Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 18 articles for you...
91

Gentoo: 202210-25 Low: ISC BIND Denial of Service Advisory

Multiple vulnerabilities have been discovered in ISC BIND, the worst of which could result in denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202210-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: ISC BIND: Multiple Vulnerabilities Date: October 31, 2022 Bugs: #820563, #835439, #872206 ID: 202210-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in ISC BIND, the worst of which could result in denial of service. Background ========= ISC BIND is the Internet Systems Consortium implementation of the Domain Name System (DNS) protocol. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-dns/bind < 9.16.33 > = 9.16.33 2 net-dns/bind-tools < 9.16.33 > = 9.16.33 Description ========== Multiple vulnerabilities have been discovered in ISC BIND. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All ISC BIND users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-dns/bind-9.16.33" All ISC BIND-tools users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-dns/bind-tools-9.16.33" References ========= [ 1 ] CVE-2021-25219 https://nvd.nist.gov/vuln/detail/CVE-2021-25219 [ 2 ]CVE-2021-25220 https://nvd.nist.gov/vuln/detail/CVE-2021-25220 [ 3 ] CVE-2022-0396 https://nvd.nist.gov/vuln/detail/CVE-2022-0396 [ 4 ] CVE-2022-2795 https://nvd.nist.gov/vuln/detail/CVE-2022-2795 [ 5 ] CVE-2022-2881 https://nvd.nist.gov/vuln/detail/CVE-2022-2881 [ 6 ] CVE-2022-2906 https://nvd.nist.gov/vuln/detail/CVE-2022-2906 [ 7 ] CVE-2022-3080 https://nvd.nist.gov/vuln/detail/CVE-2022-3080 [ 8 ] CVE-2022-38177 https://nvd.nist.gov/vuln/detail/CVE-2022-38177 [ 9 ] CVE-2022-38178 https://nvd.nist.gov/vuln/detail/CVE-2022-38178 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202210-25 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Uncover various weaknesses in ISC BIND presenting risks for denial of service on Gentoo Linux systems. Advisory marked as low severity.. ISC BIND Security,Gentoo Advisory,DNS Vulnerabilities,System Upgrade,Low Severity Issues. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Oct 30, 2022 Low Gentoo
197

Debian 9 Stretch DLA-2738-1 Critical: c-ares Input Validation Issue

An issue has been found in c-ares, an asynchronous name resolver. Missing input validation of host names returned by Domain Name Servers can lead to output of wrong hostnames. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2738-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz August 10, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : c-ares Version : 1.12.0-1+deb9u2 CVE ID : CVE-2021-3672 An issue has been found in c-ares, an asynchronous name resolver. Missing input validation of host names returned by Domain Name Servers can lead to output of wrong hostnames. For Debian 9 stretch, this problem has been fixed in version 1.12.0-1+deb9u2. We recommend that you upgrade your c-ares packages. For the detailed security status of c-ares please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/c-ares Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A vulnerability in c-ares may produce incorrect hostname results; an upgrade is advised. See Advisory DLA-2740-1.. c-ares Security, Debian Update, Input Validation Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 10, 2021 Critical Debian LTS
98

