Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
89

Fedora 44 rust-webpki-root-certs Update Mozilla Trusted Certs 2026-0010-1

Update uv and python-uv-build to 0.11.2. Version 0.11 includes changes to the networking stack used by uv. While its developers think that breakage will be rare, it is possible that these changes will result in the rejection of certificates previously trusted by uv so, they have marked the change as breaking out of an abundance of caution. The changes are largely driven by the. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b8b59dcf44 2026-03-28 00:15:26.019955+00:00 -------------------------------------------------------------------------------- Name : rust-webpki-root-certs Product : Fedora 44 Version : 1.0.6 Release : 1.fc44 URL : https://crates.io/crates/webpki-root-certs Summary : Mozilla trusted certificate authorities in self-signed X.509 format Description : Mozilla trusted certificate authorities in self-signed X.509 format for use with crates other than webpki. -------------------------------------------------------------------------------- Update Information: Update uv and python-uv-build to 0.11.2. Version 0.11 includes changes to the networking stack used by uv. While its developers think that breakage will be rare, it is possible that these changes will result in the rejection of certificates previously trusted by uv so, they have marked the change as breaking out of an abundance of caution. The changes are largely driven by the upgrade of reqwest, which powers uv's HTTP clients, to v0.13, which included some breaking changes to TLS certificate verification. This update also includes updates for several of uv\u2019s Rust library dependencies. Update rust-openssl-probe to 0.2.1, including breaking changes introduced in 0.2.0, and introduce a new rust-openssl-probe0.1 compat package. Update rust-rustls-native-certs to 0.8.3, now using openssl-probe 0.2. Update rust-native-tls to 0.2.18. Version 0.2.16 added TLS 1.3 as an option, added stack_from_pem, and upgraded openssl-probe to 0.2. Version0.2.17 added support for ALPN on the server side. Version 0.2.18 fixed min/max protocol selection fallback for very old OpenSSL versions. Add an initial package for rust-webpki-root-certs. -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 25 2026 Benjamin A. Beasley - 1.0.6-1 - Initial package (close RHBZ#2451103) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2425802 - rust-openssl-probe-0.2.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2425802 [ 2 ] Bug #2425819 - rust-rustls-native-certs-0.8.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2425819 [ 3 ] Bug #2432768 - rust-reqsign-aliyun-oss-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432768 [ 4 ] Bug #2432769 - rust-reqsign-core-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432769 [ 5 ] Bug #2432770 - rust-reqsign-0.20.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432770 [ 6 ] Bug #2432771 - rust-reqsign-azure-storage-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432771 [ 7 ] Bug #2432772 - rust-reqsign-http-send-reqwest-4.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432772 [ 8 ] Bug #2432773 - rust-reqsign-google-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432773 [ 9 ] Bug #2432774 - rust-reqsign-file-read-tokio-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432774 [ 10 ] Bug #2432775 - rust-reqsign-command-execute-tokio-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432775 [ 11 ] Bug #2432776 - rust-reqsign-aws-v4-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432776 [ 12 ] Bug #2432777 - rust-reqsign-huaweicloud-obs-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432777 [ 13 ] Bug #2432779 - rust-reqsign-tencent-cos-3.0.0 isavailable https://bugzilla.redhat.com/show_bug.cgi?id=2432779 [ 14 ] Bug #2436289 - rust-ambient-id-0.0.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=2436289 [ 15 ] Bug #2437941 - rust-astral-reqwest-middleware-0.5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2437941 [ 16 ] Bug #2437942 - rust-astral-reqwest-retry-0.9.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2437942 [ 17 ] Bug #2437976 - rust-astral_async_http_range_reader-0.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2437976 [ 18 ] Bug #2439752 - rust-native-tls-0.2.18 is available https://bugzilla.redhat.com/show_bug.cgi?id=2439752 [ 19 ] Bug #2450541 - python-uv-build-0.11.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2450541 [ 20 ] Bug #2450582 - uv-0.11.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2450582 [ 21 ] Bug #2451103 - Review Request: rust-webpki-root-certs - Mozilla trusted certificate authorities in self-signed X.509 format https://bugzilla.redhat.com/show_bug.cgi?id=2451103 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b8b59dcf44' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Explore the latest updates on Mozilla trusted root certificates and associated changes in Fedora 44 Networking.. Fedora 44, rust-webpki-root-certs, uv, TLS changes, networking stack. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 28, 2026 Important Fedora
172

