Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
202

openSUSE: 2020:1703-1 Important: PHP7 Security Update Details

An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for php7 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1703-1 Rating: important References: #1177351 #1177352 Cross-References: CVE-2020-7069 CVE-2020-7070 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for php7 fixes the following issues: - CVE-2020-7069: Fixed an issue when AES-CCM mode was used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV was used (bsc#1177351). - CVE-2020-7070: Fixed an issue where percent-encoded cookies could have been used to overwrite existing prefixed cookie names (bsc#1177352). This update was imported from the SUSE:SLE-15-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1703=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): apache2-mod_php7-7.4.6-lp152.2.9.1 apache2-mod_php7-debuginfo-7.4.6-lp152.2.9.1 php7-7.4.6-lp152.2.9.1 php7-bcmath-7.4.6-lp152.2.9.1 php7-bcmath-debuginfo-7.4.6-lp152.2.9.1 php7-bz2-7.4.6-lp152.2.9.1 php7-bz2-debuginfo-7.4.6-lp152.2.9.1 php7-calendar-7.4.6-lp152.2.9.1 php7-calendar-debuginfo-7.4.6-lp152.2.9.1 php7-ctype-7.4.6-lp152.2.9.1 php7-ctype-debuginfo-7.4.6-lp152.2.9.1 php7-curl-7.4.6-lp152.2.9.1 php7-curl-debuginfo-7.4.6-lp152.2.9.1 php7-dba-7.4.6-lp152.2.9.1 php7-dba-debuginfo-7.4.6-lp152.2.9.1 php7-debuginfo-7.4.6-lp152.2.9.1 php7-debugsource-7.4.6-lp152.2.9.1 php7-devel-7.4.6-lp152.2.9.1 php7-dom-7.4.6-lp152.2.9.1 php7-dom-debuginfo-7.4.6-lp152.2.9.1 php7-embed-7.4.6-lp152.2.9.1 php7-embed-debuginfo-7.4.6-lp152.2.9.1 php7-enchant-7.4.6-lp152.2.9.1 php7-enchant-debuginfo-7.4.6-lp152.2.9.1 php7-exif-7.4.6-lp152.2.9.1 php7-exif-debuginfo-7.4.6-lp152.2.9.1 php7-fastcgi-7.4.6-lp152.2.9.1 php7-fastcgi-debuginfo-7.4.6-lp152.2.9.1 php7-fileinfo-7.4.6-lp152.2.9.1 php7-fileinfo-debuginfo-7.4.6-lp152.2.9.1 php7-firebird-7.4.6-lp152.2.9.1 php7-firebird-debuginfo-7.4.6-lp152.2.9.1 php7-fpm-7.4.6-lp152.2.9.1 php7-fpm-debuginfo-7.4.6-lp152.2.9.1 php7-ftp-7.4.6-lp152.2.9.1 php7-ftp-debuginfo-7.4.6-lp152.2.9.1 php7-gd-7.4.6-lp152.2.9.1 php7-gd-debuginfo-7.4.6-lp152.2.9.1 php7-gettext-7.4.6-lp152.2.9.1 php7-gettext-debuginfo-7.4.6-lp152.2.9.1 php7-gmp-7.4.6-lp152.2.9.1 php7-gmp-debuginfo-7.4.6-lp152.2.9.1 php7-iconv-7.4.6-lp152.2.9.1 php7-iconv-debuginfo-7.4.6-lp152.2.9.1 php7-intl-7.4.6-lp152.2.9.1 php7-intl-debuginfo-7.4.6-lp152.2.9.1 php7-json-7.4.6-lp152.2.9.1 php7-json-debuginfo-7.4.6-lp152.2.9.1 php7-ldap-7.4.6-lp152.2.9.1 php7-ldap-debuginfo-7.4.6-lp152.2.9.1 php7-mbstring-7.4.6-lp152.2.9.1 php7-mbstring-debuginfo-7.4.6-lp152.2.9.1 php7-mysql-7.4.6-lp152.2.9.1 php7-mysql-debuginfo-7.4.6-lp152.2.9.1 php7-odbc-7.4.6-lp152.2.9.1 php7-odbc-debuginfo-7.4.6-lp152.2.9.1 php7-opcache-7.4.6-lp152.2.9.1 php7-opcache-debuginfo-7.4.6-lp152.2.9.1 php7-openssl-7.4.6-lp152.2.9.1 php7-openssl-debuginfo-7.4.6-lp152.2.9.1 php7-pcntl-7.4.6-lp152.2.9.1 php7-pcntl-debuginfo-7.4.6-lp152.2.9.1 php7-pdo-7.4.6-lp152.2.9.1 php7-pdo-debuginfo-7.4.6-lp152.2.9.1 php7-pgsql-7.4.6-lp152.2.9.1 