Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
197

Debian LTS DLA-3839-1 Critical: Putty ECDSA Key Compromise Risk

A biased ECDSA nonce generation allowed an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. In other words, an adversary may already have enough signature information to compromise a victim's . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3839-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès June 20, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : putty Version : 0.74-1+deb11u1~deb10u2 CVE ID : CVE-2024-31497 A biased ECDSA nonce generation allowed an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. In other words, an adversary may already have enough signature information to compromise a victim's private key, even if there is no further use of vulnerable PuTTY versions. This allowed an attacker to (for instance) log in to any servers the victim uses that key for. To obtain these signatures, an attacker need only briefly compromise any server the victim uses the key to authenticate to. Therefore, if you have any NIST-P521 ECDSA key, we strongly recommend you to replace it with a freshly new created with a fixed version of putty. Then, to revoke the old public key and remove it from any machine where you use it to login into, so that a signature from the compromised key has no value any more. The only affected key type is 521-bit ECDSA. That is, a key that appears in Windows PuTTYgen with ecdsa-sha2-nistp521 at the start of the 'Key fingerprint' box, or is described as 'NIST p521', or has an id starting ecdsa-sha2-nistp521 in the SSH protocol or the key file. Other sizes of ECDSA, and other key algorithms, are unaffected. In particular, Ed25519 is not affected. For Debian 10 buster, this problem has been fixed in version 0.74-1+deb11u1~deb10u2. Werecommend that you upgrade your putty packages. For the detailed security status of putty please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/putty Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-1234-1 addresses vulnerabilities in OpenSSH that jeopardize RSA key integrity under specific conditions.. Putty Security, Debian LTS Advisory, ECDSA Attack, NIST P-521 Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 20, 2024 Critical Debian LTS
89

Fedora 35: FEDORA-2022-bf58612696 Critical: Ecdsautils Signature Issue

Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous versions ecdsautils would erroneously accept all-zero signatures as valid. More information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-bf58612696 2022-05-16 02:04:05.714214 --------------------------------------------------------------------------------Name : ecdsautils Product : Fedora 35 Version : 0.4.1 Release : 1.fc35 URL : https://github.com/freifunk-gluon/ecdsautils Summary : Tiny collection of programs used for ECDSA (keygen, sign, verify) Description : This collection of ECDSA utilities can be used to sign and verify data in a simple manner. --------------------------------------------------------------------------------Update Information: Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous versions ecdsautils would erroneously accept all-zero signatures as valid. More information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw --------------------------------------------------------------------------------ChangeLog: * Thu May 5 2022 Felix Kaechele - 0.4.1-1 - update to 0.4.1 - use new upstream URLs - drop patch now upstreamed - added libs and devel subpackages * Thu Jan 20 2022 Fedora Release Engineering - 0.3.2-18 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2082427 - CVE-2022-24884 ecdsautils: Improper Verification of ECDSA Signatures [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2082427 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2022-bf58612696' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . A fresh enhancement for ecdsautils in Fedora resolves inadequate signature validation, boosting both security and dependability.. ECDSA Utilities, Fedora Update, Signature Verification, Security Patch, Improper Signature. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 15, 2022 Critical Fedora
89

