Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
100

SUSE: 2018:1130-1 Important: Corosync Integer Overflow Critical Threat

An update that solves one vulnerability and has three fixes is now available.. SUSE Security Update: Security update for corosync ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1130-1 Rating: important References: #1066585 #1083030 #1083561 #1089346 Cross-References: CVE-2018-1084 Affected Products: SUSE Linux Enterprise High Availability 12-SP2 ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for corosync provides the following fixes: - CVE-2018-1084: Integer overflow in totemcrypto:authenticate_nss_2_3() could lead to command execution (bsc#1089346) - Providing an empty uid or gid results in coroparse adding uid 0. (bsc#1066585) - Fix a problem that was causing corosync memory to increase on ring breakup. (bsc#1083030) - Fix a problem with configuration file incompatibilities that was causing corosync to not work after upgrading from SLE-11-SP4-HA to SLE-12/15-HA. (bsc#1083561) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise High Availability 12-SP2: zypper in -t patch SUSE-SLE-HA-12-SP2-2018-775=1 Package List: - SUSE Linux Enterprise High Availability 12-SP2 (ppc64le s390x x86_64): corosync-2.3.5-6.23.1 corosync-debuginfo-2.3.5-6.23.1 corosync-debugsource-2.3.5-6.23.1 libcorosync4-2.3.5-6.23.1 libcorosync4-debuginfo-2.3.5-6.23.1 References: https://www.suse.com/security/cve/CVE-2018-1084.html https://bugzilla.suse.com/1066585 https://bugzilla.suse.com/1083030 https://bugzilla.suse.com/1083561 https://bugzilla.suse.com/1089346 -- . This patch addresses asignificant vulnerability in corosync, improving both security and reliability for SUSE Enterprise customers.. SUSE Linux, corosync fix, integer overflow, security update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 02, 2018 Important SuSE
100

SUSE: 2018:1121-1 Important: Corosync Command Execution Threat

An update that solves one vulnerability and has two fixes is now available.. SUSE Security Update: Security update for corosync ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1121-1 Rating: important References: #1066585 #1083561 #1089346 Cross-References: CVE-2018-1084 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise High Availability 12-SP3 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for corosync fixes the following issue: - CVE-2018-1084: Integer overflow in totemcrypto:authenticate_nss_2_3() could lead to command execution (bsc#1089346) - Providing an empty uid or gid results in coroparse adding uid 0. (bsc#1066585) - Fix a problem with configuration file incompatibilities that was causing corosync to not work after upgrading from SLE-11-SP4-HA to SLE-12/15-HA. (bsc#1083561) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2018-771=1 - SUSE Linux Enterprise High Availability 12-SP3: zypper in -t patch SUSE-SLE-HA-12-SP3-2018-771=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): corosync-debuginfo-2.3.6-9.13.1 corosync-debugsource-2.3.6-9.13.1 libcorosync-devel-2.3.6-9.13.1 - SUSE Linux Enterprise High Availability 12-SP3 (ppc64le s390x x86_64): corosync-2.3.6-9.13.1 corosync-debuginfo-2.3.6-9.13.1 corosync-debugsource-2.3.6-9.13.1 libcorosync4-2.3.6-9.13.1 libcorosync4-debuginfo-2.3.6-9.13.1 References: https://www.suse.com/security/cve/CVE-2018-1084.html https://bugzilla.suse.com/1066585 https://bugzilla.suse.com/1083561 https://bugzilla.suse.com/1089346 -- . SUSE Security Notice: Update for pacemaker mitigates vulnerability to command execution and provides crucial system enhancements.. SUSE Security Update, Corosync Fix, Command Execution Risk, Integer Overflow Issue. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 02, 2018 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here