Red Hat Enterprise Linux 7: RHSA-2021:2417-01 Important GUPnP DNS Issue

An update for gupnp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: gupnp security update Advisory ID: RHSA-2021:2417-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:2417 Issue date: 2021-06-14 CVE Names: CVE-2021-33516 ==================================================================== 1. Summary: An update for gupnp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64 3. Description: GUPnP is an object-oriented open source framework for creating UPnP devices and control points, written in C using GObject and libsoup. The GUPnP API is intended to be easy to use, efficient and flexible. Security Fix(es): * gupnp: allows DNS rebinding which could result in tricking browser into triggering actions againstlocal UPnP services (CVE-2021-33516) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1964091 - CVE-2021-33516 gupnp: allows DNS rebinding which could result in tricking browser into triggering actions against local UPnP services 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: gupnp-1.0.2-6.el7_9.src.rpm x86_64: gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): noarch: gupnp-docs-1.0.2-6.el7_9.noarch.rpm x86_64: gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm gupnp-devel-1.0.2-6.el7_9.i686.rpm gupnp-devel-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: gupnp-1.0.2-6.el7_9.src.rpm x86_64: gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): noarch: gupnp-docs-1.0.2-6.el7_9.noarch.rpm x86_64: gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm gupnp-devel-1.0.2-6.el7_9.i686.rpm gupnp-devel-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: gupnp-1.0.2-6.el7_9.src.rpm ppc64: gupnp-1.0.2-6.el7_9.ppc.rpm gupnp-1.0.2-6.el7_9.ppc64.rpm gupnp-debuginfo-1.0.2-6.el7_9.ppc.rpm gupnp-debuginfo-1.0.2-6.el7_9.ppc64.rpm ppc64le: gupnp-1.0.2-6.el7_9.ppc64le.rpm gupnp-debuginfo-1.0.2-6.el7_9.ppc64le.rpm s390x: gupnp-1.0.2-6.el7_9.s390.rpm gupnp-1.0.2-6.el7_9.s390x.rpm gupnp-debuginfo-1.0.2-6.el7_9.s390.rpm gupnp-debuginfo-1.0.2-6.el7_9.s390x.rpm x86_64: gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): noarch: gupnp-docs-1.0.2-6.el7_9.noarch.rpm ppc64: gupnp-debuginfo-1.0.2-6.el7_9.ppc.rpm gupnp-debuginfo-1.0.2-6.el7_9.ppc64.rpm gupnp-devel-1.0.2-6.el7_9.ppc.rpm gupnp-devel-1.0.2-6.el7_9.ppc64.rpm ppc64le: gupnp-debuginfo-1.0.2-6.el7_9.ppc64le.rpm gupnp-devel-1.0.2-6.el7_9.ppc64le.rpm s390x: gupnp-debuginfo-1.0.2-6.el7_9.s390.rpm gupnp-debuginfo-1.0.2-6.el7_9.s390x.rpm gupnp-devel-1.0.2-6.el7_9.s390.rpm gupnp-devel-1.0.2-6.el7_9.s390x.rpm x86_64: gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm gupnp-devel-1.0.2-6.el7_9.i686.rpm gupnp-devel-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: gupnp-1.0.2-6.el7_9.src.rpm x86_64: gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): noarch: gupnp-docs-1.0.2-6.el7_9.noarch.rpm x86_64: gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm gupnp-devel-1.0.2-6.el7_9.i686.rpm gupnp-devel-1.0.2-6.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-33516 https://access.redhat.com/security/updates/classification#important 8. Contact: TheRed Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYMfDBtzjgjWX9erEAQh4wA//SuhKPeuUIZWeQkt2mZncTtxzm+gW/IW7 eI0HkcCZ2pAFBHk9RnAOOR4Os3er7+H/jmHpVy/DHzWqzIORZK/2hraQD2+FT7BF QZvLUKqQVUIe4XM1XTKuaQfJ7ObDnWqzKpML1m+wRcdMZjSnh5FRolB/TY2dCadJ 23RdlurPEqdHfzCscguvOX6IQQB+hzL1yEPCveQZZvAbZfqNzJatHlz1My0XJWh1 GVGeGFZea+D85F5WJXvvPbaMTrEBEgfcUDKZ+bI+YJUVyYzNu9mGlihdP0hh2nSw BKOyhTbPtDfCrMTlUtpMS0F3KE+yjrWWfKzdTUWiaHkNvTwa55kWz4LY44z8o/FK 7sjZjWy5cTNdurmWgND997u4FnToPGZRc989TifLg44gHMIDzlO/8BKbcMoXTKIz J1AY+A+POOL8r5BTQX0+tRE1NvxjXCNN1uOA1UshiutM06HhQFJ6wV9v1//1Sj1B QJFtI+WHRr4Gb6dr32wgxnvN+OjOWeA5uoBfn8EY8KUS3PQny7GzJx//Q7L99rVZ tRU1WGrKoo8cXFrfCuDdd3j7TlH6POk+qkUDY8eWoUiqAmxKDGZP177sddmOgK7y 4+6g1G40ex5VnTgZr+GB45b2vVIOGZ9e383BNAsL+TcjnWJKUC92fd+LY+eMhgpV m02U4ORvOnE=6QHR -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . Gupnp vulnerability patch for Red Hat Enterprise Linux classified as Significant. Discover the specifics and remedial actions here.. Gupnp Update, Red Hat Security, Linux Security Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 14, 2021 Important Red Hat
98

