Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
203

Mageia 8: 2023-0193 Critical: Python-Flask Session Cookie Exposure

Client 'session' cookie sent to other clients (CVE-2023-30861) References: - https://bugs.mageia.org/show_bug.cgi?id=31953 - https://lists.suse.com/pipermail/sle-security-updates/2023-May/014935.html . MGASA-2023-0193 - Updated python-flask packages fix security vulnerability Publication date: 08 Jun 2023 URL: https://advisories.mageia.org/MGASA-2023-0193.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-30861 Client 'session' cookie sent to other clients (CVE-2023-30861) References: - https://bugs.mageia.org/show_bug.cgi?id=31953 - https://lists.suse.com/pipermail/sle-security-updates/2023-May/014935.html - https://www.cve.org/CVERecord?id=CVE-2023-30861 SRPMS: - 8/core/python-flask-1.1.2-1.1.mga8 . Mageia 2023-0194 reveals an essential python-flask security patch mitigating potential client token leakage. Discover more!. Mageia Python-Flask Update, Security Cookie Issue, Authentication Flaw. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 08, 2023 Critical Mageia
87

Debian: DSA-1561-1 Urgent: ldm Remote Access Vulnerability Alert

Christian Herzog discovered that within the Linux Terminal Server Project, it was possible to connect to X on any LTSP client from any host on the network, making client windows and keystrokes visible to that host.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1561-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst April 28, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : ldm Vulnerability : programming error Problem type : remote Debian-specific: no CVE Id(s) : CVE-2008-1293 Debian Bug : 469462 Christian Herzog discovered that within the Linux Terminal Server Project, it was possible to connect to X on any LTSP client from any host on the network, making client windows and keystrokes visible to that host. NOTE: most ldm installs are likely to be in a chroot environment exported over NFS, and will not be upgraded merely by upgrading the server itself. For example, on the i386 architecture, to upgrade ldm will likely require: chroot /opt/ltsp/i386 apt-get update chroot /opt/ltsp/i386 apt-get dist-upgrade For the stable distribution (etch), this problem has been fixed in version 0.99debian11+etch1. For the unstable distribution (sid), this problem has been fixed in version 2:0.1~bzr20080308-1. We recommend that you upgrade your ldm package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0alias etch - -------------------------------Source archives: Size/MD5 checksum: 183019 c97fa50f7a30f213742be6466a7817fc Size/MD5 checksum: 1243 c8d0f83f26c580a9fcf5079d303c1958 Architecture independent packages: Size/MD5 checksum: 22346 edf27d69321dc6db44cb252719aad12b Size/MD5 checksum: 2278 bd0856196c64cfcabc1c0f47808b5f4c Size/MD5 checksum: 53332 70be96c089a449a543cfb678e55a0f1e Size/MD5 checksum: 116452 51fa6e495db54926e77aa7f62a251dff alpha architecture (DEC Alpha) Size/MD5 checksum: 50686 145f4579f02af33e644674b0a2ecff67 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 50638 9ea8d9f916b011a9f5379ed31f8a7cc7 arm architecture (ARM) Size/MD5 checksum: 49608 8c1b8f8908b2099c8f97946144dd7ca0 hppa architecture (HP PA RISC) Size/MD5 checksum: 50448 08ca2c9cdc6bc5a274bb7114495e0e7d i386 architecture (Intel ia32) Size/MD5 checksum: 49302 b20a0740d53c1c6aeffdab69b2bb14bf ia64 architecture (Intel ia64) Size/MD5 checksum: 55934 b614ff92f4cb3dcea9329ea219f77a60 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 50166 298ad47e264bf2b3e3b69fd52f772df1 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 50914 770ee6fa07216c0a2a0da7922d820ea7 powerpc architecture (PowerPC) Size/MD5 checksum: 50602 3b30a76ae56aedbfdc67c2bd975eefd6 s390 architecture (IBM S/390) Size/MD5 checksum: 51558 9c2f6986508538205f6e5d937a9bc8d7 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent Debian Security Bulletin pertains to a vulnerability in ldm's remote access that may expose private user data.Updating is advised.. ldm package fix, remote access issue, debian advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 28, 2008 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here