Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
98

RHEL 7 java-11-openjdk Security Update RHSA-2022-7008-01 Moderate Threat

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: java-11-openjdk security and bug fix update Advisory ID: RHSA-2022:7008-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:7008 Issue date: 2022-10-19 CVE Names: CVE-2022-21618 CVE-2022-21619 CVE-2022-21624 CVE-2022-21626 CVE-2022-21628 CVE-2022-39399 ==================================================================== 1. Summary: An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit. Security Fix(es): * OpenJDK: improper MultiByte conversion can lead to buffer overflow (JGSS, 8286077) (CVE-2022-21618) * OpenJDK: excessive memory allocation in X.509certificate parsing (Security, 8286533) (CVE-2022-21626) * OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628) * OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) (CVE-2022-21619) * OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) (CVE-2022-21624) * OpenJDK: missing SNI caching in HTTP/2 (Networking, 8289366) (CVE-2022-39399) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Prepare for the next quarterly OpenJDK upstream release (2022-10, 11.0.17) (BZ#2130373) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of OpenJDK Java must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2130373 - Prepare for the next quarterly OpenJDK upstream release (2022-10, 11.0.17) [rhel-7.9.z] 2133745 - CVE-2022-21619 OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) 2133753 - CVE-2022-21626 OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) 2133765 - CVE-2022-21624 OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) 2133769 - CVE-2022-21628 OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) 2133776 - CVE-2022-39399 OpenJDK: missing SNI caching in HTTP/2 (Networking, 8289366) 2133817 - CVE-2022-21618 OpenJDK: improper MultiByte conversion can lead to buffer overflow (JGSS, 8286077) 6. Package List: Red Hat Enterprise Linux Client (v.7): Source: java-11-openjdk-11.0.17.0.8-2.el7_9.src.rpm x86_64: java-11-openjdk-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: java-11-openjdk-11.0.17.0.8-2.el7_9.src.rpm x86_64: java-11-openjdk-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v.7): x86_64: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: java-11-openjdk-11.0.17.0.8-2.el7_9.src.rpm ppc64: java-11-openjdk-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.ppc64.rpm ppc64le: java-11-openjdk-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.ppc64le.rpm s390x: java-11-openjdk-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.s390x.rpm x86_64: java-11-openjdk-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.ppc64.rpm ppc64le: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.ppc64le.rpm s390x: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.s390x.rpm x86_64: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation (v.7): Source: java-11-openjdk-11.0.17.0.8-2.el7_9.src.rpm x86_64: java-11-openjdk-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-21618 https://access.redhat.com/security/cve/CVE-2022-21619 https://access.redhat.com/security/cve/CVE-2022-21624 https://access.redhat.com/security/cve/CVE-2022-21626 https://access.redhat.com/security/cve/CVE-2022-21628 https://access.redhat.com/security/cve/CVE-2022-39399 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGINPGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY1C5JNzjgjWX9erEAQhj8w//RUsDzgmgcttv7giIGG2ft9H1JMK1WmSb nA+p0bGt9jA5yp7HTxRKgfIQ9bop2+ZKh7NOj8qMyhnW9QUxGraGwmHcLOEoPV27 +yUbmyx6Vwt2gc+fyd/9VDpmH6ugtyWH0tsEx/gOXB6lina41CC0izdIt2LdcM83 tb+uQenxQd9a7V0MZfYVCiTIlo4D0IDm+rvgUtYRhZF2AbAPngH4rUj3SLUdnwMi 60KqTVmwcv6RQ2xZNbkrtDos9OgVLWqRJ9pspLe81KPW06+afkjm9Dl6e03eDd26 IK7Qmp4DgKrrInIECAVox/qQFS+8UjIleUbzvD9AOZdTSZkoUY6kqbj1EHJF8PBF bGfKa4Gn1IEnz6jWXc+0lzpmm+j5//99Uea4AhQPPNpPAiwkUSxQqeyM0g50JIx1 HkXjgXxNns2FR46/3rZzXTyObXGJVr1TyG9R1OxUAnObS90lZhsJcWdL55tgOUqr kigCwf0a6waJ2cN9yArnzywDBhWKR+FflnurxKrG7Lq5Q2Xmpsv0wKGVKjFIgzrv kly11Tq/E5r8TYy7zyTXR/j50jAqVLog4NQNaUGGxUtHdlTrWa1E1UFxPLMAZZES YnRejAecsDbrzHyzAYrvXMSbykNH6BQ2o9NpTs6zAb4AME+mPwhFQc/WkH5+8TR4 RyoR8MMXBXc=RFnE -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent advisory from Red Hat outlines a significant update for java-11-openjdk, which resolves various security vulnerabilities and bug-related concerns.. Java 11 Update, Red Hat Security, Java Runtime Environment. . LinuxSecurity.com Team

