Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
203

Mageia 7: MGASA-2021-0010 Moderate: SquirrelMail XSS Attack Risk

XSS was discovered in SquirrelMail through 1.4.22. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element (). . MGASA-2021-0010 - Updated squirrelmail packages fix security vulnerabilities Publication date: 08 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0010.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-12970 XSS was discovered in SquirrelMail through 1.4.22. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element (). An unsafe use of unserialize() in compose.php has also been fixed. References: - https://bugs.mageia.org/show_bug.cgi?id=27821 - https://www.openwall.com/lists/oss-security/2020/06/20/1 - https://ubuntu.com/security/notices/USN-4669-1 - https://www.cve.org/CVERecord?id=CVE-2019-12970 SRPMS: - 7/core/squirrelmail-1.4.23-0.svn20201220_0200.1.mga7 . Vulnerable code execution in SquirrelMail caused by input validation error. Patch available to address discovered security vulnerabilities promptly.. SquirrelMail Security,Mageia XSS,Mageia Security Patch,SquirrelMail Update,XSS Attack Prevention. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 08, 2021 Important Mageia
89

Fedora 31: FEDORA-2020-95f2c5cc25 Critical: Geary TLS Certificate Handling

Add patch for CVE-2020-24661: Handling of pinned, invalid TLS certificates.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-95f2c5cc25 2020-09-08 15:13:30.490624 --------------------------------------------------------------------------------Name : geary Product : Fedora 31 Version : 3.34.2 Release : 2.fc31 URL : https://wiki.gnome.org/Apps/Geary Summary : A lightweight email program designed around conversations Description : Geary is a new email reader for GNOME designed to let you read your email quickly and effortlessly. Its interface is based on conversations, so you can easily read an entire discussion without having to click from message to message. Geary is still in early development and has limited features today, but we're planning to add drag-and-drop attachments, lightning-fast searching, multiple account support and much more. Eventually we'd like Geary to have an extensible plugin architecture so that developers will be able to add all kinds of nifty features in a modular way. --------------------------------------------------------------------------------Update Information: Add patch for CVE-2020-24661: Handling of pinned, invalid TLS certificates. --------------------------------------------------------------------------------ChangeLog: * Sat Aug 29 2020 Thomas Moschny - 3.34.2-2 - Add patch for CVE-2020-24661. --------------------------------------------------------------------------------References: [ 1 ] Bug #1872970 - CVE-2020-24661 geary: mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1872970 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-95f2c5cc25' at the command line. For moreinformation, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The latest Geary release for Fedora 31 enhances the management of invalid TLS certificates, boosting security for its users.. Geary Email Patch,Fedora 31 Update,TLS Security Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 08, 2020 Critical Fedora
98