Red Hat 6: RHSA-2021-1468 Critical Update Regarding Bind DNS Security

An update for bind is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: bind security update Advisory ID: RHSA-2021:1468-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:1468 Issue date: 2021-04-29 CVE Names: CVE-2021-25215 ==================================================================== 1. Summary: An update for bind is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server (v. 6 ELS) - i386, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6 ELS) - i386, s390x, x86_64 3. Description: The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. Security Fix(es): * bind: An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself (CVE-2021-25215) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes thechanges described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, the BIND daemon (named) will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1953857 - CVE-2021-25215 bind: An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself 6. Package List: Red Hat Enterprise Linux Server (v. 6 ELS): Source: bind-9.8.2-0.68.rc1.el6_10.11.src.rpm i386: bind-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-chroot-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-libs-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-utils-9.8.2-0.68.rc1.el6_10.11.i686.rpm s390x: bind-9.8.2-0.68.rc1.el6_10.11.s390x.rpm bind-chroot-9.8.2-0.68.rc1.el6_10.11.s390x.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.s390.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.s390x.rpm bind-libs-9.8.2-0.68.rc1.el6_10.11.s390.rpm bind-libs-9.8.2-0.68.rc1.el6_10.11.s390x.rpm bind-utils-9.8.2-0.68.rc1.el6_10.11.s390x.rpm x86_64: bind-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm bind-chroot-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm bind-libs-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-libs-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm bind-utils-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6ELS): i386: bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-devel-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-sdb-9.8.2-0.68.rc1.el6_10.11.i686.rpm s390x: bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.s390.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.s390x.rpm bind-devel-9.8.2-0.68.rc1.el6_10.11.s390.rpm bind-devel-9.8.2-0.68.rc1.el6_10.11.s390x.rpm bind-sdb-9.8.2-0.68.rc1.el6_10.11.s390x.rpm x86_64: bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm bind-devel-9.8.2-0.68.rc1.el6_10.11.i686.rpm bind-devel-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm bind-sdb-9.8.2-0.68.rc1.el6_10.11.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-25215 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYIqbJ9zjgjWX9erEAQjwPg//SzKTahpLsqjnYf0oNawBZ5PLs39kfn+k SL5o2YzI9klcTQJ9WSz9Ty/vXKw1gHiI31YdSgLDxHayrp4eQIZn+c3vSiQf2mxh cE2qwJZCxfTRv38eOc1zKNWj9e73GJLx9ZQSaPUBB7cRHjIOs0acdkLOHGjZkvOI bjVza/JEw+eLRkJRhk8rxiWn4kjBF5Jyr+ciClySvGcLfGIc95H0rB+pSJhLxoGs 6BknesCQofbfL8jKyUChwbZ0a4CLUYh2EA3u5+KYa+qnwry/Wcy3E5yrWwMFMvV/ BQAJ4YWtQSaK7sRMkEPMMChNO010QdAmqVW7XkA7q1UMo51tsk6yCdxWnA1gbhWc UL2KbjnLv0tfPN/Bi9c4K1gEoiVQaUBKsbkqxKhjd2CQBUN8LhanGsF5n/aJFqzm XGw7nvn/lxiLC0KCIOD2b1ZKUszsR/ELMEWvCOB/VSjAsoVxIK2fsX8oRaTg1Cd+ jB+YlFQAUD64PpnK+RRRZ9GRTihAFvFPO1CHbiw+91nOWr+7HS7AR1BCPGPBmss3 SaerPj40tVSuL/fAH/vVSCviO94yXLZz7w22wGdiSvp8ze7G7yltJVhsUnrz/Wb8 IJc8nKLqhTEXjzvi7hMda2C4ZGzY8vQPGlw0Ns04HNc3zkOk3AXhALmp0D3TdvrF lm/YyuGfPFY=2CXa -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . CentOS Linux 7receives a significant samba patch addressing a vulnerability in file sharing protocols that could impact server stability.. Red Hat Security, Bind Update, DNS Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 29, 2021 Important Red Hat
98

