Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 10 Advisories: DLA-3084-1 Critical Ndpi Buffer Over-Read

Two security issues have been discovered in ndpi: deep packet inspection library. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3084-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Anton Gladky August 27, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ndpi Version : 2.6-3+deb10u1 CVE ID : CVE-2020-15472 CVE-2020-15476 Two security issues have been discovered in ndpi: deep packet inspection library. CVE-2020-15472 H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c. CVE-2020-15476 Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle. For Debian 10 buster, these problems have been fixed in version 2.6-3+deb10u1. We recommend that you upgrade your ndpi packages. For the detailed security status of ndpi please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ndpi Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-4567-1 addresses vulnerabilities in the zlib compression library. Safeguard your system by applying the recent patches.. ndpi Security Update, Debian LTS, Deep Packet Inspection, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 28, 2022 Critical Debian LTS
98

Red Hat Enterprise Linux 7.4 RHSA-2022:2188-01 Vital: Kernel Security Patch

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2022:2188-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:2188 Issue date: 2022-05-11 CVE Names: CVE-2021-4028 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.4) - noarch, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.4) - x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: use-after-free in RDMA listen() (CVE-2021-4028) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2027201 - CVE-2021-4028 kernel: use-after-free in RDMA listen() 6. Package List: Red Hat Enterprise Linux Server AUS(v. 7.4): Source: kernel-3.10.0-693.100.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-693.100.1.el7.noarch.rpm kernel-doc-3.10.0-693.100.1.el7.noarch.rpm x86_64: kernel-3.10.0-693.100.1.el7.x86_64.rpm kernel-debug-3.10.0-693.100.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-693.100.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-693.100.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-693.100.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-693.100.1.el7.x86_64.rpm kernel-devel-3.10.0-693.100.1.el7.x86_64.rpm kernel-headers-3.10.0-693.100.1.el7.x86_64.rpm kernel-tools-3.10.0-693.100.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-693.100.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-693.100.1.el7.x86_64.rpm perf-3.10.0-693.100.1.el7.x86_64.rpm perf-debuginfo-3.10.0-693.100.1.el7.x86_64.rpm python-perf-3.10.0-693.100.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-693.100.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.4): x86_64: kernel-debug-debuginfo-3.10.0-693.100.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-693.100.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-693.100.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-693.100.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-693.100.1.el7.x86_64.rpm perf-debuginfo-3.10.0-693.100.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-693.100.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-4028 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYnvxv9zjgjWX9erEAQishg/6Axs+mtynl4e6ma6bWP+WheTW3eqTc0GS owMt7X6GYB0kKza0fcx5+J5iq+NwyJVPwdOn4DJFjqqvSCZFULcvFLDahmiUsMWd 6BoycZ/Fpc0oCMadMh9puYMaJBY0fRMcu56gUIL8Xun6t7DZaVh648J//R2Un1ff /towRDfY9EEGD2BWbJ/79mBabS8C752HoyOvtwc70dhXVDF3YGH4tV2jqpp11rH7 PZUAXtfXD0oJ76i1rYKrbq/m4uD0meN/tCgn+tF867fkGrZWrOm1qdSU7SBkt+kK 4h0Slr/6Bj4sFs3C9U1SRwGkUAK+3WXLcQDFhAlsxVcuFsdZk6Tk5DS769EkUfKn RrgtEwMHWDrmU4eJS+VjuuImgSbqZJl6BI+5LetM3qAJlvPSRwecVWcGScqhoVpg pX3tH0kAnH1+zAxAGqHczh4x1GCGKo0qLX/whIltvwnOml4q135N8i/fGCw4OTVb dcuaD6kELi+i4DIaoc7v6mSmTzOVwUB2wk5abbCApSeIN4y+Tkexkxsy7/XM6k05 GDvMICq0sEVRrPC+m6jq+J7vbENsIiAeMWHQP/atbW/FMQDeUCRqkQewUKjFhkhi HSYfHfW/X3yfvq3Mc7aoMAkZzo3XmKUpxS3x+Bx3WKoC2lkK8L9VT64az5/A0F76 eA4+w/hwpak=+YMJ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Vital system patch for Red Hat Enterprise Linux 7.4, bolstering defenses against potential vulnerabilities.. Red Hat Enterprise Linux, Kernel Update, Important Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 11, 2022 Important Red Hat
202