Calendar%202 Oct 19, 2022 Red Hat
200

Scientific Linux: SLSA-2022-1066-1 Critical: openssl Infinite Loop

openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (CVE-2022-0778) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 openssl-1.0.2k-25.el7_9.x86_64.rpm openssl-debuginfo-1.0.2k-25.el7_9.i686.rpm openssl-debuginfo-1.0.2k-25.el7_9.x86_64.rpm ope [More...]. Synopsis: Important: openssl security update Advisory ID: SLSA-2022:1066-1 Issue Date: 2022-03-28 CVE Numbers: CVE-2022-0778 -- Security Fix(es): * openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (CVE-2022-0778) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 openssl-1.0.2k-25.el7_9.x86_64.rpm openssl-debuginfo-1.0.2k-25.el7_9.i686.rpm openssl-debuginfo-1.0.2k-25.el7_9.x86_64.rpm openssl-libs-1.0.2k-25.el7_9.i686.rpm openssl-libs-1.0.2k-25.el7_9.x86_64.rpm openssl-devel-1.0.2k-25.el7_9.i686.rpm openssl-devel-1.0.2k-25.el7_9.x86_64.rpm openssl-perl-1.0.2k-25.el7_9.x86_64.rpm openssl-static-1.0.2k-25.el7_9.i686.rpm openssl-static-1.0.2k-25.el7_9.x86_64.rpm - Scientific Linux Development Team . Critical patch for OpenSSL on Scientific Linux released to resolve a potential infinite loop vulnerability during the certificate parsing process.. openssl update, Scientific Linux advisory, security fix openssl. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 28, 2022 Critical Scientific Linux
203

Mageia 8 MGASA-2022-0113 Critical: Openssl Infinite Loop Threat

Infinite loop in BN_mod_sqrt() reachable when parsing certificates. (CVE-2022-0778) References: - https://bugs.mageia.org/show_bug.cgi?id=30174 . MGASA-2022-0113 - Updated openssl packages fix security vulnerability Publication date: 23 Mar 2022 URL: https://advisories.mageia.org/MGASA-2022-0113.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-0778 Infinite loop in BN_mod_sqrt() reachable when parsing certificates. (CVE-2022-0778) References: - https://bugs.mageia.org/show_bug.cgi?id=30174 - https://openssl-library.org/news/secadv/20220315.txt - https://ubuntu.com/security/notices/USN-5328-1 - https://www.cve.org/CVERecord?id=CVE-2022-0778 SRPMS: - 8/core/openssl-1.1.1n-1.mga8 . The patch for Fedora tackles a severe openssl vulnerability—a never-ending cycle in parsing certificates.. Mageia Security Advisory, OpenSSL Update, Certificate Parsing Issues, Security Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 23, 2022 Critical Mageia
100

SUSE: 2022:0854-1 Critical Vulnerability: OpenSSL Infinite Loop Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openssl ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0854-1 Rating: important References: #1196877 Cross-References: CVE-2022-0778 CVSS scores: CVE-2022-0778 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: HPE Helion Openstack 8 SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server for SAP 12-SP3 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud Crowbar 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openssl fixes the following issues: - CVE-2022-0778: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (bsc#1196877). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2022-854=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2022-854=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2022-854=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2022-854=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2022-854=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2022-854=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2022-854=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (noarch): openssl-doc-1.0.2j-60.75.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 - SUSE OpenStack Cloud 8 (x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 - SUSE OpenStack Cloud 8 (noarch): openssl-doc-1.0.2j-60.75.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (noarch): openssl-doc-1.0.2j-60.75.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (x86_64): libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (s390x x86_64): libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (noarch): openssl-doc-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP3-BCL (noarch): openssl-doc-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP2-BCL (noarch): openssl-doc-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 - HPE Helion Openstack 8 (noarch): openssl-doc-1.0.2j-60.75.1 - HPE Helion Openstack 8 (x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 References: https://www.suse.com/security/cve/CVE-2022-0778.html https://bugzilla.suse.com/1196877 . An essential patch for openssl has been released, targeting a significant concern for SUSE users related to certificate management.. SUSE Security Update, OpenSSL Patch, Important Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 15, 2022 Important SuSE
100

