Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
100

SUSE 2026 0885-1 Important Fix for Curl Connection Issues

An update that solves four vulnerabilities can now be installed.. # Security update for curl Announcement ID: SUSE-SU-2026:0885-1 Release Date: 2026-03-12T14:50:21Z Rating: important References: * bsc#1259362 * bsc#1259363 * bsc#1259364 * bsc#1259365 Cross-References: * CVE-2026-1965 * CVE-2026-3783 * CVE-2026-3784 * CVE-2026-3805 CVSS scores: * CVE-2026-1965 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-1965 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-1965 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3783 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-3783 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-3783 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-3784 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-3784 ( SUSE ): 4.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-3784 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3805 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-3805 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-3805 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves four vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2026-1965: bad reuse of HTTP Negotiate connection (bsc#1259362). * CVE-2026-3783: token leak with redirect and netrc (bsc#1259363). * CVE-2026-3784: wrong proxy connection reuse with credentials (bsc#1259364). * CVE-2026-3805: use after free in SMB connection reuse (bsc#1259365). ## PatchInstructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-885=1 openSUSE-SLE-15.6-2026-885=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-885=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-885=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * curl-debuginfo-8.14.1-150600.4.40.1 * curl-8.14.1-150600.4.40.1 * curl-mini-debugsource-8.14.1-150600.4.40.1 * libcurl-mini4-8.14.1-150600.4.40.1 * libcurl-mini4-debuginfo-8.14.1-150600.4.40.1 * curl-debugsource-8.14.1-150600.4.40.1 * libcurl4-debuginfo-8.14.1-150600.4.40.1 * libcurl4-8.14.1-150600.4.40.1 * libcurl-devel-8.14.1-150600.4.40.1 * openSUSE Leap 15.6 (noarch) * curl-zsh-completion-8.14.1-150600.4.40.1 * curl-fish-completion-8.14.1-150600.4.40.1 * libcurl-devel-doc-8.14.1-150600.4.40.1 * openSUSE Leap 15.6 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150600.4.40.1 * libcurl4-32bit-8.14.1-150600.4.40.1 * libcurl-devel-32bit-8.14.1-150600.4.40.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libcurl4-64bit-8.14.1-150600.4.40.1 * libcurl-devel-64bit-8.14.1-150600.4.40.1 * libcurl4-64bit-debuginfo-8.14.1-150600.4.40.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * curl-debuginfo-8.14.1-150600.4.40.1 * curl-8.14.1-150600.4.40.1 * curl-debugsource-8.14.1-150600.4.40.1 * libcurl4-debuginfo-8.14.1-150600.4.40.1 * libcurl4-8.14.1-150600.4.40.1 * libcurl-devel-8.14.1-150600.4.40.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150600.4.40.1 * libcurl4-32bit-8.14.1-150600.4.40.1 * SUSE Linux Enterprise Server for SAP Applications 15SP6 (ppc64le x86_64) * curl-debuginfo-8.14.1-150600.4.40.1 * curl-8.14.1-150600.4.40.1 * curl-debugsource-8.14.1-150600.4.40.1 * libcurl4-debuginfo-8.14.1-150600.4.40.1 * libcurl4-8.14.1-150600.4.40.1 * libcurl-devel-8.14.1-150600.4.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150600.4.40.1 * libcurl4-32bit-8.14.1-150600.4.40.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1965.html * https://www.suse.com/security/cve/CVE-2026-3783.html * https://www.suse.com/security/cve/CVE-2026-3784.html * https://www.suse.com/security/cve/CVE-2026-3805.html * https://bugzilla.suse.com/show_bug.cgi?id=1259362 * https://bugzilla.suse.com/show_bug.cgi?id=1259363 * https://bugzilla.suse.com/show_bug.cgi?id=1259364 * https://bugzilla.suse.com/show_bug.cgi?id=1259365 . SUSE curl update addresses multiple critical issues affecting system security. Recommendations for installation included.. curl update SUSE security issues connection vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 12, 2026 Important SuSE
98