Ubuntu 16.04 ESM: USN-5761-2 Critical TrustCor Certificate Removal

A distrusted certificate authority has been removed from ca-certificates.. =========================================================================Ubuntu Security Notice USN-5761-2 December 06, 2022 ca-certificates update ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: A distrusted certificate authority has been removed from ca-certificates. Software Description: - ca-certificates: Common CA certificates Details: USN-5761-1 updated ca-certificates. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: Due to security concerns, the TrustCor certificate authority has been marked as distrusted in Mozilla's root store. This update removes the TrustCor CA certificates from the ca-certificates package. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: ca-certificates 20211016~16.04.1~esm2 Ubuntu 14.04 ESM: ca-certificates 20211016~14.04.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5761-2 https://ubuntu.com/security/notices/USN-5761-1 . TrustCor CA has been eliminated from the ca-certificates list because of security issues. This update applies to Ubuntu 14.04 and 16.04 Extended Security Maintenance systems.. TrustCor Update, Ubuntu Security, Certificate Update, Linux ESM, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 06, 2022 Critical Ubuntu
197

Debian: DLA-2593-1 Moderate: CA Certificates Reversion Update

This update reverts the Symantec CA blacklist (which was originally #911289). The following root certificates were added back (+): + "GeoTrust Global CA" + "GeoTrust Primary Certification Authority" . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2593-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta March 14, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : ca-certificates Version : 20200601~deb9u2 Debian Bug : 962596 This update reverts the Symantec CA blacklist (which was originally #911289). The following root certificates were added back (+): + "GeoTrust Global CA" + "GeoTrust Primary Certification Authority" + "GeoTrust Primary Certification Authority - G2" + "GeoTrust Primary Certification Authority - G3" + "GeoTrust Universal CA" + "thawte Primary Root CA" + "thawte Primary Root CA - G2" + "thawte Primary Root CA - G3" + "VeriSign Class 3 Public Primary Certification Authority - G4" + "VeriSign Class 3 Public Primary Certification Authority - G5" + "VeriSign Universal Root Certification Authority" NOTE: due to bug #743339, CA certificates added back in this version won't automatically be trusted again on upgrade. Affected users may need to reconfigure the package to restore the desired state. For Debian 9 stretch, this problem has been fixed in version 20200601~deb9u2. We recommend that you upgrade your ca-certificates packages. For the detailed security status of ca-certificates please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ca-certificates Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2593-2 regarding ca-certificates whitelistupdate for root trust anchors.. Debian Security Update, CA Certificates, Certification Authority. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 13, 2021 Important Debian LTS
197

Debian 8: DLA-1417-1 Critical Security Update For CA Certificates

There have been a number of updates to the set of Certificate Authority (CA) certificates that are considered "valid" or otherwise should be trusted. . Package : ca-certificates Version : 20141019+deb8u4 Debian Bugs : #858064 #858539 #867461 #894070 There have been a number of updates to the set of Certificate Authority (CA) certificates that are considered "valid" or otherwise should be trusted. For Debian 8 "Jessie", these issues have been fixed in ca-certificates version 20141019+deb8u4. We recommend that you upgrade your ca-certificates packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Keep informed about the newest security patch for ca-certificates in Debian 8, resolving trust concerns and additional vulnerabilities.. Debian Security, CA Certificates, Security Updates, Trusted Certificates, Trust Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 07, 2018 Critical Debian LTS
98

