Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 477
Alerts This Week
Warning Icon 1 477

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
87

Debian: DSA-4020-1 Critical: Chromium Browser Heap Overflow Issues

Several vulnerabilities have been discovered in the chromium web browser. In addition, this message serves as an annoucment that security support for chromium in the oldstable release (jessie), Debian 8, is now discontinued. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4020-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Michael Gilbert November 05, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : chromium-browser CVE ID : CVE-2017-5124 CVE-2017-5125 CVE-2017-5126 CVE-2017-5127 CVE-2017-5128 CVE-2017-5129 CVE-2017-5131 CVE-2017-5132 CVE-2017-5133 CVE-2017-15386 CVE-2017-15387 CVE-2017-15388 CVE-2017-15389 CVE-2017-15390 CVE-2017-15391 CVE-2017-15392 CVE-2017-15393 CVE-2017-15394 CVE-2017-15395 CVE-2017-15396 Several vulnerabilities have been discovered in the chromium web browser. In addition, this message serves as an annoucment that security support for chromium in the oldstable release (jessie), Debian 8, is now discontinued. Debian 8 chromium users that desire continued security updates are strongly encouraged to upgrade now to the current stable release (stretch), Debian 9. An alternative is to switch to the firefox browser, which will continue to receive security updates in jessie for some time. CVE-2017-5124 A cross-site scripting issue was discovered in MHTML. CVE-2017-5125 A heap overflow issue was discovered in the skia library. CVE-2017-5126 Luat Nguyen discovered a use-after-free issue in the pdfium library. CVE-2017-5127 Luat Nguyen discovered another use-after-free issue in the pdfium library. CVE-2017-5128 Omair discovered a heap overflow issue in the WebGL implementation. CVE-2017-5129 Omair discovered a use-after-free issue in the WebAudioimplementation. CVE-2017-5131 An out-of-bounds write issue was discovered in the skia library. CVE-2017-5132 Guarav Dewan discovered an error in the WebAssembly implementation. CVE-2017-5133 Aleksandar Nikolic discovered an out-of-bounds write issue in the skia library. CVE-2017-15386 WenXu Wu discovered a user interface spoofing issue. CVE-2017-15387 Jun Kokatsu discovered a way to bypass the content security policy. CVE-2017-15388 Kushal Arvind Shah discovered an out-of-bounds read issue in the skia library. CVE-2017-15389 xisigr discovered a URL spoofing issue. CVE-2017-15390 Haosheng Wang discovered a URL spoofing issue. CVE-2017-15391 Joao Lucas Melo Brasio discovered a way for an extension to bypass its limitations. CVE-2017-15392 Xiaoyin Liu discovered an error the implementation of registry keys. CVE-2017-15393 Svyat Mitin discovered an issue in the devtools. CVE-2017-15394 Sam discovered a URL spoofing issue. CVE-2017-15395 Johannes Bergman discovered a null pointer dereference issue. CVE-2017-15396 Yuan Deng discovered a stack overflow issue in the v8 javascript library. For the oldstable distribution (jessie), security support for chromium has been discontinued. For the stable distribution (stretch), these problems have been fixed in version 62.0.3202.75-1~deb9u1. For the testing distribution (buster), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 62.0.3202.75-1. We recommend that you upgrade your chromium-browser packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple security flaws discovered in chromium-browser. Update immediately to ensure ongoing protection on Debian.. Chromium Browser Update, Debian Security Advisory, Web BrowserVulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 07, 2017 Critical Debian
202

