Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Two vulnerabilities were discovered in phpseclib, a PHP Secure Communications Library. CVE-2023-52892 Some characters in Subject Alternative Name fields in TLS certificates were incorrectly allowed to have a special meaning. Debian LTS Advisory DLA-4518-1
* bsc#1244039 * bsc#1246104 Cross-References: * CVE-2024-47081 . # Security update for python-requests Announcement ID: SUSE-SU-2025:20531-1 Release Date: 2025-07-24T11:31:28Z Rating: important References: * bsc#1244039 * bsc#1246104 Cross-References: * CVE-2024-47081 CVSS scores: * CVE-2024-47081 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-47081 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-47081 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for python-requests fixes the following issues: * Avoid problems with certificate caching in sslcontext. (bsc#1246104, gh#psf/requests#6767) Update to 2.32.4: * CVE-2024-47081 Fixed an issue where a maliciously crafted URL and trusted environment will retrieve credentials for the wrong hostname/machine from a netrc file (gh#psf/requests#6965, bsc#1244039) * Numerous documentation improvements * Added support for pypy 3.11 for Linux and macOS. * Dropped support for pypy 3.9 following its end of support. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-189=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * python311-requests-2.32.4-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-47081.html * https://bugzilla.suse.com/show_bug.cgi?id=1244039 * https://bugzilla.suse.com/show_bug.cgi?id=1246104 . Crucial update in python-requests for SUSE addresses CVE-2024-47081, remedies credential leakage vulnerabilities and bolsters overall security.. python requests security patch, SUSE update, CVE-2024-47081 fix. .Severity: Important. LinuxSecurity.com Team
Several vulnerabilities were discovered in OpenAFS, an implementation of the AFS distributed filesystem, which may result in theft of credentials in Unix client PAGs (CVE-2024-10394), fileserver crashes and information . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4168-1
Several vulnerabilities were discovered in OpenAFS, an implementation of the AFS distributed filesystem, which may result in theft of credentials in Unix client PAGs (CVE-2024-10394), fileserver crashes and information leak on StoreACL/FetchACL (CVE-2024-10396) or buffer overflows in XDR . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5842-1
It was discovered that there was a potential credential stealing attack in epiphany-browser, the default GNOME web browser. When using a sandboxed Content Security Policy (CSP) or the HTML . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3423-1
The package putty before version 0.76-1 is vulnerable to content spoofing. . Arch Linux Security Advisory ASA-202107-37 ========================================= Severity: Low Date : 2021-07-20 CVE-ID : CVE-2021-36367 Package : putty Type : content spoofing Remote : Yes Link : https://security.archlinux.org/AVG-2143 Summary ====== The package putty before version 0.76-1 is vulnerable to content spoofing. Resolution ========= Upgrade to 0.76-1. # pacman -Syu "putty> =0.76-1" The problem has been fixed upstream in version 0.76. Workaround ========= None. Description ========== PuTTY before version 0.76 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user). Impact ===== A remote SSH server could present a spoofed authentication prompt. References ========= https://security.archlinux.org/CVE-2021-36367 . Versions of PuTTY prior to 0.76-1 on Arch Linux have a security vulnerability related to content spoofing, which may compromise user credentials.. Putty Security Advisory, Arch Linux Security, Content Spoofing, Credential Theft. . Severity: Low. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . openSUSE Security Update: Security update for dovecot23 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0920-1 Rating: important References: #1187418 #1187419 Cross-References: CVE-2021-29157 CVE-2021-33515 CVSS scores: CVE-2021-29157 (SUSE): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2021-33515 (SUSE): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for dovecot23 fixes the following issues: - CVE-2021-29157: Local attacker can login as any user and access their emails (bsc#1187418) - CVE-2021-33515: Attacker can potentially steal user credentials and mails (bsc#1187419) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-920=1 Package List: - openSUSE Leap 15.2 (x86_64): dovecot23-2.3.11.3-lp152.2.9.1 dovecot23-backend-mysql-2.3.11.3-lp152.2.9.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-backend-pgsql-2.3.11.3-lp152.2.9.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-backend-sqlite-2.3.11.3-lp152.2.9.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-debugsource-2.3.11.3-lp152.2.9.1 dovecot23-devel-2.3.11.3-lp152.2.9.1 dovecot23-fts-2.3.11.3-lp152.2.9.1 dovecot23-fts-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-fts-lucene-2.3.11.3-lp152.2.9.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-fts-solr-2.3.11.3-lp152.2.9.1 dovecot23-fts-solr-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-fts-squat-2.3.11.3-lp152.2.9.1 dovecot23-fts-squat-debuginfo-2.3.11.3-lp152.2.9.1 References: https://www.suse.com/security/cve/CVE-2021-29157.html https://www.suse.com/security/cve/CVE-2021-33515.html https://bugzilla.suse.com/1187418 https://bugzilla.suse.com/1187419 . Addresses critical security flaws in Dovecot on openSUSE Leap 15.2. Upgrade your system to enhance email safety immediately.. openSUSE Security,dovecot update,email security,remote access,credential issues. . Severity: Important. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for dovecot23 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2124-1 Rating: important References: #1187418 #1187419 Cross-References: CVE-2021-29157 CVE-2021-33515 CVSS scores: CVE-2021-29157 (SUSE): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2021-33515 (SUSE): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: SUSE Manager Server 4.0 SUSE Manager Retail Branch Server 4.0 SUSE Manager Proxy 4.0 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Enterprise Storage 6 SUSE CaaS Platform 4.0 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for dovecot23 fixes the following issues: - CVE-2021-29157: Local attacker can login as any user and access their emails (bsc#1187418) - CVE-2021-33515: Attacker can potentially steal user credentials and mails (bsc#1187419) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.0-2021-2124=1 - SUSE Manager Retail Branch Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.0-2021-2124=1 -SUSE Manager Proxy 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.0-2021-2124=1 - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2021-2124=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2021-2124=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2021-2124=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2021-2124=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2021-2124=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2021-2124=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Manager Server 4.0 (ppc64le s390x x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Manager Retail Branch Server 4.0 (x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Manager Proxy 4.0 (x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE CaaS Platform 4.0 (x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 References: https://www.suse.com/security/cve/CVE-2021-29157.html https://www.suse.com/security/cve/CVE-2021-33515.html https://bugzilla.suse.com/1187418 https://bugzilla.suse.com/1187419 . New update released for dovecot23 in SUSE resolving two vulnerabilities: local login and password exposure. Review your systems immediately.. SUSE Linux,Dovecot23 Update,Security Fixes,Access Risk. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.