Red Hat: RHSA-2021-0830-01 Important: DoS and DNS Issues in Node.js

An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-nodejs14-nodejs security update Advisory ID: RHSA-2021:0830-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2021:0830 Issue date: 2021-03-15 CVE Names: CVE-2021-22883 CVE-2021-22884 ==================================================================== 1. Summary: An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The following packages have been upgraded to a later upstream version: rh-nodejs14-nodejs (14.16.0). Security Fix(es): * nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion (CVE-2021-22883) * nodejs: DNS rebinding in --inspect (CVE-2021-22884) For more details about the securityissue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1932014 - CVE-2021-22883 nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion 1932024 - CVE-2021-22884 nodejs: DNS rebinding in --inspect 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-nodejs14-nodejs-14.16.0-1.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.16.0-1.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.16.0-1.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.s390x.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.6): Source: rh-nodejs14-nodejs-14.16.0-1.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.16.0-1.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.16.0-1.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.s390x.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7): Source: rh-nodejs14-nodejs-14.16.0-1.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.16.0-1.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.ppc64le.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.16.0-1.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.s390x.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7): Source: rh-nodejs14-nodejs-14.16.0-1.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.16.0-1.el7.noarch.rpm x86_64: rh-nodejs14-nodejs-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.16.0-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.16.0-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.11-14.16.0.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature areavailable from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-22883 https://access.redhat.com/security/cve/CVE-2021-22884 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYE91GtzjgjWX9erEAQgBwg//RHeMzqbG5jkH3mulMlcMywzYaKQHEA77 AvPSPduX7hyXy4VOG4CWZXxoPKb9xibBs1zuDE4JkrWeDv+1+EsijoTfurvYXVRk QpOA4TO3zI0sKuMpEtux4WyEsnj4AcF+7BFNU8yxla0hp5O7OxT1WmJmexW6Qtlv /l54p5OTcSaZdfzW+yEgkZXUi1MpHOllhSDWRolxfHSnU3ZC9MYVfIEFnIoOtpZa wcvpUhS7g7h6f8xl5f3Z58YEFllGvKiKRUl+x/fT7fb1XN0P5yRLywxwwvk0ikci +uAZ3APornOXShEPVbl669kdghmawjP1RbhsUMayfsvNQqY6pjWl8Menk4Z0jYnR UJ2dD1Xv2jCGaQLZEslZ1HQy82GndZ47F2diEr4S4HH5b9wh9EN0aE8XmaCFLfQH uZQCQ1wPh5p/Fq/ZHk9kz5ZoNbBmprpxSZUA6lXBipBYEWjujY28ttLopNUjkZPA YZnitrBvEi+YtVAR0lCc6UVVe/Kq6UfZThrCHSzXmLs/ZfJib0i0lLKXsPd9iTAD UoHsBIlaFqqYmGluU5q3zDAVkjWubzNu/+ehWSAzZYWUKz/XCYoxLy4a+M5yuLZp Y6YUf1e+c8UyQQ2S6+pr7ZaljYdvDZVuA31p+V5YkSWv0cUMfUhdBC/i/EdGwGjs W0DWQFhzzUU=hSAO -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . Discover the crucial security patch for rh-nodejs14-nodejs that affects Red Hat Software Collections, including all relevant specifics.. NodeJs Security Update, Red Hat Advisory, DoS Issue, DNS Security, Software Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 15, 2021 Important Red Hat
89