openSUSE 11.4 End of Official Support: Evergreen Maintenance Begins

openSUSE: openSUSE 11.4 has reached end of SUSE support - 11.4 Evergreen goes on. Hi, With the release of ruby on Monday 5th of November the SUSE sponsored maintenance of openSUSE 11.4 has ended. openSUSE 11.4 is now officially discontinued and out of support by SUSE. openSUSE 11.4 was the first openSUSE distribution maintained using OpenBuildService methods (known as "OBS Maintenance"), allowing full community participation. We also migrated it from the old internal SUSE method to the OBS method on the fly during the lifetime without any interruption. openSUSE 11.4 will be continued to be maintained by the Evergreen community team. Their wikipage is on https://en.opensuse.org/Evergreen , please check it out for more information. Here are some statistics: openSUSE 11.4 was released on March 4th 2011, making it 20 months of security and bugfix support. (2 openSUSE releases + 2 months) Some statistics on the released patches (compared to 11.3): Total updates: 723 (+142) Security: 416 (+58) Recommended: 306 (+85) Optional: 1 (-1) Quite some increase on updates, both security and bugfix wise. Some of this is due to the 2 months increased lifetime compared to openSUSE 11.3, some of this is due to a more open community bugfix involvement. CVE Entries: 1113 (-99) Top issues (compared to 11.3 for issues down to 5) 10 seamonkey (-4) 10 MozillaFirefox (-2) 9 php5 (+4) 9 MozillaThunderbird (-2) 8 flash-player (-4) 6 wireshark (+1) 6 opera (-4) 6 java-1_6_0-openjdk (-1) 6 bind ( 0) 5 openssl (-2) 5 libpng14 (new) 5 icedtea-web (new) And top issues sorted by CVE (Common Vulnerability Enumeration) count down to 10) (comparison to 11.3 for some ... but due to the OBS maintenance migration some CVEs are not easily accounted for) 139 MozillaThunderbird (+26) 139 MozillaFirefox (+28) 135 seamonkey (-3) 67 kernel (-61) 56 java-1_6_0-openjdk 44 flash-player (+38) 41 mozilla-nspr 30 mysql-community-server 29php5 26 mozilla-kde4-integration 21 mariadb 21 freetype2 20 java-1_6_0-sun 18 wireshark 18 mozilla-xulrunner192 17 mysql-cluster 13 rubygem-actionpack-2_3 12 xen 11 rubygem-activerecord-2_3 10 rubygem-activesupport-2_3 10 puppet 10 libpng14 . The lifecycle of Fedora 34 has reached its conclusion, moving into a community-driven phase for updates and fixes.. openSUSE 11.4,support summary,Evergreen Maintenance,security updates,community support. . LinuxSecurity.com Team

Calendar%202 Nov 06, 2012 OpenSUSE
100

SuSE Linux 6.4 Discontinued: No Security Updates After June 2002

SuSE has announced that they will be discontinuing support for SuSE Linux version 6.4 after June 17, 2002.. Date: Mon, 10 Jun 2002 23:54:19 +0200 (MEST) From: Roman Drahtmueller To: This email address is being protected from spambots. You need JavaScript enabled to view it. Subject: [suse-security-announce] Supported Distributions Dear suse-security-announce subscriber, With the release of the SuSE Linux 8.0 i386 ftp version, we announce that the SuSE Linux 6.4 distribution will be discontinued. The high quality standard at SuSE and new features necessary for ftp support required extensive testing of the SuSE Linux 8.0 i386 ftp version. We regret the delay that was the result. Vulnerabilities found after Monday, June 17 2002, will not receive a fix for SuSE Linux 6.4 any more. After two years of successful use, SuSE Linux 6.4 will free resources for the newly released products. By consequence, the 6.4 distributions directories on the ftp server have been moved to the discontinued directory structure; the 6.4 directories in the update trees will follow near the end of the month, soon after all update packages have been published. SuSE puts much effort into adding security improvements (patches) to the software instead of publishing a new version; the same program with a fix for a specific problem promises to work just as reliable as the original version from the distribution, whereas new versions introduce new functionality which changes the behaviour. In some cases however, especially if the security leak is based on problematic design decisions or when the fix(es) are fairly large, the only reasonable fix for a security problem is to update to a newer version of the software. These newer versions tend to become incompatible with our older distribution releases because of missing features in the operating system environment. This forces us to focus on the distributions of a newer release date. As usual, SuSE will continue to provide update packages for the remaining distributions SuSE-7.0 SuSE-7.1 SuSE-7.2 SuSE-7.3 and SuSE-8.0 for a two-year periodafter the release of the respective distribution. Our SLES (SuSE Linux Enterprise Server) products and the patches support for them are not affected by this announcement. If you have any questions regarding this announcement, please send email to This email address is being protected from spambots. You need JavaScript enabled to view it. (primary security contact). Regards, Roman Drahtmuller, SuSE Security. -- - - | Roman Drahtm�ller // "You don't need eyes to see, | SuSE Linux AG - Security Phone: // you need vision!" | N�rnberg, Germany +49-911-740530 // Maxi Jazz, Faithless | - - . SuSE officially discontinues support for version 6.4, halting security updates post-June 2002, affecting users.. SuSE Linux, Support Discontinuation, Security Management. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Jun 11, 2002 Informational SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200