Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 36: 2022-08ae2dd481 Low Severity: Golang Notary Security Fix

Rebuild for CVE-2022-27191 ---- Fix FTBFS Close: rhbz#2045471. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-08ae2dd481 2022-05-07 04:08:14.315797 --------------------------------------------------------------------------------Name : golang-github-theupdateframework-notary Product : Fedora 36 Version : 0.7.0 Release : 4.fc36 URL : https://github.com/notaryproject/notary Summary : Project that allows anyone to have trust over arbitrary collections of data Description : The Notary project comprises a server and a client for running and interacting with trusted collections. See the service architecture documentation for more information. Notary aims to make the internet more secure by making it easy for people to publish and verify content. We often rely on TLS to secure our communications with a web server, which is inherently flawed, as any compromise of the server enables malicious content to be substituted for the legitimate content. With Notary, publishers can sign their content offline using keys kept highly secure. Once the publisher is ready to make the content available, they can push their signed trusted collection to a Notary Server. Consumers, having acquired the publisher's public key through a secure channel, can then communicate with any Notary server or (insecure) mirror, relying only on the publisher's key to determine the validity and integrity of the received content. --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-27191 ---- Fix FTBFS Close: rhbz#2045471 --------------------------------------------------------------------------------ChangeLog: * Sat Apr 16 2022 Fabio Alessandro Locati 0.7.0-4 - Rebuilt for CVE-2022-27191 --------------------------------------------------------------------------------References: [ 1 ] Bug #2045471 - golang-github-appc-goaci: FTBFS inFedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045471 [ 2 ] Bug #2074262 - CVE-2022-27191 golang-x-crypto: golang: crash in a golang.org/x/crypto/ssh server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2074262 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-08ae2dd481' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . To tackle CVE-2022-27191 on Fedora 36 for golang-github-theupdateframework-notary, it is essential to update the package for security reasons. Follow these steps to implement the solution. Fedora Update, Go Language, Security Fix, Trusted Collections, Software Rebuild. . Severity: Low. LinuxSecurity.com Team

Calendar 2 May 07, 2022 Low Fedora
89

Fedora 27 Docker Security Update: CVE-2017-14992 Critical Threat

- Resolves: #1510351 - CVE-2017-14992 - built docker @projectatomic/docker-1.13.1 commit 584d391 - built docker-novolume-plugin commit 385ec70 - built rhel-push-plugin commit af9107b - built docker-lvm-plugin commit 8647404 - built docker-runc @projectatomic/docker-1.13.1 commit 1c91122 - built docker-containerd @projectatomic/docker-1.13.1 commit 62a9c60 - built. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-15efa72a0c 2018-01-17 14:43:41.390375 --------------------------------------------------------------------------------Name : docker Product : Fedora 27 Version : 1.13.1 Release : 44.git584d391.fc27 URL : https://github.com/projectatomic/docker Summary : Automates deployment of containerized applications Description : Docker is an open-source engine that automates the deployment of any application as a lightweight, portable, self-sufficient container that will run virtually anywhere. Docker containers can encapsulate any payload, and will run consistently on and between virtually any server. The same container that a developer builds and tests on a laptop will run at scale, in production*, on VMs, bare-metal servers, OpenStack clusters, public instances, or combinations of the above. --------------------------------------------------------------------------------Update Information: - Resolves: #1510351 - CVE-2017-14992 - built docker @projectatomic/docker-1.13.1 commit 584d391 - built docker-novolume-plugin commit 385ec70 - built rhel-push-plugin commit af9107b - built docker-lvm-plugin commit 8647404 - built docker-runc @projectatomic/docker-1.13.1 commit 1c91122 -built docker-containerd @projectatomic/docker-1.13.1 commit 62a9c60 - built docker-init commit 0effd37 - built libnetwork commit 460ac8f ---- make /etc/sysconfig/docker-storage-setup ghost but notconfig, https://bugzilla.redhat.com/show_bug.cgi?id=1508376 --------------------------------------------------------------------------------References: [ 1 ] Bug #1510351 - CVE-2017-14992 docker: Lack of content verification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1510351 [ 2 ] Bug #1508376 - docker-storage-setup fails to start https://bugzilla.redhat.com/show_bug.cgi?id=1508376 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade docker' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Mitigate Docker security concerns in Fedora 27 by implementing this essential update that resolves CVE-2017-14992 vulnerabilities.. Docker Security,Fedora Update,Content Verification,Container Security,Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 17, 2018 Critical Fedora
89

Fedora 26: FEDORA-2017-3976710f1e Critical: Docker Content Verification

Resolves: #1510351 - CVE-2017-14992 built docker @projectatomic/docker-1.13.1 commit 584d391 built docker-novolume-plugin commit 385ec70 built rhel-push-plugin commit af9107b built docker-lvm- plugin commit 8647404 built docker-runc @projectatomic/docker-1.13.1 commit 1c91122 built docker-containerd @projectatomic/docker-1.13.1 commit 62a9c60. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-3976710f1e 2017-12-09 21:09:01.032318 --------------------------------------------------------------------------------Name : docker Product : Fedora 26 Version : 1.13.1 Release : 44.git584d391.fc26 URL : https://github.com/projectatomic/docker Summary : Automates deployment of containerized applications Description : Docker is an open-source engine that automates the deployment of any application as a lightweight, portable, self-sufficient container that will run virtually anywhere. Docker containers can encapsulate any payload, and will run consistently on and between virtually any server. The same container that a developer builds and tests on a laptop will run at scale, in production*, on VMs, bare-metal servers, OpenStack clusters, public instances, or combinations of the above. --------------------------------------------------------------------------------Update Information: Resolves: #1510351 - CVE-2017-14992 built docker @projectatomic/docker-1.13.1 commit 584d391 built docker-novolume-plugin commit 385ec70 built rhel-push-plugin commit af9107b built docker-lvm-plugin commit 8647404 built docker-runc @projectatomic/docker-1.13.1 commit 1c91122 built docker-containerd @projectatomic/docker-1.13.1 commit 62a9c60 built docker-init commit 0effd37 built libnetwork commit 460ac8f ----make /etc/sysconfig/docker-storage-setup ghost but notconfig, https://bugzilla.redhat.com/show_bug.cgi?id=1508376 --------------------------------------------------------------------------------References: [ 1 ] Bug #1510351 - CVE-2017-14992 docker: Lack of content verification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1510351 [ 2 ] Bug #1508376 - docker-storage-setup fails to start https://bugzilla.redhat.com/show_bug.cgi?id=1508376 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade docker' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . This release focuses on resolving key content validation problems in Docker for Fedora 26, improving overall system safety.. Docker Security, Fedora Update, Threat Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 09, 2017 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here