Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
197

Debian 9 Stretch DLA-2948-1: Refresh GnuPG Archive Signing Keys

debian-archive-keyring is a package containing GnuPG archive keys of the Debian archive. New GPG-keys are being constantly added with every new Debian release. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2948-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Anton Gladky March 13, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : debian-archive-keyring Version : 2017.5+deb9u2 debian-archive-keyring is a package containing GnuPG archive keys of the Debian archive. New GPG-keys are being constantly added with every new Debian release. For Debian 9 stretch, GPG-keys for 11/bullseye Debian release are added in the version 2017.5+deb9u2. We recommend that you upgrade your debian-archive-keyring packages only if you need to work with packages from 11/bullseye release. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance debian-archive-keyring for GPG key administration as per DLA-2948-1 advisory. Ensure safety with Debian patches.. Debian LTS, GnuPG Keys, Key Management, Security Update. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Mar 13, 2022 Informational Debian LTS
197

Debian Stretch DLA-2866-1: uw-imap Security Update for IMAP Access

Access to IMAP mailboxes through running imapd over rsh and ssh is now disabled by default in uw-imap, the University of Washington IMAP Toolkit. Code using the library can enable it with tcp_parameters() after making sure that the IMAP server name is sanitized. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2866-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk December 29, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : uw-imap Version : 8:2007f~dfsg-5+deb9u1 CVE ID : CVE-2018-19518 Debian Bug : 914632 Access to IMAP mailboxes through running imapd over rsh and ssh is now disabled by default in uw-imap, the University of Washington IMAP Toolkit. Code using the library can enable it with tcp_parameters() after making sure that the IMAP server name is sanitized. For Debian 9 stretch, this problem has been fixed in version 8:2007f~dfsg-5+deb9u1. We recommend that you upgrade your uw-imap packages. For the detailed security status of uw-imap please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/uw-imap Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance uw-imap software versions in Debian LTS DLA-2866-1 to restrict mailbox access via rsh/ssh protocols as a standard setting.. Debian Update, IMAP Security, uw-imap Advisory, IMAP Toolkit Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 29, 2021 Critical Debian LTS
197

Debian Stretch DLA-2663-1 Critical: Libimage-Exiftool-Perl Execution Risk

A vulnerability was discovered in libimage-exiftool-perl, a library and program to read and write meta information in multimedia files, which may result in execution of arbitrary code if a malformed DjVu file is processed. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2663-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta May 16, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : libimage-exiftool-perl Version : 10.40-1+deb9u1 CVE ID : CVE-2021-22204 Debian Bug : 987505 A vulnerability was discovered in libimage-exiftool-perl, a library and program to read and write meta information in multimedia files, which may result in execution of arbitrary code if a malformed DjVu file is processed. For Debian 9 stretch, this problem has been fixed in version 10.40-1+deb9u1. We recommend that you upgrade your libimage-exiftool-perl packages. For the detailed security status of libimage-exiftool-perl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libimage-exiftool-perl Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An important security patch for libimage-exiftool-perl mitigates the threat of code execution stemming from improperly structured DjVu documents.. Debian LTS, Libimage-Exiftool, Critical Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 16, 2021 Critical Debian LTS
197

Debian 9 Stretch: DLA-2495-1 Moderate: Tomcat8 HTTP Header Leak

It was discovered that Apache Tomcat from 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2495-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta December 16, 2020 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : tomcat8 Version : 8.5.54-0+deb9u5 CVE ID : CVE-2020-17527 It was discovered that Apache Tomcat from 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests. For Debian 9 stretch, this problem has been fixed in version 8.5.54-0+deb9u5. We recommend that you upgrade your tomcat8 packages. For the detailed security status of tomcat8 please refer to its security tracker page at: Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance your Tomcat8 installations in Debian 9 Stretch to resolve an HTTP/2 vulnerability that could allow unintended information exposure.. Debian Stretch, Tomcat8 Update, HTTP/2 Security Fix. . LinuxSecurity.com Team