Red Hat Enterprise Linux 8 RHSA-2020:1600-01 Moderate: Evolution Email Fix

An update for evolution, evolution-data-server, and evolution-ews is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: evolution security and bug fix update Advisory ID: RHSA-2020:1600-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:1600 Issue date: 2020-04-28 CVE Names: CVE-2018-15587 ==================================================================== 1. Summary: An update for evolution, evolution-data-server, and evolution-ews is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 8) - aarch64, noarch, ppc64le, x86_64 Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, x86_64 3. Description: Evolution is a GNOME application that provides integrated email, calendar, contact management, and communications functionality. The evolution-data-server packages provide a unified back end for applications which interact with contacts, tasks and calendar information. Evolution Data Server was originally developed as a back end for the Evolution information management application, but is now used by various other applications. Security Fix(es): * evolution: specially crafted email leading to OpenPGP signatures being spoofed for arbitrary messages (CVE-2018-15587) For more details about the security issue(s), including the impact, a CVSS score,acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.2 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Evolution must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1677650 - CVE-2018-15587 evolution: specially crafted email leading to OpenPGP signatures being spoofed for arbitrary messages 1741091 - Birthday date of Contact depends on system timezone 1753220 - GalA11yETableItem: Incorrect implementation of AtkObjectClass::ref_child() 1764818 - Sync CategoryList with mail Labels 1765005 - Reject creating meetings organized by other users1778799 - New Mail account wizard ignores email address change 1788478 - EDBusServer: Delay new module load 1791547 - [abrt] [faf] test-cal-meta-backend cannot run without installed Evolution 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: evolution-3.28.5-12.el8.src.rpm evolution-data-server-3.28.5-13.el8.src.rpm evolution-ews-3.28.5-9.el8.src.rpm aarch64: evolution-3.28.5-12.el8.aarch64.rpm evolution-bogofilter-3.28.5-12.el8.aarch64.rpm evolution-bogofilter-debuginfo-3.28.5-12.el8.aarch64.rpm evolution-data-server-3.28.5-13.el8.aarch64.rpm evolution-data-server-debuginfo-3.28.5-13.el8.aarch64.rpm evolution-data-server-debugsource-3.28.5-13.el8.aarch64.rpm evolution-data-server-devel-3.28.5-13.el8.aarch64.rpm evolution-data-server-tests-debuginfo-3.28.5-13.el8.aarch64.rpm evolution-debuginfo-3.28.5-12.el8.aarch64.rpm evolution-debugsource-3.28.5-12.el8.aarch64.rpm evolution-ews-3.28.5-9.el8.aarch64.rpm evolution-ews-debuginfo-3.28.5-9.el8.aarch64.rpm evolution-ews-debugsource-3.28.5-9.el8.aarch64.rpm evolution-pst-3.28.5-12.el8.aarch64.rpm evolution-pst-debuginfo-3.28.5-12.el8.aarch64.rpm evolution-spamassassin-3.28.5-12.el8.aarch64.rpm evolution-spamassassin-debuginfo-3.28.5-12.el8.aarch64.rpm noarch: evolution-data-server-langpacks-3.28.5-13.el8.noarch.rpm evolution-ews-langpacks-3.28.5-9.el8.noarch.rpm evolution-help-3.28.5-12.el8.noarch.rpm evolution-langpacks-3.28.5-12.el8.noarch.rpm ppc64le: evolution-3.28.5-12.el8.ppc64le.rpm evolution-bogofilter-3.28.5-12.el8.ppc64le.rpm evolution-bogofilter-debuginfo-3.28.5-12.el8.ppc64le.rpm evolution-data-server-3.28.5-13.el8.ppc64le.rpm evolution-data-server-debuginfo-3.28.5-13.el8.ppc64le.rpm evolution-data-server-debugsource-3.28.5-13.el8.ppc64le.rpm evolution-data-server-devel-3.28.5-13.el8.ppc64le.rpm evolution-data-server-tests-debuginfo-3.28.5-13.el8.ppc64le.rpm evolution-debuginfo-3.28.5-12.el8.ppc64le.rpm evolution-debugsource-3.28.5-12.el8.ppc64le.rpm evolution-ews-3.28.5-9.el8.ppc64le.rpm evolution-ews-debuginfo-3.28.5-9.el8.ppc64le.rpm evolution-ews-debugsource-3.28.5-9.el8.ppc64le.rpm evolution-pst-3.28.5-12.el8.ppc64le.rpm evolution-pst-debuginfo-3.28.5-12.el8.ppc64le.rpm evolution-spamassassin-3.28.5-12.el8.ppc64le.rpm evolution-spamassassin-debuginfo-3.28.5-12.el8.ppc64le.rpm x86_64: evolution-3.28.5-12.el8.x86_64.rpm evolution-bogofilter-3.28.5-12.el8.x86_64.rpm evolution-bogofilter-debuginfo-3.28.5-12.el8.x86_64.rpm evolution-data-server-3.28.5-13.el8.i686.rpm evolution-data-server-3.28.5-13.el8.x86_64.rpm evolution-data-server-debuginfo-3.28.5-13.el8.i686.rpm