Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 18 articles for you...
202

openSUSE Leap 15.1: 2020:0250-1 Moderate: Enigmail Security Update

An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0250-1 Rating: moderate References: #1159973 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for enigmail fixes the following issues: enigmail was updated to 2.1.5: * Security issue: unsigned MIME parts displayed as signed (bsc#1159973) * Ensure that upgrading GnuPG 2.0.x to 2.2.x upgrade converts keyring format * Make Enigmail Compatible with Protected-Headers spec, draft 2 enigmail 2.1.4: * Fixes for UI glitches * Option to "Attach public key to messages" was not restored properly enigmail 2.1.3: * fix a bug in the setup wizard that could lead the wizard to never complete scanning the inbox This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-250=1 Package List: - openSUSE Leap 15.1 (x86_64): enigmail-2.1.5-lp151.2.9.1 References: https://bugzilla.suse.com/1159973 -- . OpenSUSE Security Patch: Resolution for Enigmail with Announcement ID openSUSE-SU-2020:0450-1.. openSUSE, Enigmail, security update. . LinuxSecurity.com Team

Calendar%202 Feb 27, 2020 OpenSUSE
100

SUSE 15-SP1: SUSE-SU-2020:0413-1 Moderate: Enigmail Security Fix

An update that contains security fixes can now be installed. . SUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0413-1 Rating: moderate References: #1159973 Affected Products: SUSE Linux Enterprise Workstation Extension 15-SP1 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for enigmail fixes the following issues: enigmail was updated to 2.1.5: * Security issue: unsigned MIME parts displayed as signed (bsc#1159973) * Ensure that upgrading GnuPG 2.0.x to 2.2.x upgrade converts keyring format * Make Enigmail Compatible with Protected-Headers spec, draft 2 enigmail 2.1.4: * Fixes for UI glitches * Option to "Attach public key to messages" was not restored properly enigmail 2.1.3: * fix a bug in the setup wizard that could lead the wizard to never complete scanning the inbox Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP1: zypper in -t patch SUSE-SLE-Product-WE-15-SP1-2020-413=1 Package List: - SUSE Linux Enterprise Workstation Extension 15-SP1 (x86_64): enigmail-2.1.5-3.22.1 References: https://bugzilla.suse.com/1159973 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . The newest Enigmail patch addresses critical security flaws impacting SUSE 15-SP1 platforms.. SUSE Security Update, Enigmail Fixes, Security Update Instructions. . LinuxSecurity.com Team

Calendar%202 Feb 19, 2020 SuSE
89

Fedora 31: FEDORA-2020-b48e3c177e Moderate: Enigmail 2.1.5 DoS Fix

update to enigmail 2.1.5 Includes a security fix for "Unsigned MIME parts displayed as signed". --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-b48e3c177e 2020-01-24 17:07:54.394766 --------------------------------------------------------------------------------Name : thunderbird-enigmail Product : Fedora 31 Version : 2.1.5 Release : 1.fc31 URL : https://enigmail.net/index.php/en/ Summary : Authentication and encryption extension for Mozilla Thunderbird Description : Enigmail is an extension to the mail client Mozilla Thunderbird which allows users to access the authentication and encryption features provided by GnuPG --------------------------------------------------------------------------------Update Information: update to enigmail 2.1.5 Includes a security fix for "Unsigned MIME parts displayed as signed" --------------------------------------------------------------------------------ChangeLog: * Mon Jan 13 2020 Felix Schwarz - 2.1.5-1 - update to 2.1.5 * Tue Nov 12 2019 Felix Schwarz - 2.1.3-4 - do not build package on armv7hl/s390x (thunderbird not available there) * Mon Nov 11 2019 Felix Schwarz - 2.1.3-3 - enable GPG-based source file verification - package license file * Sat Nov 9 2019 Kai Hambrecht - 2.1.3-2 - adjust SPEC file rhbz#1752435 * Fri Nov 8 2019 Kai Hambrecht - 2.1.3-1 - update version to support TB 68 --------------------------------------------------------------------------------References: [ 1 ] Bug #1790323 - enigmail: Unsigned MIME parts displayed as signed https://bugzilla.redhat.com/show_bug.cgi?id=1790323 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-b48e3c177e' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The latest update for Thunderbird Enigmail version 2.1.5 resolves problems related to unsigned MIME types. To install it, simply use the 'dnf' command.. Fedora Enigmail Update, Thunderbird Security Fix, DoS Prevention. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 24, 2020 Important Fedora
89

