Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 39: 2023-4f0bb4ff5e Moderate Ruby ActionMailer Permissions Bug

Ruby on Rails security upgrade: - Versions-7-0-7-2-6-1-7-6-have-been-released - incorrect file permissions on encrypted files. Exploit not known.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-4f0bb4ff5e 2023-09-15 18:36:13.240099 -------------------------------------------------------------------------------- Name : rubygem-actionmailer Product : Fedora 39 Version : 7.0.7.2 Release : 1.fc39 URL : https://rubyonrails.org Summary : Email composition and delivery framework (part of Rails) Description : Email on Rails. Compose, deliver, and test emails using the familiar controller/view pattern. First-class support for multipart email and attachments. -------------------------------------------------------------------------------- Update Information: Ruby on Rails security upgrade: - Versions-7-0-7-2-6-1-7-6-have-been-released - incorrect file permissions on encrypted files. Exploit not known. -------------------------------------------------------------------------------- ChangeLog: * Mon Aug 28 2023 Pavel Valena - 1:7.0.7.2-1 - Update to actionmailer 7.0.7.2. -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-4f0bb4ff5e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Enhance the Ruby on Rails ActionMailer functionality on Fedora 39 to resolve the issue of improper file permissions on encrypted documents. Discover further details.. Ruby ActionMailer Upgrade,Fedora Security Notification,File Permissions Fix,Rails Email Framework. . LinuxSecurity.com Team

Calendar 2 Sep 15, 2023 Fedora
89

Fedora 37: FEDORA-2023-7002afbbb8 moderate: actionmailer XSS Threat

Update to Ruby on Rails 7.0.4.3. https://rubyonrails.org/2023/3/13/Rails-7-0-4-3-and-6-1-7-3-have-been-released. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-7002afbbb8 2023-04-05 01:34:43.146270 --------------------------------------------------------------------------------Name : rubygem-actionmailer Product : Fedora 37 Version : 7.0.4.3 Release : 1.fc37 URL : https://rubyonrails.org Summary : Email composition and delivery framework (part of Rails) Description : Email on Rails. Compose, deliver, and test emails using the familiar controller/view pattern. First-class support for multipart email and attachments. --------------------------------------------------------------------------------Update Information: Update to Ruby on Rails 7.0.4.3. https://rubyonrails.org/2023/3/13/Rails-7-0-4-3-and-6-1-7-3-have-been-released --------------------------------------------------------------------------------ChangeLog: * Tue Mar 14 2023 Pavel Valena - 1:7.0.4.3-1 - Update to actionmailer 7.0.4.3. --------------------------------------------------------------------------------References: [ 1 ] Bug #2179637 - CVE-2023-28120 rubygem-activesupport: Possible XSS in SafeBuffer#bytesplice https://bugzilla.redhat.com/show_bug.cgi?id=2179637 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-7002afbbb8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . A refresh released for rubygem actionmailer in Fedora 37 targets enhancements to the email framework along with mitigating possible security vulnerabilities.. Rubygem Actionmailer, Fedora 37 Update, Ruby on Rails Security, Email Framework Fix. . LinuxSecurity.com Team

Calendar 2 Apr 05, 2023 Fedora
89

Fedora 39: FEDORA-2023-c0698ab2f3 High: CSRF Vulnerability in MailServer

Update to 7.0.4.3. https://rubyonrails.org/2023/3/13/Rails-7-0-4-3-and-6-1-7-3-have-been-released. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-d6157bb1e2 2023-04-01 00:15:35.161368 --------------------------------------------------------------------------------Name : rubygem-actionmailer Product : Fedora 38 Version : 7.0.4.3 Release : 1.fc38 URL : https://rubyonrails.org Summary : Email composition and delivery framework (part of Rails) Description : Email on Rails. Compose, deliver, and test emails using the familiar controller/view pattern. First-class support for multipart email and attachments. --------------------------------------------------------------------------------Update Information: Update to 7.0.4.3. https://rubyonrails.org/2023/3/13/Rails-7-0-4-3-and-6-1-7-3-have-been-released --------------------------------------------------------------------------------ChangeLog: * Tue Mar 14 2023 Pavel Valena - 1:7.0.4.3-1 - Update to actionmailer 7.0.4.3. --------------------------------------------------------------------------------References: [ 1 ] Bug #2179637 - CVE-2023-28120 rubygem-activesupport: Possible XSS in SafeBuffer#bytesplice https://bugzilla.redhat.com/show_bug.cgi?id=2179637 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-d6157bb1e2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. Tounsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest update for rubygem-actionmailer in Fedora 38 resolves a critical XSS vulnerability and improves the overall functionality of the email framework.. Fedora Update, rubygem-actionmailer, software security, email framework. . LinuxSecurity.com Team