evolution-data-server-debuginfo-3.28.5-13.el8.x86_64.rpm evolution-data-server-debugsource-3.28.5-13.el8.i686.rpm evolution-data-server-debugsource-3.28.5-13.el8.x86_64.rpm evolution-data-server-devel-3.28.5-13.el8.i686.rpm evolution-data-server-devel-3.28.5-13.el8.x86_64.rpm evolution-data-server-tests-debuginfo-3.28.5-13.el8.i686.rpm evolution-data-server-tests-debuginfo-3.28.5-13.el8.x86_64.rpm evolution-debuginfo-3.28.5-12.el8.x86_64.rpm evolution-debugsource-3.28.5-12.el8.x86_64.rpm evolution-ews-3.28.5-9.el8.x86_64.rpm evolution-ews-debuginfo-3.28.5-9.el8.x86_64.rpm evolution-ews-debugsource-3.28.5-9.el8.x86_64.rpm evolution-pst-3.28.5-12.el8.x86_64.rpm evolution-pst-debuginfo-3.28.5-12.el8.x86_64.rpm evolution-spamassassin-3.28.5-12.el8.x86_64.rpm evolution-spamassassin-debuginfo-3.28.5-12.el8.x86_64.rpm Red Hat CodeReady Linux Builder (v.8): aarch64: evolution-bogofilter-debuginfo-3.28.5-12.el8.aarch64.rpm evolution-data-server-debuginfo-3.28.5-13.el8.aarch64.rpm evolution-data-server-debugsource-3.28.5-13.el8.aarch64.rpm evolution-data-server-perl-3.28.5-13.el8.aarch64.rpm evolution-data-server-tests-3.28.5-13.el8.aarch64.rpm evolution-data-server-tests-debuginfo-3.28.5-13.el8.aarch64.rpm evolution-debuginfo-3.28.5-12.el8.aarch64.rpm evolution-debugsource-3.28.5-12.el8.aarch64.rpm evolution-devel-3.28.5-12.el8.aarch64.rpm evolution-pst-debuginfo-3.28.5-12.el8.aarch64.rpm evolution-spamassassin-debuginfo-3.28.5-12.el8.aarch64.rpm noarch: evolution-data-server-doc-3.28.5-13.el8.noarch.rpm ppc64le: evolution-bogofilter-debuginfo-3.28.5-12.el8.ppc64le.rpm evolution-data-server-debuginfo-3.28.5-13.el8.ppc64le.rpm evolution-data-server-debugsource-3.28.5-13.el8.ppc64le.rpm evolution-data-server-perl-3.28.5-13.el8.ppc64le.rpm evolution-data-server-tests-3.28.5-13.el8.ppc64le.rpm evolution-data-server-tests-debuginfo-3.28.5-13.el8.ppc64le.rpm evolution-debuginfo-3.28.5-12.el8.ppc64le.rpm evolution-debugsource-3.28.5-12.el8.ppc64le.rpm evolution-devel-3.28.5-12.el8.ppc64le.rpm evolution-pst-debuginfo-3.28.5-12.el8.ppc64le.rpm evolution-spamassassin-debuginfo-3.28.5-12.el8.ppc64le.rpm x86_64: evolution-bogofilter-debuginfo-3.28.5-12.el8.i686.rpm evolution-bogofilter-debuginfo-3.28.5-12.el8.x86_64.rpm evolution-data-server-debuginfo-3.28.5-13.el8.i686.rpm evolution-data-server-debuginfo-3.28.5-13.el8.x86_64.rpm evolution-data-server-debugsource-3.28.5-13.el8.i686.rpm evolution-data-server-debugsource-3.28.5-13.el8.x86_64.rpm evolution-data-server-perl-3.28.5-13.el8.x86_64.rpm evolution-data-server-tests-3.28.5-13.el8.i686.rpm evolution-data-server-tests-3.28.5-13.el8.x86_64.rpm evolution-data-server-tests-debuginfo-3.28.5-13.el8.i686.rpm evolution-data-server-tests-debuginfo-3.28.5-13.el8.x86_64.rpm evolution-debuginfo-3.28.5-12.el8.i686.rpm evolution-debuginfo-3.28.5-12.el8.x86_64.rpm evolution-debugsource-3.28.5-12.el8.i686.rpm evolution-debugsource-3.28.5-12.el8.x86_64.rpm evolution-devel-3.28.5-12.el8.i686.rpm evolution-devel-3.28.5-12.el8.x86_64.rpm evolution-pst-debuginfo-3.28.5-12.el8.i686.rpm evolution-pst-debuginfo-3.28.5-12.el8.x86_64.rpm evolution-spamassassin-debuginfo-3.28.5-12.el8.i686.rpm evolution-spamassassin-debuginfo-3.28.5-12.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-15587 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.2_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXqhVwNzjgjWX9erEAQg8KQ/8CaKBjvP7IZxCLeDSOA7PHBylbD4zBe/l G671d7eKBUBXmZnws9gN44ccXdMmnYrUOvrJs+NteVzuew4b6DGWl+Qw/J1luvni GuTUgSnxsH0uLeBhdejpLM6okSZwQEl7UEp5zrTux0U/p0+KYxbpDI2F8Hb2ImCk jVwiwoVP4YrxFAM4QmXcRcdIX9n3yV7I/ck54LAlAOhbsvhhOJZVFNFvLpcZxT5R qNrVBs78nsEFQoWeDOXr+/tdlUMB7uZBIJ2Bld5njmUmVhbdw/DqpvmL+rLJq02k NuN8d6CtAkMZ9xh6pJCDboCyAQNv4+B7WqU4uW7vN9S8j57kLXgCXx5NTolBdZDc nSxCd3uXw7wnkCqvKwz5D4ybMre1KIULY5z/uT/lzgw7yzhjP2zdH3Y/3+NnSae0 Jem4KMQ864kiAJMliL3Vdh/5SD6gKr0cV1mPOF4yu5vB5hJFGUfd6LeBcyfBetSQ 86sI96p/b4+/FI6tAfuh7k3HskapFpqLJOHqjvrSQHTIlzjF7PIHJJAxXOnHdxHH yZ1yG3+G8IIV7KQnIdVUMph8mPjqcwRfxTvZaxMaH0om0hv80Zc2kT1SlAxfEBtR /ZHgC/IYm6wVQqZzHB7DG+iXCLE569/5VXZCCLQ0J0S/0cSd9A6RFF9pQaV4MENu Wt4NJwfb6Zw=SgCD -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat reveals an Evolution upgrade focused on addressing critical security flaws, particularly a significant email impersonation threat.. Red Hat Enterprise, Evolution Update, Email Security, Bug Fix, OpenPGP Signatures. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 28, 2020 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200