Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
197

Debian Buster: DLA-3824-1 Low: GStreamer Integer Overflow

An integer overflow in the EXIF metadata parser has been fixed in the GStreamer media framework. For Debian 10 buster, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3824-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk May 30, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : gst-plugins-base1.0 Version : 1.14.4-2+deb10u3 CVE ID : CVE-2024-4453 An integer overflow in the EXIF metadata parser has been fixed in the GStreamer media framework. For Debian 10 buster, this problem has been fixed in version 1.14.4-2+deb10u3. We recommend that you upgrade your gst-plugins-base1.0 packages. For the detailed security status of gst-plugins-base1.0 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/gst-plugins-base1.0 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Critical integer overflow vulnerability addressed in EXIF metadata parser within GStreamer for Debian Buster. Immediate upgrade advised to maintain security.. Debian Security Updates, GStreamer Fix, Integer Overflow Issue. . Severity: Low. LinuxSecurity.com Team

Calendar 2 May 30, 2024 Low Debian LTS
197

Debian 10 Buster DLA-3450-1 Critical: Ruby2.5 Input Handling Issues

A couple of security issues were discovered in ruby2.5, the Ruby interpreter, and are as follows - CVE-2021-33621 . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3450-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta June 09, 2023 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : ruby2.5 Version : 2.5.5-3+deb10u6 CVE ID : CVE-2021-33621 CVE-2022-28739 Debian Bug : 1009957 1024800 1037178 A couple of security issues were discovered in ruby2.5, the Ruby interpreter, and are as follows - CVE-2021-33621 Hiroshi Tokumaru discovered that Ruby did not properly handle certain user input for applications the generate HTTP responses using cgi gem. An attacker could possibly use this issue to maliciously modify the response a user would receive from a vulnerable application. CVE-2022-28739 It was discovered that Ruby incorrectly handled certain inputs. An attacker could possibly use this issue to expose sensitive information. For Debian 10 buster, these problems have been fixed, along with the regressions caused by the last Ruby update, in version 2.5.5-3+deb10u6. We recommend that you upgrade your ruby2.5 packages. For the detailed security status of ruby2.5 please refer to its security tracker page at: Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu LTS Notice USN-4900-1 highlights vulnerabilities in python3.8, urging users to perform an upgrade for improved safety.. Debian Security Update,Ruby2.5 Patch,CGI Input Handling Fix,Debian LTS Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 09, 2023 Critical Debian LTS
197

Debian 10 Buster DLA-3190-1 Critical: Grub2 UEFI Bypass and Code Execution

Several issues were found in GRUB2's font handling code, which could result in crashes and potentially execution of arbitrary code. These could lead to by-pass of UEFI Secure Boot on affected systems. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3190-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Steve McIntyre November 16, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : grub2 Version : 2.06-3~deb10u2 CVE ID : CVE-2022-2601 CVE-2022-3775 Several issues were found in GRUB2's font handling code, which could result in crashes and potentially execution of arbitrary code. These could lead to by-pass of UEFI Secure Boot on affected systems. Further, issues were found in image loading that could potentially lead to memory overflows. For Debian 10 buster, these problems have been fixed in version 2.06-3~deb10u2. We recommend that you upgrade your grub2 packages. For the detailed security status of grub2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/grub2 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3190-1 outlines significant grub2 vulnerabilities that enable UEFI circumvention and potential arbitrary code execution.. Debian Security, Grub2 Update, UEFI Bypass, Memory Management, Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 16, 2022 Critical Debian LTS
87

Debian Stretch and Buster: DSA-4582-1 Moderate: DAViCal Security Issue

Multiple cross-site scripting and cross-site request forgery issues were discovered in the DAViCal CalDAV Server. For the oldstable distribution (stretch), these problems have been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4582-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff December 13, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : davical CVE ID : CVE-2019-18345 CVE-2019-18346 CVE-2019-18347 Debian Bug : 946343 Multiple cross-site scripting and cross-site request forgery issues were discovered in the DAViCal CalDAV Server. For the oldstable distribution (stretch), these problems have been fixed in version 1.1.5-1+deb9u1. For the stable distribution (buster), these problems have been fixed in version 1.1.8-1+deb10u1. We recommend that you upgrade your davical packages. For the detailed security status of davical please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/davical Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several vulnerabilities related to XSS and CSRF have been addressed in DAViCal for the Debian stretch and buster releases, bolstering overall security.. Davical Security, Debian Update, Cross-Site Scripting Issues. . LinuxSecurity.com Team

Calendar 2 Dec 13, 2019 Debian
87

Debian Buster DSA-4571-2: Enigmail Update Resolves Thunderbird Issues

DSA 4571-1 updated Thunderbird to the 68.x series, which is incompatible with the Enigmail release shipped in Debian Buster. For the stable distribution (buster), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4571-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff November 24, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : enigmail DSA 4571-1 updated Thunderbird to the 68.x series, which is incompatible with the Enigmail release shipped in Debian Buster. For the stable distribution (buster), this problem has been fixed in version 2:2.1.3+ds1-4~deb10u2. We recommend that you upgrade your enigmail packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Security Advisory DSA-4571-2 resolves issues related to the incompatibility experienced by Enigmail and Thunderbird users on the Debian Buster platform.. Debian Update, Enigmail Security, Thunderbird Compatibility, Package Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 24, 2019 Important Debian
87

Debian: DSA-4535-1 Moderate: e2fsprogs Buffer Overflow Risk

Lilith of Cisco Talos discovered a buffer overflow flaw in the quota code used by e2fsck from the ext2/ext3/ext4 file system utilities. Running e2fsck on a malformed file system can result in the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4535-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso September 27, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : e2fsprogs CVE ID : CVE-2019-5094 Debian Bug : 941139 Lilith of Cisco Talos discovered a buffer overflow flaw in the quota code used by e2fsck from the ext2/ext3/ext4 file system utilities. Running e2fsck on a malformed file system can result in the execution of arbitrary code. For the oldstable distribution (stretch), this problem has been fixed in version 1.43.4-2+deb9u1. For the stable distribution (buster), this problem has been fixed in version 1.44.5-1+deb10u2. We recommend that you upgrade your e2fsprogs packages. For the detailed security status of e2fsprogs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/e2fsprogs Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Bulletin DSA-4536-1: e2fsprogs presents a critical memory corruption issue that could lead to potential exploitation in specific cases.. e2fsprogs buffer overflow, Debian security update, malformed filesystem issue, execution risk vulnerability. . LinuxSecurity.com Team

Calendar 2 Sep 27, 2019 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here