Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu 18.04 LTS: USN-4504-1 Moderate: OpenSSL Remote Attack Fixes

Several security issues were fixed in OpenSSL.. =========================================================================Ubuntu Security Notice USN-4504-1 September 16, 2020 openssl, openssl1.0 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenSSL. Software Description: - openssl1.0: Secure Socket Layer (SSL) cryptographic library and tools - openssl: Secure Socket Layer (SSL) cryptographic library and tools Details: Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky discovered that certain Diffie-Hellman ciphersuites in the TLS specification and implemented by OpenSSL contained a flaw. A remote attacker could possibly use this issue to eavesdrop on encrypted communications. This was fixed in this update by removing the insecure ciphersuites from OpenSSL. (CVE-2020-1968) Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin, Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL incorrectly handled ECDSA signatures. An attacker could possibly use this issue to perform a timing side-channel attack and recover private ECDSA keys. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-1547) Guido Vranken discovered that OpenSSL incorrectly performed the x86_64 Montgomery squaring procedure. While unlikely, a remote attacker could possibly use this issue to recover private keys. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-1551) Bernd Edlinger discovered that OpenSSL incorrectly handled certain decryption functions. In certain scenarios, a remote attacker could possibly use this issue to perform a padding oracle attack and decrypt traffic. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-1563) Update instructions: The problem can be corrected by updating your system to the following packageversions: Ubuntu 18.04 LTS: libssl1.0.0 1.0.2n-1ubuntu5.4 Ubuntu 16.04 LTS: libssl1.0.0 1.0.2g-1ubuntu4.17 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4504-1 CVE-2019-1547, CVE-2019-1551, CVE-2019-1563, CVE-2020-1968 Package Information: https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu5.4 https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.17 . Ubuntu's OpenSSL security advisory reveals critical vulnerabilities in its encryption framework impacting LTS versions. Users need to urgently update to mitigate risks. OpenSSL Security, Ubuntu Crypto Update, Ubuntu 18.04 Fixes. . LinuxSecurity.com Team

Calendar 2 Sep 16, 2020 Ubuntu
172

Ubuntu 6.06, 7.04, 7.10: USN-610-1 Critical: LTSP Eavesdropping Risk

Christian Herzog discovered that it was possible to connect to any LTSP client's X session over the network. A remote attacker could eavesdrop on X events, read window contents, and record keystrokes, possibly gaining access to private information. . =========================================================== Ubuntu Security Notice USN-610-1 May 06, 2008 ltsp vulnerability CVE-2008-1293 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 7.04 Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: ldm 0.87.1 Ubuntu 7.04: ldm 5.0.7.1 Ubuntu 7.10: ldm 5.0.39.1 After a standard system upgrade you need to update your LTSP client chroots to effect the necessary changes. For more details, please see: Details follow: Christian Herzog discovered that it was possible to connect to any LTSP client's X session over the network. A remote attacker could eavesdrop on X events, read window contents, and record keystrokes, possibly gaining access to private information. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 574 aa98ca636c72ae5baeb34de1a586a200 Size/MD5: 199717 84d1b8c77a3bde8b30068c7365ff7b27 Architecture independent packages: Size/MD5: 82966 442d19db7753c614b64d45ea270befd6 Size/MD5: 1748 a2da20fc182480e35df03c2b0aa85598 Size/MD5: 13352 090bbcba5e3e66c1ffab0b0262cb895c Size/MD5: 21894 63be6d1223a6f272cb9413fb64926f05 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 46442 dc8d11f8b2dd5a3a5a702512a221b4bc i386 architecture (x86 compatible Intel/AMD): Size/MD5: 41822 9820547fb8a0ae363891bdb5a7f367e0 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 45826 80c458e417a2793035afe8a180ed332c sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 43758 62778df1410b59e9581ffa70aadf56f2 Updated packages for Ubuntu 7.04: Source archives: Size/MD5: 576 31c3f3a26492f640874c5c200ab9cef2 Size/MD5: 274699 07c4b25992551962e0a103be55096985 Architecture independent packages: Size/MD5: 204270 f7adb6f9fc1ed6255222b7bccd6bb100 Size/MD5: 2870 839f1f796627d40ad60df43057530d66 Size/MD5: 29224 552812e1820b5addc9b820de55b86080 Size/MD5: 55922 279d71b5ca502b98ed1a90a4a2662f4f amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 60542 c862547c633f9840168ff0aa975e0cb7 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 59076 3134e2afab500926da10729bccc256dc powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 61248 09d0dbbe3e791b4fc4be44f8bba6c707 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 58886 88bec4664e587726c77828a011e86859 Updated packages for Ubuntu 7.10: Source archives: Size/MD5: 691 f015b2c4aa06417afa91fdecd993c2f0 Size/MD5: 2464651 b1e8b62039d0927b4e42a328973021c0 Architecture independent packages: Size/MD5: 3434 0d849820cefc4e98d7077919a92e5470 Size/MD5: 34440 fb5d1bcbf603d6fe79b0afe2e6514423 Size/MD5: 35288 1a005530bb7c27a98ddfdc3234e337ec Size/MD5: 68314 40014f048d44f85bec76eddc5f33f905 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 1992710 f642050148c0787c0217e3571ce91234 Size/MD5: 69598 9affbccbec07643dfa4270727a07875e i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1991780 da5e6870a0b72455a35bd0b5b1b8d3ed Size/MD5: 68374461de2c89dc19f62d39bbfa6cec55e67 lpia architecture (Low Power Intel Architecture): Size/MD5: 1990848 9a2168237991d35d8d2074e98c407df0 Size/MD5: 66770 ec62db8d569b609bd0d49c2fbf214e89 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 1995930 f45e7b5154af874eb7f1a29be3a3204a Size/MD5: 70242 8efd4b5f242777d854682c8969e568dd sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1991858 40cbb244e05286a6fdb62221686397ab Size/MD5: 67952 e7e226c3034036d5b16e837779750da3 . A vulnerability in VNC permits remote hackers to access graphical sessions, endangering confidential data on Linux machines.. LTSP Security Flaw, Ubuntu Remote Access, LTSP Eavesdropping, Open Source Security Alert. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 07, 2008 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here