Fedora 30: 2020-83a9e4c25b Important: Firefox Add-on Security Update

Security fix for CVE-2019-14664, CVE-2019-12269 and compatibility with Thunderbird 68. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-941d57ed72 2019-11-21 02:02:03.859554 --------------------------------------------------------------------------------Name : thunderbird-enigmail Product : Fedora 29 Version : 2.1.3 Release : 4.fc29 URL : https://enigmail.net/index.php/en/ Summary : Authentication and encryption extension for Mozilla Thunderbird Description : Enigmail is an extension to the mail client Mozilla Thunderbird which allows users to access the authentication and encryption features provided by GnuPG --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-14664, CVE-2019-12269 and compatibility with Thunderbird 68 --------------------------------------------------------------------------------ChangeLog: * Tue Nov 12 2019 Felix Schwarz - 2.1.3-4 - do not build package on armv7hl/s390x (thunderbird not available there) * Mon Nov 11 2019 Felix Schwarz - 2.1.3-3 - enable GPG-based source file verification - package license file * Sat Nov 9 2019 Kai Hambrecht - 2.1.3-2 - adjust SPEC file rhbz#1752435 * Fri Nov 8 2019 Kai Hambrecht - 2.1.3-1 - update version to support TB 68 --------------------------------------------------------------------------------References: [ 1 ] Bug #1660478 - thunderbird-enigmail: HTTP authentication dialog may be triggered [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1660478 [ 2 ] Bug #1752435 - enigmail version 2.1 needs to be packaged to work with thunderbird 68 https://bugzilla.redhat.com/show_bug.cgi?id=1752435 [ 3 ] Bug #1749211 - CVE-2019-14664 thunderbird-enigmail: information leak in response to encrypted mail [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1749211 [ 4 ] Bug #1712723 - CVE-2019-12269thunderbird-enigmail: signature spoofing in inline PGP message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1712723 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-941d57ed72' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Crucial patch release for Thunderbird Enigmail on Fedora 29 addresses critical weaknesses while boosting interoperability.. Fedora Updates, Thunderbird Plugin, Encryption Extensions, Authentication Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 20, 2019 Important Fedora
100

SUSE: 2019:2982-1 Important: Enigmail Security Enhancement Released

An update that contains security fixes can now be installed. . SUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2982-1 Rating: moderate References: #1141025 #1151317 Affected Products: SUSE Linux Enterprise Workstation Extension 15-SP1 SUSE Linux Enterprise Workstation Extension 15 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for enigmail fixes the following issues: - SeaMonkey is no longer supported. Update description and no longer put in SeaMonkey addons path (bsc#1151317) enigmail was updated 2.1.2: * compatibility with Mozilla Thunderbird 68 * New simplified setup wizard * Full support for keys.openpgp.org * Default to ECC keys on GnuPG 2.1 or later * Autocrypt: implemented key-gossip and updates to known keys enimail was updated to 2.0.12: * set the default keyserver to keys.openpgp.org in order to mitigate the SKS Keyserver Network Attack (bsc#1141025) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP1: zypper in -t patch SUSE-SLE-Product-WE-15-SP1-2019-2982=1 - SUSE Linux Enterprise Workstation Extension 15: zypper in -t patch SUSE-SLE-Product-WE-15-2019-2982=1 Package List: - SUSE Linux Enterprise Workstation Extension 15-SP1 (x86_64): enigmail-2.1.2-3.19.1 - SUSE Linux Enterprise Workstation Extension 15 (x86_64): enigmail-2.1.2-3.19.1 References: https://bugzilla.suse.com/1141025 https://bugzilla.suse.com/1151317 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Patch for enigmail: addresses intermediate concerns and necessitates setup. Discover additional details on the repairs provided.. SUSE Security, Enigmail Update, Software Security Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 15, 2019 Important SuSE
202

