Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
89

Fedora 44 perl-Crypt-DSA Important Key Flaw CVE-2026-14570

This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) .. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fcfc08d46c 2026-07-12 01:10:38.798612+00:00 -------------------------------------------------------------------------------- Name : perl-Crypt-DSA Product : Fedora 44 Version : 1.22 Release : 1.fc44 URL : https://metacpan.org/release/Crypt-DSA Summary : Perl module for DSA signatures and key generation Description : Crypt::DSA is an implementation of the DSA (Digital Signature Algorithm) signature verification system. This package provides DSA signing, signature verification, and key generation. DSA (Digital Signature Algorithm) signatures are no longer considered to be adequate for security. This module should only be used for verifying old signatures and should not be used for new signatures. That being said, some technologies still require DSA signatures even now. Consider using other solutions or explicitly not using DSA signatures. Crypt-DSA-GMP is a possible replacement. -------------------------------------------------------------------------------- Update Information: This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) . -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Paul Howarth - 1.22-1 - Update to 1.22 - Hardening: Use a fresh, independent CSPRNG witness every round - Security fix: Modulo bias in key generation (CVE-2026-14570); an attack with hundreds of signatures could lead to full private-key compromise; keys should be considered compromised and new keys should be generated * Fri Jun 19 2026 Yaakov Selkowitz - 1.21-2 - Rebuilt for OpenSSL4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2497529 - CVE-2026-14570 perl-Crypt-DSA: Crypt::DSA: Private key recovery due to biased random number generation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497529 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fcfc08d46c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . This Fedora advisory addresses a critical flaw in perl-Crypt-DSA affecting key generation, leading to potential private key compromise.. Fedora perl-Crypt-DSA security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 11, 2026 Important Fedora
89

Fedora 43 perl-Crypt-DSA Critical Key Generation Flaw CVE-2026-14570

This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) .. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b77b9c5f04 2026-07-12 00:58:35.903674+00:00 -------------------------------------------------------------------------------- Name : perl-Crypt-DSA Product : Fedora 43 Version : 1.22 Release : 1.fc43 URL : https://metacpan.org/release/Crypt-DSA Summary : Perl module for DSA signatures and key generation Description : Crypt::DSA is an implementation of the DSA (Digital Signature Algorithm) signature verification system. This package provides DSA signing, signature verification, and key generation. DSA (Digital Signature Algorithm) signatures are no longer considered to be adequate for security. This module should only be used for verifying old signatures and should not be used for new signatures. That being said, some technologies still require DSA signatures even now. Consider using other solutions or explicitly not using DSA signatures. Crypt-DSA-GMP is a possible replacement. -------------------------------------------------------------------------------- Update Information: This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) . -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Paul Howarth - 1.22-1 - Update to 1.22 - Hardening: Use a fresh, independent CSPRNG witness every round - Security fix: Modulo bias in key generation (CVE-2026-14570); an attack with hundreds of signatures could lead to full private-key compromise; keys should be considered compromised and new keys should be generated * Fri Jun 19 2026 Yaakov Selkowitz - 1.21-2 - Rebuilt for OpenSSL4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2497529 - CVE-2026-14570 perl-Crypt-DSA: Crypt::DSA: Private key recovery due to biased random number generation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497529 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b77b9c5f04' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . A critical flaw in the Perl Crypt-DSA module allows for private key compromise. Immediate updates are strongly advised.. Fedora 43 security flaw, Crypt-DSA update, critical flaw in key generation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 11, 2026 Critical Fedora
203

Mageia 9: 2024-0089 Critical GnuTLS Flaws and Timing Attack Mitigation

The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing . MGASA-2024-0089 - Updated gnutls packages fix security vulnerabilities Publication date: 26 Mar 2024 URL: https://advisories.mageia.org/MGASA-2024-0089.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-28834, CVE-2024-28835 The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel. (CVE-2024-28834) A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command. (CVE-2024-28835) References: - https://bugs.mageia.org/show_bug.cgi?id=32989 - http://www.slackware.com/security/viewer.php?l=slackware-security&y=2024&m=slackware-security.365688 - https://www.cve.org/CVERecord?id=CVE-2024-28834 - https://www.cve.org/CVERecord?id=CVE-2024-28835 SRPMS: - 9/core/gnutls-3.8.4-1.mga9 . OpenSSL patch resolves major vulnerabilities and mitigates information leakage risks, strengthening security across Arch Linux environments.. GnuTLS Security Update, Mageia Vulnerabilities, Timing Attack Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 26, 2024 Critical Mageia
172

