Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 595
Alerts This Week
Warning Icon 1 595

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 9 articles for you...
100

SUSE: 2025:20197-1 moderate update resolves git credential issue

* bsc#1235600 * bsc#1235601 Cross-References: * CVE-2024-50349 . # Security update for git Announcement ID: SUSE-SU-2025:20197-1 Release Date: 2025-04-22T14:06:49Z Rating: moderate References: * bsc#1235600 * bsc#1235601 Cross-References: * CVE-2024-50349 * CVE-2024-52006 CVSS scores: * CVE-2024-50349 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2024-50349 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-52006 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2024-52006 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for git fixes the following issues: * CVE-2024-50349: Passwords for trusted sites could be sent to untrusted sites (bsc#1235600). * CVE-2024-52006: Carriage Returns via the credential protocol to credential helpers (bsc#1235601). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-290=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * git-core-debuginfo-2.45.1-2.1 * git-debugsource-2.45.1-2.1 * git-core-2.45.1-2.1 * git-2.45.1-2.1 * git-debuginfo-2.45.1-2.1 * perl-Git-2.45.1-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-50349.html * https://www.suse.com/security/cve/CVE-2024-52006.html * https://bugzilla.suse.com/show_bug.cgi?id=1235600 *https://bugzilla.suse.com/show_bug.cgi?id=1235601 . Enhance Git credential management for SUSE Linux Micro 6.0 by implementing more robust security measures.. SUSE Linux Micro, git security, credential protocol, software update. . LinuxSecurity.com Team

Calendar%202 Jun 04, 2025 SuSE
172

Ubuntu 20.04 LTS USN-7207-2 Critical: Git Credential Handling Problem

Several security issues were fixed in Git.. ========================================================================== Ubuntu Security Notice USN-7207-2 February 27, 2025 git vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Git. Software Description: - git: fast, scalable, distributed revision control system Details: USN-7207-1 fixed vulnerabilities in Git. This update provides the corresponding updates for Ubuntu 20.04 LTS. Original advisory details: It was discovered that Git incorrectly handled certain URLs when asking for credentials. An attacker could possibly use this issue to mislead the user into typing passwords for trusted sites that would then be sent to untrusted sites instead. (CVE-2024-50349) It was discovered that git incorrectly handled line endings when using credential helpers. (CVE-2024-52006) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS git 1:2.25.1-1ubuntu3.14 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7207-2 https://ubuntu.com/security/notices/USN-7207-1 CVE-2024-50349, CVE-2024-52006 Package Information: https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.14 . The Ubuntu Security Notice USN-7208-3 outlines critical patches for vulnerabilities in Git impacting Ubuntu 22.04 LTS.. Ubuntu Git Update, Security Fix, Credential Management, Threat Assessment. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 27, 2025 Critical Ubuntu
100

