Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
197

Debian 11 phpseclib TLS Confusion and Padding Oracle Attack Overview

Two vulnerabilities were discovered in phpseclib, a PHP Secure Communications Library. CVE-2023-52892 Some characters in Subject Alternative Name fields in TLS certificates were incorrectly allowed to have a special meaning. Debian LTS Advisory DLA-4518-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta March 30, 2026 https://wiki.debian.org/LTS Package : phpseclib Version : 1.0.19-3+deb11u3 CVE ID : CVE-2023-52892 CVE-2026-32935 Two vulnerabilities were discovered in phpseclib, a PHP Secure Communications Library. CVE-2023-52892 Some characters in Subject Alternative Name fields in TLS certificates were incorrectly allowed to have a special meaning in regular expressions, leading to name confusion in X.509 certificate host verification. CVE-2026-32935 The AES-CBC implementation was susceptible to a padding oracle timing attack due to the use of a short-circuiting logical operator in the unpadding function. For Debian 11 bullseye, these problems have been fixed in version 1.0.19-3+deb11u3. We recommend that you upgrade your phpseclib packages. For the detailed security status of phpseclib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/phpseclib Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Discover vulnerabilities in phpseclib affecting TLS verification and AES-CBC implementation. Upgrade recommended now.. Debian Security, phpseclib, TLS Certificate, AES-CBC, Padding Oracle Attack. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 30, 2026 Important Debian LTS
100

SUSE Linux Micro 6.1: Critical Python-Requests Update for CVE-2024-47081

* bsc#1244039 * bsc#1246104 Cross-References: * CVE-2024-47081 . # Security update for python-requests Announcement ID: SUSE-SU-2025:20531-1 Release Date: 2025-07-24T11:31:28Z Rating: important References: * bsc#1244039 * bsc#1246104 Cross-References: * CVE-2024-47081 CVSS scores: * CVE-2024-47081 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-47081 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-47081 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for python-requests fixes the following issues: * Avoid problems with certificate caching in sslcontext. (bsc#1246104, gh#psf/requests#6767) Update to 2.32.4: * CVE-2024-47081 Fixed an issue where a maliciously crafted URL and trusted environment will retrieve credentials for the wrong hostname/machine from a netrc file (gh#psf/requests#6965, bsc#1244039) * Numerous documentation improvements * Added support for pypy 3.11 for Linux and macOS. * Dropped support for pypy 3.9 following its end of support. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-189=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * python311-requests-2.32.4-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-47081.html * https://bugzilla.suse.com/show_bug.cgi?id=1244039 * https://bugzilla.suse.com/show_bug.cgi?id=1246104 . Crucial update in python-requests for SUSE addresses CVE-2024-47081, remedies credential leakage vulnerabilities and bolsters overall security.. python requests security patch, SUSE update, CVE-2024-47081 fix. .Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 05, 2025 Important SuSE
197

Debian 11: DLA-4168-1 critical: openafs credential theft and DoS

Several vulnerabilities were discovered in OpenAFS, an implementation of the AFS distributed filesystem, which may result in theft of credentials in Unix client PAGs (CVE-2024-10394), fileserver crashes and information . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4168-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz May 17, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : openafs Version : 1.8.6-5+deb11u1 CVE ID : CVE-2024-10394 CVE-2024-10396 CVE-2024-10397 Debian Bug : Several vulnerabilities were discovered in OpenAFS, an implementation of the AFS distributed filesystem, which may result in theft of credentials in Unix client PAGs (CVE-2024-10394), fileserver crashes and information leak on StoreACL/FetchACL (CVE-2024-10396) or buffer overflows in XDR responses resulting in denial of service and potentially code execution (CVE-2024-10397). For Debian 11 bullseye, these problems have been fixed in version 1.8.6-5+deb11u1. We recommend that you upgrade your openafs packages. For the detailed security status of openafs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openafs Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS releases new OpenAFS patch to fix vulnerabilities related to credential leakage and service disruption. Updating is advised!. OpenAFS security, Debian update, credentials theft, denial of service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 17, 2025 Critical Debian LTS
87

