Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 34: 2021-54a73a7112 Critical: Dogtag PKI Admin Credential Exposure

[Bug 1967401](https://bugzilla.redhat.com/show_bug.cgi?id=1967401) - [CVE-2021-3551](https://access.redhat.com/security/cve/CVE-2021-3551) pki-core: pki-server: Dogtag installer "pkispawn" logs admin credentials into a world- readable log file. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-54a73a7112 2021-06-18 01:07:19.135549 --------------------------------------------------------------------------------Name : dogtag-pki Product : Fedora 34 Version : 10.10.6 Release : 1.fc34 URL : https://www.dogtagpki.org Summary : Dogtag PKI Package Description : Dogtag PKI is an enterprise software system designed to manage enterprise Public Key Infrastructure deployments. PKI consists of the following components: * Automatic Certificate Management Environment (ACME) Responder * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) --------------------------------------------------------------------------------Update Information: [Bug 1967401](https://bugzilla.redhat.com/show_bug.cgi?id=1967401) -[CVE-2021-3551](https://access.redhat.com/security/cve/CVE-2021-3551) pki-core: pki-server: Dogtag installer "pkispawn" logs admin credentials into a world-readable log file --------------------------------------------------------------------------------ChangeLog: * Wed Jun 9 2021 Dogtag PKI Team - 10.10.6-1 - Rebase to PKI 10.10.6 - CVE-2021-3551 Fix pkispawn logging admin credentials --------------------------------------------------------------------------------References: [ 1 ] Bug #1967401 - CVE-2021-3551 pki-core: pki-server: Dogtag installer "pkispawn" logs admin credentials into a world-readable log file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1967401 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-54a73a7112' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . This Debian notice highlights a security flaw in the Apache HTTP Server that inadvertently reveals sensitive data in publicly accessible log files.. Dogtag PKI, Admin Credential Exposure, Fedora Advisory, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 17, 2021 Critical Fedora
89

Fedora 35: 2022-b725a8d91c3 High: Certificate Management Update

- Use tomcat instead of pki-servlet-engine in ELN and RHEL 9 - Drop dependency on esc for s390(x) architectures - build pki-core properly for ELN and RHEL 9 - Fix CVE-2021-20179: Unprivileged users can renew any certificate - Drop i686 architecture going forward. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-c0d6637ca5 2021-03-19 19:51:22.367631 --------------------------------------------------------------------------------Name : dogtag-pki Product : Fedora 34 Version : 10.10.5 Release : 3.fc34 URL : https://www.dogtagpki.org Summary : Dogtag PKI Package Description : Dogtag PKI is an enterprise software system designed to manage enterprise Public Key Infrastructure deployments. PKI consists of the following components: * Automatic Certificate Management Environment (ACME) Responder * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) --------------------------------------------------------------------------------Update Information: - Use tomcat instead of pki-servlet-engine in ELN and RHEL 9 - Drop dependency on esc for s390(x) architectures - build pki-core properly for ELN and RHEL 9 -Fix CVE-2021-20179: Unprivileged users can renew any certificate - Drop i686 architecture going forward --------------------------------------------------------------------------------ChangeLog: * Wed Mar 10 2021 Dogtag PKI Team - 10.10.5-3 - Use tomcat instead of pki-servlet-engine in ELN * Wed Mar 10 2021 Dogtag PKI Team - 10.10.5-2 - Drop dependency on esc for s390(x) architectures --------------------------------------------------------------------------------References: [ 1 ] Bug #1914379 - CVE-2021-20179 pki-core: Unprivileged users can renew any certificate https://bugzilla.redhat.com/show_bug.cgi?id=1914379 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-c0d6637ca5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . CentOS Revision for OpenSSL includes improvements in cryptographic functions and optimization of library compatibility.. Dogtag Pki,Fedora Update,Certificate Management,PKI Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 19, 2021 Critical Fedora
89

Fedora 33: 2021-7458e2d835 Critical: Dogtag PKI LDAP Info Disclosure

- 389-ds fixes an information disclosure during unsuccessful LDAP BIND operation, CVE-2020-35518 - Dogtag PKI adopted to work with 389-ds with the fix - FreeIPA rebuilt to require new Dogtag and 389-ds versions. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-7458e2d835 2021-03-03 23:15:16.431618 --------------------------------------------------------------------------------Name : dogtag-pki Product : Fedora 33 Version : 10.10.5 Release : 1.fc33 URL : https://www.dogtagpki.org Summary : Dogtag PKI Package Description : Dogtag PKI is an enterprise software system designed to manage enterprise Public Key Infrastructure deployments. PKI consists of the following components: * Automatic Certificate Management Environment (ACME) Responder * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) --------------------------------------------------------------------------------Update Information: - 389-ds fixes an information disclosure during unsuccessful LDAP BIND operation, CVE-2020-35518 - Dogtag PKI adopted to work with 389-ds with the fix - FreeIPA rebuilt to require new Dogtag and 389-ds versions --------------------------------------------------------------------------------ChangeLog: * Thu Feb 25 2021 Dogtag PKI Team - 10.10.5-1 - Rebase to upstream stable v10.10.5 release * Tue Jan 26 2021 Fedora Release Engineering - 10.10.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1908653 - CVE-2020-35518 389-ds-base: information disclosure during the binding of a DN [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1908653 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-7458e2d835' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Explore the newest Fedora alert concerning dogtag-pki, focusing on LDAP BIND data exposure and related software prerequisites.. dogtag PKI,Fedora Update,LDAP BIND,certificate management,security patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 03, 2021 Critical Fedora
89

Fedora 34: 2021-263244c071 Moderate: Dogtag PKI Information Leak

- 389-ds fixes an information disclosure during unsuccessful LDAP BIND operation, CVE-2020-35518 - Dogtag PKI adopted to work with 389-ds with the fix - FreeIPA rebuilt to require new Dogtag and 389-ds versions. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-263244c071 2021-03-03 21:06:10.008268 --------------------------------------------------------------------------------Name : dogtag-pki Product : Fedora 34 Version : 10.10.5 Release : 1.fc34 URL : https://www.dogtagpki.org Summary : Dogtag PKI Package Description : Dogtag PKI is an enterprise software system designed to manage enterprise Public Key Infrastructure deployments. PKI consists of the following components: * Automatic Certificate Management Environment (ACME) Responder * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) --------------------------------------------------------------------------------Update Information: - 389-ds fixes an information disclosure during unsuccessful LDAP BIND operation, CVE-2020-35518 - Dogtag PKI adopted to work with 389-ds with the fix - FreeIPA rebuilt to require new Dogtag and 389-ds versions --------------------------------------------------------------------------------ChangeLog: * Thu Feb 25 2021 Dogtag PKI Team - 10.10.5-1 - Rebase to upstream stable v10.10.5 release --------------------------------------------------------------------------------References: [ 1 ] Bug #1908653 - CVE-2020-35518 389-ds-base: information disclosure during the binding of a DN [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1908653 [ 2 ] Bug #1929940 - FreeIPA server deployment fails in current F34 and Rawhide composes https://bugzilla.redhat.com/show_bug.cgi?id=1929940 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-263244c071' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Explore the recent Fedora update alert concerning dogtag-pki, which resolves vulnerabilities related to information leakage during LDAP processes.. Dogtag PKI Update, Fedora Security, LDAP Information Disclosure. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 03, 2021 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here