php7-pgsql-debuginfo-7.4.6-lp152.2.9.1 php7-phar-7.4.6-lp152.2.9.1 php7-phar-debuginfo-7.4.6-lp152.2.9.1 php7-posix-7.4.6-lp152.2.9.1 php7-posix-debuginfo-7.4.6-lp152.2.9.1 php7-readline-7.4.6-lp152.2.9.1 php7-readline-debuginfo-7.4.6-lp152.2.9.1 php7-shmop-7.4.6-lp152.2.9.1 php7-shmop-debuginfo-7.4.6-lp152.2.9.1 php7-snmp-7.4.6-lp152.2.9.1 php7-snmp-debuginfo-7.4.6-lp152.2.9.1 php7-soap-7.4.6-lp152.2.9.1 php7-soap-debuginfo-7.4.6-lp152.2.9.1 php7-sockets-7.4.6-lp152.2.9.1 php7-sockets-debuginfo-7.4.6-lp152.2.9.1 php7-sodium-7.4.6-lp152.2.9.1 php7-sodium-debuginfo-7.4.6-lp152.2.9.1 php7-sqlite-7.4.6-lp152.2.9.1 php7-sqlite-debuginfo-7.4.6-lp152.2.9.1 php7-sysvmsg-7.4.6-lp152.2.9.1 php7-sysvmsg-debuginfo-7.4.6-lp152.2.9.1 php7-sysvsem-7.4.6-lp152.2.9.1 php7-sysvsem-debuginfo-7.4.6-lp152.2.9.1 php7-sysvshm-7.4.6-lp152.2.9.1 php7-sysvshm-debuginfo-7.4.6-lp152.2.9.1 php7-test-7.4.6-lp152.2.9.1 php7-tidy-7.4.6-lp152.2.9.1 php7-tidy-debuginfo-7.4.6-lp152.2.9.1 php7-tokenizer-7.4.6-lp152.2.9.1 php7-tokenizer-debuginfo-7.4.6-lp152.2.9.1 php7-xmlreader-7.4.6-lp152.2.9.1 php7-xmlreader-debuginfo-7.4.6-lp152.2.9.1 php7-xmlrpc-7.4.6-lp152.2.9.1 php7-xmlrpc-debuginfo-7.4.6-lp152.2.9.1 php7-xmlwriter-7.4.6-lp152.2.9.1 php7-xmlwriter-debuginfo-7.4.6-lp152.2.9.1 php7-xsl-7.4.6-lp152.2.9.1 php7-xsl-debuginfo-7.4.6-lp152.2.9.1 php7-zip-7.4.6-lp152.2.9.1 php7-zip-debuginfo-7.4.6-lp152.2.9.1 php7-zlib-7.4.6-lp152.2.9.1 php7-zlib-debuginfo-7.4.6-lp152.2.9.1 References: https://www.suse.com/security/cve/CVE-2020-7069.html https://www.suse.com/security/cve/CVE-2020-7070.html https://bugzilla.suse.com/1177351 https://bugzilla.suse.com/1177352 -- . Significant security flaws addressed in php7 for openSUSE, crucial patches released for safe setup.. openSUSE Update, PHP Security, Important Fixes, AES-CCM Issue, Cookie Overwrite Problem. . Severity:Important. LinuxSecurity.com Team

Calendar 2 Oct 20, 2020 Important OpenSUSE
100

SUSE: 2020:14516-1 Important: php53 Cookie Overwrite Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php53 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:14516-1 Rating: important References: #1177352 Cross-References: CVE-2020-7070 Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php53 fixes the following issues: - CVE-2020-7070: Fixed an issue where percent-encoded cookies could have been used to overwrite existing prefixed cookie names (bsc#1177352). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-php53-14516=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-php53-14516=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-php53-14516=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-php53-14516=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (i586 ppc64 s390x x86_64): apache2-mod_php53-5.3.17-112.93.1 php53-5.3.17-112.93.1 php53-bcmath-5.3.17-112.93.1 php53-bz2-5.3.17-112.93.1 php53-calendar-5.3.17-112.93.1 php53-ctype-5.3.17-112.93.1 php53-curl-5.3.17-112.93.1 php53-dba-5.3.17-112.93.1 php53-dom-5.3.17-112.93.1 php53-exif-5.3.17-112.93.1 php53-fastcgi-5.3.17-112.93.1 php53-fileinfo-5.3.17-112.93.1 php53-ftp-5.3.17-112.93.1 