Debian: DSA-5842-1 critical: OpenAFS denial of service risks

Several vulnerabilities were discovered in OpenAFS, an implementation of the AFS distributed filesystem, which may result in theft of credentials in Unix client PAGs (CVE-2024-10394), fileserver crashes and information leak on StoreACL/FetchACL (CVE-2024-10396) or buffer overflows in XDR . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5842-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso January 11, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openafs CVE ID : CVE-2024-10394 CVE-2024-10396 CVE-2024-10397 Debian Bug : 1087406 1087407 Several vulnerabilities were discovered in OpenAFS, an implementation of the AFS distributed filesystem, which may result in theft of credentials in Unix client PAGs (CVE-2024-10394), fileserver crashes and information leak on StoreACL/FetchACL (CVE-2024-10396) or buffer overflows in XDR responses resulting in denial of service and potentially code execution (CVE-2024-10397). For the stable distribution (bookworm), these problems have been fixed in version 1.8.9-1+deb12u1. We recommend that you upgrade your openafs packages. For the detailed security status of openafs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openafs Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-5772-1 concerns various flaws in OpenAFS, prompting necessary updates to the affected packages.. OpenAFS security, Debian advisory, credential theft fix, buffer overflow patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 11, 2025 Critical Debian
197

Debian 10 Buster DLA-3423-1 Critical Epiphany Browser Credential Theft

It was discovered that there was a potential credential stealing attack in epiphany-browser, the default GNOME web browser. When using a sandboxed Content Security Policy (CSP) or the HTML . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3423-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb May 15, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : epiphany-browser Version : 3.32.1.2-3~deb10u3 CVE ID : CVE-2023-26081 Debian Bug : 1031727 It was discovered that there was a potential credential stealing attack in epiphany-browser, the default GNOME web browser. When using a sandboxed Content Security Policy (CSP) or the HTML "iframe" tag, the sandboxed web content was trusted by the main/surrounding resource. After this change, however, the password manager is disabled entirely in this situations, so that the untrusted web content cannot exfiltrate passwords. For Debian 10 buster, this problem has been fixed in version 3.32.1.2-3~deb10u3. We recommend that you upgrade your epiphany-browser packages. For the detailed security status of epiphany-browser please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/epiphany-browser Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian LTS advisory DLA-3423-1 reveals a serious vulnerability in epiphany-browser linked to credential theft, urging users to upgrade for protection against risks. Debian Security, Epiphany Browser, Credential Theft, Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 15, 2023 Critical Debian LTS
198

Arch Linux: ASA-202107-37 Low Severity Putty Content Spoofing

The package putty before version 0.76-1 is vulnerable to content spoofing. . Arch Linux Security Advisory ASA-202107-37 ========================================= Severity: Low Date : 2021-07-20 CVE-ID : CVE-2021-36367 Package : putty Type : content spoofing Remote : Yes Link : https://security.archlinux.org/AVG-2143 Summary ====== The package putty before version 0.76-1 is vulnerable to content spoofing. Resolution ========= Upgrade to 0.76-1. # pacman -Syu "putty> =0.76-1" The problem has been fixed upstream in version 0.76. Workaround ========= None. Description ========== PuTTY before version 0.76 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user). Impact ===== A remote SSH server could present a spoofed authentication prompt. References ========= https://security.archlinux.org/CVE-2021-36367 . Versions of PuTTY prior to 0.76-1 on Arch Linux have a security vulnerability related to content spoofing, which may compromise user credentials.. Putty Security Advisory, Arch Linux Security, Content Spoofing, Credential Theft. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jul 20, 2021 Low ArchLinux
202

