Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":550,"type":"x","order":1,"pct":78.57,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.29,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
91

Gentoo: GLSA-201709-04 Moderate: mod_gnutls Certificate Spoofing

A vulnerability in mod_gnutls allows remote attackers to spoof clients via crafted certificates.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201709-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: mod_gnutls: Certificate validation error Date: September 17, 2017 Bugs: #541038 ID: 201709-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in mod_gnutls allows remote attackers to spoof clients via crafted certificates. Background ========= mod_gnutls is an extension for ​Apache's httpd. It uses the ​GnuTLS library to provide HTTPS. It supports some protocols and features that mod_ssl does not. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apache/mod_gnutls < 0.7.3 > = 0.7.3 Description ========== It was discovered that the authentication hook in mod_gnutls does not validate client's certificates even when option "GnuTLSClientVerify" is set to "require". Impact ===== A remote attacker could present a crafted certificate and spoof clients data. Workaround ========= There is no known workaround at this time. Resolution ========= All mod_gnutls users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-apache/mod_gnutls-0.7.3" References ========= [ 1 ] CVE-2015-2091 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2091 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201709-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2017 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Enhance the mod_gnutls package on Gentoo to address a routine severity threat concerning certificate impersonation that may impact remote users.. Mod Gnutls Security,Gentoo Certificate Error,Client Spoofing Attack,Apache GnuTLS Upgrade. . LinuxSecurity.com Team

Calendar 2 Sep 17, 2017 Gentoo
200

Scientific Linux SL5.x Security Advisory: gnutls Moderate Threat

Moderate: gnutls security update. Date: Wed, 12 Nov 2008 12:26:34 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for gnutls on SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Moderate: gnutls security update Issue date: 2008-11-11 CVE Names: CVE-2008-4989 Martin von Gagern discovered a flaw in the way GnuTLS verified certificate chains provided by a server. A malicious server could use this flaw to spoof its identity by tricking client applications using the GnuTLS library to trust invalid certificates. (CVE-2008-4989) SL 5.x SRPMS: gnutls-1.4.1-3.el5_2.1.src.rpm i386: gnutls-1.4.1-3.el5_2.1.i386.rpm gnutls-devel-1.4.1-3.el5_2.1.i386.rpm gnutls-utils-1.4.1-3.el5_2.1.i386.rpm x86_64: gnutls-1.4.1-3.el5_2.1.i386.rpm gnutls-1.4.1-3.el5_2.1.x86_64.rpm gnutls-devel-1.4.1-3.el5_2.1.i386.rpm gnutls-devel-1.4.1-3.el5_2.1.x86_64.rpm gnutls-utils-1.4.1-3.el5_2.1.x86_64.rpm -Connie Sieh -Troy Dawson . The recent gnutls security enhancement for Scientific Linux SL5.x mitigates a vulnerability associated with potential spoofing threats.. GnuTLS Security Update, Scientific Linux 5, Moderate Security Advisory. . LinuxSecurity.com Team

Calendar 2 Nov 12, 2008 Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":550,"type":"x","order":1,"pct":78.57,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.29,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here