SUSE: 2025:0529-1 Moderate: Addressing Database Credential Risks

* bsc#1229079 * bsc#1229104 * bsc#1231497 * bsc#1231568 * bsc#1231759 . # Security update for SUSE Manager Client Tools MU 5.0.3 Announcement ID: SUSE-SU-2025:0529-1 Release Date: 2025-02-14T07:19:47Z Rating: moderate References: * bsc#1229079 * bsc#1229104 * bsc#1231497 * bsc#1231568 * bsc#1231759 * bsc#1232575 * bsc#1232769 * bsc#1232817 * bsc#1233202 * bsc#1233279 * bsc#1233630 * bsc#1233660 * bsc#1234123 * jsc#MSQA-914 Cross-References: * CVE-2024-22037 CVSS scores: * CVE-2024-22037 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L * CVE-2024-22037 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-22037 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-22037 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Manager Client Tools for Debian 12 An update that solves one vulnerability, contains one feature and has 12 security fixes can now be installed. ## Description: This update fixes the following issues: spacecmd was updated to version 5.0.11-0: * Updated translation strings uyuni-tools was updated from version 0.1.23-0 to 0.1.27-0: * Security issues fixed: * CVE-2024-22037: Use podman secret to store the database credentials (bsc#1231497) * Other changes and bugs fixed: * Version 0.1.27-0 * Bump the default image tag to 5.0.3 * IsInstalled function fix * Run systemctl daemon-reload after changing the container image config (bsc#1233279) * Coco-replicas-upgrade * Persist search server indexes (bsc#1231759) * Sync deletes files during migration (bsc#1233660) * Ignore coco and hub images when applying PTF if they are not ailable (bsc#1229079) * Add --registry back to mgrpxy (bsc#1233202) * Only add java.hostname on migrated server if notpresent * Consider the configuration file to detect the coco or hub api images should be pulled (bsc#1229104) * Only raise an error if cloudguestregistryauth fails for PAYG (bsc#1233630) * Add registry.suse.com login to mgradm upgrade podman list (bsc#1234123) * Version 0.1.26-0 * Ignore all zypper caches during migration (bsc#1232769) * Use the uyuni network for all podman containers (bsc#1232817) * Version 0.1.25-0 * Don't migrate enabled systemd services, recreate them (bsc#1232575) * Version 0.1.24-0 * Redact JSESSIONID and pxt-session-cookie values from logs and console output (bsc#1231568) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Client Tools for Debian 12 zypper in -t patch SUSE-Debian-12-CLIENT-TOOLS-x86_64-2025-529=1 ## Package List: * SUSE Manager Client Tools for Debian 12 (all) * mgrctl-fish-completion-0.1.28-2.16.1 * mgrctl-bash-completion-0.1.28-2.16.1 * spacecmd-5.0.11-3.26.1 * mgrctl-zsh-completion-0.1.28-2.16.1 * SUSE Manager Client Tools for Debian 12 (amd64) * mgrctl-0.1.28-2.16.1 ## References: * https://www.suse.com/security/cve/CVE-2024-22037.html * https://bugzilla.suse.com/show_bug.cgi?id=1229079 * https://bugzilla.suse.com/show_bug.cgi?id=1229104 * https://bugzilla.suse.com/show_bug.cgi?id=1231497 * https://bugzilla.suse.com/show_bug.cgi?id=1231568 * https://bugzilla.suse.com/show_bug.cgi?id=1231759 * https://bugzilla.suse.com/show_bug.cgi?id=1232575 * https://bugzilla.suse.com/show_bug.cgi?id=1232769 * https://bugzilla.suse.com/show_bug.cgi?id=1232817 * https://bugzilla.suse.com/show_bug.cgi?id=1233202 * https://bugzilla.suse.com/show_bug.cgi?id=1233279 * https://bugzilla.suse.com/show_bug.cgi?id=1233630 * https://bugzilla.suse.com/show_bug.cgi?id=1233660 *https://bugzilla.suse.com/show_bug.cgi?id=1234123 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FMSQA-914&page_caps=&user_role= . SUSE Manager Client Tools version 5.0.3 release tackles security vulnerabilities, especially in credential management. Upgrade today!. SUSE Manager update, security advisory, Debian tools, moderate severity. . LinuxSecurity.com Team