Red Hat Enterprise Linux: RHSA-2011:1444-01 Important: NSS Update

Updated nss packages that fix one security issue are now available for Red Hat Enterprise Linux 4, 5, and 6. The Red Hat Security Response Team has rated this update as having [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: nss security update Advisory ID: RHSA-2011:1444-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:1444.html Issue date: 2011-11-09 ==================================================================== 1. Summary: Updated nss packages that fix one security issue are now available for Red Hat Enterprise Linux 4, 5, and 6. The Red Hat Security Response Team has rated this update as having important security impact. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: Network Security Services (NSS) is a set of libraries designed to support the development of security-enabled client and server applications. It was found that the Malaysia-based Digicert Sdn. Bhd. subordinate CertificateAuthority (CA) issued HTTPS certificates with weak keys. This update renders any HTTPS certificates signed by that CA as untrusted. This covers all uses of the certificates, including SSL, S/MIME, and code signing. Note: Digicert Sdn. Bhd. is not the same company as found at digicert.com. (BZ#751366) Note: This fix only applies to applications using the NSS Builtin Object Token. It does not render the certificates untrusted for applications that use the NSS library, but do not use the NSS Builtin Object Token. This update also fixes the following bug on Red Hat Enterprise Linux 5: * When using mod_nss with the Apache HTTP Server, a bug in NSS on Red Hat Enterprise Linux 5 resulted in file descriptors leaking each time the Apache HTTP Server was restarted with the "service httpd reload" command. This could have prevented the Apache HTTP Server from functioning properly if all available file descriptors were consumed. (BZ#743508) For Red Hat Enterprise Linux 6, these updated packages upgrade NSS to version 3.12.10. As well, they upgrade NSPR (Netscape Portable Runtime) to version 4.8.8 and nss-util to version 3.12.10 on Red Hat Enterprise Linux 6, as required by the NSS update. (BZ#735972, BZ#736272, BZ#735973) All NSS users should upgrade to these updated packages, which correct this issue. After installing the update, applications using NSS must be restarted for the changes to take effect. In addition, on Red Hat Enterprise Linux 6, applications using NSPR and nss-util must also be restarted. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 735972 - Update nss to 3.12.10 735973 - Update nss-util to 3.12.10 736272 - Update nspr to 4.8.8 743508 - File descriptor leak after "service httpd reload" 751366 - RevokingTrust in DigiCert Sdn. Bhd Intermediate Certificate Authority from nss 6. Package List: Red Hat Enterprise Linux AS version 4: Source: i386: nss-3.12.10-6.el4.i386.rpm nss-debuginfo-3.12.10-6.el4.i386.rpm nss-devel-3.12.10-6.el4.i386.rpm nss-tools-3.12.10-6.el4.i386.rpm ia64: nss-3.12.10-6.el4.i386.rpm nss-3.12.10-6.el4.ia64.rpm nss-debuginfo-3.12.10-6.el4.i386.rpm nss-debuginfo-3.12.10-6.el4.ia64.rpm nss-devel-3.12.10-6.el4.ia64.rpm