openSUSE Leap 42.1 Advisory: Important php5 Security Fixes

An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available.. openSUSE Security Update: Security update for php5 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:1173-1 Rating: important References: #968284 #969821 #971611 #971612 #971912 #973351 #973792 Cross-References: CVE-2014-9767 CVE-2015-8835 CVE-2015-8838 CVE-2016-2554 CVE-2016-3141 CVE-2016-3142 CVE-2016-3185 Affected Products: openSUSE Leap 42.1 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: This update for php5 fixes the following security issues: - CVE-2015-8838: mysqlnd was vulnerable to BACKRONYM (bnc#973792). - CVE-2015-8835: SoapClient s_call method suffered from a type confusion issue that could have lead to crashes [bsc#973351] - CVE-2016-2554: A NULL pointer dereference in phar_get_fp_offset could lead to crashes. [bsc#968284] Note: we do not ship the phar extension currently, so we are not affected. - CVE-2016-3141: A use-after-free / double-free in the WDDX deserialization could lead to crashes or potential code execution. [bsc#969821] - CVE-2016-3142: An Out-of-bounds read in phar_parse_zipfile() could lead to crashes. [bsc#971912] Note: we do not ship the phar extension currently, so we are not affected. - CVE-2014-9767: A directory traversal when extracting zip files was fixed that could lead to overwritten files. [bsc#971612] - CVE-2016-3185: A type confusion vulnerability in make_http_soap_request() could lead to crashes or potentially code execution. [bsc#971611] This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: Toinstall this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.1: zypper in -t patch openSUSE-2016-517=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.1 (i586 x86_64): apache2-mod_php5-5.5.14-44.1 apache2-mod_php5-debuginfo-5.5.14-44.1 php5-5.5.14-44.1 php5-bcmath-5.5.14-44.1 php5-bcmath-debuginfo-5.5.14-44.1 php5-bz2-5.5.14-44.1 php5-bz2-debuginfo-5.5.14-44.1 php5-calendar-5.5.14-44.1 php5-calendar-debuginfo-5.5.14-44.1 php5-ctype-5.5.14-44.1 php5-ctype-debuginfo-5.5.14-44.1 php5-curl-5.5.14-44.1 php5-curl-debuginfo-5.5.14-44.1 php5-dba-5.5.14-44.1 php5-dba-debuginfo-5.5.14-44.1 php5-debuginfo-5.5.14-44.1 php5-debugsource-5.5.14-44.1 php5-devel-5.5.14-44.1 php5-dom-5.5.14-44.1 php5-dom-debuginfo-5.5.14-44.1 php5-enchant-5.5.14-44.1 php5-enchant-debuginfo-5.5.14-44.1 php5-exif-5.5.14-44.1 php5-exif-debuginfo-5.5.14-44.1 php5-fastcgi-5.5.14-44.1 php5-fastcgi-debuginfo-5.5.14-44.1 php5-fileinfo-5.5.14-44.1 php5-fileinfo-debuginfo-5.5.14-44.1 php5-firebird-5.5.14-44.1 php5-firebird-debuginfo-5.5.14-44.1 php5-fpm-5.5.14-44.1 php5-fpm-debuginfo-5.5.14-44.1 php5-ftp-5.5.14-44.1 php5-ftp-debuginfo-5.5.14-44.1 php5-gd-5.5.14-44.1 php5-gd-debuginfo-5.5.14-44.1 php5-gettext-5.5.14-44.1 php5-gettext-debuginfo-5.5.14-44.1 php5-gmp-5.5.14-44.1 php5-gmp-debuginfo-5.5.14-44.1 php5-iconv-5.5.14-44.1 php5-iconv-debuginfo-5.5.14-44.1 php5-imap-5.5.14-44.1 php5-imap-debuginfo-5.5.14-44.1 