Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
197

Debian 10 Buster: DLA-3714-1 critical: keystone data breach

Brief introduction CVE-2021-3563 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3714-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès January 21, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : keystone Version : 2:14.2.0-0+deb10u2 CVE ID : CVE-2021-3563 CVE-2021-38155 Debian Bug : 992070 989998 Brief introduction CVE-2021-3563 A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. CVE-2021-38155 Keystone allowed information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected. For Debian 10 buster, these problems have been fixed in version 2:14.2.0-0+deb10u2. We recommend that you upgrade your keystone packages. For the detailed security status of keystone please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/keystone Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest advisory DLA-3714-1 for Debian LTS emphasizes significant security flaws within the keystone component.. Debian LTS Advisory, Keystone Security, Critical Flaws, Cybersecurity Risks. . Severity:Critical. LinuxSecurity.com Team

Calendar 2 Jan 21, 2024 Critical Debian LTS
91

Gentoo: GLSA-202105-02 Low: Stunnel Certificate Integrity Issue

Stunnel was not properly verifying TLS certificates, possibly allowing an integrity/confidentiality compromise.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202105-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: stunnel: Improper certificate validation Date: May 26, 2021 Bugs: #772146 ID: 202105-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Stunnel was not properly verifying TLS certificates, possibly allowing an integrity/confidentiality compromise. Background ========= The stunnel program is designed to work as an SSL/TLS encryption wrapper between a client and a local or remote server. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/stunnel < 5.58 > = 5.58 Description ========== It was discovered that stunnel did not correctly verified the client certificate when options "redirect" and "verifyChain" are used. Impact ===== A remote attacker could send a specially crafted certificate, possibly resulting in a breach of integrity or confidentiality. Workaround ========= There is no known workaround at this time. Resolution ========= All stunnel users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/stunnel-5.58" References ========= [ 1 ] CVE-2021-20230 https://nvd.nist.gov/vuln/detail/CVE-2021-20230 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202105-02 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo GLSA 202109-01 addresses vulnerabilities in OpenSSL that compromise security and functionality.. Stunnel Impairment,Critical Security Advisory,Gentoo Linux Security,Certificate Authentication Issues,SSL/TLS Compromise. . Severity: Low. LinuxSecurity.com Team

Calendar 2 May 26, 2021 Low Gentoo
89

Fedora 36: HIGH - Axel Encryption Vulnerability (FEDORA-2022-8rf1gh3e34)

Update to new release. 2.17.8+ include the security fix for CVE-2020-13614 axel: TLS implementation lacks hostname verification leading to possible confidentiality breach. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-5214bd8f14 2021-05-05 01:20:25.877561 --------------------------------------------------------------------------------Name : axel Product : Fedora 34 Version : 2.17.10 Release : 1.fc34 URL : https://github.com/axel-download-accelerator/axel Summary : Light command line download accelerator for Linux and Unix Description : Axel tries to accelerate HTTP/FTP downloading process by using multiple connections for one file. It can use multiple mirrors for a download. Axel has no dependencies and is lightweight, so it might be useful as a wget clone on byte-critical systems. --------------------------------------------------------------------------------Update Information: Update to new release. 2.17.8+ include the security fix for CVE-2020-13614 axel: TLS implementation lacks hostname verification leading to possible confidentiality breach --------------------------------------------------------------------------------ChangeLog: * Mon Apr 26 2021 Frantisek Zatloukal - 2.17.10-1 - Updated to axel-2.17.10 --------------------------------------------------------------------------------References: [ 1 ] Bug #1848468 - CVE-2020-13614 axel: TLS implementation lacks hostname verification leading to possible confidentiality breach [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1848468 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-5214bd8f14' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed withthe Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Update axel to version 2.17.10 to resolve TLS vulnerabilities and enhance the security of your downloading workflows.. Axel Download Accelerator,Fedora Security Fix,TLS Implementation Issue. . LinuxSecurity.com Team

Calendar 2 May 04, 2021 Fedora
89

Fedora 33: FEDORA-2021-90b4716992 Moderate: Axel TLS Hostname Breach

Update to new release. 2.17.8+ include the security fix for CVE-2020-13614 axel: TLS implementation lacks hostname verification leading to possible confidentiality breach. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-90b4716992 2021-05-05 00:52:51.707432 --------------------------------------------------------------------------------Name : axel Product : Fedora 33 Version : 2.17.10 Release : 1.fc33 URL : https://github.com/axel-download-accelerator/axel Summary : Light command line download accelerator for Linux and Unix Description : Axel tries to accelerate HTTP/FTP downloading process by using multiple connections for one file. It can use multiple mirrors for a download. Axel has no dependencies and is lightweight, so it might be useful as a wget clone on byte-critical systems. --------------------------------------------------------------------------------Update Information: Update to new release. 2.17.8+ include the security fix for CVE-2020-13614 axel: TLS implementation lacks hostname verification leading to possible confidentiality breach --------------------------------------------------------------------------------ChangeLog: * Mon Apr 26 2021 Frantisek Zatloukal - 2.17.10-1 - Updated to axel-2.17.10 * Tue Jan 26 2021 Fedora Release Engineering - 2.16-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1848468 - CVE-2020-13614 axel: TLS implementation lacks hostname verification leading to possible confidentiality breach [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1848468 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-90b4716992' at the command line. For more information,refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The recent update for Ubuntu 21.10 includes an essential patch for SSL vulnerabilities. Uncover additional details regarding the data exposure incident here.. TLS Security Update,Fedora Axel,Axel Download Accelerator,Hostname Verification. . LinuxSecurity.com Team