Calendar%202 Dec 16, 2020 Debian LTS
87

Debian Stretch and Buster: DSA-4582-1 Moderate: DAViCal Security Issue

Multiple cross-site scripting and cross-site request forgery issues were discovered in the DAViCal CalDAV Server. For the oldstable distribution (stretch), these problems have been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4582-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff December 13, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : davical CVE ID : CVE-2019-18345 CVE-2019-18346 CVE-2019-18347 Debian Bug : 946343 Multiple cross-site scripting and cross-site request forgery issues were discovered in the DAViCal CalDAV Server. For the oldstable distribution (stretch), these problems have been fixed in version 1.1.5-1+deb9u1. For the stable distribution (buster), these problems have been fixed in version 1.1.8-1+deb10u1. We recommend that you upgrade your davical packages. For the detailed security status of davical please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/davical Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several vulnerabilities related to XSS and CSRF have been addressed in DAViCal for the Debian stretch and buster releases, bolstering overall security.. Davical Security, Debian Update, Cross-Site Scripting Issues. . LinuxSecurity.com Team

Calendar%202 Dec 13, 2019 Debian
87

Debian: DSA-4535-1 Moderate: e2fsprogs Buffer Overflow Risk

Lilith of Cisco Talos discovered a buffer overflow flaw in the quota code used by e2fsck from the ext2/ext3/ext4 file system utilities. Running e2fsck on a malformed file system can result in the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4535-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso September 27, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : e2fsprogs CVE ID : CVE-2019-5094 Debian Bug : 941139 Lilith of Cisco Talos discovered a buffer overflow flaw in the quota code used by e2fsck from the ext2/ext3/ext4 file system utilities. Running e2fsck on a malformed file system can result in the execution of arbitrary code. For the oldstable distribution (stretch), this problem has been fixed in version 1.43.4-2+deb9u1. For the stable distribution (buster), this problem has been fixed in version 1.44.5-1+deb10u2. We recommend that you upgrade your e2fsprogs packages. For the detailed security status of e2fsprogs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/e2fsprogs Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Bulletin DSA-4536-1: e2fsprogs presents a critical memory corruption issue that could lead to potential exploitation in specific cases.. e2fsprogs buffer overflow, Debian security update, malformed filesystem issue, execution risk vulnerability. . LinuxSecurity.com Team

Calendar%202 Sep 27, 2019 Debian
87

Debian: DSA-4434-1 Critical Update for Drupal7 Cross-Site Scripting

A cross-site scripting vulnerability has been found in Drupal, a fully-featured content management framework. For additional information, please refer to the upstream advisory at https:// . . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4434-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso April 20, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : drupal7 CVE ID : CVE-2019-11358 Debian Bug : 927330 A cross-site scripting vulnerability has been found in Drupal, a fully-featured content management framework. For additional information, please refer to the upstream advisory at https:// . For the stable distribution (stretch), this problem has been fixed in version 7.52-2+deb9u8. We recommend that you upgrade your drupal7 packages. For the detailed security status of drupal7 please refer to its security tracker page at: Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Ubuntu Security Notice USN-4344-1 concerns a vulnerability related to cross-site scripting discovered in Drupal 7. Please ensure you update your system urgently.. Drupal Security, Cross-Site Scripting, Debian Advisory, Drupal7 Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 20, 2019 Critical Debian
87

Debian Stretch: DSA-4387-2 Critical: Openssh File Overwrite Issue

It was found that a security update (DSA-4387-1) of OpenSSH, an implementation of the SSH protocol suite, was incomplete. This update did not completely fix CVE-2019-6111, an arbitrary file overwrite vulnerability in the scp client implementing the SCP protocol. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4387-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Yves-Alexis Perez March 02, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openssh CVE ID : CVE-2019-6111 Debian Bug : 923486 It was found that a security update (DSA-4387-1) of OpenSSH, an implementation of the SSH protocol suite, was incomplete. This update did not completely fix CVE-2019-6111, an arbitrary file overwrite vulnerability in the scp client implementing the SCP protocol. For the stable distribution (stretch), this problem has been fixed in version 1:7.4p1-10+deb9u6. We recommend that you upgrade your openssh packages. For the detailed security status of openssh please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openssh Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Security Announcement DSA-4390-1 concerns a partial resolution of a vulnerability tied to OpenSSH's handling of user files.. Debian Security, OpenSSH, Security Update, File Overwrite, DSA-4387-2. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 02, 2019 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here