Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Cookie exposure to third parties (CVE-2022-24737) References: - https://bugs.mageia.org/show_bug.cgi?id=30188 - https://lists.fedoraproject.org/archives/list/
Two security vulnerabilities have been discovered in the Tomcat servlet and JSP engine. CVE-2022-42252 . -------------------------------------------------------------------------Debian LTS Advisory DLA-3384-1
Libzypp from mageia 7 is affected by a security issue. This update fixes this. Incorrect Default Permissions vulnerability in libzypp allowed local . MGASA-2020-0245 - Updated libzypp packages fix security vulnerability Publication date: 10 Jun 2020 URL: https://advisories.mageia.org/MGASA-2020-0245.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-18900 Libzypp from mageia 7 is affected by a security issue. This update fixes this. Incorrect Default Permissions vulnerability in libzypp allowed local attackers to read a cookie store used by libzypp, exposing private cookies. References: - https://bugs.mageia.org/show_bug.cgi?id=26068 - https://bugzilla.suse.com/show_bug.cgi?id=1158763 - https://github.com/openSUSE/libzypp/pull/196 - https://github.com/openSUSE/libzypp/commit/ea50981352bb5c7ab48663edaeb2df1ddd66953e - https://github.com/openSUSE/libzypp/commit/508b1201f23b44ee90dee6dbbeb3ac5f8bd4c089 - https://www.cve.org/CVERecord?id=CVE-2019-18900 SRPMS: - 7/core/libzypp-17.9.0-1.1.mga7 . MGASA-2020-0246 resolves a vulnerability in libzypp, improving the overall safety of Mageia 7.. libzypp update, mageia security, permissions fix, cookie security. . Severity: Critical. LinuxSecurity.com Team
Requests could be made to expose cookies over the network.. =========================================================================Ubuntu Security Notice USN-2531-1 March 16, 2015 requests vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS Summary: Requests could be made to expose cookies over the network. Software Description: - requests: elegant and simple HTTP library for Python Details: Matthew Daley discovered that Requests incorrectly handled cookies without host values when being redirected. A remote attacker could possibly use this issue to perform session fixation or cookie stealing attacks. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: python-requests 2.3.0-1ubuntu0.1 python3-requests 2.3.0-1ubuntu0.1 Ubuntu 14.04 LTS: python-requests 2.2.1-1ubuntu0.2 python3-requests 2.2.1-1ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2531-1 CVE-2015-2296 Package Information: https://launchpad.net/ubuntu/+source/requests/2.3.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/requests/2.2.1-1ubuntu0.2 . Network communications in Ubuntu might inadvertently reveal cookies, posing a risk of exploitation. Urgent patch advised.. Ubuntu Requests Vulnerability, Cookie Exposure, Session Fixation, Python HTTP Library, Security Advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.