Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
197

Debian 10: DLA-3468-1 Moderate Advisory for HSQLDB Scripting Risks

Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output . -------------------------------------------------------------------------Debian LTS Advisory DLA-3468-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany June 22, 2023 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : hsqldb1.8.0 Version : 1.8.0.10+dfsg-10+deb10u1 CVE ID : CVE-2023-1183 Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output such a script. In combination with LibreOffice, an attacker could craft an odb containing a "database/script" file which itself contained a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. For Debian 10 buster, this problem has been fixed in version 1.8.0.10+dfsg-10+deb10u1. We recommend that you upgrade your hsqldb1.8.0 packages. For the detailed security status of hsqldb1.8.0 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/hsqldb1.8.0 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . HSQLDB Notice DLA-3468-2: Security enhancement for the Java SQL database to mitigate the risks associated with script command execution vulnerabilities.. HSQLDB Security, Debian LTS, Java SQL Update, ScriptingCommands, Database Engine. . LinuxSecurity.com Team

Calendar 2 Jun 21, 2023 Debian LTS
89

Fedora 37: FEDORA-2022-e0e9a43546 Critical: Galera Engine Update

**MariaDB 10.5.18 & Galera 26.4.13** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-18-release-notes. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e0e9a43546 2022-11-30 01:33:59.394774 --------------------------------------------------------------------------------Name : galera Product : Fedora 37 Version : 26.4.13 Release : 1.fc37 URL : https://mariadb.com/products/enterprise/galera-cluster/ Summary : Synchronous multi-master wsrep provider (replication engine) Description : Galera is a fast synchronous multimaster wsrep provider (replication engine) for transactional databases and similar applications. For more information about wsrep API see https://github.com/mariadb-corporation/wsrep-API repository. For a description of Galera replication engine see https://mariadb.com/products/enterprise/galera-cluster/ web. --------------------------------------------------------------------------------Update Information: **MariaDB 10.5.18 & Galera 26.4.13** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-18-release-notes --------------------------------------------------------------------------------ChangeLog: * Tue Nov 15 2022 Michal Schorm - 26.4.13-1 - Rebase to 26.4.13 * Wed Aug 24 2022 Michal Schorm - 26.4.12-1 - Rebase to 26.4.12 --------------------------------------------------------------------------------References: [ 1 ] Bug #2114892 - CVE-2022-32081 CVE-2022-32082 CVE-2022-32084 CVE-2022-32089 CVE-2022-32091 CVE-2022-38791 mariadb: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2114892 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-e0e9a43546' at thecommand line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Galera 26.4.13 update enhances replication, fixes database compatibility, improves security, and updates documentation for Fedora 37 users during installation.. MariaDB, Galera, Fedora Security Update, Database Replication, Update Notifications. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 29, 2022 Critical Fedora
89

Fedora 31: FEDORA-2020-ac2d47d89a Security Advisory for Galera

**MariaDB 10.3.26** **MariaDB connector C/C++ 3.1.11** **Galera 25.3.26** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/release-notes-mariadb-10-3-series/mariadb-10326-release-notes https://mariadb.com/docs/release-notes/connectors/c/3.1/3.1.11 ---- **MariaDB 10.3.25** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/release-notes-mariadb-10-3-series/mariadb-10325-release-notes. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-ac2d47d89a 2020-11-11 01:31:11.923446 --------------------------------------------------------------------------------Name : galera Product : Fedora 31 Version : 25.3.31 Release : 1.fc31 URL : https://mariadb.com/products/enterprise/galera-cluster/ Summary : Synchronous multi-master wsrep provider (replication engine) Description : Galera is a fast synchronous multi-master wsrep provider (replication engine) for transactional databases and similar applications. For more information about wsrep API see https://launchpad.net/wsrep. For a description of Galera replication engine see . --------------------------------------------------------------------------------Update Information: **MariaDB 10.3.26** **MariaDB connector C/C++ 3.1.11** **Galera 25.3.26** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/release-notes-mariadb-10-3-series/mariadb-10326-release-notes https://mariadb.com/docs/release-notes/connectors/c/3.1/3.1.11 ----**MariaDB 10.3.25** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/release-notes-mariadb-10-3-series/mariadb-10325-release-notes --------------------------------------------------------------------------------ChangeLog: * Wed Nov 4 2020 Michal Schorm - 25.3.31-1 - Rebase to 25.3.31 * Mon Oct 26 2020 Michal Schorm - 25.3.30-1 - Rebase to 25.3.30 * Fri Jun 5 2020 Michal Schorm - 25.3.29-1 - Rebase to 25.3.29 Resolves: rhbz#1546787 --------------------------------------------------------------------------------References: [ 1 ] Bug #1830119 - CVE-2020-2752 CVE-2020-2760 CVE-2020-2812 CVE-2020-2814 mariadb:10.3/mariadb: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1830119 [ 2 ] Bug #1843796 - CVE-2020-13249 mariadb:10.3/mariadb: mariadb-connector-c: Improper validation of content in a OK packet received from server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1843796 [ 3 ] Bug #1846527 - CVE-2020-2780 mariadb:10.3/mariadb: mysql: Server: DML unspecified vulnerability (CPU Apr 2020) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1846527 [ 4 ] Bug #1894078 - CVE-2020-14765 CVE-2020-14776 CVE-2020-14789 CVE-2020-14812 mariadb: various flaws [fedora-31] https://bugzilla.redhat.com/show_bug.cgi?id=1894078 [ 5 ] Bug #1894663 - mariadb-connector-c-3.1.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=1894663 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-ac2d47d89a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The latest Fedora 31 update for Galera presents significant security enhancements and vital notes on MariaDB Connector C/C++.. Galera Update, Fedora Notification, MariaDB Connector, Database Engine, Security Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 10, 2020 Important Fedora
172

