Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
100

SUSE Advises on libsoup Critical Cookie Handling DoS CVE-2025-11021

* bsc#1250562 Cross-References: * CVE-2025-11021 . # Security update for libsoup Announcement ID: SUSE-SU-2025:3753-1 Release Date: 2025-10-23T10:26:49Z Rating: important References: * bsc#1250562 Cross-References: * CVE-2025-11021 CVSS scores: * CVE-2025-11021 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-11021 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-11021 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libsoup fixes the following issues: * CVE-2025-11021: Ignored invalid date when processing cookies to prevent out- of-bounds read (bsc#1250562). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-3753=1 openSUSE-SLE-15.6-2025-3753=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-3753=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3753=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * typelib-1_0-Soup-3_0-3.4.4-150600.3.18.1 * libsoup-debugsource-3.4.4-150600.3.18.1 * libsoup-3_0-0-3.4.4-150600.3.18.1 * libsoup-devel-3.4.4-150600.3.18.1 *libsoup-3_0-0-debuginfo-3.4.4-150600.3.18.1 * openSUSE Leap 15.6 (x86_64) * libsoup-3_0-0-32bit-debuginfo-3.4.4-150600.3.18.1 * libsoup-3_0-0-32bit-3.4.4-150600.3.18.1 * libsoup-devel-32bit-3.4.4-150600.3.18.1 * openSUSE Leap 15.6 (noarch) * libsoup-lang-3.4.4-150600.3.18.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libsoup-3_0-0-64bit-debuginfo-3.4.4-150600.3.18.1 * libsoup-devel-64bit-3.4.4-150600.3.18.1 * libsoup-3_0-0-64bit-3.4.4-150600.3.18.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * typelib-1_0-Soup-3_0-3.4.4-150600.3.18.1 * libsoup-debugsource-3.4.4-150600.3.18.1 * libsoup-3_0-0-3.4.4-150600.3.18.1 * libsoup-devel-3.4.4-150600.3.18.1 * libsoup-3_0-0-debuginfo-3.4.4-150600.3.18.1 * Basesystem Module 15-SP6 (noarch) * libsoup-lang-3.4.4-150600.3.18.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * typelib-1_0-Soup-3_0-3.4.4-150600.3.18.1 * libsoup-debugsource-3.4.4-150600.3.18.1 * libsoup-3_0-0-3.4.4-150600.3.18.1 * libsoup-devel-3.4.4-150600.3.18.1 * libsoup-3_0-0-debuginfo-3.4.4-150600.3.18.1 * Basesystem Module 15-SP7 (noarch) * libsoup-lang-3.4.4-150600.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11021.html * https://bugzilla.suse.com/show_bug.cgi?id=1250562 . A security advisory for SUSE updates addressing an important issue in libsoup affecting multiple distributions.. SUSE Update Libsoup Security Important Cookie Handling. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 23, 2025 Important SuSE
172

