el8_8.1.s390x.rpm python3.11-debuginfo-3.11.2-2.el8_8.1.s390x.rpm python3.11-debugsource-3.11.2-2.el8_8.1.s390x.rpm python3.11-idle-3.11.2-2.el8_8.1.s390x.rpm python3.11-test-3.11.2-2.el8_8.1.s390x.rpm x86_64: python3.11-3.11.2-2.el8_8.1.i686.rpm python3.11-debug-3.11.2-2.el8_8.1.i686.rpm python3.11-debug-3.11.2-2.el8_8.1.x86_64.rpm python3.11-debuginfo-3.11.2-2.el8_8.1.i686.rpm python3.11-debuginfo-3.11.2-2.el8_8.1.x86_64.rpm python3.11-debugsource-3.11.2-2.el8_8.1.i686.rpm python3.11-debugsource-3.11.2-2.el8_8.1.x86_64.rpm python3.11-idle-3.11.2-2.el8_8.1.i686.rpm python3.11-idle-3.11.2-2.el8_8.1.x86_64.rpm python3.11-test-3.11.2-2.el8_8.1.i686.rpm python3.11-test-3.11.2-2.el8_8.1.x86_64.rpm python3.11-tkinter-3.11.2-2.el8_8.1.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZIm3TNzjgjWX9erEAQiibxAAh0yT3bW825e1BSTJBUNz8MCruj+3DclX 37gbPrbrXD3zfS0RgtfZa3fFXqu8ifFqwE1tt/R9lDZrJRQGPp5nb10qhvJn0qXC yRbZ4v3S2qrc2k/EFPccWUVVZmE3vTyOKQmN7P4TCI9Ew6PbzlqFSIk2MOTMVw0m ICmas2GqH/6RFhD7DCXMMaEa6UI5F6V2TkuXXLjWNNT2oYCARa8bqoyKrj4hL8KM gA+/TuzT2EHxOUuF51015j40oubbgJPMdeBbpNwqg/ASqr9QUtVJH9qNZKEI0DKR k/69xtdB6JTdSRJx23VrwQi73eYxTO0Ro0zGGxfvNwZRfDPdowxMbYnCSxQQ+bgK mx7vnPYoTdKS4fik8hs3HANrtmYvploZYYw/xn4EMr0/Vm/Mjy6gBA7FkQ4NtgK/ juXnlUuj7GNiDBEAwlJDveuWjXOmA4xz1Kr75s8B5/NqRNoEomOsjJv0UszrBppk 4nlsnYOnNJ0HqprKA/3OvNn2YxX0oMIJHnOYuMo80t1qfOxkvCBZpChZT99N3RHA S6z0nO+AFkyDxKKWNhuIF7JCJyJb6FT9uwZk24iinKjQsoNKsYvX74g0onoLTBrT Czc7ph5J2C5AWwvf7mFK27/SrkXz8UxjLvDLEA4asWRpPURdQvom2N9Tih4dYSEY poobsHzGH8o=vGcI -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A significant announcement for python3.11 on Red Hat Enterprise Linux 8 tackles security vulnerabilities and their respective impact assessments.. Red Hat Security Update, Python3.11 Fix, Important Security Update, Linux Application Security, CVSS Impact Rating. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 14, 2023 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here