Ubuntu 12.04 ESM USN-3675-3 Critical: GnuPG Cryptographic Flaw

GnuPG could be made to incorrectly interpret the status of the cryptographic operation if it received specially crafted file.. =========================================================================Ubuntu Security Notice USN-3675-3 June 18, 2018 gnupg vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: GnuPG could be made to incorrectly interpret the status of the cryptographic operation if it received specially crafted file. Software Description: - gnupg: GNU privacy guard - a free PGP replacement Details: USN-3675-1 fixed a vulnerability in GnuPG. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Marcus Brinkmann discovered that during decryption or verification, GnuPG did not properly filter out terminal sequences when reporting the original filename. An attacker could use this to specially craft a file that would cause an application parsing GnuPG output to incorrectly interpret the status of the cryptographic operation reported by GnuPG. (CVE-2018-12020) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: gnupg 1.4.11-3ubuntu2.11 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3675-3 https://ubuntu.com/security/notices/USN-3675-1 CVE-2018-12020 . Ubuntu Security Notice USN-3675-3 June 18, 2018 gnupg vulnerability A security issue affects these r. gnupg, incorrectly, interpret, status, cryptographic, operation, receive. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 18, 2018 Critical Ubuntu
100

SUSE Linux 11 SP3: SUSE-SU-2015:0259-1 Important: NTP Security Flaws

An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.. SUSE Security Update: Security update for ntp ______________________________________________________________________________ Announcement ID: SUSE-SU-2015:0259-1 Rating: important References: #910764 #911792 Cross-References: CVE-2014-9293 CVE-2014-9294 CVE-2014-9297 CVE-2014-9298 Affected Products: SUSE Linux Enterprise Server 11 SP3 for VMware SUSE Linux Enterprise Server 11 SP3 SUSE Linux Enterprise Desktop 11 SP3 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: ntp has been updated to fix four security issues: * CVE-2014-9294: ntp-keygen used a weak RNG seed, which made it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. (bsc#910764) * CVE-2014-9293: The config_auth function, when an auth key is not configured, improperly generated a key, which made it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. (bsc#910764) * CVE-2014-9298: ::1 can be spoofed on some operating systems, so ACLs based on IPv6 ::1 addresses could be bypassed. (bsc#910764) * CVE-2014-9297: vallen is not validated in several places in ntp_crypto.c, leading to potential information leak. (bsc#910764) Security Issues: * CVE-2014-9294 * CVE-2014-9293 * CVE-2014-9298 * CVE-2014-9297 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP3 forVMware: zypper in -t patch slessp3-ntp=10293 - SUSE Linux Enterprise Server 11 SP3: zypper in -t patch slessp3-ntp=10293 - SUSE Linux Enterprise Desktop 11 SP3: zypper in -t patch sledsp3-ntp=10293 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11 SP3 for VMware (i586 x86_64): ntp-4.2.4p8-1.29.32.1 ntp-doc-4.2.4p8-1.29.32.1 - SUSE Linux Enterprise Server 11 SP3 (i586 ia64 ppc64 s390x x86_64): ntp-4.2.4p8-1.29.32.1 ntp-doc-4.2.4p8-1.29.32.1 - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64): ntp-4.2.4p8-1.29.32.1 ntp-doc-4.2.4p8-1.29.32.1 References: https://www.suse.com/security/cve/CVE-2014-9293.html https://www.suse.com/security/cve/CVE-2014-9294.html https://www.suse.com/security/cve/CVE-2014-9297.html https://www.suse.com/security/cve/CVE-2014-9298.html https://bugzilla.suse.com/show_bug.cgi?id=910764 https://bugzilla.suse.com/show_bug.cgi?id=911792 https://scc.suse.com:443/patches/ . A crucial revision for ntp on openSUSE addresses several significant vulnerabilities to boost overall system security.. SUSE Linux, NTP Issues, Security Updates, Remote Attacks. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 12, 2015 Important SuSE
87

