Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
203

Mageia 8 Advisory 2023-0140 Moderate: Trustcor Certificates Issue

Disable bundled Trustcor root cerificate signatures generated after Wednesday November 30 00:00:00 2022. (CVE-2022-23491) References: - https://bugs.mageia.org/show_bug.cgi?id=31248 . MGASA-2023-0140 - Updated python-certifi packages fix security vulnerability Publication date: 15 Apr 2023 URL: https://advisories.mageia.org/MGASA-2023-0140.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-23491 Disable bundled Trustcor root cerificate signatures generated after Wednesday November 30 00:00:00 2022. (CVE-2022-23491) References: - https://bugs.mageia.org/show_bug.cgi?id=31248 - https://ubuntu.com/security/notices/USN-5761-1 - - https://github.com/certifi/python-certifi/security/advisories/GHSA-43fp-rhv2-5gv8 - https://lists.suse.com/pipermail/sle-security-updates/2023-January/013525.html - - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/XVERIAPNA4QIBOA26OBVAYISGS3HRQDC/ - https://www.cve.org/CVERecord?id=CVE-2022-23491 SRPMS: - 8/core/python-certifi-2022.12.7-1.mga8 . Mageia 2023-0140 resolves Trustcor certificates issues in python-certifi, improving safety measures for users.. Python Certifi Security, Trustcor Certificate Update, Mageia Advisory. . LinuxSecurity.com Team

Calendar%202 Apr 15, 2023 Mageia
200

Scientific Linux SL7: SLSA-2023-0403-1 Critical SSSD LDAP Fix

sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters (CVE-2022-4254) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * smartcards: special characters must be escaped when building search filter SL7 x86_64 libipa_hbac-1.16.5-10.el7_9.15.i686.rpm l [More...]. Synopsis: Important: sssd security and bug fix update Advisory ID: SLSA-2023:0403-1 Issue Date: 2023-01-24 CVE Numbers: CVE-2022-4254 -- Security Fix(es): * sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters (CVE-2022-4254) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * smartcards: special characters must be escaped when building search filter -- SL7 x86_64 libipa_hbac-1.16.5-10.el7_9.15.i686.rpm libipa_hbac-1.16.5-10.el7_9.15.x86_64.rpm libsss_autofs-1.16.5-10.el7_9.15.x86_64.rpm libsss_certmap-1.16.5-10.el7_9.15.i686.rpm libsss_certmap-1.16.5-10.el7_9.15.x86_64.rpm libsss_idmap-1.16.5-10.el7_9.15.i686.rpm libsss_idmap-1.16.5-10.el7_9.15.x86_64.rpm libsss_nss_idmap-1.16.5-10.el7_9.15.i686.rpm libsss_nss_idmap-1.16.5-10.el7_9.15.x86_64.rpm libsss_simpleifp-1.16.5-10.el7_9.15.i686.rpm libsss_simpleifp-1.16.5-10.el7_9.15.x86_64.rpm libsss_sudo-1.16.5-10.el7_9.15.x86_64.rpm python-libipa_hbac-1.16.5-10.el7_9.15.x86_64.rpm python-sss-1.16.5-10.el7_9.15.x86_64.rpm python-sss-murmur-1.16.5-10.el7_9.15.x86_64.rpm sssd-1.16.5-10.el7_9.15.x86_64.rpm sssd-ad-1.16.5-10.el7_9.15.x86_64.rpm sssd-client-1.16.5-10.el7_9.15.i686.rpm sssd-client-1.16.5-10.el7_9.15.x86_64.rpm sssd-common-1.16.5-10.el7_9.15.x86_64.rpm sssd-common-pac-1.16.5-10.el7_9.15.x86_64.rpm sssd-dbus-1.16.5-10.el7_9.15.x86_64.rpm sssd-debuginfo-1.16.5-10.el7_9.15.i686.rpm sssd-debuginfo-1.16.5-10.el7_9.15.x86_64.rpm sssd-ipa-1.16.5-10.el7_9.15.x86_64.rpm sssd-kcm-1.16.5-10.el7_9.15.x86_64.rpm sssd-krb5-1.16.5-10.el7_9.15.x86_64.rpm sssd-krb5-common-1.16.5-10.el7_9.15.x86_64.rpm sssd-ldap-1.16.5-10.el7_9.15.x86_64.rpm sssd-libwbclient-1.16.5-10.el7_9.15.x86_64.rpm sssd-polkit-rules-1.16.5-10.el7_9.15.x86_64.rpm sssd-proxy-1.16.5-10.el7_9.15.x86_64.rpm sssd-tools-1.16.5-10.el7_9.15.x86_64.rpm sssd-winbind-idmap-1.16.5-10.el7_9.15.x86_64.rpm libipa_hbac-devel-1.16.5-10.el7_9.15.i686.rpm libipa_hbac-devel-1.16.5-10.el7_9.15.x86_64.rpm libsss_certmap-devel-1.16.5-10.el7_9.15.i686.rpm libsss_certmap-devel-1.16.5-10.el7_9.15.x86_64.rpm libsss_idmap-devel-1.16.5-10.el7_9.15.i686.rpm libsss_idmap-devel-1.16.5-10.el7_9.15.x86_64.rpm libsss_nss_idmap-devel-1.16.5-10.el7_9.15.i686.rpm libsss_nss_idmap-devel-1.16.5-10.el7_9.15.x86_64.rpm libsss_simpleifp-devel-1.16.5-10.el7_9.15.i686.rpm libsss_simpleifp-devel-1.16.5-10.el7_9.15.x86_64.rpm python-libsss_nss_idmap-1.16.5-10.el7_9.15.x86_64.rpm sssd-libwbclient-devel-1.16.5-10.el7_9.15.i686.rpm sssd-libwbclient-devel-1.16.5-10.el7_9.15.x86_64.rpm noarch python-sssdconfig-1.16.5-10.el7_9.15.noarch.rpm - Scientific Linux Development Team . Important sssd security patch rollout for Scientific Linux SL7.x targeting vulnerabilities related to certificate validation. This update rectifies significant sanitization flaws.. Scientific Linux, SSSD, Certificate Fix, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 24, 2023 Critical Scientific Linux
89

