Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
98

Red Hat Software Collections RHSA-2022:7044-01 Moderate: Node.js Update

An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-nodejs14-nodejs security update Advisory ID: RHSA-2022:7044-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2022:7044 Issue date: 2022-10-19 CVE Names: CVE-2021-44531 CVE-2021-44532 CVE-2021-44533 CVE-2021-44906 CVE-2022-21824 CVE-2022-35256 ==================================================================== 1. Summary: An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * nodejs: Improper handling of URI Subject Alternative Names (CVE-2021-44531) * nodejs: Certificate Verification Bypass via String Injection (CVE-2021-44532) * nodejs: Incorrect handling of certificate subject and issuer fields (CVE-2021-44533) * minimist: prototype pollution (CVE-2021-44906) * nodejs: HTTP Request Smuggling due to incorrect parsing of header fields (CVE-2022-35256) * nodejs: Prototype pollution viaconsole.table properties (CVE-2022-21824) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2040839 - CVE-2021-44531 nodejs: Improper handling of URI Subject Alternative Names 2040846 - CVE-2021-44532 nodejs: Certificate Verification Bypass via String Injection 2040856 - CVE-2021-44533 nodejs: Incorrect handling of certificate subject and issuer fields 2040862 - CVE-2022-21824 nodejs: Prototype pollution via console.table properties 2066009 - CVE-2021-44906 minimist: prototype pollution 2130518 - CVE-2022-35256 nodejs: HTTP Request Smuggling due to incorrect parsing of header fields 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-nodejs14-nodejs-14.20.1-2.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.20.1-2.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.20.1-2.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.20.1-2.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.20.1-2.el7.ppc64le.rpm rh-nodejs14-npm-6.14.17-14.20.1.2.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.20.1-2.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.20.1-2.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.20.1-2.el7.s390x.rpm rh-nodejs14-npm-6.14.17-14.20.1.2.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.20.1-2.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.20.1-2.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.20.1-2.el7.x86_64.rpm rh-nodejs14-npm-6.14.17-14.20.1.2.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v.7): Source: rh-nodejs14-nodejs-14.20.1-2.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.20.1-2.el7.noarch.rpm x86_64: rh-nodejs14-nodejs-14.20.1-2.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.20.1-2.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.20.1-2.el7.x86_64.rpm rh-nodejs14-npm-6.14.17-14.20.1.2.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-44531 https://access.redhat.com/security/cve/CVE-2021-44532 https://access.redhat.com/security/cve/CVE-2021-44533 https://access.redhat.com/security/cve/CVE-2021-44906 https://access.redhat.com/security/cve/CVE-2022-21824 https://access.redhat.com/security/cve/CVE-2022-35256 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY1Bkk9zjgjWX9erEAQh9DQ//dSOPbtnYD3f9AvLUnQpnJb7OyGisGpPW von8hNiTCD5J3FP2DlY3/wGX9H1g2BXmuwpojS/sh17E2+sHldBTMk5kxT8bkBkB ZWnmIwqA1PfjAO4FEc7MtePJXsqCrBne63Bpo7k3ALc4hHtP2BEMkjA4ZOJJDl82 ydj74PPr0uVuZAn0jcLKsIPq1OmUW9jNuzY0p5uqhXKVP4XfFWfpi2dd34Nej+dv RbSABk5jZ0R6bQlPOdG4bI8vevvmhkeAqkcWgHWBZ9n34SFdiGKFdxUI3+SM2zvl tB7zuDc9rsLnF7DLZq3HVG3eOVdxJ1MKwap89iQrmQCy1kz4iq3hZbAKJHIjLTEy gWpwYI9nCamIsNwYB1pUM5RexkKTPKDRttZh9hff2RO9QCvdnecw3386blkhsb8s XJMAywflJeBrTnMPQ9tSNx60CgGI8JkU40RtnfwwS5yS1upd56jYbL+W4CzbZmzd bj48/l+fl3Ny0bGZ6QAG0ZWrH0eTs6hL/xYKFu2Z7jDteP9ITE1kSKeISjE/G0Rb Hjjp6sfEiR07PEJx2/Lne+o5JvCGu7wviT2SnJIfjX9C056CtO4IjRXEqdPqZqYq 3+T1AOLM1M2vu55WagYhnTtfGefIj5EScstARXZjz5pF0dQyhNZNO+p/S0coNUWz y4v1DFKlYtA=JvnP -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . An upgrade for rh-nodejs14-nodejs has been released for Red Hat Software Collections, carrying a moderate security impact rating..Red Hat Software Collections, rh-nodejs14-nodejs update, nodejs security issues. . LinuxSecurity.com Team