Calendar 2 Apr 01, 2023 Fedora
89

Fedora 33: FEDORA-2020-4dd34860a3 Moderate: Actionmailer Security Fix

Upgrade to Ruby on Rails 6.0.3.3. Fixes CVEs: #1877568 #1831529 #1852381. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-4dd34860a3 2020-10-05 00:15:05.246453 --------------------------------------------------------------------------------Name : rubygem-actionmailer Product : Fedora 33 Version : 6.0.3.3 Release : 1.fc33 URL : https://rubyonrails.org Summary : Email composition and delivery framework (part of Rails) Description : Email on Rails. Compose, deliver, and test emails using the familiar controller/view pattern. First-class support for multipart email and attachments. --------------------------------------------------------------------------------Update Information: Upgrade to Ruby on Rails 6.0.3.3. Fixes CVEs: #1877568 #1831529 #1852381 --------------------------------------------------------------------------------ChangeLog: * Tue Sep 22 2020 Pavel Valena - 1:6.0.3.3-1 - Update to actionmailer 6.0.3.3. Resolves: rhbz#1877505 --------------------------------------------------------------------------------References: [ 1 ] Bug #1831529 - CVE-2020-5267 rubygem-actionview: views that use the `j` or `escape_javascript` methods are susceptible to XSS attacks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1831529 [ 2 ] Bug #1852381 - CVE-2020-8185 rubygem-rails: untrusted users able to run pending migrations in production [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1852381 [ 3 ] Bug #1877568 - CVE-2020-15169 rubygem-actionview: rubygem-activeview: Cross-site scripting in translation helpers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1877568 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-4dd34860a3' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Transition to Ruby on Rails 6.0.3.3 addressing severe vulnerabilities in Fedora, improving overall application protection.. Ruby On Rails, Actionmailer, Security Fixes, Email Framework, Fedora Update. . LinuxSecurity.com Team

Calendar 2 Oct 04, 2020 Fedora
89

Fedora 30 FEDORA-2019-1cfe24db5c Moderate: Actionmailer Exec Flaws

Update Ruby on Rails to 5.2.3. Fixes CVE-2019-5418 CVE-2019-5419 CVE-2019-5420.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-1cfe24db5c 2019-05-10 00:46:38.157347 --------------------------------------------------------------------------------Name : rubygem-actionmailer Product : Fedora 30 Version : 5.2.3 Release : 1.fc30 URL : https://rubyonrails.org/ Summary : Email composition, delivery, and receiving framework (part of Rails) Description : Email on Rails. Compose, deliver, receive, and test emails using the familiar controller/view pattern. First-class support for multipart email and attachments. --------------------------------------------------------------------------------Update Information: Update Ruby on Rails to 5.2.3. Fixes CVE-2019-5418 CVE-2019-5419 CVE-2019-5420. --------------------------------------------------------------------------------ChangeLog: * Thu Mar 28 2019 Pavel Valena - 1:5.2.3-1 - Update to Action Mailer 5.2.3. * Thu Mar 14 2019 Pavel Valena - 1:5.2.2.1-1 - Update to Action Mailer 5.2.2.1. --------------------------------------------------------------------------------References: [ 1 ] Bug #1689161 - CVE-2019-5418 CVE-2019-5419 rubygem-actionview: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1689161 [ 2 ] Bug #1689155 - CVE-2019-5420 rubygem-rails: Weak secret token leading to possible code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1689155 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-1cfe24db5c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys usedby the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Security notification for Fedora 30 regarding an upgrade of rubygem-actionpack to rectify numerous severe vulnerabilities.. rubygem-actionmailer,Ruby On Rails,Fedora 30,email framework,security update. . LinuxSecurity.com Team

Calendar 2 May 09, 2019 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here