Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
172

Ubuntu 23.10: USN-6591-2 Critical Postfix Email Authentication Bypass

Postfix could allow bypass of email authentication if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-6591-2 January 31, 2024 postfix update ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: Postfix could allow bypass of email authentication if it received specially crafted network traffic. Software Description: - postfix: High-performance mail transport agent Details: USN-6591-1 fixed vulnerabilities in Postfix. A fix with less risk of regression has been made available since the last update. This update updates the fix and aligns with the latest configuration guidelines regarding this vulnerability. We apologize for the inconvenience. Original advisory details: Timo Longin discovered that Postfix incorrectly handled certain email line endings. A remote attacker could possibly use this issue to bypass an email authentication mechanism, allowing domain spoofing and potential spamming. Please note that certain configuration changes are required to address this issue. They are not enabled by default for backward compatibility. Information can be found athttps://www.postfix.org/smtp-smuggling.html. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: postfix 3.8.1-2ubuntu0.2 Ubuntu 22.04 LTS: postfix 3.6.4-1ubuntu1.3 Ubuntu 20.04 LTS: postfix 3.4.13-0ubuntu1.4 Ubuntu 18.04 LTS (Available with Ubuntu Pro): postfix 3.3.0-1ubuntu0.4+esm3 Ubuntu 16.04 LTS(Available with Ubuntu Pro): postfix 3.1.0-3ubuntu0.4+esm3 Ubuntu 14.04 LTS (Available with Ubuntu Pro): postfix 2.11.0-1ubuntu1.2+esm3 After a standard system update, you need to set "smtpd_forbid_bare_newline = normalize" in your configuration and reload it to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6591-2 https://ubuntu.com/security/notices/USN-6591-1 CVE-2023-51764, Package Information: https://launchpad.net/ubuntu/+source/postfix/3.8.1-2ubuntu0.2 https://launchpad.net/ubuntu/+source/postfix/3.6.4-1ubuntu1.3 https://launchpad.net/ubuntu/+source/postfix/3.4.13-0ubuntu1.4 . ### Vital Upgrade for Postfix to Address Email Authentication Flaw in Ubuntu. Crucial actions include. Postfix Issue, Email Bypass, Security Update, Authentication Flaw, Ubuntu Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 31, 2024 Critical Ubuntu
172

Ubuntu 23.10 USN-6591-1 Moderate: Postfix Email Auth Bypass

Postfix could allow bypass of email authentication if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-6591-1 January 22, 2024 postfix vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: Postfix could allow bypass of email authentication if it received specially crafted network traffic. Software Description: - postfix: High-performance mail transport agent Details: Timo Longin discovered that Postfix incorrectly handled certain email line endings. A remote attacker could possibly use this issue to bypass an email authentication mechanism, allowing domain spoofing and potential spamming. Please note that certain configuration changes are required to address this issue. They are not enabled by default for backward compatibility. Information can be found athttps://www.postfix.org/smtp-smuggling.html. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: postfix 3.8.1-2ubuntu0.1 Ubuntu 22.04 LTS: postfix 3.6.4-1ubuntu1.2 Ubuntu 20.04 LTS: postfix 3.4.13-0ubuntu1.3 Ubuntu 18.04 LTS (Available with Ubuntu Pro): postfix 3.3.0-1ubuntu0.4+esm2 Ubuntu 16.04 LTS (Available with Ubuntu Pro): postfix 3.1.0-3ubuntu0.4+esm2 Ubuntu 14.04 LTS (Available with Ubuntu Pro): postfix 2.11.0-1ubuntu1.2+esm2 After a standard system update you need to enable smtpd_forbid_bare_newline in your configuration and reload it tomake all the necessary changes. References: https://ubuntu.com/security/notices/USN-6591-1 CVE-2023-51764,https://bugs.launchpad.net/ubuntu/+source/postfix/+bug/2049337 Package Information: https://launchpad.net/ubuntu/+source/postfix/3.8.1-2ubuntu0.1 https://launchpad.net/ubuntu/+source/postfix/3.6.4-1ubuntu1.2 https://launchpad.net/ubuntu/+source/postfix/3.4.13-0ubuntu1.3 . A vulnerability in Postfix could be exploited, leading to potential email authentication breaches and increased domain spoofing threats. Update immediately.. Postfix Authentication, Email Spoofing, Ubuntu Update. . LinuxSecurity.com Team

Calendar 2 Jan 22, 2024 Ubuntu
197

Debian Buster DLA-3546-1 Critical: Opendmarc Email Authentication Issue

It was discovered that there was an issue in the opendmarc DMARC email filter system. A vulnerability allowed attackers to inject authentication results to provide false information about the domain that originated an email message. This was caused by incorrect . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3546-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb August 28, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : opendmarc Version : 1.3.2-6+deb10u3 CVE ID : CVE-2020-12272 Debian Bug : 977767 It was discovered that there was an issue in the opendmarc DMARC email filter system. A vulnerability allowed attackers to inject authentication results to provide false information about the domain that originated an email message. This was caused by incorrect parsing and interpretation of SPF/DKIM authentication results. For Debian 10 buster, this problem has been fixed in version 1.3.2-6+deb10u3. We recommend that you upgrade your opendmarc packages. For the detailed security status of opendmarc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/opendmarc Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . This advisory highlights a critical opendmarc update to fix an email authentication vulnerability in Debian LTS, essential for maintaining system security. Opendmarc Update, Email Security, Debian LTS Advisory, DMARC Protection. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 28, 2023 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here