Calendar%202 Feb 14, 2025 SuSE
202

openSUSE: 2025:0144-1 important: git credential leak issue

An update that solves two vulnerabilities can now be installed.. # Security update for git Announcement ID: SUSE-SU-2025:0144-1 Release Date: 2025-01-16T13:30:38Z Rating: important References: * bsc#1235600 * bsc#1235601 Cross-References: * CVE-2024-50349 * CVE-2024-52006 CVSS scores: * CVE-2024-50349 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2024-50349 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-52006 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2024-52006 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE ManagerServer 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for git fixes the following issues: * CVE-2024-50349: Passwords for trusted sites could be sent to untrusted sites (bsc#1235600). * CVE-2024-52006: Carriage Returns via the credential protocol to credential helpers (bsc#1235601). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-144=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-144=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-144=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-144=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-144=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-144=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-144=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-144=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-144=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-144=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-144=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-144=1 * SUSE Linux Enterprise Server forSAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-144=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-144=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2025-144=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-144=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-144=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-credential-libsecret-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-credential-libsecret-debuginfo-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 * git-credential-gnome-keyring-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-credential-gnome-keyring-debuginfo-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * git-p4-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * openSUSE Leap 15.3 (noarch) * git-doc-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 *git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * git-doc-2.35.3-150300.10.48.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 * git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * git-doc-2.35.3-150300.10.48.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 * git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * SUSE Linux Enterprise HighPerformance Computing LTSS 15 SP4 (noarch) * git-doc-2.35.3-150300.10.48.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 * git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * git-doc-2.35.3-150300.10.48.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 * git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * git-doc-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 * git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 *git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * git-doc-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 * git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * git-doc-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 * git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * git-doc-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 * git-2.35.3-150300.10.48.1 *perl-Git-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * git-doc-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 * git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * git-doc-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 * git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) *git-doc-2.35.3-150300.10.48.1 * SUSE Manager Proxy 4.3 (x86_64) * git-debuginfo-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * git-debuginfo-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * git-debuginfo-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * git-web-2.35.3-150300.10.48.1 * git-email-2.35.3-150300.10.48.1 * git-gui-2.35.3-150300.10.48.1 * git-2.35.3-150300.10.48.1 * perl-Git-2.35.3-150300.10.48.1 * git-daemon-2.35.3-150300.10.48.1 * git-debugsource-2.35.3-150300.10.48.1 * git-core-2.35.3-150300.10.48.1 * git-svn-2.35.3-150300.10.48.1 * git-debuginfo-2.35.3-150300.10.48.1 * git-core-debuginfo-2.35.3-150300.10.48.1 * git-cvs-2.35.3-150300.10.48.1 * git-arch-2.35.3-150300.10.48.1 * gitk-2.35.3-150300.10.48.1 * git-daemon-debuginfo-2.35.3-150300.10.48.1 * SUSE Enterprise Storage 7.1 (noarch) * git-doc-2.35.3-150300.10.48.1 ## References: * https://www.suse.com/security/cve/CVE-2024-50349.html * https://www.suse.com/security/cve/CVE-2024-52006.html * https://bugzilla.suse.com/show_bug.cgi?id=1235600 * https://bugzilla.suse.com/show_bug.cgi?id=1235601 . A crucial Git security patch addressing credential exposure on openSUSE has been released. Users must update their systems swiftly to avoid breaches. SUSE update, git advisory, credential leak, software patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 16, 2025 Important OpenSUSE
202

openSUSE Leap 15.6: 2025:0116-1 important: git credential issues

An update that solves two vulnerabilities can now be installed.. # Security update for git Announcement ID: SUSE-SU-2025:0116-1 Release Date: 2025-01-15T08:32:46Z Rating: important References: * bsc#1235600 * bsc#1235601 Cross-References: * CVE-2024-50349 * CVE-2024-52006 CVSS scores: * CVE-2024-50349 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-52006 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP6 * Development Tools Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for git fixes the following issues: * CVE-2024-50349: Passwords for trusted sites could be sent to untrusted sites (bsc#1235600). * CVE-2024-52006: Carriage Returns via the credential protocol to credential helpers (bsc#1235601). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-116=1 openSUSE-SLE-15.6-2025-116=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-116=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-116=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * perl-Git-2.43.0-150600.3.9.1 * gitk-2.43.0-150600.3.9.1 *git-daemon-2.43.0-150600.3.9.1 * git-credential-libsecret-2.43.0-150600.3.9.1 * git-credential-libsecret-debuginfo-2.43.0-150600.3.9.1 * git-core-debuginfo-2.43.0-150600.3.9.1 * git-email-2.43.0-150600.3.9.1 * git-debuginfo-2.43.0-150600.3.9.1 * git-web-2.43.0-150600.3.9.1 * git-gui-2.43.0-150600.3.9.1 * git-2.43.0-150600.3.9.1 * git-arch-2.43.0-150600.3.9.1 * git-p4-2.43.0-150600.3.9.1 * git-cvs-2.43.0-150600.3.9.1 * git-core-2.43.0-150600.3.9.1 * git-daemon-debuginfo-2.43.0-150600.3.9.1 * git-svn-2.43.0-150600.3.9.1 * git-debugsource-2.43.0-150600.3.9.1 * openSUSE Leap 15.6 (noarch) * git-doc-2.43.0-150600.3.9.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * git-core-debuginfo-2.43.0-150600.3.9.1 * git-core-2.43.0-150600.3.9.1 * git-debuginfo-2.43.0-150600.3.9.1 * git-debugsource-2.43.0-150600.3.9.1 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * perl-Git-2.43.0-150600.3.9.1 * gitk-2.43.0-150600.3.9.1 * git-daemon-2.43.0-150600.3.9.1 * git-email-2.43.0-150600.3.9.1 * git-debuginfo-2.43.0-150600.3.9.1 * git-web-2.43.0-150600.3.9.1 * git-gui-2.43.0-150600.3.9.1 * git-2.43.0-150600.3.9.1 * git-arch-2.43.0-150600.3.9.1 * git-cvs-2.43.0-150600.3.9.1 * git-daemon-debuginfo-2.43.0-150600.3.9.1 * git-svn-2.43.0-150600.3.9.1 * git-debugsource-2.43.0-150600.3.9.1 * Development Tools Module 15-SP6 (noarch) * git-doc-2.43.0-150600.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-50349.html * https://www.suse.com/security/cve/CVE-2024-52006.html * https://bugzilla.suse.com/show_bug.cgi?id=1235600 * https://bugzilla.suse.com/show_bug.cgi?id=1235601 . Recent enhancements in git have addressed several vulnerabilities impacting various SUSE offerings, promoting more secure development methodologies.. openSUSE, git update, security patch, software vulnerabilities, advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 15, 2025 Important OpenSUSE
89