Ubuntu 23.10 USN-6535-1 moderate: curl handling cookie threats

Several security issues were fixed in curl.. ========================================================================== Ubuntu Security Notice USN-6535-1 December 06, 2023 curl vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in curl. Software Description: - curl: HTTP, HTTPS, and FTP client and client libraries Details: Harry Sintonen discovered that curl incorrectly handled mixed case cookie domains. A remote attacker could possibly use this issue to set cookies that get sent to different and unrelated sites and domains. (CVE-2023-46218) Maksymilian Arciemowicz discovered that curl incorrectly handled long file names when saving HSTS data. This could result in curl losing HSTS data, and subsequent requests to a site would be done without it, contrary to expectations. This issue only affected Ubuntu 23.04 and Ubuntu 23.10. (CVE-2023-46219) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: curl 8.2.1-1ubuntu3.2 libcurl3-gnutls 8.2.1-1ubuntu3.2 libcurl3-nss 8.2.1-1ubuntu3.2 libcurl4 8.2.1-1ubuntu3.2 Ubuntu 23.04: curl 7.88.1-8ubuntu2.4 libcurl3-gnutls 7.88.1-8ubuntu2.4 libcurl3-nss 7.88.1-8ubuntu2.4 libcurl4 7.88.1-8ubuntu2.4 Ubuntu 22.04 LTS: curl 7.81.0-1ubuntu1.15 libcurl3-gnutls 7.81.0-1ubuntu1.15 libcurl3-nss 7.81.0-1ubuntu1.15 libcurl4 7.81.0-1ubuntu1.15 Ubuntu 20.04 LTS: curl 7.68.0-1ubuntu2.21 libcurl3-gnutls 7.68.0-1ubuntu2.21 libcurl3-nss 7.68.0-1ubuntu2.21 libcurl4 7.68.0-1ubuntu2.21 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6535-1 CVE-2023-46218, CVE-2023-46219 Package Information: https://launchpad.net/ubuntu/+source/curl/8.2.1-1ubuntu3.2 https://launchpad.net/ubuntu/+source/curl/7.88.1-8ubuntu2.4 https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.15 https://launchpad.net/ubuntu/+source/curl/7.68.0-1ubuntu2.21 . Updates for Ubuntu versions 23.04 and 23.10 address vulnerabilities with curl; it's crucial to install the most recent fixes to safeguard your sensitive information and cookies.. curl Update, Cookie Handling Risk, HSTS Data Loss. . LinuxSecurity.com Team

Calendar 2 Dec 06, 2023 Ubuntu
172

Ubuntu 16.04 LTS: USN-4609-1 Critical: gosa Access Control Issues

Several security issues were fixed in gosa.. =========================================================================Ubuntu Security Notice USN-4609-1 October 28, 2020 gosa vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in gosa. Software Description: - gosa: Web Based LDAP Administration Program Details: Fabian Henneke discovered that GOsa incorrectly handled client cookies. An authenticated user could exploit this with a crafted cookie to perform file deletions in the context of the user account that runs the web server. (CVE-2019-14466) It was discovered that GOsa incorrectly handled user access control. A remote attacker could use this issue to log into any account with a username containing the word "success". (CVE-2019-11187) Fabian Henneke discovered that GOsa was vulnerable to cross-site scripting attacks via the change password form. A remote attacker could use this flaw to run arbitrary web scripts. (CVE-2018-1000528) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: gosa 2.7.4+reloaded2-9ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4609-1 CVE-2018-1000528, CVE-2019-11187, CVE-2019-14466 Package Information: https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1 . Important security patch for gosa on Ubuntu, targeting various flaws and possible remote exploitation.. gosa vulnerabilities, Ubuntu security issues, XSS attacks, access control flaws, cookie handling vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 28, 2020 Critical Ubuntu
100

