Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 39: FEDORA-2024-3699706b25 Critical: Thunderbird Security Update

Update to 115.8.1 https://www.mozilla.org/en-US/security/advisories/mfsa2024-11/ read that if you have mails with encrypted email subjects https://www.thunderbird.net/en-US/thunderbird/115.8.1/releasenotes/. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-3699706b25 2024-03-08 01:18:13.751720 -------------------------------------------------------------------------------- Name : thunderbird Product : Fedora 39 Version : 115.8.1 Release : 1.fc39 URL : https://wiki.mozilla.org/Thunderbird:Home_Page Summary : Mozilla Thunderbird mail/newsgroup client Description : Mozilla Thunderbird is a standalone mail and newsgroup client. -------------------------------------------------------------------------------- Update Information: Update to 115.8.1 https://www.mozilla.org/en-US/security/advisories/mfsa2024-11/ read that if you have mails with encrypted email subjects https://www.thunderbird.net/en-US/thunderbird/115.8.1/releasenotes/ -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 5 2024 Eike Rathke - 115.8.1-1 - Update to 115.8.1 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-3699706b25' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. FedoraCode of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . To upgrade Thunderbird to version 115.8.1 in Fedora 39, use the command line for vital security updates. See the detailed release notes below for enhancements and fixes. Fedora Thunderbird Update, Security Fixes, Email Encryption, Thunderbird 115.8.1. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 08, 2024 Critical Fedora
203

Mageia: 2021-0189 Moderate: OpenSSH Remote Access Vulnerability

An attacker may use Thunderbird's OpenPGP key refresh mechanism to poison an existing key (CVE-2021-23991). A crafted OpenPGP key with an invalid user ID could be used to confuse the user (MOZ-2021-23992). . MGASA-2021-0189 - Updated thunderbird packages fix security vulnerabilities Publication date: 15 Apr 2021 URL: https://advisories.mageia.org/MGASA-2021-0189.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-23991, CVE-2021-23993 An attacker may use Thunderbird's OpenPGP key refresh mechanism to poison an existing key (CVE-2021-23991). A crafted OpenPGP key with an invalid user ID could be used to confuse the user (MOZ-2021-23992). Inability to send encrypted OpenPGP email after importing a crafted OpenPGP key (CVE-2021-23993). References: - https://bugs.mageia.org/show_bug.cgi?id=28764 - https://www.mozilla.org/en-US/security/advisories/mfsa2021-13/ - https://www.thunderbird.net/en-US/thunderbird/78.9.1/releasenotes/ - https://www.cve.org/CVERecord?id=CVE-2021-23991 - https://www.cve.org/CVERecord?id=CVE-2021-23993 SRPMS: - 7/core/thunderbird-78.9.1-1.mga7 - 7/core/thunderbird-l10n-78.9.1-1.mga7 - 8/core/thunderbird-78.9.1-1.mga8 - 8/core/thunderbird-l10n-78.9.1-1.mga8 . Latest Thunderbird releases address significant vulnerabilities affecting password safeguarding and secure communication protocols.. Thunderbird Security,Mageia Updates,OpenPGP Threats,Email Encryption Risks. . LinuxSecurity.com Team

Calendar 2 Apr 15, 2021 Mageia
200

Scientific Linux: SLSA-2021-1215-2 Moderate: Thunderbird Security Fixes

This update upgrades Thunderbird to version 78.9.1. * Mozilla: An attacker may use Thunderbird's OpenPGP key refresh mechanism to poison an existing key (CVE-2021-23991) * Mozilla: A crafted OpenPGP key with an invalid user ID could be used to confuse the user (CVE-2021-23992) * Mozilla: Inability to send encrypted OpenPGP email after importing a crafted OpenPGP key (CVE-2021-23993) For more [More...]. Synopsis: Moderate: thunderbird security update Advisory ID: SLSA-2021:1192-1 Issue Date: 2021-04-14 CVE Numbers: CVE-2021-23991 CVE-2021-23992 CVE-2021-23993 -- This update upgrades Thunderbird to version 78.9.1. Security Fix(es): * Mozilla: An attacker may use Thunderbird's OpenPGP key refresh mechanism to poison an existing key (CVE-2021-23991) * Mozilla: A crafted OpenPGP key with an invalid user ID could be used to confuse the user (CVE-2021-23992) * Mozilla: Inability to send encrypted OpenPGP email after importing a crafted OpenPGP key (CVE-2021-23993) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- - Scientific Linux Development Team . Mozilla Firefox recent security patch addresses a range of vulnerabilities in web rendering processes. Further details can be found in this announcement.. Thunderbird Security, OpenPGP Management, Mozilla Fixes, Security Update. . LinuxSecurity.com Team