php53-gd-5.3.17-112.93.1 php53-gettext-5.3.17-112.93.1 php53-gmp-5.3.17-112.93.1 php53-iconv-5.3.17-112.93.1 php53-intl-5.3.17-112.93.1 php53-json-5.3.17-112.93.1 php53-ldap-5.3.17-112.93.1 php53-mbstring-5.3.17-112.93.1 php53-mcrypt-5.3.17-112.93.1 php53-mysql-5.3.17-112.93.1 php53-odbc-5.3.17-112.93.1 php53-openssl-5.3.17-112.93.1 php53-pcntl-5.3.17-112.93.1 php53-pdo-5.3.17-112.93.1 php53-pear-5.3.17-112.93.1 php53-pgsql-5.3.17-112.93.1 php53-pspell-5.3.17-112.93.1 php53-shmop-5.3.17-112.93.1 php53-snmp-5.3.17-112.93.1 php53-soap-5.3.17-112.93.1 php53-suhosin-5.3.17-112.93.1 php53-sysvmsg-5.3.17-112.93.1 php53-sysvsem-5.3.17-112.93.1 php53-sysvshm-5.3.17-112.93.1 php53-tokenizer-5.3.17-112.93.1 php53-wddx-5.3.17-112.93.1 php53-xmlreader-5.3.17-112.93.1 php53-xmlrpc-5.3.17-112.93.1 php53-xmlwriter-5.3.17-112.93.1 php53-xsl-5.3.17-112.93.1 php53-zip-5.3.17-112.93.1 php53-zlib-5.3.17-112.93.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): apache2-mod_php53-5.3.17-112.93.1 php53-5.3.17-112.93.1 php53-bcmath-5.3.17-112.93.1 php53-bz2-5.3.17-112.93.1 php53-calendar-5.3.17-112.93.1 php53-ctype-5.3.17-112.93.1 php53-curl-5.3.17-112.93.1 php53-dba-5.3.17-112.93.1 php53-dom-5.3.17-112.93.1 php53-exif-5.3.17-112.93.1 php53-fastcgi-5.3.17-112.93.1 php53-fileinfo-5.3.17-112.93.1 php53-ftp-5.3.17-112.93.1 php53-gd-5.3.17-112.93.1 php53-gettext-5.3.17-112.93.1 php53-gmp-5.3.17-112.93.1 php53-iconv-5.3.17-112.93.1 php53-intl-5.3.17-112.93.1 php53-json-5.3.17-112.93.1 php53-ldap-5.3.17-112.93.1 php53-mbstring-5.3.17-112.93.1 php53-mcrypt-5.3.17-112.93.1 php53-mysql-5.3.17-112.93.1 php53-odbc-5.3.17-112.93.1 php53-openssl-5.3.17-112.93.1 php53-pcntl-5.3.17-112.93.1 php53-pdo-5.3.17-112.93.1 php53-pear-5.3.17-112.93.1 php53-pgsql-5.3.17-112.93.1 php53-pspell-5.3.17-112.93.1 php53-shmop-5.3.17-112.93.1 php53-snmp-5.3.17-112.93.1 php53-soap-5.3.17-112.93.1 php53-suhosin-5.3.17-112.93.1 php53-sysvmsg-5.3.17-112.93.1 php53-sysvsem-5.3.17-112.93.1 php53-sysvshm-5.3.17-112.93.1 php53-tokenizer-5.3.17-112.93.1 php53-wddx-5.3.17-112.93.1 php53-xmlreader-5.3.17-112.93.1 php53-xmlrpc-5.3.17-112.93.1 php53-xmlwriter-5.3.17-112.93.1 php53-xsl-5.3.17-112.93.1 php53-zip-5.3.17-112.93.1 php53-zlib-5.3.17-112.93.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390x x86_64): php53-debuginfo-5.3.17-112.93.1 php53-debugsource-5.3.17-112.93.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): php53-debuginfo-5.3.17-112.93.1 php53-debugsource-5.3.17-112.93.1 References: https://www.suse.com/security/cve/CVE-2020-7070.html https://bugzilla.suse.com/1177352 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . Patch for php53 addresses critical vulnerability related to cookie manipulation. Discover more about this security advisory now.. SUSE Security Advisory, php53 Update, Cookie Overwrite Fix, Vulnerability Management, Important Patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 14, 2020 Important SuSE
100