SUSE: 2020:2943-1 Important: php72 OpenSSL And Cookie Issues

An update that solves two vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2943-1 Rating: important References: #1173786 #1177351 #1177352 Cross-References: CVE-2020-7069 CVE-2020-7070 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for php72 fixes the following issues: - CVE-2020-7069: Fixed an issue when AES-CCM mode was used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV was used (bsc#1177351). - CVE-2020-7070: Fixed an issue where percent-encoded cookies could have been used to overwrite existing prefixed cookie names (bsc#1177352). - Added tmpfiles.d for php-fpm to provide a base for a socket (bsc#1173786) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-2943=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2020-2943=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.54.1 php72-debugsource-7.2.5-1.54.1 php72-devel-7.2.5-1.54.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.54.1 apache2-mod_php72-debuginfo-7.2.5-1.54.1 php72-7.2.5-1.54.1 php72-bcmath-7.2.5-1.54.1 php72-bcmath-debuginfo-7.2.5-1.54.1 php72-bz2-7.2.5-1.54.1 php72-bz2-debuginfo-7.2.5-1.54.1 php72-calendar-7.2.5-1.54.1 php72-calendar-debuginfo-7.2.5-1.54.1 php72-ctype-7.2.5-1.54.1 php72-ctype-debuginfo-7.2.5-1.54.1 php72-curl-7.2.5-1.54.1 php72-curl-debuginfo-7.2.5-1.54.1 php72-dba-7.2.5-1.54.1 php72-dba-debuginfo-7.2.5-1.54.1 php72-debuginfo-7.2.5-1.54.1 php72-debugsource-7.2.5-1.54.1 php72-dom-7.2.5-1.54.1 php72-dom-debuginfo-7.2.5-1.54.1 php72-enchant-7.2.5-1.54.1 php72-enchant-debuginfo-7.2.5-1.54.1 php72-exif-7.2.5-1.54.1 php72-exif-debuginfo-7.2.5-1.54.1 php72-fastcgi-7.2.5-1.54.1 php72-fastcgi-debuginfo-7.2.5-1.54.1 php72-fileinfo-7.2.5-1.54.1 php72-fileinfo-debuginfo-7.2.5-1.54.1 php72-fpm-7.2.5-1.54.1 php72-fpm-debuginfo-7.2.5-1.54.1 php72-ftp-7.2.5-1.54.1 php72-ftp-debuginfo-7.2.5-1.54.1 php72-gd-7.2.5-1.54.1 php72-gd-debuginfo-7.2.5-1.54.1 php72-gettext-7.2.5-1.54.1 php72-gettext-debuginfo-7.2.5-1.54.1 php72-gmp-7.2.5-1.54.1 php72-gmp-debuginfo-7.2.5-1.54.1 php72-iconv-7.2.5-1.54.1 php72-iconv-debuginfo-7.2.5-1.54.1 php72-imap-7.2.5-1.54.1 php72-imap-debuginfo-7.2.5-1.54.1 php72-intl-7.2.5-1.54.1 php72-intl-debuginfo-7.2.5-1.54.1 php72-json-7.2.5-1.54.1 php72-json-debuginfo-7.2.5-1.54.1 php72-ldap-7.2.5-1.54.1 php72-ldap-debuginfo-7.2.5-1.54.1 php72-mbstring-7.2.5-1.54.1 php72-mbstring-debuginfo-7.2.5-1.54.1 php72-mysql-7.2.5-1.54.1 php72-mysql-debuginfo-7.2.5-1.54.1 php72-odbc-7.2.5-1.54.1 php72-odbc-debuginfo-7.2.5-1.54.1 php72-opcache-7.2.5-1.54.1 php72-opcache-debuginfo-7.2.5-1.54.1 php72-openssl-7.2.5-1.54.1 php72-openssl-debuginfo-7.2.5-1.54.1 php72-pcntl-7.2.5-1.54.1 php72-pcntl-debuginfo-7.2.5-1.54.1 php72-pdo-7.2.5-1.54.1 php72-pdo-debuginfo-7.2.5-1.54.1 php72-pgsql-7.2.5-1.54.1 php72-pgsql-debuginfo-7.2.5-1.54.1 php72-phar-7.2.5-1.54.1 php72-phar-debuginfo-7.2.5-1.54.1 php72-posix-7.2.5-1.54.1 php72-posix-debuginfo-7.2.5-1.54.1 php72-pspell-7.2.5-1.54.1 php72-pspell-debuginfo-7.2.5-1.54.1 php72-readline-7.2.5-1.54.1 php72-readline-debuginfo-7.2.5-1.54.1 php72-shmop-7.2.5-1.54.1 php72-shmop-debuginfo-7.2.5-1.54.1 php72-snmp-7.2.5-1.54.1 php72-snmp-debuginfo-7.2.5-1.54.1 php72-soap-7.2.5-1.54.1 php72-soap-debuginfo-7.2.5-1.54.1 php72-sockets-7.2.5-1.54.1 php72-sockets-debuginfo-7.2.5-1.54.1 php72-sodium-7.2.5-1.54.1 php72-sodium-debuginfo-7.2.5-1.54.1 php72-sqlite-7.2.5-1.54.1 php72-sqlite-debuginfo-7.2.5-1.54.1 php72-sysvmsg-7.2.5-1.54.1 php72-sysvmsg-debuginfo-7.2.5-1.54.1 php72-sysvsem-7.2.5-1.54.1 php72-sysvsem-debuginfo-7.2.5-1.54.1 php72-sysvshm-7.2.5-1.54.1 php72-sysvshm-debuginfo-7.2.5-1.54.1 php72-tidy-7.2.5-1.54.1 php72-tidy-debuginfo-7.2.5-1.54.1 php72-tokenizer-7.2.5-1.54.1 php72-tokenizer-debuginfo-7.2.5-1.54.1 php72-wddx-7.2.5-1.54.1 php72-wddx-debuginfo-7.2.5-1.54.1 php72-xmlreader-7.2.5-1.54.1 php72-xmlreader-debuginfo-7.2.5-1.54.1 php72-xmlrpc-7.2.5-1.54.1 php72-xmlrpc-debuginfo-7.2.5-1.54.1 php72-xmlwriter-7.2.5-1.54.1 php72-xmlwriter-debuginfo-7.2.5-1.54.1 php72-xsl-7.2.5-1.54.1 php72-xsl-debuginfo-7.2.5-1.54.1 php72-zip-7.2.5-1.54.1 php72-zip-debuginfo-7.2.5-1.54.1 php72-zlib-7.2.5-1.54.1 php72-zlib-debuginfo-7.2.5-1.54.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.54.1 php72-pear-Archive_Tar-7.2.5-1.54.1 References: https://www.suse.com/security/cve/CVE-2020-7069.html https://www.suse.com/security/cve/CVE-2020-7070.html https://bugzilla.suse.com/1173786 https://bugzilla.suse.com/1177351 https://bugzilla.suse.com/1177352 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE announces significant security patch for php72 tackling severe vulnerabilities. Resolved problems related to OpenSSL and session management.. SUSE Security Update, php72 vulnerabilities, Software Development Kit, Web Scripting Module. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 16, 2020 Important SuSE
172