Calendar%202 Oct 19, 2022 Red Hat
100

SUSE: 2022:15034-1 Important: Ruby Man In The Middle Threats

An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for ruby ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:15034-1 Rating: important References: #1112530 #1188160 #1188161 Cross-References: CVE-2018-16395 CVE-2021-31810 CVE-2021-32066 CVE-2021-81810 CVSS scores: CVE-2018-16395 (NVD) : 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2018-16395 (SUSE): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N CVE-2021-31810 (NVD) : 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N CVE-2021-31810 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2021-32066 (NVD) : 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2021-32066 (SUSE): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: SUSE Webyast 1.3 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for ruby fixes the following issues: - CVE-2018-16395: Fixed an issue where two x509 certificates could be considered to be equal when this was not the case (bsc#1112530). - CVE-2021-32066: Fixed an issue where the IMAP client API would not report a failure when StartTLS failed, leading to potential man in the middle attacks (bsc#1188160). - CVE-2021-31810: Fixed an issue where the FTP client API would trust certain responses from a malicious server, tricking the client into connecting to addresses not (bsc#1188161). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Webyast 1.3: zypper in -t patchslewyst13-ruby-15034=1 Package List: - SUSE Webyast 1.3 (i586 ia64 ppc64 s390x x86_64): ruby-devel-1.8.7.p357-0.9.20.3.1 References: https://www.suse.com/security/cve/CVE-2018-16395.html https://www.suse.com/security/cve/CVE-2021-31810.html https://www.suse.com/security/cve/CVE-2021-32066.html https://www.suse.com/security/cve/CVE-2021-81810.html https://bugzilla.suse.com/1112530 https://bugzilla.suse.com/1188160 https://bugzilla.suse.com/1188161 . Crucial SUSE Security Patch for Python: Addresses three critical flaws that pose significant risks.. SUSE Security Update, Ruby Patch, Man In The Middle, Certificate Issues, Software Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 06, 2022 Important SuSE
89

Fedora 34: FEDORA-2022-78090d2099 Medium: Node.js URI Handling Issues

## 2022-01-10, Version 14.18.3 'Fermium' (LTS), @richardlau This is a security release. ### Notable changes #### Improper handling of URI Subject Alternative Names (Medium)(CVE-2021-44531) Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js was accepting. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-78090d2099 2022-01-20 08:31:04.549654 --------------------------------------------------------------------------------Name : nodejs Product : Fedora 34 Version : 14.18.3 Release : 1.fc34 URL : https://nodejs.org/en/ Summary : JavaScript runtime Description : Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. --------------------------------------------------------------------------------Update Information: ## 2022-01-10, Version 14.18.3 'Fermium' (LTS), @richardlau This is a security release. ### Notable changes #### Improper handling of URI Subject Alternative Names (Medium)(CVE-2021-44531) Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js was accepting URI SAN types, which PKIs are often not defined to use. Additionally, when a protocol allows URI SANs, Node.js did not match the URI correctly. Versions of Node.js with the fix for this disable the URI SAN type when checking a certificate against a hostname. This behavior can be reverted through the `--security-revert` command-line option. More details will be availableat [CVE-2021-44531](https://www.cve.org/CVERecord?id=CVE-2021-44531) after publication. #### Certificate Verification Bypass via String Injection (Medium)(CVE-2021-44532) Node.js converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints. Versions of Node.js with the fix for this escape SANs containing the problematic characters in order to prevent the injection. This behavior can be reverted through the `--security-revert` command-line option. More details will be available at [CVE-2021-44532](https://www.cve.org/CVERecord?id=CVE-2021-44532) after publication. #### Incorrect handling of certificate subject and issuer fields (Medium)(CVE-2021-44533) Node.js did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification. Affected versions of Node.js do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable. More details will be available at [CVE-2021-44533](https://www.cve.org/CVERecord?id=CVE-2021-44533) after publication. #### Prototype pollution via `console.table` properties (Low)(CVE-2022-21824) Due to the formatting logic of the `console.table()` function it was not safe to allow user controlled input to be passed to the `properties` parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be `__proto__`. Theprototype pollution has very limited control, in that it only allows an empty string to be assigned numerical keys of the object prototype. Versions of Node.js with the fix for this use a null protoype for the object these properties are being assigned to. More details will be available at [CVE-2022-21824](https://www.cve.org/CVERecord?id=CVE-2022-21824) after publication. Thanks to Patrik Oldsberg (rugvip) for reporting this vulnerability. --------------------------------------------------------------------------------ChangeLog: * Tue Jan 11 2022 Stephen Gallagher - 1:14.18.3-1 - Security release 14.18.3 - Improper handling of URI Subject Alternative Names (Medium)(CVE-2021-44531) - Certificate Verification Bypass via String Injection (Medium)(CVE-2021-44532) - Incorrect handling of certificate subject and issuer fields (Medium)(CVE-2021-44533) - Prototype pollution via `console.table` properties (Low)(CVE-2022-21824) --------------------------------------------------------------------------------References: [ 1 ] Bug #2040839 - CVE-2021-44531 nodejs: Improper handling of URI Subject Alternative Names https://bugzilla.redhat.com/show_bug.cgi?id=2040839 [ 2 ] Bug #2040846 - CVE-2021-44532 nodejs: Certificate Verification Bypass via String Injection https://bugzilla.redhat.com/show_bug.cgi?id=2040846 [ 3 ] Bug #2040856 - CVE-2021-44533 nodejs: Incorrect handling of certificate subject and issuer fields https://bugzilla.redhat.com/show_bug.cgi?id=2040856 [ 4 ] Bug #2040862 - CVE-2022-21824 nodejs: Prototype pollution via console.table properties https://bugzilla.redhat.com/show_bug.cgi?id=2040862 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-78090d2099' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html Allpackages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Node.js has issued an important security update for Fedora users, addressing URI SAN processing vulnerabilities, improving certificate verification, and tackling prototype pollution issues. NodeJS Update, Fedora Security, URI Handling Issues. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jan 20, 2022 Medium Fedora
100