Calendar 2 May 04, 2021 Fedora
172

Ubuntu 18.04 LTS USN-3860-1 Critical Libcaca Denial of Service

Several security issues were fixed in libcaca.. =========================================================================Ubuntu Security Notice USN-3860-1 January 15, 2019 libcaca vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in libcaca. Software Description: - libcaca: text mode graphics utilities Details: It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-20544) It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-20545, CVE-2018-20548, CVE-2018-20459) It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to access sensitive information. (CVE-2018-20546, CVE-2018-20547) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10: caca-utils 0.99.beta19-2ubuntu0.18.10.1 libcaca0 0.99.beta19-2ubuntu0.18.10.1 Ubuntu 18.04 LTS: caca-utils 0.99.beta19-2ubuntu0.18.04.1 libcaca0 0.99.beta19-2ubuntu0.18.04.1 Ubuntu 16.04 LTS: caca-utils 0.99.beta19-2ubuntu0.16.04.1 libcaca0 0.99.beta19-2ubuntu0.16.04.1 Ubuntu 14.04 LTS: caca-utils 0.99.beta18-1ubuntu5.1 libcaca0 0.99.beta18-1ubuntu5.1 In general, a standard system update will make all thenecessary changes. References: https://ubuntu.com/security/notices/USN-3860-1 CVE-2018-20544, CVE-2018-20545, CVE-2018-20546, CVE-2018-20547, CVE-2018-20548, CVE-2018-20549 Package Information: https://launchpad.net/ubuntu/+source/libcaca/0.99.beta19-2ubuntu0.18.10.1 https://launchpad.net/ubuntu/+source/libcaca/0.99.beta19-2ubuntu0.18.04.1 https://launchpad.net/ubuntu/+source/libcaca/0.99.beta19-2ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/libcaca/0.99.beta18-1ubuntu5.1 . Ubuntu addresses libcaca security flaws impacting various versions; ensure updates are applied promptly to mitigate exploit risks.. Libcaca Update, Ubuntu Security Notices, Denial of Service, Code Execution, Confidentiality Breach. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 15, 2019 Critical Ubuntu
100

SUSE 15: 2018:2318-1 Important: Samba Buffer Overflow Issue

An update that fixes 5 vulnerabilities is now available. . SUSE Security Update: Security update for samba ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2318-1 Rating: important References: #1095048 #1095056 #1095057 #1103411 #1103414 Cross-References: CVE-2018-10858 CVE-2018-10918 CVE-2018-10919 CVE-2018-1139 CVE-2018-1140 Affected Products: SUSE Linux Enterprise Module for Basesystem 15 SUSE Linux Enterprise High Availability 15 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for samba fixes the following issues: The following security vulnerabilities were fixed: - CVE-2018-1139: Disable NTLMv1 auth if smb.conf doesn't allow it; (bsc#1095048) - CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes; (bsc#1095056) - CVE-2018-10919: Confidential attribute disclosure via substring search; (bsc#1095057) - CVE-2018-10858: smbc_urlencode helper function is a subject to buffer overflow; (bsc#1103411) - CVE-2018-10918: Fix NULL ptr dereference in DsCrackNames on a user without a SPN; (bsc#1103414) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-1555=1 - SUSE Linux Enterprise High Availability 15: zypper in -t patch SUSE-SLE-Product-HA-15-2018-1555=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): libdcerpc-binding0-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc-binding0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc-samr-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc-samr0-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc-samr0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc0-4.7.8+git.86.94b6d10f7dd-4.15.1 libdcerpc0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-krb5pac-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-krb5pac0-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-krb5pac0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-nbt-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-nbt0-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-nbt0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-standard-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-standard0-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr-standard0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr0-4.7.8+git.86.94b6d10f7dd-4.15.1 libndr0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libnetapi-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libnetapi0-4.7.8+git.86.94b6d10f7dd-4.15.1 libnetapi0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-credentials-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-credentials0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-credentials0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-errors-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-errors0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-errors0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-hostconfig-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-hostconfig0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-hostconfig0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-passdb-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-passdb0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-passdb0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-policy-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-policy0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-util-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-util0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamba-util0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamdb-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamdb0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsamdb0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbclient-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbclient0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbclient0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbconf-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbconf0-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbconf0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbldap-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbldap2-4.7.8+git.86.94b6d10f7dd-4.15.1 libsmbldap2-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libtevent-util-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libtevent-util0-4.7.8+git.86.94b6d10f7dd-4.15.1 libtevent-util0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 libwbclient-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 libwbclient0-4.7.8+git.86.94b6d10f7dd-4.15.1 libwbclient0-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-client-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-client-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-core-devel-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-debugsource-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-libs-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-libs-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-winbind-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-winbind-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 - SUSE Linux Enterprise High Availability 15 (aarch64 ppc64le s390x x86_64): ctdb-4.7.8+git.86.94b6d10f7dd-4.15.1 ctdb-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-debuginfo-4.7.8+git.86.94b6d10f7dd-4.15.1 samba-debugsource-4.7.8+git.86.94b6d10f7dd-4.15.1 References: https://www.suse.com/security/cve/CVE-2018-10858.html https://www.suse.com/security/cve/CVE-2018-10918.html https://www.suse.com/security/cve/CVE-2018-10919.html https://www.suse.com/security/cve/CVE-2018-1139.html https://www.suse.com/security/cve/CVE-2018-1140.html https://bugzilla.suse.com/1095048 https://bugzilla.suse.com/1095056 https://bugzilla.suse.com/1095057 https://bugzilla.suse.com/1103411 https://bugzilla.suse.com/1103414 . Crucial SUSE Security Patch for Samba tackling several vulnerabilities and offering essential update guidelines.. SUSE Security, Samba Patch, System Security Update, Linux vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 14, 2018 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here