Ubuntu 16.04/18.04 LTS/19.04 Moderate: Python Security Advisory

Several security issues were fixed in Python.. =========================================================================Ubuntu Security Notice USN-4127-1 September 09, 2019 python2.7, python3.5, python3.6, python3.7 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.04 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Python. Software Description: - python2.7: An interactive high-level object-oriented language - python3.7: An interactive high-level object-oriented language - python3.6: An interactive high-level object-oriented language - python3.5: An interactive high-level object-oriented language Details: It was discovered that Python incorrectly handled certain pickle files. An attacker could possibly use this issue to consume memory, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-20406) It was discovered that Python incorrectly validated the domain when handling cookies. An attacker could possibly trick Python into sending cookies to the wrong domain. (CVE-2018-20852) Jonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly handled Unicode encoding during NFKC normalization. An attacker could possibly use this issue to obtain sensitive information. (CVE-2019-9636, CVE-2019-10160) Colin Read and Nicolas Edet discovered that Python incorrectly handled parsing certain X509 certificates. An attacker could possibly use this issue to cause Python to crash, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-5010) It was discovered that Python incorrectly handled certain urls. A remote attacker could possibly use this issue to perform CRLF injection attacks. (CVE-2019-9740, CVE-2019-9947) Sihoon Lee discovered that Python incorrectly handled the local_file: scheme. Aremote attacker could possibly use this issue to bypass blacklist meschanisms. (CVE-2019-9948) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: python2.7 2.7.16-2ubuntu0.1 python2.7-minimal 2.7.16-2ubuntu0.1 python3.7 3.7.3-2ubuntu0.1 python3.7-minimal 3.7.3-2ubuntu0.1 Ubuntu 18.04 LTS: python2.7 2.7.15-4ubuntu4~18.04.1 python2.7-minimal 2.7.15-4ubuntu4~18.04.1 python3.6 3.6.8-1~18.04.2 python3.6-minimal 3.6.8-1~18.04.2 Ubuntu 16.04 LTS: python2.7 2.7.12-1ubuntu0~16.04.8 python2.7-minimal 2.7.12-1ubuntu0~16.04.8 python3.5 3.5.2-2ubuntu0~16.04.8 python3.5-minimal 3.5.2-2ubuntu0~16.04.8 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4127-1 CVE-2018-20406, CVE-2018-20852, CVE-2019-10160, CVE-2019-5010, CVE-2019-9636, CVE-2019-9740, CVE-2019-9947, CVE-2019-9948 Package Information: https://launchpad.net/ubuntu/+source/python2.7/2.7.16-2ubuntu0.1 https://launchpad.net/ubuntu/+source/python3.7/3.7.3-2ubuntu0.1 https://launchpad.net/ubuntu/+source/python2.7/2.7.15-4ubuntu4~18.04.1 https://launchpad.net/ubuntu/+source/python3.6/3.6.8-1~18.04.2 https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.8 https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.8 . Discovered security flaws in Python libraries for Ubuntu 16.04, 18.04 LTS, and 19.04 present significant risks of exploitation.. Ubuntu Security Notice, Python Security Issues, Python Update Information, Denial of Service. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 09, 2019 Important Ubuntu
197