Fedora 34: 2022-7704d5e885 Critical: Improper ECDSA Signature Validation

Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous versions ecdsautils would erroneously accept all-zero signatures as valid. More information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7704d5e885 2022-05-16 01:43:34.426938 --------------------------------------------------------------------------------Name : ecdsautils Product : Fedora 34 Version : 0.4.1 Release : 1.fc34 URL : https://github.com/freifunk-gluon/ecdsautils Summary : Tiny collection of programs used for ECDSA (keygen, sign, verify) Description : This collection of ECDSA utilities can be used to sign and verify data in a simple manner. --------------------------------------------------------------------------------Update Information: Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous versions ecdsautils would erroneously accept all-zero signatures as valid. More information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw --------------------------------------------------------------------------------ChangeLog: * Thu May 5 2022 Felix Kaechele - 0.4.1-1 - update to 0.4.1 - use new upstream URLs - drop patch now upstreamed - added libs and devel subpackages * Thu Jan 20 2022 Fedora Release Engineering - 0.3.2-18 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Wed Jul 21 2021 Fedora Release Engineering - 0.3.2-17 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2082427 - CVE-2022-24884 ecdsautils: Improper Verification of ECDSA Signatures [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2082427 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-7704d5e885' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Revamped ecdsautils on Fedora to address flawed ECDSA validation problem. Confirm legitimate signatures moving forward.. ecdsa utilities,Fedora updates,security advisory ecdsautils. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 15, 2022 Critical Fedora
89

Fedora 36: FEDORA-2022-111177a5ac Moderate Severity ECDSA Signature Issue

Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous versions ecdsautils would erroneously accept all-zero signatures as valid. More information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-111177a5ac 2022-05-14 01:48:30.603225 --------------------------------------------------------------------------------Name : ecdsautils Product : Fedora 36 Version : 0.4.1 Release : 1.fc36 URL : https://github.com/freifunk-gluon/ecdsautils Summary : Tiny collection of programs used for ECDSA (keygen, sign, verify) Description : This collection of ECDSA utilities can be used to sign and verify data in a simple manner. --------------------------------------------------------------------------------Update Information: Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous versions ecdsautils would erroneously accept all-zero signatures as valid. More information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw --------------------------------------------------------------------------------ChangeLog: * Thu May 5 2022 Felix Kaechele - 0.4.1-1 - update to 0.4.1 - use new upstream URLs - drop patch now upstreamed - added libs and devel subpackages --------------------------------------------------------------------------------References: [ 1 ] Bug #2082427 - CVE-2022-24884 ecdsautils: Improper Verification of ECDSA Signatures [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2082427 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-111177a5ac' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The recent upgrade for Fedora 36 resolves CVE-2022-24884, which rectifies issues related to incorrect ECDSA signatures found in ecdsautils, thereby reinforcing security protocols.. Fedora Updates,ECDSA Security Patch,Signature Issues,Security Advisories. . LinuxSecurity.com Team

Calendar 2 May 13, 2022 Fedora
197

Debian 9: DLA-3000-1 Important: OpenSSL Vulnerability Exploit Threat

In ecdsautils, a collection of ECDSA elliptic curve cryptography command line tools, an improper verification of cryptographic signatures was detected. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2997-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sven Eckelmann May 07, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ecdsautils Version : 0.3.2+git20151018-2+deb9u1 CVE ID : CVE-2022-24884 In ecdsautils, a collection of ECDSA elliptic curve cryptography command line tools, an improper verification of cryptographic signatures was detected. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. For Debian 9 stretch, this problem has been fixed in version 0.3.2+git20151018-2+deb9u1. We recommend that you upgrade your ecdsautils packages. For the detailed security status of ecdsautils please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ecdsautils Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . To bolster security on Debian 9, it's essential to upgrade the ecdsautils package to resolve known signature forgery vulnerabilities. Here's a safe and efficient upgrade guide.. ecdsa Security Update, Debian LTS, Signature Forgery Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 07, 2022 Important Debian LTS
87

Debian 10 DSA-4933-1 Moderate: Nettle Denial Of Service Threat

Multiple vulnerabilities were discovered in nettle, a low level cryptographic library, which could result in denial of service (remote crash in RSA decryption via specially crafted ciphertext, crash on ECDSA signature verification) or incorrect verification of ECDSA signatures. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4933-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso June 18, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nettle CVE ID : CVE-2021-3580 CVE-2021-20305 Debian Bug : 985652 989631 Multiple vulnerabilities were discovered in nettle, a low level cryptographic library, which could result in denial of service (remote crash in RSA decryption via specially crafted ciphertext, crash on ECDSA signature verification) or incorrect verification of ECDSA signatures. For the stable distribution (buster), these problems have been fixed in version 3.4.1-1+deb10u1. We recommend that you upgrade your nettle packages. For the detailed security status of nettle please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/nettle Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Nettle contains multiple weaknesses that could lead to denial of service or incorrect ECDSA validation. An upgrade is strongly recommended.. Debian Update,Nettle Cryptography,Security Advisory,ECDSA Vulnerability,Denial Of Service. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 18, 2021 Important Debian
203