Fedora: 34 Critical Advisory for Python and Node.js DoS Risks

https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-f6bd75e9d4 2021-03-12 00:06:28.167832 --------------------------------------------------------------------------------Name : nodejs Product : Fedora 32 Version : 12.21.0 Release : 2.fc32 URL : https://nodejs.org/en/ Summary : JavaScript runtime Description : Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. --------------------------------------------------------------------------------Update Information: https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/ --------------------------------------------------------------------------------ChangeLog: * Thu Feb 25 2021 Stephen Gallagher - 1:12.21.0-2 - Backport patch to use getauxval * Tue Feb 23 2021 Stephen Gallagher - 1:12.21.0-1 - Update to 12.21.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1932016 - CVE-2021-22883 nodejs:10/nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932016 [ 2 ] Bug #1932018 - CVE-2021-22883 nodejs:14/nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932018 [ 3 ] Bug #1932019 - CVE-2021-22883 nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932019 [ 4 ] Bug #1932020 - CVE-2021-22883 nodejs:12/nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932020 [ 5 ] Bug #1932026 - CVE-2021-22884 nodejs:10/nodejs: DNS rebinding in --inspect [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932026 [ 6 ] Bug #1932028 - CVE-2021-22884 nodejs:14/nodejs: DNS rebinding in --inspect [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932028 [ 7 ] Bug #1932029 - CVE-2021-22884 nodejs: DNS rebinding in --inspect [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932029 [ 8 ] Bug #1932030 - CVE-2021-22884 nodejs:12/nodejs: DNS rebinding in --inspect [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1932030 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-f6bd75e9d4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Stay secure with the latest Fedora 32 update for Node.js, addressing critical vulnerabilities in HTTP2 and DNS. Update now to ensure safety. Fedora Security, Nodejs Update, DoS Threats, DNS Issues. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Mar 11, 2021 Critical Fedora
203

Mageia 2019-0270: Security Update Addressing Links DNS Vulnerability

Security bug fixed: when links was connected to tor, it would send real dns requests outside the tor network when the displayed page contains link rel="dns-prefetch" code References: . MGASA-2019-0270 - Updated links packages fix security vulnerability Publication date: 12 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0270.html Type: security Affected Mageia releases: 6, 7 Security bug fixed: when links was connected to tor, it would send real dns requests outside the tor network when the displayed page contains link rel="dns-prefetch" code References: - https://bugs.mageia.org/show_bug.cgi?id=25378 - http://links.twibright.com/download/ChangeLog SRPMS: - 7/core/links-2.20-1.mga7 - 6/core/links-2.20-1.mga6 . An advisory has been released regarding Mageia’s links package, focusing on DNS-related vulnerabilities. This applies to both versions 6 and 7, with updates provided to enhance security.. Mageia Security, Links Package Fix, DNS Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 12, 2019 Important Mageia
100

SUSE: 2019:0579-1 Important: Ovmf Buffer Overflow & DNS Issues

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for ovmf ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0579-1 Rating: important References: #1127820 #1127821 #1127822 Cross-References: CVE-2018-12178 CVE-2018-12180 CVE-2018-3630 Affected Products: SUSE Linux Enterprise Server 12-SP3 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for ovmf fixes the following issues: Security issues fixed: - CVE-2018-12180: Fixed a buffer overflow in BlockIo service, which could lead to memory read/write overrun (bsc#1127820). - CVE-2018-12178: Fixed an improper DNS check upon receiving a new DNS packet (bsc#1127821). - CVE-2018-3630: Fixed a logic error in FV parsing which could allow a local attacker to bypass the chain of trust checks (bsc#1127822). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-579=1 Package List: - SUSE Linux Enterprise Server 12-SP3 (aarch64 x86_64): ovmf-2017+git1492060560.b6d11d7c46-4.20.1 ovmf-tools-2017+git1492060560.b6d11d7c46-4.20.1 - SUSE Linux Enterprise Server 12-SP3 (noarch): qemu-ovmf-x86_64-2017+git1492060560.b6d11d7c46-4.20.1 qemu-uefi-aarch64-2017+git1492060560.b6d11d7c46-4.20.1 References: https://www.suse.com/security/cve/CVE-2018-12178.html https://www.suse.com/security/cve/CVE-2018-12180.html https://www.suse.com/security/cve/CVE-2018-3630.html https://bugzilla.suse.com/1127820 https://bugzilla.suse.com/1127821 https://bugzilla.suse.com/1127822 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Update: Security update for ovmf _____________________________________________________. update, security, fixes, three, vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 11, 2019 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200