SUSE: 2017:0348-1 Important: gnutls DoS Threat Advisory

An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.. SUSE Security Update: Security update for gnutls ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:0348-1 Rating: important References: #1005879 #1018832 #999646 Cross-References: CVE-2016-7444 CVE-2016-8610 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Software Development Kit 12-SP1 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Server 12-SP1 SUSE Linux Enterprise Desktop 12-SP2 SUSE Linux Enterprise Desktop 12-SP1 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for gnutls fixes the following security issues: - GnuTLS could have crashed when processing maliciously crafted OpenPGP certificates (GNUTLS-SA-2017-2, bsc#1018832, CVE-2017-5335, CVE-2017-5337, CVE-2017-5336) - GnuTLS could have falsely accepted certificates when using OCSP (GNUTLS-SA-2016-3, bsc#999646, CVE-2016-7444) - GnuTLS could have suffered from 100% CPU load DoS attacks by using SSL alert packets during the handshake (bsc#1005879, CVE-2016-8610) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-177=1 - SUSE Linux Enterprise Software Development Kit 12-SP1: zypper in -t patchSUSE-SLE-SDK-12-SP1-2017-177=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-177=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-177=1 - SUSE Linux Enterprise Server 12-SP1: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-177=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-177=1 - SUSE Linux Enterprise Desktop 12-SP1: zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2017-177=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): gnutls-debuginfo-3.2.15-16.1 gnutls-debugsource-3.2.15-16.1 libgnutls-devel-3.2.15-16.1 libgnutls-openssl-devel-3.2.15-16.1 libgnutlsxx-devel-3.2.15-16.1 libgnutlsxx28-3.2.15-16.1 libgnutlsxx28-debuginfo-3.2.15-16.1 - SUSE Linux Enterprise Software Development Kit 12-SP1 (ppc64le s390x x86_64): gnutls-debuginfo-3.2.15-16.1 gnutls-debugsource-3.2.15-16.1 libgnutls-devel-3.2.15-16.1 libgnutls-openssl-devel-3.2.15-16.1 libgnutlsxx-devel-3.2.15-16.1 libgnutlsxx28-3.2.15-16.1 libgnutlsxx28-debuginfo-3.2.15-16.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): gnutls-3.2.15-16.1 gnutls-debuginfo-3.2.15-16.1 gnutls-debugsource-3.2.15-16.1 libgnutls-openssl27-3.2.15-16.1 libgnutls-openssl27-debuginfo-3.2.15-16.1 libgnutls28-3.2.15-16.1 libgnutls28-debuginfo-3.2.15-16.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): gnutls-3.2.15-16.1 gnutls-debuginfo-3.2.15-16.1 gnutls-debugsource-3.2.15-16.1 libgnutls-openssl27-3.2.15-16.1 libgnutls-openssl27-debuginfo-3.2.15-16.1 libgnutls28-3.2.15-16.1 libgnutls28-debuginfo-3.2.15-16.1 - SUSE Linux Enterprise Server 12-SP2 (x86_64): libgnutls28-32bit-3.2.15-16.1 libgnutls28-debuginfo-32bit-3.2.15-16.1 - SUSE Linux Enterprise Server 12-SP1 (ppc64le s390x x86_64): gnutls-3.2.15-16.1 gnutls-debuginfo-3.2.15-16.1 gnutls-debugsource-3.2.15-16.1 libgnutls-openssl27-3.2.15-16.1 libgnutls-openssl27-debuginfo-3.2.15-16.1 libgnutls28-3.2.15-16.1 libgnutls28-debuginfo-3.2.15-16.1 - SUSE Linux Enterprise Server 12-SP1 (s390x x86_64): libgnutls28-32bit-3.2.15-16.1 libgnutls28-debuginfo-32bit-3.2.15-16.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): gnutls-3.2.15-16.1 gnutls-debuginfo-3.2.15-16.1 gnutls-debugsource-3.2.15-16.1 libgnutls28-3.2.15-16.1 libgnutls28-32bit-3.2.15-16.1 libgnutls28-debuginfo-3.2.15-16.1 libgnutls28-debuginfo-32bit-3.2.15-16.1 - SUSE Linux Enterprise Desktop 12-SP1 (x86_64): gnutls-3.2.15-16.1 gnutls-debuginfo-3.2.15-16.1 gnutls-debugsource-3.2.15-16.1 libgnutls28-3.2.15-16.1 libgnutls28-32bit-3.2.15-16.1 libgnutls28-debuginfo-3.2.15-16.1 libgnutls28-debuginfo-32bit-3.2.15-16.1 References: https://www.suse.com/security/cve/CVE-2016-7444.html https://www.suse.com/security/cve/CVE-2016-8610.html https://www.suse.com/security/cve/CVE-2017-5335.html https://www.suse.com/security/cve/CVE-2017-5336.html https://www.suse.com/security/cve/CVE-2017-5337.html https://bugzilla.suse.com/1005879 https://bugzilla.suse.com/1018832 https://bugzilla.suse.com/999646 . Red Hat rolls out a critical OpenSSL update addressing various vulnerabilities. Make sure your servers are secured with the latest patches!. GnuTLS Update, Security Advisory, DoS Attack Fixes, SUSE Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 01, 2017 Important SuSE
87

Debian DSA-2994-1 Moderate: NSS Certificate Issues and Fixes

Several vulnerabilities have been discovered in nss, the Mozilla Network Security Service library: CVE-2013-1741 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2994-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Raphael Geissert July 31, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nss CVE ID : CVE-2013-1741 CVE-2013-5606 CVE-2014-1491 CVE-2014-1492 Several vulnerabilities have been discovered in nss, the Mozilla Network Security Service library: CVE-2013-1741 Runaway memset in certificate parsing on 64-bit computers leading to a crash by attempting to write 4Gb of nulls. CVE-2013-5606 Certificate validation with the verifylog mode did not return validation errors, but instead expected applications to determine the status by looking at the log. CVE-2014-1491 Ticket handling protection mechanisms bypass due to the lack of restriction of public values in Diffie-Hellman key exchanges. CVE-2014-1492 Incorrect IDNA domain name matching for wildcard certificates could allow specially-crafted invalid certificates to be considered as valid. For the stable distribution (wheezy), these problems have been fixed in version 2:3.14.5-1+deb7u1. For the testing distribution (jessie), and the unstable distribution (sid), these problems have been fixed in version 2:3.16-1. We recommend that you upgrade your nss packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-2994-1 alerts of critical vulnerabilities in the NSS package. Users are urged to update promptly to enhance security andprevent breaches. Debian Security,nss Update,Certificate Validation,Security Threats,Certificate Issues. . LinuxSecurity.com Team