nss-tools-3.12.10-6.el4.ia64.rpm ppc: nss-3.12.10-6.el4.ppc.rpm nss-3.12.10-6.el4.ppc64.rpm nss-debuginfo-3.12.10-6.el4.ppc.rpm nss-debuginfo-3.12.10-6.el4.ppc64.rpm nss-devel-3.12.10-6.el4.ppc.rpm nss-tools-3.12.10-6.el4.ppc.rpm s390: nss-3.12.10-6.el4.s390.rpm nss-debuginfo-3.12.10-6.el4.s390.rpm nss-devel-3.12.10-6.el4.s390.rpm nss-tools-3.12.10-6.el4.s390.rpm s390x: nss-3.12.10-6.el4.s390.rpm nss-3.12.10-6.el4.s390x.rpm nss-debuginfo-3.12.10-6.el4.s390.rpm nss-debuginfo-3.12.10-6.el4.s390x.rpm nss-devel-3.12.10-6.el4.s390x.rpm nss-tools-3.12.10-6.el4.s390x.rpm x86_64: nss-3.12.10-6.el4.i386.rpm nss-3.12.10-6.el4.x86_64.rpm nss-debuginfo-3.12.10-6.el4.i386.rpm nss-debuginfo-3.12.10-6.el4.x86_64.rpm nss-devel-3.12.10-6.el4.x86_64.rpm nss-tools-3.12.10-6.el4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: nss-3.12.10-6.el4.i386.rpm nss-debuginfo-3.12.10-6.el4.i386.rpm nss-devel-3.12.10-6.el4.i386.rpm nss-tools-3.12.10-6.el4.i386.rpm x86_64: nss-3.12.10-6.el4.i386.rpm nss-3.12.10-6.el4.x86_64.rpm nss-debuginfo-3.12.10-6.el4.i386.rpm nss-debuginfo-3.12.10-6.el4.x86_64.rpm nss-devel-3.12.10-6.el4.x86_64.rpm nss-tools-3.12.10-6.el4.x86_64.rpm Red Hat Enterprise Linux ES version4: Source: i386: nss-3.12.10-6.el4.i386.rpm nss-debuginfo-3.12.10-6.el4.i386.rpm nss-devel-3.12.10-6.el4.i386.rpm nss-tools-3.12.10-6.el4.i386.rpm ia64: nss-3.12.10-6.el4.i386.rpm nss-3.12.10-6.el4.ia64.rpm nss-debuginfo-3.12.10-6.el4.i386.rpm nss-debuginfo-3.12.10-6.el4.ia64.rpm nss-devel-3.12.10-6.el4.ia64.rpm nss-tools-3.12.10-6.el4.ia64.rpm x86_64: nss-3.12.10-6.el4.i386.rpm nss-3.12.10-6.el4.x86_64.rpm nss-debuginfo-3.12.10-6.el4.i386.rpm nss-debuginfo-3.12.10-6.el4.x86_64.rpm nss-devel-3.12.10-6.el4.x86_64.rpm nss-tools-3.12.10-6.el4.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: nss-3.12.10-6.el4.i386.rpm nss-debuginfo-3.12.10-6.el4.i386.rpm nss-devel-3.12.10-6.el4.i386.rpm nss-tools-3.12.10-6.el4.i386.rpm ia64: nss-3.12.10-6.el4.i386.rpm nss-3.12.10-6.el4.ia64.rpm nss-debuginfo-3.12.10-6.el4.i386.rpm nss-debuginfo-3.12.10-6.el4.ia64.rpm nss-devel-3.12.10-6.el4.ia64.rpm nss-tools-3.12.10-6.el4.ia64.rpm x86_64: nss-3.12.10-6.el4.i386.rpm nss-3.12.10-6.el4.x86_64.rpm nss-debuginfo-3.12.10-6.el4.i386.rpm nss-debuginfo-3.12.10-6.el4.x86_64.rpm nss-devel-3.12.10-6.el4.x86_64.rpm nss-tools-3.12.10-6.el4.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: nss-3.12.10-7.el5_7.i386.rpm nss-debuginfo-3.12.10-7.el5_7.i386.rpm nss-tools-3.12.10-7.el5_7.i386.rpm x86_64: nss-3.12.10-7.el5_7.i386.rpm nss-3.12.10-7.el5_7.x86_64.rpm nss-debuginfo-3.12.10-7.el5_7.i386.rpm nss-debuginfo-3.12.10-7.el5_7.x86_64.rpm nss-tools-3.12.10-7.el5_7.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: nss-debuginfo-3.12.10-7.el5_7.i386.rpm nss-devel-3.12.10-7.el5_7.i386.rpm nss-pkcs11-devel-3.12.10-7.el5_7.i386.rpm x86_64: nss-debuginfo-3.12.10-7.el5_7.i386.rpm nss-debuginfo-3.12.10-7.el5_7.x86_64.rpm nss-devel-3.12.10-7.el5_7.i386.rpm nss-devel-3.12.10-7.el5_7.x86_64.rpm nss-pkcs11-devel-3.12.10-7.el5_7.i386.rpm nss-pkcs11-devel-3.12.10-7.el5_7.