Debian DSA-1703-1 moderate: BIND9 Remote Threat due to Cryptographic Issue

It was discovered that BIND, an implementation of the DNS protocol suite, does not properly check the result of an OpenSSL function which is used to verify DSA cryptographic signatures. As a result, incorrect DNS resource records in zones protected by DNSSEC could be . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-1703-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer January 12, 2009 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : bind9 Vulnerability : interpretation conflict Problem type : remote Debian-specific: no CVE Id(s) : CVE-2009-0025 It was discovered that BIND, an implementation of the DNS protocol suite, does not properly check the result of an OpenSSL function which is used to verify DSA cryptographic signatures. As a result, incorrect DNS resource records in zones protected by DNSSEC could be accepted as genuine. For the stable distribution (etch), this problem has been fixed in version 9.3.4-2etch4. For the unstable distribution (sid) and the testing distribution (lenny), this problem will be fixed soon. We recommend that you upgrade your BIND packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - ------------------------------- Source archives: Size/MD5 checksum: 1197 aa679c6e3106b422fa8de952556cc98e Size/MD5 checksum: 30285912d089f391d6ac1a60e2a7b7b8c49f42 Size/MD5 checksum: 4043577 198181d47c58a0a9c0265862cd5557b0 Architecture independent packages: Size/MD5 checksum: 187564 d3609a90363331288018fcdbba29a047 alpha architecture (DEC Alpha) Size/MD5 checksum: 226154 9adec25147fa3f2c85cef36c75148335 Size/MD5 checksum: 96576 8ca632cac9163decf3c3dd24a373cc1b Size/MD5 checksum: 112678 273ba2508722416d3a7090153922c01e Size/MD5 checksum: 98226 eef74b1024e184fcea8a09f3800cf544 Size/MD5 checksum: 190164 7eac73aae4fabfcfec8e9ecdcde45ff5 Size/MD5 checksum: 322348 a5a5ea6ddbfaab6c8aeaf247d1c95874 Size/MD5 checksum: 116594 61d56b68f75ef2693169176efa07512e Size/MD5 checksum: 564948 2827fe2266733bd0439ec8a22f167f25 Size/MD5 checksum: 115860 0bb76803abf4d4799c7d2a64cd0af449 Size/MD5 checksum: 1407512 95c550a74d02dbe81886f33499e249cc Size/MD5 checksum: 188806 420104ba72fe220ae0e7eff269fc086d amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 317636 d5841784354f118901f08f48a0e886e8 Size/MD5 checksum: 96156 ce4d2168a261c296f6b60dc2c52a0ac0 Size/MD5 checksum: 224438 460704b96b0b279f5f54346a02356f18 Size/MD5 checksum: 190758 21f6b7f6dca59161cf1ba423b97a013e Size/MD5 checksum: 552562 4cdcf10ca2572737e63c6269e4d7ef6b Size/MD5 checksum: 117040 24dd657bb0b671a48fb1498948fdca41 Size/MD5 checksum: 114878 02b9e3b075f638e91b92248e40f46cea Size/MD5 checksum: 1107812 587e9613589665f4ccecac2d1bb7c4e7 Size/MD5 checksum: 187666 e359081c8f81d6380655bc563a844803 Size/MD5 checksum: 96942 07f2b24d6f2815bb4fcad64a206d21b2 Size/MD5 checksum: 111304 f85b9997f97e24dd1c972a6c25d3713f arm architecture (ARM) Size/MD5 checksum: 95824 cd0dbfd76dc1a9a7ae66c3d17dd2c076 Size/MD5 checksum: 187430 4d066c4c8fda96616654f0e5c5f269d4 Size/MD5 checksum: 532276 f15132b68c23e3a2b7bcbb1d0c7e9e1c