Ubuntu 19.10 Security Advisory: SQLite Denial Of Service Risks

Several security issues were fixed in SQLite.. =========================================================================Ubuntu Security Notice USN-4205-1 December 02, 2019 sqlite3 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 - Ubuntu 19.04 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 12.04 ESM Summary: Several security issues were fixed in SQLite. Software Description: - sqlite3: C library that implements an SQL database engine Details: It was discovered that SQLite incorrectly handled certain schemas. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 12.04 ESM. (CVE-2018-8740) It was discovered that SQLite incorrectly handled certain schemas. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 19.04. (CVE-2019-16168) It was discovered that SQLite incorrectly handled certain schemas. An attacker could possibly use this issue to mishandles some expressions. This issue only affected Ubuntu 19.04 and Ubuntu 19.10. (CVE-2019-19242) It was discovered that SQLite incorrectly handled certain queries. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 19.04 and Ubuntu 19.10. (CVE-2019-19244) It was discovered that SQLite incorrectly handled certain SQL commands. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 19.04. (CVE-2019-5018) It was discovered that SQLite incorrectly handled certain commands. An attacker could possibly use this issue to execute arbitrary code. (CVE-2019-5827) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: libsqlite3-0 3.29.0-2ubuntu0.1 sqlite3 3.29.0-2ubuntu0.1 Ubuntu 19.04: libsqlite3-0 3.27.2-2ubuntu0.2 sqlite3 3.27.2-2ubuntu0.2 Ubuntu 18.04 LTS: libsqlite3-0 3.22.0-1ubuntu0.2 sqlite3 3.22.0-1ubuntu0.2 Ubuntu 16.04 LTS: libsqlite3-0 3.11.0-1ubuntu1.3 sqlite3 3.11.0-1ubuntu1.3 Ubuntu 12.04 ESM: libsqlite3-0 3.7.9-2ubuntu1.4 sqlite3 3.7.9-2ubuntu1.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4205-1 CVE-2018-8740, CVE-2019-16168, CVE-2019-19242, CVE-2019-19244, CVE-2019-5018, CVE-2019-5827 Package Information: https://launchpad.net/ubuntu/+source/sqlite3/3.29.0-2ubuntu0.1 https://launchpad.net/ubuntu/+source/sqlite3/3.27.2-2ubuntu0.2 https://launchpad.net/ubuntu/+source/sqlite3/3.22.0-1ubuntu0.2 https://launchpad.net/ubuntu/+source/sqlite3/3.11.0-1ubuntu1.3 . Numerous vulnerabilities patched in SQLite for Ubuntu, posing risks such as DoS and potential code execution exploits. Ensure you update immediately!. SQL Injection, SQLite Security, Database Vulnerabilities, Ubuntu Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 02, 2019 Critical Ubuntu
89

Fedora 29 mingw-sqlite: 2019-49f80a78bc critical: Database DoS Issues

- update to 3.26.0.0. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-49f80a78bc 2019-08-13 01:58:20.879284 --------------------------------------------------------------------------------Name : mingw-sqlite Product : Fedora 29 Version : 3.26.0.0 Release : 1.fc29 URL : https://sqlite.org/ Summary : MinGW Windows port of sqlite embeddable SQL database engine Description : SQLite is a C library that implements an SQL database engine. A large subset of SQL92 is supported. A complete database is stored in a single disk file. The API is designed for convenience and ease of use. Applications that link against SQLite can enjoy the power and flexibility of an SQL database without the administrative hassles of supporting a separate database server. Version 2 and version 3 binaries are named to permit each to be installed on a single host This package contains cross-compiled libraries and development tools for Windows. --------------------------------------------------------------------------------Update Information: - update to 3.26.0.0 --------------------------------------------------------------------------------ChangeLog: * Thu Feb 7 2019 Thomas Sailer - 3.26.0.0-1 - update to 3.26.0.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1659908 - CVE-2018-20346 mingw-sqlite: sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1659908 [ 2 ] Bug #1558808 - CVE-2018-8740 mingw-sqlite: sqlite: NULL pointer dereference with databases with schema corrupted with CREATE TABLE AS allows for denial of service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1558808 [ 3 ] Bug #1352440 - CVE-2016-6153 mingw-sqlite: sqlite: Tempdir selection vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1352440 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-49f80a78bc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . CentOS Security Alert regarding mingw-sqlite enhancements and urgent patches impacting database framework and related software components.. mingw-sqlite, Fedora Updates, Database Security, Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 12, 2019 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here