Fedora 38: 2023-185f3e8ad7 critical: default access keys in qbittorrent

- Update. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-185f3e8ad7 2023-11-30 03:33:42.162769 -------------------------------------------------------------------------------- Name : qbittorrent Product : Fedora 38 Version : 4.6.1 Release : 1.fc38 URL : https://www.qbittorrent.org Summary : A Bittorrent Client Description : A Bittorrent client using rb_libtorrent and a Qt6 Graphical User Interface. It aims to be as fast as possible and to provide multi-OS, unicode support. -------------------------------------------------------------------------------- Update Information: - Update -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 21 2023 Leigh Scott - 1:4.6.1-1 - Update to 4.6.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2250750 - qbittorrent-4.6.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2250750 [ 2 ] Bug #2251628 - CVE-2023-30801 qbittorrent: default credentials allowed by default [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2251628 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-185f3e8ad7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Ubuntu Security Notice concerning transmission addresses default password flaw in version 3.0.4 update.. qbittorrent update,Fedora 38,software patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 30, 2023 Critical Fedora
98

Red Hat Linux 7.2 RHSA-2001:132-04 Critical: PAM Credentials Issue

New util-linux packages are available that fix a problem with /bin/login'sPAM implementation. This could, in some non-default setups, cause users toreceive credentials of other users. It is recommended that all usersupdate to the fixed packages. . --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: New util-linux packages available to fix /bin/login pam problem Advisory ID: RHSA-2001:132-04 Issue date: 2001-10-11 Updated on: 2001-10-16 Product: Red Hat Linux Keywords: login pam pam_limits Cross references: Obsoletes: RHSA-2001:095-04 ---------------------------------------------------------------------1. Topic: New util-linux packages are available that fix a problem with /bin/login's PAM implementation. This could, in some non-default setups, cause users to receive credentials of other users. It is recommended that all users update to the fixed packages. 2001-10-22: Packages are now available for Red Hat Linux 7.2. Notably, these packages also fix the problem noted in RHSA-2001:095-04 (vipw incorrectly setting permissions on some files) - this bug was accidentally reintroduced in Red Hat Linux 7.2. 2. Relevant releases/architectures: Red Hat Linux 7.1 - alpha, i386, ia64 Red Hat Linux 7.2 - i386 3. Problem description: A problem existed in /bin/login's PAM implementation; it stored the value of a static pwent buffer across PAM calls; when used with some PAM modules in non-default configuration (such as pam_limits), it would overwrite the buffer, causing a user to get credentials of another user. Thanks go to Tarhon-Onu Victor for bringing the problem to our attention, and to Olaf Kirch for providing the patch. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh[filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 51646 - pam limits drops other user privileges 6. RPMs required: Red Hat Linux 7.1: SRPMS: alpha: i386: ia64: Red Hat Linux 7.2: SRPMS: i386: 7. Verification: MD5 sum Package Name --------------------------------------------------------------------------db33b22f50978471a25fd5cc973f8f54 7.1/en/os/SRPMS/util-linux-2.11f-11.7.1.src.rpm d55f6ec42e3c0268f2ab4decb24deb53 7.1/en/os/alpha/util-linux-2.11f-11.7.1.alpha.rpm 2bf1db1cadc50f783220f70aa2b7a09c 7.1/en/os/i386/util-linux-2.11f-11.7.1.i386.rpm 568c4ec61cb9cc0ebd6313fb14d0419c 7.1/en/os/ia64/util-linux-2.11f-11.7.1.ia64.rpm 3b5448a60fa6cb5580eb690a303827a5 7.2/en/os/SRPMS/util-linux-2.11f-12.src.rpm c0f329c070e416fbb20c97670199d3fe 7.2/en/os/i386/util-linux-2.11f-12.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000, 2001 Red Hat, Inc. . The latest changes to util-linux tackle a security flaw related toincreased permissions in the PAM features of /bin/login on CentOS Linux systems.. Red Hat Linux,PAM,util-linux,elevated privileges,security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 08, 2023 Critical Red Hat
98