Size/MD5 checksum: 116148 821abd04e8459db5bd026dce7c5007c8 Size/MD5 checksum: 112778 b0737de9602f9844b17f8c79c0c7bee9 Size/MD5 checksum: 107920 93094487c134673000797d03326bcfbb Size/MD5 checksum: 183016 668007a69bc0bcb174fb3af007a06a2d Size/MD5 checksum: 217782 fe30c568a6f694e31f323c5a7c65a489 Size/MD5 checksum: 311142 a5ad717d9c53e22fc559e2b846af6761 Size/MD5 checksum: 95240 bec7ba6d11e71d4a5203ffd8775ce61b Size/MD5 checksum: 1074544 a8d33e799364caf2a1a6119ba980fb5c hppa architecture (HP PA RISC) Size/MD5 checksum: 96486 780b5f6edcb2594c074faaacac84a506 Size/MD5 checksum: 217580 f4eb031a7c5a6c4454d84cd784c218aa Size/MD5 checksum: 188274 b8428b8e5c42e5f809d9180196435023 Size/MD5 checksum: 115708 144ebf381de71a09bca8bd0dd0899969 Size/MD5 checksum: 1258938 60e891b0432a731536a921964a5ba3e7 Size/MD5 checksum: 185524 291fd0feff440c39dcdfa77b19fb70dd Size/MD5 checksum: 314068 441b640e2d300524bf352d613833afdf Size/MD5 checksum: 543334 89560b776cd247e6dfbc37b5a8ad541d Size/MD5 checksum: 114236 452ab3e612e68e21df601d3a1f3016bc Size/MD5 checksum: 96668 749a3664788afdf253d40123630c913d Size/MD5 checksum: 113042 c77ab83bf8b702a0f221299f63f84275 i386 architecture (Intel ia32) Size/MD5 checksum: 110234 cb2d13c313d5061d6af864325b9b7d0d Size/MD5 checksum: 95040 b8d8c02291c6fa58cfc6405902c39ba0 Size/MD5 checksum: 206548 05f6acbfc0982ed87a378e35f3ad8be9 Size/MD5 checksum: 472778 22d8b1ea77e191686c5affab4c869240 Size/MD5 checksum: 296242 86357a0f5353674fb5b73ddf97d8a242 Size/MD5 checksum: 170214 163fdc7612a950d7a32b0992af767b23 Size/MD5 checksum: 995236 a747c1d27a79515936517d301a534e07 Size/MD5 checksum: 180794 4bc0c43e3454131453454d08d6029de4 Size/MD5 checksum: 95042 7656f21f85e5489d595a5fc43627199b Size/MD5 checksum: 106106 6b5985e30d0536eb56dfd5b31b479b58 Size/MD5 checksum: 113194 3ae945c6b46bda56b407e81bf285fad6 ia64 architecture (Intel ia64) Size/MD5 checksum: 117816 c06945e1506470a93158549c6e94ec80 Size/MD5 checksum: 102474 4cd35b5a1cfb24b1fb156441fae565e9 Size/MD5 checksum: 1584324 7e7b49e71bde1abc7fec8a6845b4e376 Size/MD5 checksum: 216428 682aa4769f46a7dfb2b2bdaf7ec53dde Size/MD5 checksum: 127650 7206fa330fc8b115a95f8a20073b2683 Size/MD5 checksum: 232106 e8a5ae82b88f1288ee91fb6879a38035 Size/MD5 checksum: 393396 f6d1ec1bdd9b7d3bf0543c1f72184c5e Size/MD5 checksum: 100022 b080abf8bcf2f7d33944c0f5ab07d5db Size/MD5 checksum: 740278 684ee73762dc6a569e0ad5458cb39a63 Size/MD5 checksum: 280944 434b3f2bf7b6eac8c8eadbc9ff71b88a Size/MD5 checksum: 125878 78c533671d65799444a6abeecb066102 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 95048 1a1adcb72a4a988eb862dbfa70a05993 Size/MD5 checksum: 94272 494f78dca4285c9784f92779d08516a0 Size/MD5 checksum: 180574 d4bace2add3362896bdb17e794642d80 Size/MD5 checksum: 211456 a317473e059e7670b6bb603a1fb532b2 Size/MD5 checksum: 107968 9d86c2744569db8b9110c37be4de8aba Size/MD5 checksum: 110378 ab471c9ce1bb5a666413d00253c84c71 Size/MD5 checksum: 491896 984d83789bb28f65d78130b5ffe58783 Size/MD5 checksum: 1229560 6bae9ceb7a1a604f3a45c6df905fb2c8 Size/MD5 checksum: 301540 084df4d5378ecb47eee2715a709005ef Size/MD5 checksum: 