SUSE: 2020:2894-1 Important: php5 Cookie Overwrite Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php5 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2894-1 Rating: important References: #1177352 Cross-References: CVE-2020-7070 Affected Products: SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php5 fixes the following issues: - CVE-2020-7070: Fixed an issue where percent-encoded cookies could have been used to overwrite existing prefixed cookie names (bsc#1177352). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2020-2894=1 Package List: - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php5-5.5.14-109.82.1 apache2-mod_php5-debuginfo-5.5.14-109.82.1 php5-5.5.14-109.82.1 php5-bcmath-5.5.14-109.82.1 php5-bcmath-debuginfo-5.5.14-109.82.1 php5-bz2-5.5.14-109.82.1 php5-bz2-debuginfo-5.5.14-109.82.1 php5-calendar-5.5.14-109.82.1 php5-calendar-debuginfo-5.5.14-109.82.1 php5-ctype-5.5.14-109.82.1 php5-ctype-debuginfo-5.5.14-109.82.1 php5-curl-5.5.14-109.82.1 php5-curl-debuginfo-5.5.14-109.82.1 php5-dba-5.5.14-109.82.1 php5-dba-debuginfo-5.5.14-109.82.1 php5-debuginfo-5.5.14-109.82.1 php5-debugsource-5.5.14-109.82.1 php5-dom-5.5.14-109.82.1 php5-dom-debuginfo-5.5.14-109.82.1 php5-enchant-5.5.14-109.82.1 php5-enchant-debuginfo-5.5.14-109.82.1 php5-exif-5.5.14-109.82.1 php5-exif-debuginfo-5.5.14-109.82.1 php5-fastcgi-5.5.14-109.82.1 php5-fastcgi-debuginfo-5.5.14-109.82.1 php5-fileinfo-5.5.14-109.82.1 php5-fileinfo-debuginfo-5.5.14-109.82.1 php5-fpm-5.5.14-109.82.1 php5-fpm-debuginfo-5.5.14-109.82.1 php5-ftp-5.5.14-109.82.1 php5-ftp-debuginfo-5.5.14-109.82.1 php5-gd-5.5.14-109.82.1 php5-gd-debuginfo-5.5.14-109.82.1 php5-gettext-5.5.14-109.82.1 php5-gettext-debuginfo-5.5.14-109.82.1 php5-gmp-5.5.14-109.82.1 php5-gmp-debuginfo-5.5.14-109.82.1 php5-iconv-5.5.14-109.82.1 php5-iconv-debuginfo-5.5.14-109.82.1 php5-imap-5.5.14-109.82.1 php5-imap-debuginfo-5.5.14-109.82.1 php5-intl-5.5.14-109.82.1 php5-intl-debuginfo-5.5.14-109.82.1 php5-json-5.5.14-109.82.1 php5-json-debuginfo-5.5.14-109.82.1 php5-ldap-5.5.14-109.82.1 php5-ldap-debuginfo-5.5.14-109.82.1 php5-mbstring-5.5.14-109.82.1 php5-mbstring-debuginfo-5.5.14-109.82.1 php5-mcrypt-5.5.14-109.82.1 php5-mcrypt-debuginfo-5.5.14-109.82.1 php5-mysql-5.5.14-109.82.1 php5-mysql-debuginfo-5.5.14-109.82.1 php5-odbc-5.5.14-109.82.1 php5-odbc-debuginfo-5.5.14-109.82.1 php5-opcache-5.5.14-109.82.1 php5-opcache-debuginfo-5.5.14-109.82.1 php5-openssl-5.5.14-109.82.1 php5-openssl-debuginfo-5.5.14-109.82.1 php5-pcntl-5.5.14-109.82.1 php5-pcntl-debuginfo-5.5.14-109.82.1 php5-pdo-5.5.14-109.82.1 php5-pdo-debuginfo-5.5.14-109.82.1 php5-pgsql-5.5.14-109.82.1 php5-pgsql-debuginfo-5.5.14-109.82.1 php5-phar-5.5.14-109.82.1 php5-phar-debuginfo-5.5.14-109.82.1 php5-posix-5.5.14-109.82.1 php5-posix-debuginfo-5.5.14-109.82.1 php5-pspell-5.5.14-109.82.1 php5-pspell-debuginfo-5.5.14-109.82.1 php5-shmop-5.5.14-109.82.1 php5-shmop-debuginfo-5.5.14-109.82.1 php5-snmp-5.5.14-109.82.1 php5-snmp-debuginfo-5.5.14-109.82.1 php5-soap-5.5.14-109.82.1 php5-soap-debuginfo-5.5.14-109.82.1 php5-sockets-5.5.14-109.82.1 php5-sockets-debuginfo-5.5.14-109.82.1 php5-sqlite-5.5.14-109.82.1 php5-sqlite-debuginfo-5.5.14-109.82.1 php5-suhosin-5.5.14-109.82.1 