Red Hat Enterprise Linux 8.1: RHSA-2022:7003-01 Moderate: Java Threats

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: java-1.8.0-openjdk security update Advisory ID: RHSA-2022:7003-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:7003 Issue date: 2022-10-19 CVE Names: CVE-2022-21619 CVE-2022-21624 CVE-2022-21626 CVE-2022-21628 ==================================================================== 1. Summary: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.1) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. Security Fix(es): * OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) (CVE-2022-21626) * OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628) * OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) (CVE-2022-21619) * OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) (CVE-2022-21624) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, andother related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of OpenJDK Java must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2133745 - CVE-2022-21619 OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) 2133753 - CVE-2022-21626 OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) 2133765 - CVE-2022-21624 OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) 2133769 - CVE-2022-21628 OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) 6. Package List: Red Hat Enterprise Linux AppStream E4S (v.8.1): Source: java-1.8.0-openjdk-1.8.0.352.b08-2.el8_1.src.rpm aarch64: java-1.8.0-openjdk-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-accessibility-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-debugsource-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-demo-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-demo-debuginfo-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-demo-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-devel-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-devel-debuginfo-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-devel-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-headless-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-headless-debuginfo-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-headless-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.aarch64.rpm java-1.8.0-openjdk-src-1.8.0.352.b08-2.el8_1.aarch64.rpm noarch: java-1.8.0-openjdk-javadoc-1.8.0.352.b08-2.el8_1.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.352.b08-2.el8_1.noarch.rpm ppc64le: java-1.8.0-openjdk-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-accessibility-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-debugsource-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-demo-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-demo-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-demo-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-devel-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-devel-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-devel-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-headless-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-headless-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-headless-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm java-1.8.0-openjdk-src-1.8.0.352.b08-2.el8_1.ppc64le.rpm s390x: java-1.8.0-openjdk-1.8.0.352.b08-2.el8_1.s390x.rpm java-1.8.0-openjdk-accessibility-1.8.0.352.b08-2.el8_1.s390x.rpm java-1.8.0-openjdk-debuginfo-1.8.0.352.b08-2.el8_1.s390x.rpm java-1.8.0-openjdk-debugsource-1.8.0.352.b08-2.el8_1.s390x.rpm java-1.8.0-openjdk-demo-1.8.0.352.b08-2.el8_1.s390x.rpm java-1.8.0-openjdk-demo-debuginfo-1.8.0.352.b08-2.el8_1.s390x.rpm java-1.8.0-openjdk-devel-1.8.0.352.b08-2.el8_1.s390x.rpm java-1.8.0-openjdk-devel-debuginfo-1.8.0.352.b08-2.el8_1.s390x.rpm java-1.8.0-openjdk-headless-1.8.0.352.b08-2.el8_1.s390x.rpm java-1.8.0-openjdk-headless-debuginfo-1.8.0.352.b08-2.el8_1.s390x.rpm java-1.8.0-openjdk-src-1.8.0.352.b08-2.el8_1.s390x.rpm x86_64: java-1.8.0-openjdk-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-accessibility-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-debugsource-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-demo-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-demo-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-devel-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-devel-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-headless-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-headless-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm java-1.8.0-openjdk-src-1.8.0.352.b08-2.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2022-21619 https://access.redhat.com/security/cve/CVE-2022-21624 https://access.redhat.com/security/cve/CVE-2022-21626 https://access.redhat.com/security/cve/CVE-2022-21628 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY1C5m9zjgjWX9erEAQiF3Q/9E/j+2xvwjt5EGlhKmZxeg9lIexgZcdYh 1F85mLue3T5qsZL2QOhDP9h2fP42MyPpXgv3TRidZ57cEQ/JIK88KV7kRftA5+pC a8oTNlOAw6KSngocXcN/PR76EnUZoOZVDpuo6sq5ge8ruPrSEdhw/qcjo1MR+8P0 ITu+Akbap3kQIitGH7kXjU767GZ5xZBVypIIZj/pM15cEy/sMqfwckM2Gu9Bpbbu x5kssTngUvDt3Q9QajmVFSNIFMzFbQT+2pJyGuXrm0zsY9AB+Gfu+5X/cWDBLW8D j9vvBCdzUVTflKfGqsV//QVVGCxEtXsmPEOoCOTgcRg1YC1SfWygKIxUR8NACh0K /RpiRPq1/VnNjKwKdGkMtNY/RYhWcxLtV1L5BMSQtIPjjF5egZ3u/PbNTMxWwhp+ 3kiSFyt8bxrJ4ajGABHW9ZnQn1mJ8yCqjfVGrlegBQjngAEeTZ+dsFoujPgu8gJV g2+zFuPK0ipQO1A8O6vdkgMm0TldF6IVCKo0avOTHDtY0p9AA3k3fibam4w/PmFk IRSAEqoMjkDqqDLPZ+4fcljt+DPgHqwz5eT0IRYk9dD0qSfZ6NLdlKE+SPnNHec+ ine3q00UUgN8YmPvaDAXWSeJdFetlzRrfUYraQtR3C8RSRbwYV07I2RcTKvq+HSA F5hs8brjHNY=1jgU -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A balanced security patch for java-1.8.0-openjdk addresses memory usage and connection problems within Red Hat Enterprise Linux.. Red Hat Enterprise Linux, Java openjdk security, patch management, JNDI issues. . LinuxSecurity.com Team