174080 29e62329993fe21bd2d412b659a3c220 Size/MD5 checksum: 113348 c697f17d93aa609ef448edf740ca132a mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 94150 0177400160d90cc2d662ca3a6688178e Size/MD5 checksum: 179698 310f99bbfb09db4f5ea5dff07b66bb63 Size/MD5 checksum: 107218 c6b342a831948a7bf7801d46d38290c4 Size/MD5 checksum: 113072 a27b2fe4ed7a345d258313ddc4f8346f Size/MD5 checksum: 110300 fb55450e28a08d2010b6e93e17b895ae Size/MD5 checksum: 94980 fb919221192449e70239f8991f01636b Size/MD5 checksum: 488288 8a089d802fd33105a3699e81480439c9 Size/MD5 checksum: 210968 e5c3f788c66086cf7dcd26215a17a0f8 Size/MD5 checksum: 1205504 260e40c7c015eca2a29612c725d8dd35 Size/MD5 checksum: 174202 765ab3865c5a811dac4ac157e358a318 Size/MD5 checksum: 299586 5f5e170a809055667994b7b76b0745a1 powerpc architecture (PowerPC) Size/MD5 checksum: 301350 a20ea0a911818a574701d68e29f3a2d1 Size/MD5 checksum: 183376 c550243d0a3b401d2970a3973f656120 Size/MD5 checksum: 96210 4116f47d69a3f83ce9022b306b1e6826 Size/MD5 checksum: 96250 112e99a3eead25467bbb19895cc1eb3a Size/MD5 checksum: 173642 27ea1f6607f69941e718884d7b90b626 Size/MD5 checksum: 109316 2158dc4b86fcc4b841776df478bafe2d Size/MD5 checksum: 206910 0f1968d555573c2fd230ffb92109e729 Size/MD5 checksum: 488474 8fc4aa4a58958441f5cda10c83a24e05 Size/MD5 checksum: 1167916 45c319145305d976c147af786f10f65a Size/MD5 checksum: 113906 a908806289ae42f4947557f82952d1c6 Size/MD5 checksum: 112320 3bf75de9190d5c0012510fffacd4d980 s390 architecture (IBM S/390) Size/MD5 checksum: 114300 d5ab339f6f1505b6efe1caab0f91b4b0 Size/MD5 checksum: 95710 23cc9069086681ec048ab64d04150b78 Size/MD5 checksum: 196642 a135997ee33f30d6a9656563cf398ce1 Size/MD5 checksum: 331958 3c560c643e1a60548ef5c4f567b3bbf6 Size/MD5 checksum: 194782 bd4744eff4c131183da5c32fa9197b81 Size/MD5 checksum: 118206 ddd094acc29a60f0ad39deb9ffcc3b53 Size/MD5 checksum: 579538 6b6bb21b3ba7fcc3d0a96fb29e32b24e Size/MD5 checksum: 1137454 2b639e2c0c5e2bed36db838611141876 Size/MD5 checksum: 116708 bab63e3ca69977baa87b07181ca5d1a4 Size/MD5 checksum: 97832 5e3591957078a61702b71fdb2e24fdfc Size/MD5 checksum: 234026 dcf706e32b50ab97068af14126bb65bd sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 183878 eee08db142d1871d4b692dbbcd15999a Size/MD5 checksum: 111224 261734b90a58046ad8ccd7ecf45629c3 Size/MD5 checksum: 114294 b9d3bc689a758181f7a6068db8970fe5 Size/MD5checksum: 1122546 27f759bbc75c0da9c82cb26769d122c2 Size/MD5 checksum: 175962 9a2373e0bb287efc7eb53697b91de147 Size/MD5 checksum: 107672 348e2faed12a7a66d00c3d3eed509605 Size/MD5 checksum: 210612 0f479f72667f152c97491331fd3a7ed8 Size/MD5 checksum: 494486 69c393bf175654857ec2151d4ee47a4e Size/MD5 checksum: 95434 34974e2951421e842ea394dbba268bb2 Size/MD5 checksum: 95384 429ec6ce3ab7f33b25e008277b542a03 Size/MD5 checksum: 300876 a0a9ae53e63e2dbb54b6db43dfbb1c72 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Ubuntu security notice USN-5000-1 highlights a vulnerability in OpenSSL that compromises encryption security. Update suggested.. Bind9 Update, Debian Security, Cryptographic Flaw, Remote Threat. . LinuxSecurity.com Team