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: nss-3.12.10-7.el5_7.i386.rpm nss-debuginfo-3.12.10-7.el5_7.i386.rpm nss-devel-3.12.10-7.el5_7.i386.rpm nss-pkcs11-devel-3.12.10-7.el5_7.i386.rpm nss-tools-3.12.10-7.el5_7.i386.rpm ia64: nss-3.12.10-7.el5_7.i386.rpm nss-3.12.10-7.el5_7.ia64.rpm nss-debuginfo-3.12.10-7.el5_7.i386.rpm nss-debuginfo-3.12.10-7.el5_7.ia64.rpm nss-devel-3.12.10-7.el5_7.ia64.rpm nss-pkcs11-devel-3.12.10-7.el5_7.ia64.rpm nss-tools-3.12.10-7.el5_7.ia64.rpm ppc: nss-3.12.10-7.el5_7.ppc.rpm nss-3.12.10-7.el5_7.ppc64.rpm nss-debuginfo-3.12.10-7.el5_7.ppc.rpm nss-debuginfo-3.12.10-7.el5_7.ppc64.rpm nss-devel-3.12.10-7.el5_7.ppc.rpm nss-devel-3.12.10-7.el5_7.ppc64.rpm nss-pkcs11-devel-3.12.10-7.el5_7.ppc.rpm nss-pkcs11-devel-3.12.10-7.el5_7.ppc64.rpm nss-tools-3.12.10-7.el5_7.ppc.rpm s390x: nss-3.12.10-7.el5_7.s390.rpm nss-3.12.10-7.el5_7.s390x.rpm nss-debuginfo-3.12.10-7.el5_7.s390.rpm nss-debuginfo-3.12.10-7.el5_7.s390x.rpm nss-devel-3.12.10-7.el5_7.s390.rpm nss-devel-3.12.10-7.el5_7.s390x.rpm nss-pkcs11-devel-3.12.10-7.el5_7.s390.rpm nss-pkcs11-devel-3.12.10-7.el5_7.s390x.rpm nss-tools-3.12.10-7.el5_7.s390x.rpm x86_64: nss-3.12.10-7.el5_7.i386.rpm nss-3.12.10-7.el5_7.x86_64.rpm nss-debuginfo-3.12.10-7.el5_7.i386.rpm nss-debuginfo-3.12.10-7.el5_7.x86_64.rpm nss-devel-3.12.10-7.el5_7.i386.rpm nss-devel-3.12.10-7.el5_7.x86_64.rpm nss-pkcs11-devel-3.12.10-7.el5_7.i386.rpm nss-pkcs11-devel-3.12.10-7.el5_7.x86_64.rpm nss-tools-3.12.10-7.el5_7.x86_64.rpm Red Hat Enterprise Linux Desktop (v.6): Source: i386: nspr-4.8.8-1.el6_1.i686.rpm nspr-debuginfo-4.8.8-1.el6_1.i686.rpm nss-3.12.10-2.el6_1.i686.rpm nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-sysinit-3.12.10-2.el6_1.i686.rpm nss-tools-3.12.10-2.el6_1.i686.rpm nss-util-3.12.10-1.el6_1.i686.rpm nss-util-debuginfo-3.12.10-1.el6_1.i686.rpm x86_64: nspr-4.8.8-1.el6_1.i686.rpm nspr-4.8.8-1.el6_1.x86_64.rpm nspr-debuginfo-4.8.8-1.el6_1.i686.rpm nspr-debuginfo-4.8.8-1.el6_1.x86_64.rpm nss-3.12.10-2.el6_1.i686.rpm nss-3.12.10-2.el6_1.x86_64.rpm nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-debuginfo-3.12.10-2.el6_1.x86_64.rpm nss-sysinit-3.12.10-2.el6_1.x86_64.rpm nss-tools-3.12.10-2.el6_1.x86_64.rpm nss-util-3.12.10-1.el6_1.i686.rpm nss-util-3.12.10-1.el6_1.x86_64.rpm nss-util-debuginfo-3.12.10-1.el6_1.i686.rpm nss-util-debuginfo-3.12.10-1.el6_1.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: nspr-debuginfo-4.8.8-1.el6_1.i686.rpm nspr-devel-4.8.8-1.el6_1.i686.rpm nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-devel-3.12.10-2.el6_1.i686.rpm nss-pkcs11-devel-3.12.10-2.el6_1.i686.rpm nss-util-debuginfo-3.12.10-1.el6_1.i686.rpm nss-util-devel-3.12.10-1.el6_1.i686.rpm x86_64: nspr-debuginfo-4.8.8-1.el6_1.i686.rpm nspr-debuginfo-4.8.8-1.el6_1.x86_64.rpm nspr-devel-4.8.8-1.el6_1.i686.rpm nspr-devel-4.8.8-1.el6_1.x86_64.rpm nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-debuginfo-3.12.10-2.el6_1.x86_64.rpm nss-devel-3.12.10-2.el6_1.i686.rpm nss-devel-3.12.10-2.el6_1.x86_64.rpm nss-pkcs11-devel-3.12.10-2.el6_1.i686.rpm nss-pkcs11-devel-3.12.10-2.el6_1.x86_64.rpm nss-util-debuginfo-3.12.10-1.el6_1.i686.rpm nss-util-debuginfo-3.12.10-1.el6_1.x86_64.rpm nss-util-devel-3.12.10-1.el6_1.i686.rpm nss-util-devel-3.12.10-1.el6_1.x86_64.rpm