Several security issues were fixed in Apache Shiro.. ========================================================================== Ubuntu Security Notice USN-6352-1 September 07, 2023 shiro vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Apache Shiro. Software Description: - shiro: Powerful and easy-to-use Java security framework Details: It was discovered that Apache Shiro incorrectly handled certain HTTP requests. A remote attacker could possibly use this issue to bypass security restrictions. (CVE-2020-13933, CVE-2020-17510) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libshiro-java 1.3.2-4ubuntu0.2 Ubuntu 18.04 LTS (Available with Ubuntu Pro): libshiro-java 1.3.2-3ubuntu0.18.04.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6352-1 CVE-2020-13933, CVE-2020-17510 Package Information: https://launchpad.net/ubuntu/+source/shiro/1.3.2-4ubuntu0.2 . Numerous vulnerabilities resolved in Apache Shiro for Ubuntu. Make sure your system is current to uphold security protocols.. Apache Shiro, Ubuntu Security Notice, Security Patch, Java Security. . Severity: Critical. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 18 for SLE 15 SP1) ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3690-1 Rating: important References: #1178622 #1178783 Cross-References: CVE-2020-25668 CVE-2020-25705 Affected Products: SUSE Linux Enterprise Module for Live Patching 15-SP1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 4.12.14-197_67 fixes several issues. The following security issues were fixed: - CVE-2020-25668: Fixed a concurrency use-after-free in con_font_op (bsc#1178622). - CVE-2020-25705: Fixed a flaw which could have allowed an off-path remote user to effectively bypass source port UDP randomization (bsc#1178783). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP1: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP1-2020-3690=1 Package List: - SUSE Linux Enterprise Module for Live Patching 15-SP1 (ppc64le x86_64): kernel-livepatch-4_12_14-197_67-default-2-2.1 References: https://www.suse.com/security/cve/CVE-2020-25668.html https://www.suse.com/security/cve/CVE-2020-25705.html https://bugzilla.suse.com/show_bug.cgi?id=1178622 https://bugzilla.suse.com/show_bug.cgi?id=1178783 . SUSE has released a security update for the Linux Kernel (Live Patch 18) to address significant vulnerabilities in SLE 15 SP1.. Linux Kernel Update, SUSE Security Patch, Live Patching Fixes. . Severity: Critical. LinuxSecurity.com Team
Updated mediawiki packages fix security vulnerability: MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 . MGASA-2020-0021 - Updated mediawiki packages fix security vulnerability Publication date: 05 Jan 2020 URL: https://advisories.mageia.org/MGASA-2020-0021.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-19709 Updated mediawiki packages fix security vulnerability: MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page (CVE-2019-19709). References: - https://bugs.mageia.org/show_bug.cgi?id=25986 - https://lists.wikimedia.org/hyperkitty/list/
Get the latest Linux and open source security news straight to your inbox.