Calendar%202 Jan 12, 2009 Debian
87

Debian 3.1 DSA 1182-1 Critical: GnuTLS Signature Forgery Issue

Daniel Bleichenbacher discovered a flaw in GNU TLS cryptographic package that could allow an attacker to generate a forged signature that GNU TLS will accept as valid.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1182-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff September 22nd, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : gnutls11 Vulnerability : cryptographic weakness Problem-Type : local Debian-specific: no CVE ID : CVE-2006-4790 Daniel Bleichenbacher discovered a flaw in GNU TLS cryptographic package that could allow an attacker to generate a forged signature that GNU TLS will accept as valid. For the stable distribution (sarge) this problem has been fixed in version 1.0.16-13.2sarge2. The unstable distribution (sid) does no longer contain gnutls11, for gnutls13 this problem has been fixed in version 1.4.4-1. We recommend that you upgrade your GNU TLS package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 820 72116e13ca8af0d4c0420a6a5fba01fb Size/MD5 checksum: 346146 46c4495ad9c32f53a362669432b548d0 Size/MD5 checksum: 1504638 7b410fa3c563c7988e434a8c8671b3cd Alpha architecture: Size/MD5 checksum: 229836 759bb1fb11af8022228651e5ee996c2a Size/MD5 checksum: 335034 e25273a2f6a338e0a864759723f7927f Size/MD5 checksum: 589736 7318e2d5e9e5c1706e4e3baeadbe5e95 Size/MD5 checksum: 512202 25396b24bd00c6c2d0c52f744072b972 AMD64 architecture: Size/MD5 checksum: 217586 8c925e3b730e6b72d776e7b132c15a04 Size/MD5 checksum: 327012 14301cbecc28ec34e998decbabf3ce58 Size/MD5 checksum: 575502 bb6e0f0d2312a49ea9466a0261c667a0 Size/MD5 checksum: 392470 01728ddd9d1a2493f95f7b88fd77063d ARM architecture: Size/MD5 checksum: 204892 4979873690a1bdd10b87de313f50e823 Size/MD5 checksum: 294784 a1f084e60a11242ea2d0d8aa6b9e0a92 Size/MD5 checksum: 585114 e7a6b7471fc1696936c7b1a2d842dd0a Size/MD5 checksum: 400060 b385b5cbca545e9c3956c0c43d0946e0 HP Precision architecture: Size/MD5 checksum: 217594 5597e912c19fb5f3cea5350fc4867948 Size/MD5 checksum: 329544 fb715f8fb54a6fb9e430edb1774ada8e Size/MD5 checksum: 584956 6c488c7997328cecda7afd7497d85ff5 Size/MD5 checksum: 434780 7560c9da720dad66554a0459af06d0f8 Intel IA-32 architecture: Size/MD5 checksum: 206826 3a6b6996db3db6bd92947fb552b61599 Size/MD5 checksum: 301988 7af47286dd7a1fca42f80b1dfd87bb7d Size/MD5 checksum: 558658 c5e07873a863d46892921effa3423038 Size/MD5 checksum: 370390 e649a2f476791e825c923003b152484c Intel IA-64 architecture: Size/MD5 checksum: 259060 252fafaf93df717cc09bfe1c33b2d382 Size/MD5 checksum: 384930 9b16fbd9b504907db1d1c4f08669989e Size/MD5 checksum: 585920 64245f68bb5c1c795b4143462bbb25f5 Size/MD5 checksum: 521916 d8eb2fec68f52dbd52c351402ab99b6f Motorola 680x0 architecture: Size/MD5 checksum: 198834 a12fd077c07b171dc6e99feb78375b08 Size/MD5 checksum: 282984 577f5774ba0f2c274b8c62071f7202cf Size/MD5 checksum: 561098a08a318581f5db996d9c382bd495c709 Size/MD5 checksum: 341710 4bc318fbbfc2046fe4dd47d12ba88425 Big endian MIPS architecture: Size/MD5 checksum: 211728 c3c1695268e1201ac2e9081b94c17366 Size/MD5 checksum: 291666 f8fbf909070719d38243643d5dc7bf1d Size/MD5 checksum: 595774 f9ee1f7ceb3db2d93f9fcc758ccecab5 Size/MD5 checksum: 408540 c1c1dcad15359180555a6256818c0686 Little endian MIPS architecture: Size/MD5 checksum: 211476 f28cc4f345ae11897ae12ec1ac324719 Size/MD5 checksum: 290328 fd27ef5dd5e20763912f5384b920360d Size/MD5 checksum: 591336 9c704e57721d0cf7a12bf844731a9fd7 Size/MD5 checksum: 404628 b1201dea3f671b1e651f86e45803d7c7 PowerPC architecture: Size/MD5 checksum: 218500 e6b92e1d34fa41b18c9aac4765e52191 Size/MD5 checksum: 299502 9377a3aa261f852a8666934bb0825f04 Size/MD5 checksum: 1415916 e27b0176c54741aff5b45d0466438ee1 Size/MD5 checksum: 388910 1a2997848bc55fc28730370891797297 IBM S/390 architecture: Size/MD5 checksum: 215448 9b20f31f10b2b91524453c7a768402a0 Size/MD5 checksum: 318674 6ace59100c9131a1cea01c7d635d633a Size/MD5 checksum: 632292 60c0acb0ba3046ed4462627ed74db531 Size/MD5 checksum: 376622 c11864c64293723e02f07bbeb59c36a7 Sun Sparc architecture: Size/MD5 checksum: 204564 a826236438bfe0fbbffe6841fc0380be Size/MD5 checksum: 295780 b68bb873076fad0a20082e8f1601a43d Size/MD5 checksum: 577540 4bdfb6604d142bf8665846ef235724a0 Size/MD5 checksum: 399936 10103cd5f9f40c434b9c6412cad4edb2 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list:This email address is being protected from spambots. You need JavaScript enabled to view it. . - --------------------------------------------------------------------------Debian Security Advisory. daniel, bleichenbacher, cryptographic, package, allow, attacke. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 22, 2006 Critical Debian
89