Red Hat Enterprise Linux HPC Node (v.6): Source: x86_64: nspr-4.8.8-1.el6_1.i686.rpm nspr-4.8.8-1.el6_1.x86_64.rpm nspr-debuginfo-4.8.8-1.el6_1.i686.rpm nspr-debuginfo-4.8.8-1.el6_1.x86_64.rpm nss-3.12.10-2.el6_1.i686.rpm nss-3.12.10-2.el6_1.x86_64.rpm nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-debuginfo-3.12.10-2.el6_1.x86_64.rpm nss-sysinit-3.12.10-2.el6_1.x86_64.rpm nss-tools-3.12.10-2.el6_1.x86_64.rpm nss-util-3.12.10-1.el6_1.i686.rpm nss-util-3.12.10-1.el6_1.x86_64.rpm nss-util-debuginfo-3.12.10-1.el6_1.i686.rpm nss-util-debuginfo-3.12.10-1.el6_1.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: nspr-debuginfo-4.8.8-1.el6_1.i686.rpm nspr-debuginfo-4.8.8-1.el6_1.x86_64.rpm nspr-devel-4.8.8-1.el6_1.i686.rpm nspr-devel-4.8.8-1.el6_1.x86_64.rpm nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-debuginfo-3.12.10-2.el6_1.x86_64.rpm nss-devel-3.12.10-2.el6_1.i686.rpm nss-devel-3.12.10-2.el6_1.x86_64.rpm nss-pkcs11-devel-3.12.10-2.el6_1.i686.rpm nss-pkcs11-devel-3.12.10-2.el6_1.x86_64.rpm nss-util-debuginfo-3.12.10-1.el6_1.i686.rpm nss-util-debuginfo-3.12.10-1.el6_1.x86_64.rpm nss-util-devel-3.12.10-1.el6_1.i686.rpm nss-util-devel-3.12.10-1.el6_1.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: i386: nspr-4.8.8-1.el6_1.i686.rpm nspr-debuginfo-4.8.8-1.el6_1.i686.rpm nspr-devel-4.8.8-1.el6_1.i686.rpm nss-3.12.10-2.el6_1.i686.rpm nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-devel-3.12.10-2.el6_1.i686.rpm nss-sysinit-3.12.10-2.el6_1.i686.rpm nss-tools-3.12.10-2.el6_1.i686.rpm nss-util-3.12.10-1.el6_1.i686.rpm nss-util-debuginfo-3.12.10-1.el6_1.i686.rpm nss-util-devel-3.12.10-1.el6_1.i686.rpm ppc64: nspr-4.8.8-1.el6_1.ppc.rpm nspr-4.8.8-1.el6_1.ppc64.rpm nspr-debuginfo-4.8.8-1.el6_1.ppc.rpm nspr-debuginfo-4.8.8-1.el6_1.ppc64.rpm nspr-devel-4.8.8-1.el6_1.ppc.rpm nspr-devel-4.8.8-1.el6_1.ppc64.rpm nss-3.12.10-2.el6_1.ppc.rpm nss-3.12.10-2.el6_1.ppc64.rpm nss-debuginfo-3.12.10-2.el6_1.ppc.rpm nss-debuginfo-3.12.10-2.el6_1.ppc64.rpm nss-devel-3.12.10-2.el6_1.ppc.rpm nss-devel-3.12.10-2.el6_1.ppc64.rpm nss-sysinit-3.12.10-2.el6_1.ppc64.rpm nss-tools-3.12.10-2.el6_1.ppc64.rpm nss-util-3.12.10-1.el6_1.ppc.rpm nss-util-3.12.10-1.el6_1.ppc64.rpm nss-util-debuginfo-3.12.10-1.el6_1.ppc.rpm nss-util-debuginfo-3.12.10-1.el6_1.ppc64.rpm nss-util-devel-3.12.10-1.el6_1.ppc.rpm nss-util-devel-3.12.10-1.el6_1.ppc64.rpm s390x: nspr-4.8.8-1.el6_1.s390.rpm nspr-4.8.8-1.el6_1.s390x.rpm nspr-debuginfo-4.8.8-1.el6_1.s390.rpm nspr-debuginfo-4.8.8-1.el6_1.s390x.rpm nspr-devel-4.8.8-1.el6_1.s390.rpm nspr-devel-4.8.8-1.el6_1.s390x.rpm nss-3.12.10-2.el6_1.s390.rpm nss-3.12.10-2.el6_1.s390x.rpm nss-debuginfo-3.12.10-2.el6_1.s390.rpm nss-debuginfo-3.12.10-2.el6_1.s390x.rpm nss-devel-3.12.10-2.el6_1.s390.rpm nss-devel-3.12.10-2.el6_1.s390x.rpm nss-sysinit-3.12.10-2.el6_1.s390x.rpm nss-tools-3.12.10-2.el6_1.s390x.rpm nss-util-3.12.10-1.el6_1.s390.rpm nss-util-3.12.10-1.el6_1.s390x.rpm nss-util-debuginfo-3.12.10-1.el6_1.s390.rpm nss-util-debuginfo-3.12.10-1.el6_1.s390x.rpm nss-util-devel-3.12.10-1.el6_1.s390.rpm nss-util-devel-3.12.10-1.el6_1.s390x.rpm x86_64: nspr-4.8.8-1.el6_1.i686.rpm nspr-4.8.8-1.el6_1.x86_64.rpm