Calendar%202 Jul 31, 2014 Debian
200

Scientific Linux: SLSA-2013:1861-1 Moderate: NSS Certificate Issue

Moderate: nss security update. Date: Thu, 26 Dec 2013 20:53:10 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Bonnie King Subject: Security ERRATA Moderate: nss on SL5.x, SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: nss security update Advisory ID: SLSA-2013:1861-1 Issue Date: 2013-12-19 CVE Numbers: None -- It was found that a subordinate Certificate Authority (CA) mis-issued an intermediate certificate, which could be used to conduct man-in-the-middle attacks. This update renders that particular intermediate certificate as untrusted. Note: This fix only applies to applications using the NSS Builtin Object Token. It does not render the certificates untrusted for applications that use the NSS library, but do not use the NSS Builtin Object Token. After installing the update, applications using NSS must be restarted for the changes to take effect. -- SL5 x86_64 nss-3.15.3-4.el5_10.i386.rpm nss-3.15.3-4.el5_10.x86_64.rpm nss-debuginfo-3.15.3-4.el5_10.i386.rpm nss-debuginfo-3.15.3-4.el5_10.x86_64.rpm nss-tools-3.15.3-4.el5_10.x86_64.rpm nss-devel-3.15.3-4.el5_10.i386.rpm nss-devel-3.15.3-4.el5_10.x86_64.rpm nss-pkcs11-devel-3.15.3-4.el5_10.i386.rpm nss-pkcs11-devel-3.15.3-4.el5_10.x86_64.rpm i386 nss-3.15.3-4.el5_10.i386.rpm nss-debuginfo-3.15.3-4.el5_10.i386.rpm nss-tools-3.15.3-4.el5_10.i386.rpm nss-devel-3.15.3-4.el5_10.i386.rpm nss-pkcs11-devel-3.15.3-4.el5_10.i386.rpm SL6 x86_64 nss-3.15.3-3.el6_5.i686.rpm nss-3.15.3-3.el6_5.x86_64.rpm nss-debuginfo-3.15.3-3.el6_5.i686.rpm nss-debuginfo-3.15.3-3.el6_5.x86_64.rpm nss-sysinit-3.15.3-3.el6_5.x86_64.rpm nss-tools-3.15.3-3.el6_5.x86_64.rpm nss-devel-3.15.3-3.el6_5.i686.rpm nss-devel-3.15.3-3.el6_5.x86_64.rpm nss-pkcs11-devel-3.15.3-3.el6_5.i686.rpm nss-pkcs11-devel-3.15.3-3.el6_5.x86_64.rpm i386 nss-3.15.3-3.el6_5.i686.rpm nss-debuginfo-3.15.3-3.el6_5.i686.rpm nss-sysinit-3.15.3-3.el6_5.i686.rpm nss-tools-3.15.3-3.el6_5.i686.rpm nss-devel-3.15.3-3.el6_5.i686.rpm nss-pkcs11-devel-3.15.3-3.el6_5.i686.rpm - Scientific Linux Development Team lastline . Routine NSS patch released for Scientific Linux to rectify certificate mis-issuance, enhancing defense against potential exploits.. NSS Security Update, Scientific Linux, Certificate Authority, Security Advisory, Software Update. . LinuxSecurity.com Team