Calendar 2 Apr 14, 2021 Scientific Linux
89

Fedora 27 Security Advisory: Thunderbird-Enigmail 2.0.4 Critical Efail Fix

Enigmail update to version 2.0.4, introduces fixes for the efail attack. Please check and modify your Thunderbird settings if required: https://enigmail.net/index.php/en/home/news/66-2018-05-16-efail-vulnerability-affects-encrypted-mails. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-25525a9346 2018-05-27 19:50:53.638839 --------------------------------------------------------------------------------Name : thunderbird-enigmail Product : Fedora 27 Version : 2.0.4 Release : 1.fc27 URL : https://enigmail.net/index.php/en/ Summary : Authentication and encryption extension for Mozilla Thunderbird Description : Enigmail is an extension to the mail client Mozilla Thunderbird which allows users to access the authentication and encryption features provided by GnuPG --------------------------------------------------------------------------------Update Information: Enigmail update to version 2.0.4, introduces fixes for the efail attack. Please check and modify your Thunderbird settings if required: https://enigmail.net/index.php/en/home/news/66-2018-05-16-efail-vulnerability-affects-encrypted-mails --------------------------------------------------------------------------------ChangeLog: * Sat May 19 2018 Christian Dersch - 2.0.4-1 - new version fixing efail vulnerability * Fri Feb 9 2018 Fedora Release Engineering - 1.9.9-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Fri Dec 22 2017 Christian Dersch - 1.9.9-1 - new version --------------------------------------------------------------------------------References: [ 1 ] Bug #1577912 - CVE-2017-17688 CVE-2017-17689 thunderbird-enigmail: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1577912 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2018-25525a9346' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/PTRS5UKHGL2GORWPTN2GAJ52MHPVFEKP/ . The latest Enigmail release 2.0.4 for Thunderbird tackles the efail vulnerability; remember to modify your configurations to boost security.. Thunderbird Enigmail Update, Efail Security Fix, Fedora Software Update, GnuPG, Email Encryption. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 27, 2018 Critical Fedora
202

openSUSE: 2018:1329-1 Moderate: Enigmail Email Exfiltration Fix

An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:1329-1 Rating: moderate References: #1093151 #1093152 Cross-References: CVE-2017-17688 CVE-2017-17689 Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for enigmail to version 2.0.4 fixes multiple issues. Security issues fixed: - CVE-2017-17688: CFB gadget attacks allowed to exfiltrate plaintext out of encrypted emails. enigmail now fails on GnuPG integrity check warnings for old Algorithms (bsc#1093151) - CVE-2017-17689: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails (bsc#1093152) This update also includes new and updated functionality: - The Encryption and Signing buttons now work for both OpenPGP and S/MIME. Enigmail will chose between S/MIME or OpenPGP depending on whether the keys for all recipients are available for the respective standard - Support for the Autocrypt standard, which is now enabled by default - Support for Pretty Easy Privacy (p?p) - Support for Web Key Directory (WKD) - The message subject can now be encrypted and replaced with a dummy subject, following the Memory Hole standard forprotected Email Headers - keys on keyring are automatically refreshed from keyservers at irregular intervals - Subsequent updates of Enigmail no longer require a restart of Thunderbird - Keys are internally addressed using the fingerprint instead of the key ID Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run thecommand listed for your product: - SUSE Package Hub for SUSE Linux Enterprise 12: zypper in -t patch openSUSE-2018-470=1 Package List: - SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64): enigmail-2.0.4-9.1 References: https://www.suse.com/security/cve/CVE-2017-17688.html https://www.suse.com/security/cve/CVE-2017-17689.html https://bugzilla.suse.com/1093151 https://bugzilla.suse.com/1093152 -- . The latest Fedora update targets several significant vulnerabilities in Thunderbird, reinforcing the security of email communications and improving verification processes.. openSUSE Security, Enigmail Update, Email Security Issues. . LinuxSecurity.com Team

Calendar 2 May 17, 2018 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here