RedHat OpenStack Platform 15: RHSA-2020-3102-01 Important Security Update

An update for openstack-keystone is now available for Red Hat OpenStack Platform 15 (Stein). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: openstack-keystone security update Advisory ID: RHSA-2020:3102-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2020:3102 Issue date: 2020-07-22 CVE Names: CVE-2020-12689 CVE-2020-12690 CVE-2020-12691 CVE-2020-12692 ==================================================================== 1. Summary: An update for openstack-keystone is now available for Red Hat OpenStack Platform 15 (Stein). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 15.0 - noarch 3. Description: The OpenStack Identity service (keystone) authenticates and authorizes OpenStack users by keeping track of users and their permitted activities. The Identity service supports multiple forms of authentication, including user name and password credentials, token-based systems, and AWS-style logins. Security Fix(es): * EC2 and credential endpoints are not protected from a scoped context (CVE-2020-12689) * OAuth1 request token authorize silently ignores roles parameter (CVE-2020-12690) * Credentials endpoint policy logic allows changing credential owner and target project ID (CVE-2020-12691) * failure to check signature TTL of the EC2 credential auth method (CVE-2020-12692) For more details about the security issue(s), including the impact, aCVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1830384 - CVE-2020-12691 openstack-keystone: Credentials endpoint policy logic allows changing credential owner and target project ID 1830395 - CVE-2020-12690 openstack-keystone: OAuth1 request token authorize silently ignores roles parameter 1830396 - CVE-2020-12689 openstack-keystone: EC2 and credential endpoints are not protected from a scoped context 1833164 - CVE-2020-12692 openstack-keystone: failure to check signature TTL of the EC2 credential auth method 6. Package List: Red Hat OpenStack Platform 15.0: Source: openstack-keystone-15.0.1-0.20200512110437.95b2bbe.el8ost.src.rpm noarch: openstack-keystone-15.0.1-0.20200512110437.95b2bbe.el8ost.noarch.rpm python3-keystone-15.0.1-0.20200512110437.95b2bbe.el8ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-12689 https://access.redhat.com/security/cve/CVE-2020-12690 https://access.redhat.com/security/cve/CVE-2020-12691 https://access.redhat.com/security/cve/CVE-2020-12692 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXxg0gNzjgjWX9erEAQhacw//eB76nntWll2GcgSaF0S2vcDvP9tvtdHl QXR5nWqf7mpxppA2GKc+tepasiIXRtYdrQgZWUMjlqMjddp9fwvuYJfrDHsNegn8 z2JMSrshsJUUUsc22sHTrmeo7aOn3UNEZFmUto5G21GD7rHNPavCFtzYxSeSpBlL EjFTAGP8JpBchAEtXjHolo8eND9xP/gdznceC5/q8MRSho6posJuUCi0EQ4a3ZAI BbAZKPyYv8DPQBJThLyzgKgo/kwXavGUMJLiLB+AMXS2xllWVRVHGm16F+2Q2Ao4 2u0v+NNrz0zHAZW7SSHQXchU0Yq6wQYvaOsK+h4wudQsFaNbBF8dRj9R8RnhVjuG 7n/PpzptTrLbky5ZSJ9lI9rE1YdRmWjYguReajI0RAF/Q523yDni/CuQ14QM9Bt2 aXH98qH4+2kkAV1ldMb1X1eVMuCffvqiUfDMLcFxaMSQKh3RpEsId+mps9fKK3/v TwcDParcf04bBeokroWy+wfzfLyuPyyfdsAoOR3f3EVhislXilskzKxw6qU578QY soGE7JAdd2iMhKUf88Eyd39eZOZJ6kvkINJNkSjtsE8HDuwmpGZQ+vGA/x1dNCSz kcfbrWmPFOZZGRVvGBfcVkUn/TCOZmiMGbia0opSZVXlWgGZX9iM0fNJNKesLoSJ Dta1AgjMe0c=Kqzs -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A significant security notice has emerged for openstack-keystone, impacting Red Hat OpenStack Platform version 15. Comprehensive remedial measures are outlined to address this issue.. Openstack Keystone, Security Advisory, Red Hat OpenStack, Important Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 22, 2020 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200