Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-13604 http://linux.oracle.com/errata/ELSA-2025-13604.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: python3-requests-2.32.4-1.el10_0.noarch.rpm aarch64: python3-requests-2.32.4-1.el10_0.noarch.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/python-requests-2.32.4-1.el10_0.src.rpm Related CVEs: CVE-2024-47081 Description of changes: [2.32.4-1] - Update to 2.32.4 - Security fix for CVE-2024-47081: .netrc credentials leak via malicious URLs Resolves: RHEL-105460 _______________________________________________ El-errata mailing list
Update to 2.32.4. Fixes CVE-2024-47081.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-47916db6c7 2025-07-14 02:33:25.946188+00:00 -------------------------------------------------------------------------------- Name : mingw-python-requests Product : Fedora 41 Version : 2.32.4 Release : 1.fc41 URL : https://requests.readthedocs.io/en/latest/ Summary : MinGW Windows Python requests library Description : MinGW Windows Python requests. -------------------------------------------------------------------------------- Update Information: Update to 2.32.4. Fixes CVE-2024-47081. -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 5 2025 Sandro Mani - 2.32.4-1 - Update to 2.32.4 * Fri Jan 17 2025 Fedora Release Engineering - 2.32.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2375883 - CVE-2024-47081 mingw-python-requests: Requests vulnerable to .netrc credentials leak via malicious URLs [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2375883 [ 2 ] Bug #2375885 - CVE-2024-47081 mingw-python-requests: Requests vulnerable to .netrc credentials leak via malicious URLs [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2375885 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-47916db6c7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 2.32.4 Security fix for CVE-2024-47081: .netrc credentials leak via malicious URLs . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-87207b946a 2025-07-12 01:44:29.847191+00:00 -------------------------------------------------------------------------------- Name : python-requests Product : Fedora 42 Version : 2.32.4 Release : 1.fc42 URL : https://pypi.org/project/requests Summary : HTTP library, written in Python, for human beings Description : Most existing Python modules for sending HTTP requests are extremely verbose and cumbersome. Python\u2019s built-in urllib2 module provides most of the HTTP capabilities you should need, but the API is thoroughly broken. This library is designed to make HTTP requests easy for developers. -------------------------------------------------------------------------------- Update Information: Update to 2.32.4 Security fix for CVE-2024-47081: .netrc credentials leak via malicious URLs -------------------------------------------------------------------------------- ChangeLog: * Mon Jul 7 2025 Miro Hron\u010dok - 2.32.4-1 - Update to 2.32.4 - Security fix for CVE-2024-47081: .netrc credentials leak via malicious URLs * Wed Jun 4 2025 Python Maint - 2.32.3-14 - Rebuilt for Python 3.14 * Tue Jun 3 2025 Python Maint - 2.32.3-13 - Bootstrap for Python 3.14 * Tue Apr 15 2025 Benjamin A. Beasley - 2.32.3-5 - Backport test-cert. fixes for urllib3 2.4.0 compatibility -------------------------------------------------------------------------------- References: [ 1 ] Bug #2371255 - python-requests-2.32.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2371255 [ 2 ] Bug #2375886 - CVE-2024-47081 python-requests: Requests vulnerable to .netrc credentials leak via malicious URLs [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2375886 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-87207b946a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Urgent security notice regarding python-requests in Fedora 42 updates concerning .netrc credential exposure flaw.. Fedora 42, python-requests, security fix, .netrc leak, cybersecurity. . Severity: Critical. LinuxSecurity.com Team
Update to v1.93.0 (CVE-2023-41335, CVE-2023-42453). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-84ee781688 2023-10-06 01:28:08.203664 -------------------------------------------------------------------------------- Name : matrix-synapse Product : Fedora 38 Version : 1.93.0 Release : 2.fc38 URL : https://github.com/matrix-org/synapse Summary : A Matrix reference homeserver written in Python using Twisted Description : Matrix is an ambitious new ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix from the core development team at matrix.org, written in Python/Twisted. It is intended to showcase the concept of Matrix and let folks see the spec in the context of a coded base and let you run your own homeserver and generally help bootstrap the ecosystem. -------------------------------------------------------------------------------- Update Information: Update to v1.93.0 (CVE-2023-41335, CVE-2023-42453) -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 27 2023 Kai A. Hiller - 1.93.0-2 - Relax pillow requirement * Wed Sep 27 2023 Kai A. Hiller - 1.93.0-1 - Update to v1.93.0 (CVE-2023-41335, CVE-2023-42453) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2242239 - CVE-2023-42453 matrix-synapse: improper validation of receipts allows forged read receipts https://bugzilla.redhat.com/show_bug.cgi?id=2242239 [ 2 ] Bug #2242240 - CVE-2023-41335 matrix-synapse: temporary storage of plaintext passwords during password changes https://bugzilla.redhat.com/show_bug.cgi?id=2242240 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-84ee781688' at thecommand line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability and has three fixes is now available. . SUSE Security Update: Security update for yast2-samba-provision ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3199-1 Rating: moderate References: #1117597 #1132676 #1140548 #1184897 Cross-References: CVE-2018-17956 CVSS scores: CVE-2018-17956 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Server Applications 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for yast2-samba-provision fixes the following issues: Security issue fixed: - CVE-2018-17956: Fixed a credentials leak (bsc#1117597). Non-Security issues fixed: - Stop packaging docdir, it only contained the license which is now in licensedir. (bsc#1184897) - Catch and show internal python exceptions. (bsc#1140548) - Show a dialog with provision details or errors. (bsc#1132676) - Add metainfo (fate#319035) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-3199=1 - SUSE Linux Enterprise Module for Server Applications 15-SP4: zypper in -t patchSUSE-SLE-Module-Server-Applications-15-SP4-2022-3199=1 Package List: - openSUSE Leap 15.4 (noarch): yast2-samba-provision-1.0.5-150400.9.3.3 - SUSE Linux Enterprise Module for Server Applications 15-SP4 (noarch): yast2-samba-provision-1.0.5-150400.9.3.3 References: https://www.suse.com/security/cve/CVE-2018-17956.html https://bugzilla.suse.com/1117597 https://bugzilla.suse.com/1132676 https://bugzilla.suse.com/1140548 https://bugzilla.suse.com/1184897 . The samba-server-update tackles security vulnerabilities and introduces enhancements. Explore its implications and remedies.. SUSE Linux Update,yast2-samba-provision,credentials leak fix,security patch,moderate severity. . LinuxSecurity.com Team
In the download utility aria2, --log was leaking HTTP user credentials in local log file. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2873-1
- fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-f59bda7d94 2021-09-08 15:05:54.167624 --------------------------------------------------------------------------------Name : lynx Product : Fedora 34 Version : 2.8.9 Release : 13.fc34 URL : http://lynx.browser.org/ Summary : A text-based Web browser Description : Lynx is a text-based Web browser. Lynx does not display any images, but it does support frames, tables, and most other HTML tags. One advantage Lynx has over graphical browsers is speed; Lynx starts and exits quickly and swiftly displays web pages. --------------------------------------------------------------------------------Update Information: - fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165) --------------------------------------------------------------------------------ChangeLog: * Tue Aug 31 2021 Kamil Dudka - 2.8.9-13 - fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165) * Thu Jul 22 2021 Fedora Release Engineering - 2.8.9-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1994998 - CVE-2021-38165 lynx: Disclosure of HTTP authentication credentials via SNI data https://bugzilla.redhat.com/show_bug.cgi?id=1994998 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-f59bda7d94' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Wrong content via metalink not discarded (CVE-2021-22922). Metalink download sends credentials (CVE-2021-22923). Bad connection reuse due to flawed path name checks (CVE-2021-22924). . MGASA-2021-0384 - Updated curl packages fix security vulnerabilities Publication date: 27 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0384.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-22922, CVE-2021-22923, CVE-2021-22924, CVE-2021-22925 Wrong content via metalink not discarded (CVE-2021-22922). Metalink download sends credentials (CVE-2021-22923). Bad connection reuse due to flawed path name checks (CVE-2021-22924). TELNET stack contents disclosure again (CVE-2021-22925). References: - https://bugs.mageia.org/show_bug.cgi?id=29278 - https://curl.se/docs/CVE-2021-22922.html - https://curl.se/docs/CVE-2021-22923.html - https://curl.se/docs/CVE-2021-22924.html - https://curl.se/docs/CVE-2021-22925.html - https://lists.suse.com/pipermail/sle-security-updates/2021-July/009187.html - https://www.cve.org/CVERecord?id=CVE-2021-22922 - https://www.cve.org/CVERecord?id=CVE-2021-22923 - https://www.cve.org/CVERecord?id=CVE-2021-22924 - https://www.cve.org/CVERecord?id=CVE-2021-22925 SRPMS: - 8/core/curl-7.74.0-1.3.mga8 . New curl updates for Mageia address multiple significant security vulnerabilities, enhancing overall system security and operational efficiency.. curl Security Update, Mageia 8, Security Advisory, Connection Issues, Credential Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.