nspr-debuginfo-4.8.8-1.el6_1.i686.rpm nspr-debuginfo-4.8.8-1.el6_1.x86_64.rpm nspr-devel-4.8.8-1.el6_1.i686.rpm nspr-devel-4.8.8-1.el6_1.x86_64.rpm nss-3.12.10-2.el6_1.i686.rpm nss-3.12.10-2.el6_1.x86_64.rpm nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-debuginfo-3.12.10-2.el6_1.x86_64.rpm nss-devel-3.12.10-2.el6_1.i686.rpm nss-devel-3.12.10-2.el6_1.x86_64.rpm nss-sysinit-3.12.10-2.el6_1.x86_64.rpm nss-tools-3.12.10-2.el6_1.x86_64.rpm nss-util-3.12.10-1.el6_1.i686.rpm nss-util-3.12.10-1.el6_1.x86_64.rpm nss-util-debuginfo-3.12.10-1.el6_1.i686.rpm nss-util-debuginfo-3.12.10-1.el6_1.x86_64.rpm nss-util-devel-3.12.10-1.el6_1.i686.rpm nss-util-devel-3.12.10-1.el6_1.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: i386: nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-pkcs11-devel-3.12.10-2.el6_1.i686.rpm ppc64: nss-debuginfo-3.12.10-2.el6_1.ppc.rpm nss-debuginfo-3.12.10-2.el6_1.ppc64.rpm nss-pkcs11-devel-3.12.10-2.el6_1.ppc.rpm nss-pkcs11-devel-3.12.10-2.el6_1.ppc64.rpm s390x: nss-debuginfo-3.12.10-2.el6_1.s390.rpm nss-debuginfo-3.12.10-2.el6_1.s390x.rpm nss-pkcs11-devel-3.12.10-2.el6_1.s390.rpm nss-pkcs11-devel-3.12.10-2.el6_1.s390x.rpm x86_64: nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-debuginfo-3.12.10-2.el6_1.x86_64.rpm nss-pkcs11-devel-3.12.10-2.el6_1.i686.rpm nss-pkcs11-devel-3.12.10-2.el6_1.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: i386: nspr-4.8.8-1.el6_1.i686.rpm nspr-debuginfo-4.8.8-1.el6_1.i686.rpm nspr-devel-4.8.8-1.el6_1.i686.rpm nss-3.12.10-2.el6_1.i686.rpm nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-devel-3.12.10-2.el6_1.i686.rpm nss-sysinit-3.12.10-2.el6_1.i686.rpm nss-tools-3.12.10-2.el6_1.i686.rpm nss-util-3.12.10-1.el6_1.i686.rpm nss-util-debuginfo-3.12.10-1.el6_1.i686.rpm nss-util-devel-3.12.10-1.el6_1.i686.rpm x86_64: nspr-4.8.8-1.el6_1.i686.rpm nspr-4.8.8-1.el6_1.x86_64.rpm nspr-debuginfo-4.8.8-1.el6_1.i686.rpm nspr-debuginfo-4.8.8-1.el6_1.x86_64.rpm nspr-devel-4.8.8-1.el6_1.i686.rpm nspr-devel-4.8.8-1.el6_1.x86_64.rpm nss-3.12.10-2.el6_1.i686.rpm nss-3.12.10-2.el6_1.x86_64.rpm nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-debuginfo-3.12.10-2.el6_1.x86_64.rpm nss-devel-3.12.10-2.el6_1.i686.rpm nss-devel-3.12.10-2.el6_1.x86_64.rpm nss-sysinit-3.12.10-2.el6_1.x86_64.rpm nss-tools-3.12.10-2.el6_1.x86_64.rpm nss-util-3.12.10-1.el6_1.i686.rpm nss-util-3.12.10-1.el6_1.x86_64.rpm nss-util-debuginfo-3.12.10-1.el6_1.i686.rpm nss-util-debuginfo-3.12.10-1.el6_1.x86_64.rpm nss-util-devel-3.12.10-1.el6_1.i686.rpm nss-util-devel-3.12.10-1.el6_1.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-pkcs11-devel-3.12.10-2.el6_1.i686.rpm x86_64: nss-debuginfo-3.12.10-2.el6_1.i686.rpm nss-debuginfo-3.12.10-2.el6_1.x86_64.rpm nss-pkcs11-devel-3.12.10-2.el6_1.i686.rpm nss-pkcs11-devel-3.12.10-2.el6_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2011 Red Hat, Inc. . Recent NSS package enhancements address vulnerabilities in Red Hat Enterprise Linux. Key updates pertain to SSL/TLS certificates.. NSSUpdate, Red Hat Advisory, Network Security Services, HTTPS Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 09, 2011 Important Red Hat
87