Calendar%202 Oct 19, 2022 Red Hat
217

Oracle Linux 8 ELSA-2021-3583 Moderate: Curl Network Security Update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2021-3582 https://linux.oracle.com/errata/ELSA-2021-3582.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: curl-7.61.1-18.el8_4.1.x86_64.rpm libcurl-7.61.1-18.el8_4.1.i686.rpm libcurl-7.61.1-18.el8_4.1.x86_64.rpm libcurl-devel-7.61.1-18.el8_4.1.i686.rpm libcurl-devel-7.61.1-18.el8_4.1.x86_64.rpm libcurl-minimal-7.61.1-18.el8_4.1.i686.rpm libcurl-minimal-7.61.1-18.el8_4.1.x86_64.rpm aarch64: curl-7.61.1-18.el8_4.1.aarch64.rpm libcurl-7.61.1-18.el8_4.1.aarch64.rpm libcurl-devel-7.61.1-18.el8_4.1.aarch64.rpm libcurl-minimal-7.61.1-18.el8_4.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/curl-7.61.1-18.el8_4.1.src.rpm Related CVEs: CVE-2021-22922 CVE-2021-22923 CVE-2021-22924 Description of changes: [7.61.1-18.el8_4.1] - fix bad connection reuse due to flawed path name checks (CVE-2021-22924) - disable metalink support to fix the following vulnerabilities CVE-2021-22923 - metalink download sends credentials CVE-2021-22922 - wrong content via metalink not discarded _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Notice ELSA-2021-3583 delivers a significant patch addressing vulnerabilities in curl for Oracle Linux 8.. Oracle Security Update,curl Patch,Oracle Linux 8. . LinuxSecurity.com Team

Calendar%202 Sep 21, 2021 Oracle
89

Fedora 34: 2021-83fdddca0f Critical: Curl Connection Issues

- fix TELNET stack contents disclosure again (CVE-2021-22925) - fix bad connection reuse due to flawed path name checks (CVE-2021-22924) - disable metalink support to fix the following vulnerabilities CVE-2021-22923 - metalink download sends credentials CVE-2021-22922 - wrong content via metalink not discarded. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-83fdddca0f 2021-07-23 01:03:07.021615 --------------------------------------------------------------------------------Name : curl Product : Fedora 34 Version : 7.76.1 Release : 7.fc34 URL : https://curl.se/ Summary : A utility for getting files from remote servers (FTP, HTTP, and others) Description : curl is a command line tool for transferring data with URL syntax, supporting FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3 and RTSP. curl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, cookies, user+password authentication (Basic, Digest, NTLM, Negotiate, kerberos...), file transfer resume, proxy tunneling and a busload of other useful tricks. --------------------------------------------------------------------------------Update Information: - fix TELNET stack contents disclosure again (CVE-2021-22925) - fix bad connection reuse due to flawed path name checks (CVE-2021-22924) - disable metalink support to fix the following vulnerabilities CVE-2021-22923 -metalink download sends credentials CVE-2021-22922 - wrong content via metalink not discarded --------------------------------------------------------------------------------ChangeLog: --------------------------------------------------------------------------------References: [ 1 ] Bug #1984325 - CVE-2021-22922 curl: wrong content via metalink is not being discarded [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1984325 [ 2 ] Bug #1984326 -CVE-2021-22923 curl: Metalink download sends credentials [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1984326 [ 3 ] Bug #1984327 - CVE-2021-22924 curl: bad connection reuse due to flawed path name checks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1984327 [ 4 ] Bug #1984328 - CVE-2021-22925 curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1984328 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-83fdddca0f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 34 users must urgently update the curl package to fix security vulnerabilities and bugs. Run 'sudo dnf update curl' to ensure security and performance.. Fedora Update, Curl Tool, Security Fix, Connection Issues, Content Disclosure. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 22, 2021 Critical Fedora
89

Fedora 23: 2016-1234 Critical: OpenSSH Security Update Required Now

Update to upstream release 0.2.5.12. Update to upstream release 0.2.5.11.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-5890 2015-04-09 15:30:34 -------------------------------------------------------------------------------- Name : tor Product : Fedora 22 Version : 0.2.5.12 Release : 1.fc22 URL : https://www.torproject.org Summary : Anonymizing overlay network for TCP (The onion router) Description : Tor is a connection-based low-latency anonymous communication system. Applications connect to the local Tor proxy using the SOCKS protocol. The local proxy chooses a path through a set of relays, in which each relay knows its predecessor and successor, but no others. Traffic flowing down the circuit is unwrapped by a symmetric key at each relay, which reveals the downstream relay. Warnings: Tor does no protocol cleaning. That means there is a danger that application protocols and associated programs can be induced to reveal information about the initiator. Tor depends on Privoxy and similar protocol cleaners to solve this problem. This is alpha code, and is even more likely than released code to have anonymity-spoiling bugs. The present network is very small -- this further reduces the strength of the anonymity provided. Tor is not presently suitable for high-stakes anonymity. -------------------------------------------------------------------------------- Update Information: Update to upstream release 0.2.5.12. Update to upstream release 0.2.5.11. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1209804 - CVE-2015-2928 CVE-2015-2929 tor: multiple issues fixed in the new upstream releases https://bugzilla.redhat.com/show_bug.cgi?id=1209804 [ 2 ] Bug #1204773 - CVE-2015-2688 CVE-2015-2689 tor: security fixes in 0.2.4.26 and 0.2.5.11 https://bugzilla.redhat.com/show_bug.cgi?id=1204773 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update tor' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Unveil the newly released Fedora 22 patch for Tor, tackling vital vulnerabilities to boost privacy and efficiency.. Tor Anonymity,Fedora Update,Security Patch,Network Security,Anonymizing Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 21, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200