Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 32: FEDORA-2020-0ab6656303 Moderate: GnuTLS Heap Overflow

https://lists.gnupg.org/pipermail/gnutls-help/2020-September/004669.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-0ab6656303 2020-09-13 14:27:05.374615 --------------------------------------------------------------------------------Name : mingw-gnutls Product : Fedora 32 Version : 3.6.15 Release : 1.fc32 URL : http://www.gnutls.org/ Summary : MinGW GnuTLS TLS/SSL encryption library Description : GnuTLS TLS/SSL encryption library. This library is cross-compiled for MinGW. --------------------------------------------------------------------------------Update Information: https://lists.gnupg.org/pipermail/gnutls-help/2020-September/004669.html --------------------------------------------------------------------------------ChangeLog: * Fri Sep 4 2020 Michael Cronenworth - 3.6.15-1 - New upstream release 3.6.15 * Tue Jul 28 2020 Fedora Release Engineering - 3.6.14-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1875864 - CVE-2020-24659 mingw-gnutls: gnutls: Heap buffer overflow in handshake with no_renegotiation alert sent [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1875864 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-0ab6656303' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailinglist -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . OpenSSL for MinGW update resolves critical buffer overflow issue. Upgrade today to improve your system's security and gain performance upgrades.. MinGW, GnuTLS, Fedora Security Update, Heap Overflow. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 13, 2020 Important Fedora
89

Fedora 32 Security Update: Critical DoS Vulnerabilities in mingw-gnutls

https://lists.gnupg.org/pipermail/gnutls-help/2020-March/004642.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-f90fb78f70 2020-05-08 02:43:36.320562 --------------------------------------------------------------------------------Name : mingw-gnutls Product : Fedora 32 Version : 3.6.13 Release : 1.fc32 URL : http://www.gnutls.org/ Summary : MinGW GnuTLS TLS/SSL encryption library Description : GnuTLS TLS/SSL encryption library. This library is cross-compiled for MinGW. --------------------------------------------------------------------------------Update Information: https://lists.gnupg.org/pipermail/gnutls-help/2020-March/004642.html --------------------------------------------------------------------------------ChangeLog: * Tue Mar 31 2020 Michael Cronenworth - 3.6.13-1 - New upstream release 3.6.13 --------------------------------------------------------------------------------References: [ 1 ] Bug #1619511 - CVE-2018-10844 mingw-gnutls: gnutls: HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy function calls [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1619511 [ 2 ] Bug #1619518 - CVE-2018-10845 mingw-gnutls: gnutls: HMAC-SHA-384 vulnerable to Lucky thirteen attack due to use of wrong constant [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1619518 [ 3 ] Bug #1619523 - CVE-2018-10846 mingw-gnutls: gnutls: "Just in Time" PRIME + PROBE cache-based side channel attack can lead to plaintext recovery [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1619523 [ 4 ] Bug #1821899 - CVE-2020-11501 mingw-gnutls: gnutls: DTLS client hello contains a random value of all zeroes [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1821899 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su-c 'dnf upgrade --advisory FEDORA-2020-f90fb78f70' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . MinGW GnuTLS TLS/SSL package revised to address security vulnerabilities. Use dnf to install for updates and improvements.. MinGW GnuTLS, Fedora, TLS/SSL, Encryption Library, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 07, 2020 Critical Fedora
89

Fedora 22: Crucial Python-RSA Security Update Unveiled - Essential Advisory

New upstream release with security bug fix. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-15fb7deba0 2016-04-07 12:06:06.793002 -------------------------------------------------------------------------------- Name : python-rsa Product : Fedora 22 Version : 3.4.1 Release : 1.fc22 URL : http://stuvel.eu/rsa Summary : Pure-Python RSA implementation Description : Python-RSA is a pure-Python RSA implementation. It supports encryption and decryption, signing and verifying signatures, and key generation according to PKCS#1 version 1.5. It can be used as a Python library as well as on the command-line. -------------------------------------------------------------------------------- Update Information: New upstream release with security bug fix -------------------------------------------------------------------------------- References: [ 1 ] Bug #1170702 - Long-unfixed security vulnerabilities https://bugzilla.redhat.com/show_bug.cgi?id=1170702 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update python-rsa' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Recent upstream update of python-rsa in Fedora 22 fixes important security vulnerabilities. Please update your system immediately to enhance protection.. Fedora Python-RSA, Security Update, Software Fix, Encryption Library, Fedora Security. .Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 07, 2016 Critical Fedora
89

Fedora 21: 2015-5245 Critical: GnuTLS Update for libtasn1 Overflow

libtasn1 4.4 release, fixing CVE-2015-2806. GnuTLS 3.3.14 release . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-5245 2015-04-01 21:10:51 -------------------------------------------------------------------------------- Name : mingw-gnutls Product : Fedora 21 Version : 3.3.14 Release : 1.fc21 URL : http://www.gnutls.org/ Summary : MinGW GnuTLS TLS/SSL encryption library Description : GnuTLS TLS/SSL encryption library. This library is cross-compiled for MinGW. -------------------------------------------------------------------------------- Update Information: libtasn1 4.4 release, fixing CVE-2015-2806. GnuTLS 3.3.14 release -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2015 Michael Cronenworth - 3.3.14-1 - Update to 3.3.14 * Fri Jan 30 2015 Michael Cronenworth - 3.3.12-1 - Update to 3.3.12 * Mon Dec 15 2014 Michael Cronenworth - 3.3.11-1 - Update to 3.3.11-------------------------------------------------------------------------------- References: [ 1 ] Bug #1207192 - CVE-2015-2806 libtasn1: stack overflow in asn1_der_decoding https://bugzilla.redhat.com/show_bug.cgi?id=1207192 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mingw-gnutls' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Fedora users receive aMinGW GnuTLS security patch enhancing defenses against libtasn1 weaknesses, ensuring stronger encryption protocols.. Fedora Security Advisory,GnuTLS Update,MinGW Package,Encryption Library. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 21, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here