Debian: DSA-2339-1 Moderate: NSS Trust Revocation and Fix

This update to the NSS cryptographic libraries revokes the trust in the "DigiCert Sdn. Bhd" certificate authority. More information can be found in the Mozilla Security Blog: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2339-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff November 07, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nss Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2011-3640 Debian Bug : 647614 This update to the NSS cryptographic libraries revokes the trust in the "DigiCert Sdn. Bhd" certificate authority. More information can be found in the Mozilla Security Blog: This update also fixes an insecure load path for pkcs11.txt configuration file (CVE-2011-3640). For the oldstable distribution (lenny), this problem has been fixed in version 3.12.3.1-0lenny7. For the stable distribution (squeeze), this problem has been fixed in version 3.12.8-1+squeeze4. For the unstable distribution (sid), this problem has been fixed in version 3.13.1.with.ckbi.1.88-1. We recommend that you upgrade your nss packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . DigiCert CA trust status withdrawn following NSS upgrade. Critical security patch released for Debian-based systems.. Debian Security,NSS Update,DigiCert Trust,Cryptographic Libraries,Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 07, 2011 Important Debian
172

Ubuntu 11.04: USN-1197-6 High Severity: Qt Certificate Authority Issue

A certificate authority mis-issued fraudulent certificates.. =========================================================================Ubuntu Security Notice USN-1197-6 September 22, 2011 qt4-x11 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: A certificate authority mis-issued fraudulent certificates. Software Description: - qt4-x11: Qt 4 libraries and support modules Details: USN-1197-1 and USN-1197-3 addressed an issue in Firefox and Xulrunner pertaining to the Dutch Certificate Authority DigiNotar mis-issuing fraudulent certificates. This update provides an update for Qt that blacklists the known fraudulent certificates. Original advisory details: USN-1197-1 It was discovered that Dutch Certificate Authority DigiNotar had mis-issued multiple fraudulent certificates. These certificates could allow an attacker to perform a "man in the middle" (MITM) attack which would make the user believe their connection is secure, but is actually being monitored. For the protection of its users, Mozilla has removed the DigiNotar certificate. Sites using certificates issued by DigiNotar will need to seek another certificate vendor. We are currently aware of a regression that blocks one of two Staat der Nederlanden root certificates which are believed to still be secure. This regression is being tracked at https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/838322. USN-1197-3 USN-1197-1 partially addressed an issue with Dutch Certificate Authority DigiNotar mis-issuing fraudulent certificates. This update actively distrusts the DigiNotar root certificate as well as several intermediary certificates. Also included in this list of distrusted certificates are the "PKIOverheid" (PKIGovernment) intermediates under DigiNotar's control that did not chain to DigiNotar's root andwere not previously blocked. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.04: libqt4-network 4:4.7.2-0ubuntu6.3 Ubuntu 10.10: libqt4-network 4:4.7.0-0ubuntu4.4 Ubuntu 10.04 LTS: libqt4-network 4:4.6.2-0ubuntu5.3 After a standard system upgrade you need to restart your session to effect the necessary changes. References: https://ubuntu.com/security/notices/USN-1197-6 https://ubuntu.com/security/notices/USN-1197-1 https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/837557 Package Information: https://launchpad.net/ubuntu/+source/qt4-x11/4:4.7.2-0ubuntu6.3 https://launchpad.net/ubuntu/+source/qt4-x11/4:4.7.0-0ubuntu4.4 https://launchpad.net/ubuntu/+source/qt4-x11/4:4.6.2-0ubuntu5.3 . Concerning the problem of unauthorized certificates released by a certificate authority affecting Ubuntu's Qt frameworks.. Qt Vulnerability, Certificate Misissuance, Fraudulent Certificates. . LinuxSecurity.com Team

Calendar%202 Sep 22, 2011 Ubuntu
87

Debian: DSA-2309-1 Critical: Remote Threat From DigiNotar Certificates

Several fraudulent SSL certificates have been found in the wild issued by the DigiNotar Certificate Authority, obtained through a security compromise of said company. After further updates on this incident, it has been determined that all of DigiNotar's signing certificates can no . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2309-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Raphael Geissert September 13, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openssl Vulnerability : compromised certificate authority Problem type : remote Debian-specific: no CVE ID : CVE-2011-1945 Several fraudulent SSL certificates have been found in the wild issued by the DigiNotar Certificate Authority, obtained through a security compromise of said company. After further updates on this incident, it has been determined that all of DigiNotar's signing certificates can no longer be trusted. Debian, like other software distributors and vendors, has decided to distrust all of DigiNotar's CAs. In this update, this is done in the crypto library (a component of the OpenSSL toolkit) by marking such certificates as revoked. Any application that uses said component should now reject certificates signed by DigiNotar. Individual applications may allow users to overrride the validation failure. However, making exceptions is highly discouraged and should be carefully verified. Additionally, a vulnerability has been found in the ECDHE_ECDS cipher where timing attacks make it easier to determine private keys. The Common Vulnerabilities and Exposures project identifies it as CVE-2011-1945. For the oldstable distribution (lenny), these problems have been fixed in version 0.9.8g-15+lenny12. For the stable distribution (squeeze), these problems have been fixed in version0.9.8o-4squeeze2. For the testing distribution (wheezy), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 1.0.0e-1. We recommend that you upgrade your openssl packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian releases patch for openssl as compromised CAcert certificates highlight vulnerabilities. Immediate upgrade advised.. OpenSSL Update, DigiNotar Threat, Debian Security Advisory, Remote Threats, Certificate Authority. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 13, 2011 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200