Debian 8: DLA-1906-1 Critical: Python2.7 Cookie Handling Issue

A vulnerability has been discovered in Python, an interactive high-level object-oriented language, that is relevant for cookie handling. By using a malicious server an attacker might steal cookies that are meant for other . Package : python2.7 Version : 2.7.9-2+deb8u4 CVE ID : CVE-2018-20852 A vulnerability has been discovered in Python, an interactive high-level object-oriented language, that is relevant for cookie handling. By using a malicious server an attacker might steal cookies that are meant for other domains For Debian 8 "Jessie", this problem has been fixed in version 2.7.9-2+deb8u4. We recommend that you upgrade your python2.7 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An exploit in python2.7 concerning cookie management enables adversaries to capture cookies from different domains.. Python Security, Debian LTS, Cookie Handling Issue, Debian Upgrade, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 31, 2019 Critical Debian LTS
197

Debian 8 Jessie DLA-1889-1 Critical: Python 3.4 Cookie Threat

A vulnerability has been discovered in Python, an interactive high-level object-oriented language, that is relevant for cookie handling. By using a malicious server an attacker might steal cookies that are . Package : python3.4 Version : 3.4.2-1+deb8u6 CVE ID : CVE-2018-20852 A vulnerability has been discovered in Python, an interactive high-level object-oriented language, that is relevant for cookie handling. By using a malicious server an attacker might steal cookies that are meant for other domains For Debian 8 "Jessie", this problem has been fixed in version 3.4.2-1+deb8u6. We recommend that you upgrade your python3.4 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An update for Python 3.4 has been released to fix a cookie security issue on Debian 8 Jessie. Please upgrade to enhance your security.. Python 3.4 Security Update, Debian Cookie Handling Threat, Python Vulnerability Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 17, 2019 Critical Debian LTS
98