Calendar%202 Dec 26, 2013 Scientific Linux
98

Red Hat Enterprise Linux 4: RHSA-2011:0375-01 Important SeaMonkey DoS

Updated seamonkey packages that fix one security issue are now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: seamonkey security update Advisory ID: RHSA-2011:0375-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:0375.html Issue date: 2011-03-22 ==================================================================== 1. Summary: Updated seamonkey packages that fix one security issue are now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having important security impact. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Description: SeaMonkey is an open source web browser, email and newsgroup client, IRC chat client, and HTML editor. This erratum blacklists a small number of HTTPS certificates. (BZ#689430) All SeaMonkey users should upgrade to these updated packages, which correct this issue. After installing the update, SeaMonkey must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 689430 - Compromised certificates 6. Package List: Red Hat Enterprise Linux AS version4: Source: i386: seamonkey-1.0.9-68.el4_8.i386.rpm seamonkey-chat-1.0.9-68.el4_8.i386.rpm seamonkey-debuginfo-1.0.9-68.el4_8.i386.rpm seamonkey-devel-1.0.9-68.el4_8.i386.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.i386.rpm seamonkey-js-debugger-1.0.9-68.el4_8.i386.rpm seamonkey-mail-1.0.9-68.el4_8.i386.rpm ia64: seamonkey-1.0.9-68.el4_8.ia64.rpm seamonkey-chat-1.0.9-68.el4_8.ia64.rpm seamonkey-debuginfo-1.0.9-68.el4_8.ia64.rpm seamonkey-devel-1.0.9-68.el4_8.ia64.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.ia64.rpm seamonkey-js-debugger-1.0.9-68.el4_8.ia64.rpm seamonkey-mail-1.0.9-68.el4_8.ia64.rpm ppc: seamonkey-1.0.9-68.el4_8.ppc.rpm seamonkey-chat-1.0.9-68.el4_8.ppc.rpm seamonkey-debuginfo-1.0.9-68.el4_8.ppc.rpm seamonkey-devel-1.0.9-68.el4_8.ppc.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.ppc.rpm seamonkey-js-debugger-1.0.9-68.el4_8.ppc.rpm seamonkey-mail-1.0.9-68.el4_8.ppc.rpm s390: seamonkey-1.0.9-68.el4_8.s390.rpm seamonkey-chat-1.0.9-68.el4_8.s390.rpm seamonkey-debuginfo-1.0.9-68.el4_8.s390.rpm seamonkey-devel-1.0.9-68.el4_8.s390.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.s390.rpm seamonkey-js-debugger-1.0.9-68.el4_8.s390.rpm seamonkey-mail-1.0.9-68.el4_8.s390.rpm s390x: seamonkey-1.0.9-68.el4_8.s390x.rpm seamonkey-chat-1.0.9-68.el4_8.s390x.rpm seamonkey-debuginfo-1.0.9-68.el4_8.s390x.rpm seamonkey-devel-1.0.9-68.el4_8.s390x.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.s390x.rpm seamonkey-js-debugger-1.0.9-68.el4_8.s390x.rpm seamonkey-mail-1.0.9-68.el4_8.s390x.rpm x86_64: seamonkey-1.0.9-68.el4_8.x86_64.rpm seamonkey-chat-1.0.9-68.el4_8.x86_64.rpm seamonkey-debuginfo-1.0.9-68.el4_8.x86_64.rpm seamonkey-devel-1.0.9-68.el4_8.x86_64.