Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 9 Stretch DLA-2306-1 Critical: libphp-phpmailer Escaping Issue

It was discovered that there was an escaping issue in libphp-phpmailer, an email generation utility class for the PHP programming language. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2306-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Abhijith PA August 01, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libphp-phpmailer Version : 5.2.14+dfsg-2.3+deb9u2 CVE ID : CVE-2020-13625 Debian Bug : 962827 It was discovered that there was an escaping issue in libphp-phpmailer, an email generation utility class for the PHP programming language. The `Content-Type` and `Content-Disposition` headers could have permitted file attachments that bypassed attachment filters which match on filename extensions. For Debian 9 stretch, this problem has been fixed in version 5.2.14+dfsg-2.3+deb9u2. We recommend that you upgrade your libphp-phpmailer packages. For the detailed security status of libphp-phpmailer please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libphp-phpmailer Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A security patch for libphp-phpmailer resolves an issue related to improper escaping that permitted evasion of attachment restrictions in Debian.. Debian Security, PHP Mailer Update, Escaping Issue, Email Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 02, 2020 Critical Debian LTS
197

Debian LTS: DLA-2244-1 Release for libphp-phpmailer - Medium Escaping Flaw

It was discovered that there was an escaping issue in libphp-phpmailer, an email generation utility class for the PHP programming language. . Package : libphp-phpmailer Version : 5.2.9+dfsg-2+deb8u6 CVE ID : CVE-2020-13625 It was discovered that there was an escaping issue in libphp-phpmailer, an email generation utility class for the PHP programming language. The `Content-Type` and `Content-Disposition` headers could have permitted file attachments that bypassed attachment filters which match on filename extensions. For more information, please see the following URL: https://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-f7hx-fqxw-rvvj For Debian 8 "Jessie", this issue has been fixed in libphp-phpmailer version 5.2.9+dfsg-2+deb8u6. We recommend that you upgrade your libphp-phpmailer packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . A vulnerability has been identified in libphp-phpmailer concerning file uploads. Update is advised to resolve the concern.. libphp-phpmailer, security update, escaping issue, php utility, debian. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Jun 11, 2020 Medium Debian LTS
89

Fedora Core 4: 2006-703 Critical Vulnerability in MySQL Escaping Method

Repairs multibyte string escaping vulnerability.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-703 2006-06-13 ---------------------------------------------------------------------Product : Fedora Core 4 Name : mysql Version : 4.1.20 Release : 1.FC4.1 Summary : MySQL client programs and shared libraries. Description : MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the MySQL client programs, the client shared libraries, and generic MySQL files. ---------------------------------------------------------------------Update Information: Repairs multibyte string escaping vulnerability. ---------------------------------------------------------------------* Thu Jun 1 2006 Tom Lane 4.1.20-1.FC4.1 - Update to MySQL 4.1.20 (fixes CVE-2006-2753) ---------------------------------------------------------------------This update can be downloaded from: f9d7512362a9d098339fe1095b1eaf304fd6082e SRPMS/mysql-4.1.20-1.FC4.1.src.rpm f9d7512362a9d098339fe1095b1eaf304fd6082e noarch/mysql-4.1.20-1.FC4.1.src.rpm 292bad3ea934f89db78b3eba2b55bf8ea2bae7f4 ppc/mysql-4.1.20-1.FC4.1.ppc.rpm 758ca4284f66f9ca6e88c41eb3452e7ec209c9a3 ppc/mysql-server-4.1.20-1.FC4.1.ppc.rpm 91d8729a8c8c7f67bdfc3e9bb9ffeebe39f5337e ppc/mysql-devel-4.1.20-1.FC4.1.ppc.rpm 9765d31fccf06a1038aec1bfa03f08917abbeb95 ppc/mysql-bench-4.1.20-1.FC4.1.ppc.rpm 7e7c8a3e17fa30b2f7815d36b92ab3c58555867c ppc/debug/mysql-debuginfo-4.1.20-1.FC4.1.ppc.rpm bf3943073ab82bc5e235b5ab30ade2dd954f17f3 x86_64/mysql-4.1.20-1.FC4.1.x86_64.rpm 5a099047243fb308dcb1c4b207b7d4ddae60e247 x86_64/mysql-server-4.1.20-1.FC4.1.x86_64.rpm 342b58d9388276c9284aa7336927fd5e5e1669f9 x86_64/mysql-devel-4.1.20-1.FC4.1.x86_64.rpm c069cfaa7263fac4152c782c8b0852f9b58c6bf8 x86_64/mysql-bench-4.1.20-1.FC4.1.x86_64.rpm f189ec9fcb823946b597c94ebd8e97cfc806bad9 x86_64/debug/mysql-debuginfo-4.1.20-1.FC4.1.x86_64.rpm 4685407fc3d74c374f303972e8c7d9426251a08e i386/mysql-4.1.20-1.FC4.1.i386.rpm 0d3793c3afa3df8af3dc3db7cef77fc1b6138f31 i386/mysql-server-4.1.20-1.FC4.1.i386.rpm 3edbc9f896f3bc7333883b37387d70739a0236b8 i386/mysql-devel-4.1.20-1.FC4.1.i386.rpm f8922d149279b1e93fa32ad416870b370341565e i386/mysql-bench-4.1.20-1.FC4.1.i386.rpm 1713824ea3a2227e9ac68aa466720c0bcdca9e01 i386/debug/mysql-debuginfo-4.1.20-1.FC4.1.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Important advisory for Fedora Core 4 tackling the multibyte character handling vulnerability in MySQL. Immediate steps needed for system safety.. MySQL, Fedora Core 4, Escaping Issue, Security Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 13, 2006 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here