Red Hat Linux 9 RHSA-2004:112-01 Critical: Mozilla DoS and XSS Fixes

This patch resolves a DoS attack, a cross-site scripting vulnerability, and a cookie path escape vulnerability.. Red Hat Security Advisory Synopsis: Updated Mozilla packages fix security issues Advisory ID: RHSA-2004:112-01 Issue date: 2004-03-17 Updated on: 2004-03-17 Product: Red Hat Linux Keywords: nss mozilla Cross references: Obsoletes: CVE Names: CAN-2003-0564 CAN-2003-0594 CAN-2004-0191 - --------------------------------------------------------------------- 1. Topic: Updated Mozilla packages that fix vulnerabilities in S/MIME parsing as well as other issues and bugs are now available. 2. Relevant releases/architectures: Red Hat Linux 9 - i386 3. Problem description: Mozilla is a Web browser and mail reader, designed for standards compliance, performance and portability. Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled server applications. NISCC testing of implementations of the S/MIME protocol uncovered a number of bugs in NSS versions prior to 3.9. The parsing of unexpected ASN.1 constructs within S/MIME data could cause Mozilla to crash or consume large amounts of memory. A remote attacker could potentially trigger these bugs by sending a carefully-crafted S/MIME message to a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0564 to this issue. Andreas Sandblad discovered a cross-site scripting issue that affects various versions of Mozilla. When linking to a new page it is still possible to interact with the old page before the new page has been successfully loaded. Any Javascript events will be invoked in the context of the new page, making cross-site scripting possible if the different pages belong to different domains. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0191 to this issue. Flaws have been found in the cookie path handlingbetween a number of Web browsers and servers. The HTTP cookie standard allows a Web server supplying a cookie to a client to specify a subset of URLs on the origin server to which the cookie applies. Web servers such as Apache do not filter returned cookies and assume that the client will only send back cookies for requests that fall within the server-supplied subset of URLs. However, by supplying URLs that use path traversal (/../) and character encoding, it is possible to fool many browsers into sending a cookie to a path outside of the originally-specified subset. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0594 to this issue. Users of Mozilla are advised to upgrade to these updated packages, which contain Mozilla version 1.4.2 and are not vulnerable to these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. If up2date fails to connect to Red Hat Network due to SSL Certificate Errors, you need to install a version of the up2date client with an updated certificate. The latest version of up2date is available from the Red Hat FTP site and may also be downloaded directly from the RHN website: https://access.redhat.com 5. RPMs required: Red Hat Linux9: SRPMS: i386: 6. Verificationx: MD5 sum Package Name - -------------------------------------------------------------------------- 992ef9250ed9c98cebbb8dece0b42a40 9/en/os/SRPMS/galeon-1.2.13-0.9.0.src.rpm 392c1e8d54668de9114ced4cb26f2239 9/en/os/SRPMS/mozilla-1.4.2-0.9.0.src.rpm 4246168924d57be9a4b3549e119c0fa7 9/en/os/i386/galeon-1.2.13-0.9.0.i386.rpm 0fba1f22954569f2fe62b20c12badde8 9/en/os/i386/mozilla-1.4.2-0.9.0.i386.rpm f36041c9afacb8ac07d7caf0ffba5636 9/en/os/i386/mozilla-chat-1.4.2-0.9.0.i386.rpm 134a3539d5f3d3de4456bb2c2b70948d 9/en/os/i386/mozilla-devel-1.4.2-0.9.0.i386.rpm 0bfad47e55d2d8202a5dc80b504cf68b 9/en/os/i386/mozilla-dom-inspector-1.4.2-0.9.0.i386.rpm e5a9af2c6b720adb3ca8f831568ce208 9/en/os/i386/mozilla-js-debugger-1.4.2-0.9.0.i386.rpm 8909de56f2915ffb9c3adbedad0da0dc 9/en/os/i386/mozilla-mail-1.4.2-0.9.0.i386.rpm f4d1279c459694868473c8ad2609b490 9/en/os/i386/mozilla-nspr-1.4.2-0.9.0.i386.rpm 3a2f9360085c0ecb0a312da2dec1e703 9/en/os/i386/mozilla-nspr-devel-1.4.2-0.9.0.i386.rpm 5198348d07a15c8a064688baf03f4aea 9/en/os/i386/mozilla-nss-1.4.2-0.9.0.i386.rpm cb849bc1da29db4d3e5a9e50e708fae6 9/en/os/i386/mozilla-nss-devel-1.4.2-0.9.0.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from https://access.redhat.com/security/team/key You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: https://firefox-source-docs.mozilla.org/security/nss/index.html 227417 - Cross-domain exploit on zombie document with event handlers CVE -CVE-2003-0564 CVE -CVE-2003-0594 CVE -CVE-2004-0191 8. Contact: The Red Hat security contact is . More contact details at https://www.redhat.com/en/technologies/all-products Copyright 2003 Red Hat, Inc. . Updated Mozilla releases tacklesecurity challenges including Denial of Service attacks and cookie handling weaknesses for Red Hat Linux users.. Mozilla Vulnerabilities, Red Hat Linux Security, DoS Attack Mitigation, Cross-Site Scripting Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 18, 2004 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here