Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian Bullseye DSA-5382-1 Critical: Cairosvg Request Forgery Issue

It was reported that cairosvg, a SVG converter based on Cairo, can send requests to external hosts when processing specially crafted SVG files with external file resource loading. An attacker can take advantage of this flaw to perform a server-side request forgery or denial of service. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5382-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso April 05, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : cairosvg CVE ID : CVE-2023-27586 Debian Bug : 1033295 It was reported that cairosvg, a SVG converter based on Cairo, can send requests to external hosts when processing specially crafted SVG files with external file resource loading. An attacker can take advantage of this flaw to perform a server-side request forgery or denial of service. Fetching of external files is disabled by default with this update. For the stable distribution (bullseye), this problem has been fixed in version 2.5.0-1.1+deb11u1. We recommend that you upgrade your cairosvg packages. For the detailed security status of cairosvg please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/cairosvg Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Cairosvg performs a security patch to fix vulnerabilities regarding external requests. For comprehensive information, refer to Debian advisory DSA-5382-1 and suggested upgrade actions.. Cairosvg Security Update, Debian DSA-5382-1, Server-Side Request Forgery, SVG Converter, Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 05, 2023 Critical Debian
203

Mageia: 2021-0149 Moderate: Python-cairosvg Denial of Service Attack

When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time (CVE-2021-21236). . MGASA-2021-0149 - Updated python-cairosvg packages fix security vulnerability Publication date: 21 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0149.html Type: security Affected Mageia releases: 7 CVE: CVE-2021-21236 When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time (CVE-2021-21236). References: - https://bugs.mageia.org/show_bug.cgi?id=28122 - https://github.com/advisories/GHSA-hq37-853p-g5cf - https://www.cve.org/CVERecord?id=CVE-2021-21236 SRPMS: - 7/core/python-cairosvg-2.2.1-1.1.mga7 . Newly revised python-cairosvg packages mitigate Regular Expression Denial of Service threats on Mageia platforms.. Mageia Security, python cairosvg, Denial of Service Fix. . LinuxSecurity.com Team

Calendar%202 Mar 21, 2021 Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200