Fedora Core 4: FEDORA-2006-147 Critical: GnuPG Cryptographic Flaw

Tavis Ormandy discovered a flaw in the way GnuPG verifies cryptographically signed data with inline signatures. It is possible for an attacker to add unsigned text to a signed message in such a way so that when the signed text is extracted, the unsigned text is extracted as well, appearing as if it had been signed. The Common Vulnerabilities and Exposures project assigned the name CVE-2006-0049 to this issue.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-147 2006-03-13 ---------------------------------------------------------------------Product : Fedora Core 4 Name : gnupg Version : 1.4.2.2 Release : 1 Summary : A GNU utility for secure communication and data storage. Description : GnuPG (GNU Privacy Guard) is a GNU utility for encrypting data and creating digital signatures. GnuPG has advanced key management capabilities and is compliant with the proposed OpenPGP Internet standard described in RFC2440. Since GnuPG doesn't use any patented algorithm, it is not compatible with any version of PGP2 (PGP2.x uses only IDEA for symmetric-key encryption, which is patented worldwide). ---------------------------------------------------------------------Update Information: Tavis Ormandy discovered a flaw in the way GnuPG verifies cryptographically signed data with inline signatures. It is possible for an attacker to add unsigned text to a signed message in such a way so that when the signed text is extracted, the unsigned text is extracted as well, appearing as if it had been signed. The Common Vulnerabilities and Exposures project assigned the name CVE-2006-0049 to this issue. ---------------------------------------------------------------------* Fri Mar 10 2006 Nalin Dahyabhai - 1.4.2.2-1 - update to 1.4.2.2 to fix detection of unsigned data (CVE-2006-0049, #184557) ---------------------------------------------------------------------This update can bedownloaded from: 399347d86a34ec777de3fa46a8931774bf425679 SRPMS/gnupg-1.4.2.2-1.src.rpm a42396ca1e3828f725c903f3a38a03096bea3e91 ppc/gnupg-1.4.2.2-1.ppc.rpm d080a2ac636e7200970f7bca2cde0897d9949910 ppc/debug/gnupg-debuginfo-1.4.2.2-1.ppc.rpm 5f0cb70184126988f240c3487fe38ed37bae0df6 x86_64/gnupg-1.4.2.2-1.x86_64.rpm bc935e3520882a6461ddb27318fa909ebd9d47b4 x86_64/debug/gnupg-debuginfo-1.4.2.2-1.x86_64.rpm fa64b2b2645982e7abe49a2ca0ae85c899d65eff i386/gnupg-1.4.2.2-1.i386.rpm 8c146199cc14d0dbfaebbc2c4b8fbeb17e9589f1 i386/debug/gnupg-debuginfo-1.4.2.2-1.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A recent patch for GnuPG addresses a security vulnerability that could permit the extraction of unsigned content from authenticated messages.. GnuPG Update, Fedora Security, Cryptographic Flaw Fix, Secure Communication. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 13, 2006 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200