Fedora: 2017-8840ec0204 Critical: Empathy Instant Messaging Update

Fix certificate validation to work without legacy CAs. ---- empathy 3.12.13 release. For details, see https://mail.gnome.org/archives/ftp-release-list/2017-March/msg00077.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-8840ec0204 2017-04-01 16:46:19.662323 -------------------------------------------------------------------------------- Name : empathy Product : Fedora 26 Version : 3.12.13 Release : 2.fc26 URL : Summary : Instant Messaging Client for GNOME Description : Empathy is powerful multi-protocol instant messaging client which supports Jabber, GTalk, MSN, IRC, Salut, and other protocols. It is built on top of the Telepathy framework. -------------------------------------------------------------------------------- Update Information: Fix certificate validation to work without legacy CAs. ---- empathy 3.12.13 release. For details, see https://mail.gnome.org/archives/ftp-release-list/2017-March/msg00077.html -------------------------------------------------------------------------------- References: [ 1 ] Bug #1381671 - Fails to connect to Google, with legacy CAs disabled, or with ca-certificates version 2.10 https://bugzilla.redhat.com/show_bug.cgi?id=1381671 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade empathy' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. . Resolves certificate verification issues in compassion for Fedora 26, eliminating outdated CAs in the newest security patch.. Empathy Update,Fedora Security,Certificate Validation,Instant Messaging,Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 01, 2017 Critical Fedora
89