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.x86_64.rpm seamonkey-js-debugger-1.0.9-68.el4_8.x86_64.rpm seamonkey-mail-1.0.9-68.el4_8.x86_64.rpm Red Hat Enterprise Linux Desktop version4: Source: i386: seamonkey-1.0.9-68.el4_8.i386.rpm seamonkey-chat-1.0.9-68.el4_8.i386.rpm seamonkey-debuginfo-1.0.9-68.el4_8.i386.rpm seamonkey-devel-1.0.9-68.el4_8.i386.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.i386.rpm seamonkey-js-debugger-1.0.9-68.el4_8.i386.rpm seamonkey-mail-1.0.9-68.el4_8.i386.rpm x86_64: seamonkey-1.0.9-68.el4_8.x86_64.rpm seamonkey-chat-1.0.9-68.el4_8.x86_64.rpm seamonkey-debuginfo-1.0.9-68.el4_8.x86_64.rpm seamonkey-devel-1.0.9-68.el4_8.x86_64.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.x86_64.rpm seamonkey-js-debugger-1.0.9-68.el4_8.x86_64.rpm seamonkey-mail-1.0.9-68.el4_8.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: seamonkey-1.0.9-68.el4_8.i386.rpm seamonkey-chat-1.0.9-68.el4_8.i386.rpm seamonkey-debuginfo-1.0.9-68.el4_8.i386.rpm seamonkey-devel-1.0.9-68.el4_8.i386.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.i386.rpm seamonkey-js-debugger-1.0.9-68.el4_8.i386.rpm seamonkey-mail-1.0.9-68.el4_8.i386.rpm ia64: seamonkey-1.0.9-68.el4_8.ia64.rpm seamonkey-chat-1.0.9-68.el4_8.ia64.rpm seamonkey-debuginfo-1.0.9-68.el4_8.ia64.rpm seamonkey-devel-1.0.9-68.el4_8.ia64.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.ia64.rpm seamonkey-js-debugger-1.0.9-68.el4_8.ia64.rpm seamonkey-mail-1.0.9-68.el4_8.ia64.rpm x86_64: seamonkey-1.0.9-68.el4_8.x86_64.rpm seamonkey-chat-1.0.9-68.el4_8.x86_64.rpm seamonkey-debuginfo-1.0.9-68.el4_8.x86_64.rpm seamonkey-devel-1.0.9-68.el4_8.x86_64.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.x86_64.rpm seamonkey-js-debugger-1.0.9-68.el4_8.x86_64.rpm seamonkey-mail-1.0.9-68.el4_8.x86_64.rpm Red Hat Enterprise Linux WS version4: Source: i386: seamonkey-1.0.9-68.el4_8.i386.rpm seamonkey-chat-1.0.9-68.el4_8.i386.rpm seamonkey-debuginfo-1.0.9-68.el4_8.i386.rpm seamonkey-devel-1.0.9-68.el4_8.i386.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.i386.rpm seamonkey-js-debugger-1.0.9-68.el4_8.i386.rpm seamonkey-mail-1.0.9-68.el4_8.i386.rpm ia64: seamonkey-1.0.9-68.el4_8.ia64.rpm seamonkey-chat-1.0.9-68.el4_8.ia64.rpm seamonkey-debuginfo-1.0.9-68.el4_8.ia64.rpm seamonkey-devel-1.0.9-68.el4_8.ia64.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.ia64.rpm seamonkey-js-debugger-1.0.9-68.el4_8.ia64.rpm seamonkey-mail-1.0.9-68.el4_8.ia64.rpm x86_64: seamonkey-1.0.9-68.el4_8.x86_64.rpm seamonkey-chat-1.0.9-68.el4_8.x86_64.rpm seamonkey-debuginfo-1.0.9-68.el4_8.x86_64.rpm seamonkey-devel-1.0.9-68.el4_8.x86_64.rpm seamonkey-dom-inspector-1.0.9-68.el4_8.x86_64.rpm seamonkey-js-debugger-1.0.9-68.el4_8.x86_64.rpm seamonkey-mail-1.0.9-68.el4_8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2011 Red Hat, Inc. . Canonical announces a significant Firefox upgrade addressing vulnerabilities impacting outdated SSL certificates in Ubuntu 16.04.. Red Hat Enterprise Linux, SeaMonkey Update, Security Advisory, Certificate Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 22, 2011 Important Red Hat
172