openSUSE Leap 15.2 Security Update: Dovecot23 Important Access Issues

An update that fixes two vulnerabilities is now available. . openSUSE Security Update: Security update for dovecot23 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0920-1 Rating: important References: #1187418 #1187419 Cross-References: CVE-2021-29157 CVE-2021-33515 CVSS scores: CVE-2021-29157 (SUSE): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2021-33515 (SUSE): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for dovecot23 fixes the following issues: - CVE-2021-29157: Local attacker can login as any user and access their emails (bsc#1187418) - CVE-2021-33515: Attacker can potentially steal user credentials and mails (bsc#1187419) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-920=1 Package List: - openSUSE Leap 15.2 (x86_64): dovecot23-2.3.11.3-lp152.2.9.1 dovecot23-backend-mysql-2.3.11.3-lp152.2.9.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-backend-pgsql-2.3.11.3-lp152.2.9.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-backend-sqlite-2.3.11.3-lp152.2.9.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-debugsource-2.3.11.3-lp152.2.9.1 dovecot23-devel-2.3.11.3-lp152.2.9.1 dovecot23-fts-2.3.11.3-lp152.2.9.1 dovecot23-fts-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-fts-lucene-2.3.11.3-lp152.2.9.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-fts-solr-2.3.11.3-lp152.2.9.1 dovecot23-fts-solr-debuginfo-2.3.11.3-lp152.2.9.1 dovecot23-fts-squat-2.3.11.3-lp152.2.9.1 dovecot23-fts-squat-debuginfo-2.3.11.3-lp152.2.9.1 References: https://www.suse.com/security/cve/CVE-2021-29157.html https://www.suse.com/security/cve/CVE-2021-33515.html https://bugzilla.suse.com/1187418 https://bugzilla.suse.com/1187419 . Addresses critical security flaws in Dovecot on openSUSE Leap 15.2. Upgrade your system to enhance email safety immediately.. openSUSE Security,dovecot update,email security,remote access,credential issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 25, 2021 Important OpenSUSE
100

SUSE: 2021:2124-1 Important: Local Access Risk in Dovecot23

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for dovecot23 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2124-1 Rating: important References: #1187418 #1187419 Cross-References: CVE-2021-29157 CVE-2021-33515 CVSS scores: CVE-2021-29157 (SUSE): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2021-33515 (SUSE): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: SUSE Manager Server 4.0 SUSE Manager Retail Branch Server 4.0 SUSE Manager Proxy 4.0 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Enterprise Storage 6 SUSE CaaS Platform 4.0 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for dovecot23 fixes the following issues: - CVE-2021-29157: Local attacker can login as any user and access their emails (bsc#1187418) - CVE-2021-33515: Attacker can potentially steal user credentials and mails (bsc#1187419) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.0-2021-2124=1 - SUSE Manager Retail Branch Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.0-2021-2124=1 -SUSE Manager Proxy 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.0-2021-2124=1 - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2021-2124=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2021-2124=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2021-2124=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2021-2124=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2021-2124=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2021-2124=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Manager Server 4.0 (ppc64le s390x x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Manager Retail Branch Server 4.0 (x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Manager Proxy 4.0 (x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 - SUSE CaaS Platform 4.0 (x86_64): dovecot23-2.3.11.3-24.1 dovecot23-backend-mysql-2.3.11.3-24.1 dovecot23-backend-mysql-debuginfo-2.3.11.3-24.1 dovecot23-backend-pgsql-2.3.11.3-24.1 dovecot23-backend-pgsql-debuginfo-2.3.11.3-24.1 dovecot23-backend-sqlite-2.3.11.3-24.1 dovecot23-backend-sqlite-debuginfo-2.3.11.3-24.1 dovecot23-debuginfo-2.3.11.3-24.1 dovecot23-debugsource-2.3.11.3-24.1 dovecot23-devel-2.3.11.3-24.1 dovecot23-fts-2.3.11.3-24.1 dovecot23-fts-debuginfo-2.3.11.3-24.1 dovecot23-fts-lucene-2.3.11.3-24.1 dovecot23-fts-lucene-debuginfo-2.3.11.3-24.1 dovecot23-fts-solr-2.3.11.3-24.1 dovecot23-fts-solr-debuginfo-2.3.11.3-24.1 dovecot23-fts-squat-2.3.11.3-24.1 dovecot23-fts-squat-debuginfo-2.3.11.3-24.1 References: https://www.suse.com/security/cve/CVE-2021-29157.html https://www.suse.com/security/cve/CVE-2021-33515.html https://bugzilla.suse.com/1187418 https://bugzilla.suse.com/1187419 . New update released for dovecot23 in SUSE resolving two vulnerabilities: local login and password exposure. Review your systems immediately.. SUSE Linux,Dovecot23 Update,Security Fixes,Access Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 22, 2021 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200