Fedora 10 Critical: kdeplasma-addons 4.3.1 KIO Certificate Fix

This updates KDE to 4.3.1, the latest upstream bugfix release. The main improvements are: * KDE 4.3 is now also available in Croatian. * A crash when editing toolbar setup has been fixed. * Support for transferring files through SSH using KIO::Fish has been fixed. * A number of bugs in KWin, KDE's window and compositing manager has been fixed. * A large number of bugs in KMail, KDE's email client are now gone. See https://kde.org/announcements/announce-4.3.1/ for more information. In addition, this update: * fixes a potential security issue (CVE-2009-2702) with certificate validation in the KIO KSSL code. It is believed that the affected code is not actually used (the code in Qt, for which a security update was already issued, is) and thus the issue is only potential, but KSSL is being patched just in case, * splits PolicyKit-kde out of kdebase-workspace again to avoid forcing it onto GNOME-based setups, where PolicyKit-gnome is desired instead (#519654).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-9427 2009-09-09 00:48:07 -------------------------------------------------------------------------------- Name : kdeplasma-addons Product : Fedora 10 Version : 4.3.1 Release : 1.fc10 URL : https://kde.org/ Summary : Additional plasmoids for KDE Description : Additional plasmoids for KDE. -------------------------------------------------------------------------------- Update Information: This updates KDE to 4.3.1, the latest upstream bugfix release. The main improvements are: * KDE 4.3 is now also available in Croatian. * A crash when editing toolbar setup has been fixed. * Support for transferring files through SSH using KIO::Fish has been fixed. * A number of bugs in KWin, KDE's window and compositing manager has been fixed. * A large number of bugs in KMail, KDE's email client are now gone. See https://kde.org/announcements/announce-4.3.1/ for more information. In addition, thisupdate: * fixes a potential security issue (CVE-2009-2702) with certificate validation in the KIO KSSL code. It is believed that the affected code is not actually used (the code in Qt, for which a security update was already issued, is) and thus the issue is only potential, but KSSL is being patched just in case, * splits PolicyKit-kde out of kdebase-workspace again to avoid forcing it onto GNOME-based setups, where PolicyKit-gnome is desired instead (#519654). -------------------------------------------------------------------------------- ChangeLog: * Fri Aug 28 2009 Than Ngo - 4.3.1-1 - 4.3.1 * Thu Aug 13 2009 Than Ngo - 4.3.0-9 - omit BR on kdeedu-devel/eigen2-devel for rhel * Fri Aug 7 2009 Ben Boeckel - 4.3.0-8 - Waited for newRepo task * Fri Aug 7 2009 Ben Boeckel - 4.3.0-7 - Rebuild for mising rawhide oxygen-icon-theme - Fix patch comments * Fri Aug 7 2009 Ben Boeckel - 4.3.0-6 - Add patch to fix kde#196809 * Tue Aug 4 2009 Than Ngo - 4.3.0-5 - respin * Mon Aug 3 2009 Rex Dieter - 4.3.0-4 - fix microblog post crasher (kdebug#202364) * Mon Aug 3 2009 Rex Dieter - 4.3.0-3 - -libs subpkg to sanitize multilib * Sun Aug 2 2009 Rex Dieter - 4.3.0-2 - fix to allow updating of status via microblog plasmoid * Thu Jul 30 2009 Than Ngo - 4.3.0-1 - 4.3.0 * Wed Jul 22 2009 Than Ngo - 4.2.98-1 - 4.3rc3 * Thu Jul 16 2009 Rex Dieter - 4.2.96-2 - BR: libXcomposite-devel (lancelot eye-candy) * Sun Jul 12 2009 Than Ngo - 4.2.96-1 - 4.3rc2 * Fri Jun 26 2009 Than Ngo - 4.2.95-1 - 4.3rc1 * Thu Jun 4 2009 Rex Dieter - 4.2.90-1 - KDE-4.3 beta2 (4.2.90) * Mon May 25 2009 Rex Dieter - 4.2.85-4 - BR: eigen2-devel soprano-devel * Tue May 19 2009 Kevin Kofler - 4.2.85-3 - BR kdeedu-devel (for Marble) * Sun May 17 2009 Kevin Kofler - 4.2.85-2 - Obsoletes/Provides: kde-plasma-weather * Wed May 13 2009 Lukáš Tinkl - 4.2.85-1 - KDE 4.3 beta 1 * Thu Apr 30 2009 Rex Dieter - 4.2.2-3 - disable contacts krunner by default * Wed Apr 1 2009 Rex Dieter - 4.2.2-2 - optimize scriptlets *Tue Mar 31 2009 Lukáš Tinkl - 4.2.2-1 - KDE 4.2.2 * Mon Mar 16 2009 Rex Dieter - 4.2.1-3 - make bball applet work, ship .svg instead of .svgz (kdebug#185568) - use new %_qt45 macro - spec housecleaning * Fri Mar 13 2009 Kevin Kofler - 4.2.1-2 - fix Lancelot rendering issues with Qt 4.5 (F11+ only, as the effect of that patch with 4.4.3 is unknown) * Fri Feb 27 2009 Than Ngo - 4.2.1-1 - 4.2.1 * Wed Feb 25 2009 Fedora Release Engineering - 4.2.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Thu Jan 22 2009 Than Ngo - 4.2.0-1 - 4.2.0 * Wed Jan 7 2009 Than Ngo - 4.1.96-1 - 4.2rc1 * Tue Dec 16 2008 Rex Dieter 4.1.85-2 - saner versioned Obsoletes * Fri Dec 12 2008 Than Ngo 4.1.85-1 - 4.2beta2 * Tue Dec 2 2008 Kevin Kofler 4.1.80-3 - BR plasma-devel - add Provides: kde-plasma-lancelot - fix file list - BR libkexiv2-devel > = 0.4.0 on F10+ * Thu Nov 20 2008 Than Ngo 4.1.80-2 - merged - add Obsoletes: kde-plasma-lancelot * Thu Nov 20 2008 Lorenzo Villani - 4.1.80-1 - 4.1.80 - BR cmake > = 2.6.2 - make install/fast * Wed Nov 12 2008 Than Ngo 4.1.3-1 - 4.1.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #520661 - CVE-2009-2702 kdelibs: kssl incorrect verification of SSL certificate with NUL in subjectAltName https://bugzilla.redhat.com/show_bug.cgi?id=520661 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update kdeplasma-addons' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The recent update for KDE 4.3.1 on Fedora 10 addresses various bugs and enhances security concerning KIO KSSL. Users can easily apply this update using the yum package manager.. KDE Update,Fedora 10,kdeplasma-addons,certificate fix,security updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 15, 2009 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here