php5-intl-5.5.14-44.1 php5-intl-debuginfo-5.5.14-44.1 php5-json-5.5.14-44.1 php5-json-debuginfo-5.5.14-44.1 php5-ldap-5.5.14-44.1 php5-ldap-debuginfo-5.5.14-44.1 php5-mbstring-5.5.14-44.1 php5-mbstring-debuginfo-5.5.14-44.1 php5-mcrypt-5.5.14-44.1 php5-mcrypt-debuginfo-5.5.14-44.1 php5-mssql-5.5.14-44.1 php5-mssql-debuginfo-5.5.14-44.1 php5-mysql-5.5.14-44.1 php5-mysql-debuginfo-5.5.14-44.1 php5-odbc-5.5.14-44.1 php5-odbc-debuginfo-5.5.14-44.1 php5-opcache-5.5.14-44.1 php5-opcache-debuginfo-5.5.14-44.1 php5-openssl-5.5.14-44.1 php5-openssl-debuginfo-5.5.14-44.1 php5-pcntl-5.5.14-44.1 php5-pcntl-debuginfo-5.5.14-44.1 php5-pdo-5.5.14-44.1 php5-pdo-debuginfo-5.5.14-44.1 php5-pgsql-5.5.14-44.1 php5-pgsql-debuginfo-5.5.14-44.1 php5-phar-5.5.14-44.1 php5-phar-debuginfo-5.5.14-44.1 php5-posix-5.5.14-44.1 php5-posix-debuginfo-5.5.14-44.1 php5-pspell-5.5.14-44.1 php5-pspell-debuginfo-5.5.14-44.1 php5-readline-5.5.14-44.1 php5-readline-debuginfo-5.5.14-44.1 php5-shmop-5.5.14-44.1 php5-shmop-debuginfo-5.5.14-44.1 php5-snmp-5.5.14-44.1 php5-snmp-debuginfo-5.5.14-44.1 php5-soap-5.5.14-44.1 php5-soap-debuginfo-5.5.14-44.1 php5-sockets-5.5.14-44.1 php5-sockets-debuginfo-5.5.14-44.1 php5-sqlite-5.5.14-44.1 php5-sqlite-debuginfo-5.5.14-44.1 php5-suhosin-5.5.14-44.1 php5-suhosin-debuginfo-5.5.14-44.1 php5-sysvmsg-5.5.14-44.1 php5-sysvmsg-debuginfo-5.5.14-44.1 php5-sysvsem-5.5.14-44.1 php5-sysvsem-debuginfo-5.5.14-44.1 php5-sysvshm-5.5.14-44.1 php5-sysvshm-debuginfo-5.5.14-44.1 php5-tidy-5.5.14-44.1 php5-tidy-debuginfo-5.5.14-44.1 php5-tokenizer-5.5.14-44.1 php5-tokenizer-debuginfo-5.5.14-44.1 php5-wddx-5.5.14-44.1 php5-wddx-debuginfo-5.5.14-44.1 php5-xmlreader-5.5.14-44.1 php5-xmlreader-debuginfo-5.5.14-44.1 php5-xmlrpc-5.5.14-44.1 php5-xmlrpc-debuginfo-5.5.14-44.1 php5-xmlwriter-5.5.14-44.1 php5-xmlwriter-debuginfo-5.5.14-44.1 php5-xsl-5.5.14-44.1 php5-xsl-debuginfo-5.5.14-44.1 php5-zip-5.5.14-44.1 php5-zip-debuginfo-5.5.14-44.1 php5-zlib-5.5.14-44.1 php5-zlib-debuginfo-5.5.14-44.1 - openSUSE Leap 42.1 (noarch): php5-pear-5.5.14-44.1 References: https://www.suse.com/security/cve/CVE-2014-9767.html https://www.suse.com/security/cve/CVE-2015-8835.html https://www.suse.com/security/cve/CVE-2015-8838.html https://www.suse.com/security/cve/CVE-2016-2554.html https://www.suse.com/security/cve/CVE-2016-3141.html https://www.suse.com/security/cve/CVE-2016-3142.html https://www.suse.com/security/cve/CVE-2016-3185.html https://bugzilla.suse.com/968284 https://bugzilla.suse.com/969821 https://bugzilla.suse.com/971611 https://bugzilla.suse.com/971612 https://bugzilla.suse.com/971912 https://bugzilla.suse.com/973351 https://bugzilla.suse.com/973792 . openSUSE Security Patch for php5 addresses various vulnerabilities, enhancing system reliability and safeguarding against threats.. OpenSUSE Security, Php5 Update, Linux Updates, Security Fixes, Code Protection. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 28, 2016 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here