SUSE: 2020:2357-1 Moderate: libqt5-qtbase DoS Threat Update

An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for libqt5-qtbase ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2357-1 Rating: moderate References: #1172726 #1173758 Cross-References: CVE-2020-13962 Affected Products: SUSE Linux Enterprise Module for Desktop Applications 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for libqt5-qtbase fixes the following issues: - Fixed a possible crash in certificate parsing. - Fixed a DoS in QSslSocket (bsc#1172726, CVE-2020-13962). - Added support for PostgreSQL 12 (bsc#1173758). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Desktop Applications 15-SP2: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP2-2020-2357=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2020-2357=1 Package List: - SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (aarch64 ppc64le s390x x86_64): libQt5OpenGLExtensions-devel-static-5.12.7-4.3.1 libQt5Sql5-mysql-5.12.7-4.3.1 libQt5Sql5-mysql-debuginfo-5.12.7-4.3.1 libQt5Sql5-postgresql-5.12.7-4.3.1 libQt5Sql5-postgresql-debuginfo-5.12.7-4.3.1 libQt5Sql5-unixODBC-5.12.7-4.3.1 libQt5Sql5-unixODBC-debuginfo-5.12.7-4.3.1 libqt5-qtbase-debugsource-5.12.7-4.3.1 libqt5-qtbase-platformtheme-gtk3-5.12.7-4.3.1 libqt5-qtbase-platformtheme-gtk3-debuginfo-5.12.7-4.3.1 - SUSELinux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): libQt5Concurrent-devel-5.12.7-4.3.1 libQt5Concurrent5-5.12.7-4.3.1 libQt5Concurrent5-debuginfo-5.12.7-4.3.1 libQt5Core-devel-5.12.7-4.3.1 libQt5Core5-5.12.7-4.3.1 libQt5Core5-debuginfo-5.12.7-4.3.1 libQt5DBus-devel-5.12.7-4.3.1 libQt5DBus-devel-debuginfo-5.12.7-4.3.1 libQt5DBus5-5.12.7-4.3.1 libQt5DBus5-debuginfo-5.12.7-4.3.1 libQt5Gui-devel-5.12.7-4.3.1 libQt5Gui5-5.12.7-4.3.1 libQt5Gui5-debuginfo-5.12.7-4.3.1 libQt5KmsSupport-devel-static-5.12.7-4.3.1 libQt5Network-devel-5.12.7-4.3.1 libQt5Network5-5.12.7-4.3.1 libQt5Network5-debuginfo-5.12.7-4.3.1 libQt5OpenGL-devel-5.12.7-4.3.1 libQt5OpenGL5-5.12.7-4.3.1 libQt5OpenGL5-debuginfo-5.12.7-4.3.1 libQt5PlatformHeaders-devel-5.12.7-4.3.1 libQt5PlatformSupport-devel-static-5.12.7-4.3.1 libQt5PrintSupport-devel-5.12.7-4.3.1 libQt5PrintSupport5-5.12.7-4.3.1 libQt5PrintSupport5-debuginfo-5.12.7-4.3.1 libQt5Sql-devel-5.12.7-4.3.1 libQt5Sql5-5.12.7-4.3.1 libQt5Sql5-debuginfo-5.12.7-4.3.1 libQt5Sql5-sqlite-5.12.7-4.3.1 libQt5Sql5-sqlite-debuginfo-5.12.7-4.3.1 libQt5Test-devel-5.12.7-4.3.1 libQt5Test5-5.12.7-4.3.1 libQt5Test5-debuginfo-5.12.7-4.3.1 libQt5Widgets-devel-5.12.7-4.3.1 libQt5Widgets5-5.12.7-4.3.1 libQt5Widgets5-debuginfo-5.12.7-4.3.1 libQt5Xml-devel-5.12.7-4.3.1 libQt5Xml5-5.12.7-4.3.1 libQt5Xml5-debuginfo-5.12.7-4.3.1 libqt5-qtbase-common-devel-5.12.7-4.3.1 libqt5-qtbase-common-devel-debuginfo-5.12.7-4.3.1 libqt5-qtbase-debugsource-5.12.7-4.3.1 libqt5-qtbase-devel-5.12.7-4.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (noarch): libQt5Core-private-headers-devel-5.12.7-4.3.1 libQt5DBus-private-headers-devel-5.12.7-4.3.1 libQt5Gui-private-headers-devel-5.12.7-4.3.1 libQt5KmsSupport-private-headers-devel-5.12.7-4.3.1 libQt5Network-private-headers-devel-5.12.7-4.3.1 libQt5OpenGL-private-headers-devel-5.12.7-4.3.1 libQt5PlatformSupport-private-headers-devel-5.12.7-4.3.1 libQt5PrintSupport-private-headers-devel-5.12.7-4.3.1 libQt5Sql-private-headers-devel-5.12.7-4.3.1 libQt5Test-private-headers-devel-5.12.7-4.3.1 libQt5Widgets-private-headers-devel-5.12.7-4.3.1 libqt5-qtbase-private-headers-devel-5.12.7-4.3.1 References: https://www.suse.com/security/cve/CVE-2020-13962.html https://bugzilla.suse.com/1172726 https://bugzilla.suse.com/1173758 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE issues an important patch for libqt5-qtbase to tackle a significant DoS vulnerability and potential stability problems.. SUSE Security Update, libqt5-qtbase, DoS threat, Linux security update. . LinuxSecurity.com Team

Calendar%202 Aug 27, 2020 SuSE
87

Debian Jessie: DSA-3673-2 Moderate: OpenSSL Certificate Parsing Issue

It was discovered that the original patch applied for CVE-2016-2182 in DSA-3673-1 was incomplete, causing a regression when parsing certificates. Updated packages are now available to address this problem. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3673-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso September 23, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openssl Debian Bug : 838652 838659 It was discovered that the original patch applied for CVE-2016-2182 in DSA-3673-1 was incomplete, causing a regression when parsing certificates. Updated packages are now available to address this problem. For the stable distribution (jessie), this problem has been fixed in version 1.0.1t-1+deb8u5. We recommend that you upgrade your openssl packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu resolves a vulnerability in OpenSSL to address a regression impact on CVE-2021-3450 that influences key exchange.. OpenSSL Update, Debian Security Advisory, Regression Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 23, 2016 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200