Mageia 7: MGASA-2020-0265 Moderate: mbedtls Key Recovery Threat

Updated mbedtls packages fix security vulnerability Fix side channel in ECC code that allowed an adversary with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave) to fully recover an ECDSA private key. . MGASA-2020-0265 - Updated mbedtls packages fix security vulnerability Publication date: 16 Jun 2020 URL: https://advisories.mageia.org/MGASA-2020-0265.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-10932 Updated mbedtls packages fix security vulnerability Fix side channel in ECC code that allowed an adversary with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave) to fully recover an ECDSA private key. (CVE-2020-10932) Fix a potentially remotely exploitable buffer overread in a DTLS client when parsing the Hello Verify Request message. References: - https://bugs.mageia.org/show_bug.cgi?id=26758 - https://www.trustedfirmware.org/projects/mbed-tls/ - - https://www.cve.org/CVERecord?id=CVE-2020-10932 SRPMS: - 7/core/mbedtls-2.16.6-1.mga7 . Recent updates to mbedtls packages address a critical security vulnerability in Mageia 7. It is strongly advised to act promptly to protect ECDSA keys.. Mageia Security Update, mbedtls Vulnerability, ECDSA Key Security, Buffer Overread Fix. . LinuxSecurity.com Team

Calendar 2 Jun 16, 2020 Mageia
89

Fedora: 2019-07940971b2 Critical: mbedtls Side Channel Attack Resolution

- Update to 2.16.3 - Side channel attack on deterministic ECDSA (CVE-2019-16910) Release notes: https://www.trustedfirmware.org/projects/mbed-tls/ Security Advisory: . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-07940971b2 2019-10-07 00:53:40.514560 --------------------------------------------------------------------------------Name : mbedtls Product : Fedora 30 Version : 2.16.3 Release : 1.fc30 URL : https://www.trustedfirmware.org/projects/mbed-tls/ Summary : Light-weight cryptographic and SSL/TLS library Description : Mbed TLS is a light-weight open source cryptographic and SSL/TLS library written in C. Mbed TLS makes it easy for developers to include cryptographic and SSL/TLS capabilities in their (embedded) applications with as little hassle as possible. FOSS License Exception: https://www.trustedfirmware.org/projects/mbed-tls/ --------------------------------------------------------------------------------Update Information: - Update to 2.16.3 - Side channel attack on deterministic ECDSA (CVE-2019-16910) Release notes: https://www.trustedfirmware.org/projects/mbed-tls/ Security Advisory: --------------------------------------------------------------------------------ChangeLog: * Sat Sep 28 2019 Morten Stevens - 2.16.3-1 - Update to 2.16.3 - Side channel attack on deterministic ECDSA (CVE-2019-16910) * Tue Sep 3 2019 Morten Stevens - 2.16.2-4 - devel package needs pkcs11-helper-devel (#1748468) * Sat Aug 3 2019 Morten Stevens - 2.16.2-3 - Fix building on RHEL8 * Thu Jul 25 2019 Fedora Release Engineering - 2.16.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Sat Jul 20 2019 Morten Stevens - 2.16.2-1 - Update to 2.16.2 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-07940971b2' at thecommand line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . OpenSSL upgrade addresses vulnerability in RSA signatures on Ubuntu. Improve your defenses with the newest fix today.. mbedTLS Update, Fedora Security, Side Channel Fix, ECDSA Patch, Cryptographic Library. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 06, 2019 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here