Ubuntu 6.06 LTS USN-858-1: Critical OpenLDAP SSL Attack Risk

It was discovered that OpenLDAP did not correctly handle SSL certificates with zero bytes in the Common Name. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. [More...]. ==========================================================Ubuntu Security Notice USN-858-1 November 12, 2009 openldap2.2 vulnerability CVE-2009-3767 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libldap-2.2-7 2.2.26-5ubuntu2.9 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that OpenLDAP did not correctly handle SSL certificates with zero bytes in the Common Name. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 516098 098a03b4f7d511ce730e9647deca2072 Size/MD5: 1028 5a95dae94a1016fbcf41c1c1992ea8e6 Size/MD5: 2626629 afc8700b5738da863b30208e1d3e9de8 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 130854 1f1b40b12adcb557a810194d0c4f7993 Size/MD5: 166444 500528d10502361c075a08578c1586f5 Size/MD5: 961974 f56eef919306d6ca7f4a7a090d2ae6ba i386 architecture (x86 compatible Intel/AMD): Size/MD5: 118638 0558a833fb6eadf4d87bd9fd6e687838 Size/MD5: 146444 fc85d5259c97622324047bbda153937d Size/MD5: 873424 358c78f76ee16010c1fb81e89adfe849 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 13301292d9de435a795261e6bf4143f2bf59c7 Size/MD5: 157480 099b1ee5e158f77be109a7972587f596 Size/MD5: 960052 850fb56995224edd6ae329af1b8236ef sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 120932 4fa0f7accd968ba71dff1f7c5b2ef811 Size/MD5: 148546 2d1af209a8b53a8315fbd4bd86573d70 Size/MD5: 903928 4aa6b0478821e803c80a020b031aafed . Recent OpenLDAP flaw exposes systems to remote threats targeting SSL vulnerabilities for data theft. Ensure your Ubuntu is updated immediately!. OpenLDAP Exploitation, SSL Security Threat, Ubuntu Update, Remote Attack. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 12, 2009 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200