Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
91

Gentoo: GLSA-202310-15 Important: KDE Plasma Security Flaw Mitigation

A vulnerability in the GNOME desktop library may allow attackers to escape the sandbox.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201908-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: GNOME desktop library: Security bypass Date: August 31, 2019 Bugs: #692782 ID: 201908-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in the GNOME desktop library may allow attackers to escape the sandbox. Background ========= Library with common API for various GNOME modules. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 gnome-base/gnome-desktop < 3.30.2.3 > = 3.30.2.3 Description ========== A vulnerability was discovered in the GNOME desktop library which allows an attacker to escape the sandbox. Impact ===== A local attacker could possibly bypass sandbox protection. Workaround ========= There is no known workaround at this time. Resolution ========= All GNOME desktop library users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =gnome-base/gnome-desktop-3.30.2.3" References ========= [ 1 ] CVE-2019-11460 https://nvd.nist.gov/vuln/detail/CVE-2019-11460 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201908-28 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is ofutmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2019 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . A regional threat actor might exploit a vulnerability in the KDE framework to break free from confinement. Users must update for protection.. GNOME Security Bypass, Gentoo Security Advisory, Sandbox Escape. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 31, 2019 Important Gentoo
172

Ubuntu 4011-1 Jinja2 Security Advisory: Escape Sandbox Issues

Several security issues were fixed in Jinja2.. =========================================================================Ubuntu Security Notice USN-4011-1 June 06, 2019 jinja2 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.04 - Ubuntu 18.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Jinja2. Software Description: - jinja2: small but fast and easy to use stand-alone template engine Details: Olivier Dony discovered that Jinja incorrectly handled str.format. An attacker could possibly use this issue to escape the sandbox. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10745) Brian Welch discovered that Jinja incorrectly handled str.format_map. An attacker could possibly use this issue to escape the sandbox. (CVE-2019-10906) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: python-jinja2 2.10-1ubuntu0.19.04.1 python3-jinja2 2.10-1ubuntu0.19.04.1 Ubuntu 18.10: python-jinja2 2.10-1ubuntu0.18.10.1 python3-jinja2 2.10-1ubuntu0.18.10.1 Ubuntu 18.04 LTS: python-jinja2 2.10-1ubuntu0.18.04.1 python3-jinja2 2.10-1ubuntu0.18.04.1 Ubuntu 16.04 LTS: python-jinja2 2.8-1ubuntu0.1 python3-jinja2 2.8-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4011-1 CVE-2016-10745, CVE-2019-10906 Package Information: https://launchpad.net/ubuntu/+source/jinja2/2.10-1ubuntu0.19.04.1 https://launchpad.net/ubuntu/+source/jinja2/2.10-1ubuntu0.18.10.1 https://launchpad.net/ubuntu/+source/jinja2/2.10-1ubuntu0.18.04.1 https://launchpad.net/ubuntu/+source/jinja2/2.8-1ubuntu0.1 . Jinja2 security flaws addressed in Ubuntu versions 16.04 through 19.04. Ensure your system is current to mitigate vulnerabilities.. Ubuntu Security, Jinja2 Vulnerabilities, Update Instructions. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 06, 2019 Critical Ubuntu
203

Mageia 6 MGASA-2018-0408 Moderate: Ghostscript Escape Sandbox

Updated ghostscript packages fix many bugs and security vulnerabilities: Bypassing executeonly to escape -dSAFER sandbox. (CVE-2018-17961) Saved execution stacks can leak operator arrays. (CVE-2018-18073) . MGASA-2018-0408 - Updated ghostscript packages fix security vulnerabilities Publication date: 19 Oct 2018 URL: https://advisories.mageia.org/MGASA-2018-0408.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-17961, CVE-2018-18073, CVE-2018-18284 Updated ghostscript packages fix many bugs and security vulnerabilities: Bypassing executeonly to escape -dSAFER sandbox. (CVE-2018-17961) Saved execution stacks can leak operator arrays. (CVE-2018-18073) 1Policy operator gives access to .forceput. (CVE-2018-18284) References: - https://bugs.mageia.org/show_bug.cgi?id=23659 - https://www.openwall.com/lists/oss-security/2018/10/09/4 - https://www.openwall.com/lists/oss-security/2018/10/11/3 - https://www.openwall.com/lists/oss-security/2018/10/10/12 - https://www.openwall.com/lists/oss-security/2018/10/16/2 - https://www.cve.org/CVERecord?id=CVE-2018-17961 - https://www.cve.org/CVERecord?id=CVE-2018-18073 - https://www.cve.org/CVERecord?id=CVE-2018-18284 SRPMS: - 6/core/ghostscript-9.25-1.2.mga6 . Revamped ghostscript updates rectify vulnerabilities within Mageia 6, boosting package reliability and overall system protection.. Mageia Updates, Ghostscript Security, Software Integrity. . LinuxSecurity.com Team

Calendar 2 Oct 19, 2018 Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here