php5-suhosin-debuginfo-5.5.14-109.82.1 php5-sysvmsg-5.5.14-109.82.1 php5-sysvmsg-debuginfo-5.5.14-109.82.1 php5-sysvsem-5.5.14-109.82.1 php5-sysvsem-debuginfo-5.5.14-109.82.1 php5-sysvshm-5.5.14-109.82.1 php5-sysvshm-debuginfo-5.5.14-109.82.1 php5-tokenizer-5.5.14-109.82.1 php5-tokenizer-debuginfo-5.5.14-109.82.1 php5-wddx-5.5.14-109.82.1 php5-wddx-debuginfo-5.5.14-109.82.1 php5-xmlreader-5.5.14-109.82.1 php5-xmlreader-debuginfo-5.5.14-109.82.1 php5-xmlrpc-5.5.14-109.82.1 php5-xmlrpc-debuginfo-5.5.14-109.82.1 php5-xmlwriter-5.5.14-109.82.1 php5-xmlwriter-debuginfo-5.5.14-109.82.1 php5-xsl-5.5.14-109.82.1 php5-xsl-debuginfo-5.5.14-109.82.1 php5-zip-5.5.14-109.82.1 php5-zip-debuginfo-5.5.14-109.82.1 php5-zlib-5.5.14-109.82.1 php5-zlib-debuginfo-5.5.14-109.82.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php5-pear-5.5.14-109.82.1 References: https://www.suse.com/security/cve/CVE-2020-7070.html https://bugzilla.suse.com/1177352 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Update for php7 addresses a critical vulnerability in session management, boosting your system's defense.. SUSE Security Update, PHP Fix, Cookie Overwrite Issue, Important Patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 12, 2020 Important SuSE
100

SUSE: 2020:2678-1 Moderate: Rubygem-Rack Updates for Multiple Issues

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for rubygem-rack ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2678-1 Rating: moderate References: #1159548 #1172037 #1173351 Cross-References: CVE-2019-16782 CVE-2020-8161 CVE-2020-8184 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 7 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for rubygem-rack to version 1.6.13 fixes the following issues: - CVE-2020-8184: Fixed an issue where percent-encoded cookies could have been used to overwrite existing prefixed cookie names (bsc#1173351). - CVE-2020-8161: Fixed a directory traversal (bsc#1172037). - CVE-2019-16782: Fixed an information leak / session hijack vulnerability (bsc#1159548). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2020-2678=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-2678=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-2678=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): ruby2.1-rubygem-rack-1.6.13-3.8.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): ruby2.1-rubygem-rack-1.6.13-3.8.1 - SUSE OpenStack Cloud 7 (aarch64 s390x x86_64): ruby2.1-rubygem-rack-1.6.13-3.8.1 References: https://www.suse.com/security/cve/CVE-2019-16782.html https://www.suse.com/security/cve/CVE-2020-8161.html https://www.suse.com/security/cve/CVE-2020-8184.html https://bugzilla.suse.com/1159548 https://bugzilla.suse.com/1172037 https://bugzilla.suse.com/1173351 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . An SUSE patch resolves vulnerabilities in rubygem-rack, effectively mitigating three security risks.. rubygem-rack update, SUSE security patch, moderate vulnerability fix. . LinuxSecurity.com Team

Calendar 2 Sep 18, 2020 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here