openSUSE: 2019:1612-1 Important: Enigmail Inline PGP Spoofing

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1612-1 Rating: important References: #1135855 Cross-References: CVE-2019-12269 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.1 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for enigmail fixes the following issues: enigmail was updated to 2.0.11: * CVE-2019-12269: Specially crafted inline PGP messages could spoof a "correctly signed" message (boo#1135855) enigmail was updated to 2.0.10: * various bug fixes for configuring and handling encrypted e-mail * UI fixes for dialogs, messages, and dark Thunderbird themes Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2019-1612=1 - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-1612=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1612=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): enigmail-2.0.11-31.1 - openSUSE Leap 15.1 (x86_64): enigmail-2.0.11-lp151.2.3.1 - openSUSE Leap 15.0 (x86_64): enigmail-2.0.11-lp150.31.1 References: https://www.suse.com/security/cve/CVE-2019-12269.html https://bugzilla.suse.com/1135855 -- . openSUSE has released a crucial security patch for Enigmail, tackling a significant vulnerability associated with inline PGP message forgery.. openSUSE Enigmail Update, Security Fixes, Important Updates, PGP Spoofing. . Severity: Important.LinuxSecurity.com Team

Calendar%202 Jun 24, 2019 Important OpenSUSE
100

SUSE: 2019:1576-1 Critical Update: Enigmail Spoofing Vulnerability Patch

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1576-1 Rating: important References: #1135855 Cross-References: CVE-2019-12269 Affected Products: SUSE Linux Enterprise Workstation Extension 15-SP1 SUSE Linux Enterprise Workstation Extension 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for enigmail to version 2.0.11 fixes the following issues: Security issue fixed: - CVE-2019-12269: Fixed an issue where a specially crafted inline PGP messages could spoof a "correctly signed" message (bsc#1135855). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP1: zypper in -t patch SUSE-SLE-Product-WE-15-SP1-2019-1576=1 - SUSE Linux Enterprise Workstation Extension 15: zypper in -t patch SUSE-SLE-Product-WE-15-2019-1576=1 Package List: - SUSE Linux Enterprise Workstation Extension 15-SP1 (x86_64): enigmail-2.0.11-3.16.1 - SUSE Linux Enterprise Workstation Extension 15 (x86_64): enigmail-2.0.11-3.16.1 References: https://www.suse.com/security/cve/CVE-2019-12269.html https://bugzilla.suse.com/1135855 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE enhances security with critical Enigmail update against spoofing threats, ID: SUSE-SU-2019:1576-1.. update, security, fixes, vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 20, 2019 Important SuSE
100

SUSE: 2018:4215-1 Moderate: Enigmail Email Credentials Issue

An update that contains security fixes can now be installed. . SUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:4215-1 Rating: moderate References: #1118935 Affected Products: SUSE Linux Enterprise Workstation Extension 15 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for enigmail to version 2.0.9 fixes the following issues: Security issue fixed: - When using Web Key Discovery, a HTTP authentication may be triggered. This may trick users into possibly sending e-mail credentials (bsc#1118935). Non-security issues fixed: - pEp - PGP/MIME signed-only messages are ignored - Autocrypt overrules manually created Per-Recipient Rules - "Re:" prefix on subject line disappears when editing encrypted, saved draft Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15: zypper in -t patch SUSE-SLE-Product-WE-15-2018-3024=1 Package List: - SUSE Linux Enterprise Workstation Extension 15 (x86_64): enigmail-2.0.9-3.13.1 References: https://bugzilla.suse.com/1118935 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE enhances Claws Mail with vital patches to fortify security and boost email privacy. Key updates implemented.. SUSE Update, Security Fixes, Enigmail Software Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 21, 2018 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200