Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
203

Mageia 7: 2021-0070 Moderate: Mutt Denial of Service Advisory

It was discovered that Mutt incorrectly handled certain email messages. An attacker could possibly use this issue to cause a denial of service because rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). . MGASA-2021-0070 - Updated mutt packages fix a security vulnerability Publication date: 05 Feb 2021 URL: https://advisories.mageia.org/MGASA-2021-0070.html Type: security Affected Mageia releases: 7 CVE: CVE-2021-3181 It was discovered that Mutt incorrectly handled certain email messages. An attacker could possibly use this issue to cause a denial of service because rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). (CVE-2021-3181). mutt-1.11.4 has been patched for Mageia 7. References: - https://bugs.mageia.org/show_bug.cgi?id=28159 - https://www.openwall.com/lists/oss-security/2021/01/19/10 - https://www.openwall.com/lists/oss-security/2021/01/17/2 - https://lists.debian.org/debian-lts-announce/2021/01/msg00017.html - https://ubuntu.com/security/notices/USN-4703-1 - https://www.cve.org/CVERecord?id=CVE-2021-3181 SRPMS: - 7/core/mutt-1.11.4-1.5.mga7 . A new security patch has been issued for Mutt in Mageia to fix a denial of service flaw. Find more information regarding the update within.. Mageia Security Update, Mutt Email Client, DOS Threats. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 05, 2021 Important Mageia
198

Arch Linux: Advisory ASA-202002-6 Medium: Dovecot Denial Of Service

The package dovecot before version 2.3.9.3-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-202002-6 ======================================== Severity: Medium Date : 2020-02-12 CVE-ID : CVE-2020-7046 CVE-2020-7957 Package : dovecot Type : denial of service Remote : Yes Link : https://security.archlinux.org/AVG-1097 Summary ====== The package dovecot before version 2.3.9.3-1 is vulnerable to denial of service. Resolution ========= Upgrade to 2.3.9.3-1. # pacman -Syu "dovecot> =2.3.9.3-1" The problems have been fixed upstream in version 2.3.9.3. Workaround ========= None. Description ========== - CVE-2020-7046 (denial of service) A denial of service has been found in Dovecot before 2.3.9.3, where lib-smtp doesn't handle truncated command parameters properly, resulting in infinite loop taking 100% CPU for the process. This happens for LMTP (where it doesn't matter so much) and also for submission-login where unauthenticated users can trigger it. - CVE-2020-7957 (denial of service) A denial of service have been found in Dovecot before 2.3.9.3, where a specially crafted e-mail can cause a mailbox to have permanently inaccessible mail, or the e-mail itself can be stuck in delivery. This happens because the snippet generation crashes if a message is large enough that message-parser returns multiple body blocks, the first block(s) don't contain the full snippet (e.g. full of whitespace) and the input ends with '> '. Impact ===== A remote, unauthenticated user can cause a denial of service via a crafted message. References ========= https://dovecot.org/pipermail/dovecot-news/2020-February/000430.html https://dovecot.org/pipermail/dovecot-news/2020-February/000431.html https://security.archlinux.org/CVE-2020-7046 https://security.archlinux.org/CVE-2020-7957 . Dovecot releases before 2.3.9.3-1 on Arch Linux possess a moderate severity denial of service flaw. It is crucial to update immediately.. Dovecot Denial OfService, Arch Linux Advisory, Security Update. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Feb 13, 2020 Medium ArchLinux
89

Fedora 31: 2020-adb4f0143a Moderate: Python-Django Account Takeover Risk

fix CVE-2019-19844 (rhbz#1788426). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-adb4f0143a 2020-01-17 05:04:53.758932 --------------------------------------------------------------------------------Name : python-django Product : Fedora 31 Version : 2.2.9 Release : 1.fc31 URL : http://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. --------------------------------------------------------------------------------Update Information: fix CVE-2019-19844 (rhbz#1788426) --------------------------------------------------------------------------------ChangeLog: --------------------------------------------------------------------------------References: [ 1 ] Bug #1788425 - CVE-2019-19844 Django: crafted email address allows account takeover https://bugzilla.redhat.com/show_bug.cgi?id=1788425 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-adb4f0143a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Django update fixes account takeover risk CVE-2019-19844 on Fedora 31. Patch recommended for security protection.. cve-2019-19844, (rhbz#1788426), ------------------------------------------------------------------. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 17, 2020 Important Fedora
89

Fedora: 2009-10484 Moderate: Actionmailer Email Vulnerability Fix

- Fixes CVE-2009-3009 - Downgrade to Rails 2.3.2 to avoid update issues for existing applications. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-10484 2009-10-14 00:49:00 -------------------------------------------------------------------------------- Name : rubygem-actionmailer Product : Fedora 11 Version : 2.3.2 Release : 3.fc11 URL : https://rubyonrails.org/ Summary : Service layer for easy email delivery and testing Description : Makes it trivial to test and deliver emails sent from a single service layer. -------------------------------------------------------------------------------- Update Information: - Fixes CVE-2009-3009 - Downgrade to Rails 2.3.2 to avoid update issues for existing applications -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 7 2009 David Lutterkort - 1:2.3.2-3 - Bump epoch; rails is not updatable across versions (bz 520843) - Kill test for now * Sun Sep 27 2009 Mamoru Tasaka - 2.3.3-3 - Force rebuild * Sun Aug 2 2009 Jeroen van Meeuwen - 2.3.3-2 - Disable test * Sun Aug 2 2009 Mamoru Tasaka - 2.3.3-1 - 2.3.3 - Enable test * Sun Jul 26 2009 Fedora Release Engineering - 2.3.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #520843 - CVE-2009-3009 ruby-activesupport: XSS vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=520843 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-actionmailer' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Upgrade the rubygem-actionmailer package on Fedora by updating your system, checking current versions, and running gem updates for security. rubygem actionmailer,email service,security patch,Fedora. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 13, 2009 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here