Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
100

SUSE: 2020:14489-1 Moderate: MozillaFirefox Security Update

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:14489-1 Rating: moderate References: #1174284 #1175686 Cross-References: CVE-2020-15663 CVE-2020-15664 CVE-2020-15670 Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for MozillaFirefox fixes the following issues: - Firefox Extended Support Release 78.2.0 ESR * Fixed: Various stability, functionality, and security fixes - Mozilla Firefox ESR 78.2 MFSA 2020-38 (bsc#1175686) * CVE-2020-15663 (bmo#1643199) Downgrade attack on the Mozilla Maintenance Service could have resulted in escalation of privilege * CVE-2020-15664 (bmo#1658214) Attacker-induced prompt for extension installation * CVE-2020-15670 (bmo#1651001, bmo#1651449, bmo#1653626, bmo#1656957) Memory safety bugs fixed in Firefox 80 and Firefox ESR 78.2 - Fixed Firefox tab crash in FIPS mode (bsc#1174284). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-MozillaFirefox-14489=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-MozillaFirefox-14489=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (x86_64): MozillaFirefox-78.2.0-78.90.2 MozillaFirefox-translations-common-78.2.0-78.90.2 MozillaFirefox-translations-other-78.2.0-78.90.2 - SUSE LinuxEnterprise Debuginfo 11-SP4 (x86_64): MozillaFirefox-debuginfo-78.2.0-78.90.2 References: https://www.suse.com/security/cve/CVE-2020-15663.html https://www.suse.com/security/cve/CVE-2020-15664.html https://www.suse.com/security/cve/CVE-2020-15670.html https://bugzilla.suse.com/1174284 https://bugzilla.suse.com/1175686 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Update: MozillaFirefox alert concerning the resolution of a trio of vulnerabilities. Continue reading for the patch specifics.. SUSE Security Update, MozillaFirefox Fixes, Privilege Escalation, Extension Installation. . LinuxSecurity.com Team

Calendar 2 Sep 14, 2020 SuSE
98

RedHat: RHSA-2020-3634-01 Important: Thunderbird Security Update

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2020:3634-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:3634 Issue date: 2020-09-07 CVE Names: CVE-2020-15664 CVE-2020-15669 ==================================================================== 1. Summary: An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 68.12.0. Security Fix(es): * Mozilla: Attacker-induced prompt for extension installation (CVE-2020-15664) * Mozilla: Use-After-Free when aborting an operation (CVE-2020-15669) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Thunderbird must be restarted for the update to take effect. 5. Bugs fixed(https://bugzilla.redhat.com/): 1872531 - CVE-2020-15664 Mozilla: Attacker-induced prompt for extension installation 1872532 - CVE-2020-15669 Mozilla: Use-After-Free when aborting an operation 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: thunderbird-68.12.0-1.el8_2.src.rpm aarch64: thunderbird-68.12.0-1.el8_2.aarch64.rpm thunderbird-debuginfo-68.12.0-1.el8_2.aarch64.rpm thunderbird-debugsource-68.12.0-1.el8_2.aarch64.rpm ppc64le: thunderbird-68.12.0-1.el8_2.ppc64le.rpm thunderbird-debuginfo-68.12.0-1.el8_2.ppc64le.rpm thunderbird-debugsource-68.12.0-1.el8_2.ppc64le.rpm x86_64: thunderbird-68.12.0-1.el8_2.x86_64.rpm thunderbird-debuginfo-68.12.0-1.el8_2.x86_64.rpm thunderbird-debugsource-68.12.0-1.el8_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-15664 https://access.redhat.com/security/cve/CVE-2020-15669 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX1XvmtzjgjWX9erEAQhPcw/9Gv9Hp+LKKtojIi99auQKwvmlvqD9ERWy nEXuXmz+KH5tF1R2Ni8rzZrSGrvv6fUQWpovndMPiv7M050ilDqHqIZ0rz/paH6D XsWtSviTMY36b30PH0ZsskRDH9FLLzeyznNaNQz9/PMWb18gLfOPx0ursSxod1be H6SUKInXassdFmQg5z0MvlnrPDuxy0/TsllDU4QeQdXnW+HvUrFM+P+wAebtxkaV JmIQFMoUqMM46COhop52vlHnoxdXL2VYXS0ZDUztknT04qQc+0JTAvoo2yd+4NdE Yd8ocGiXZxo5JN9M5AA2lDGHUnt6L8VQqpvSEVCAIRfXBXP+7o1JO1Rs992MspEw JJmGUdKQIKQ1PPvbaC9787B7bHQbr11757/SyPokVN/7dKTGO7jfFbectmqijDxW 93uMF46WQmPJLhU/TxUZvvxnank/E9fJ127+rOO0pgQ5q1PJfF48t4YUFJqluuqV 6Uv/4U7IGkoXrrLI/P9z2t/KMsPhW+uLnt6chdL052yj0ad0Zie6rVRPz1ww6YTP qO/cfE6645C8rj5fFws6gAnJeZdU7910RSW2vQ7dkJfXENeESJwk4c/4CKfkzPI3 p4X9zuD+CQsl94olKcwGcqfqi8DOVGAW1Us3pOhgbSjDc0R9G0irGeUGc4OetU24 t0IFhpWe7jA=gyFF -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial patch released for Red Hat Enterprise Linux Thunderbird resolves several high-priority vulnerabilities. System restart necessary.. thunderbird, red hat, security update, important update, mail client. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 07, 2020 Important Red Hat
197

Debian: DLA-2360-1 Critical: Thunderbird Execution Issues

Multiple security issues have been found in Thunderbird which could result in the execution of arbitrary code or the unintended installation of extensions. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2360-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort August 31, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : thunderbird Version : 1:68.12.0-1~deb9u1 CVE ID : CVE-2020-15664 CVE-2020-15669 Multiple security issues have been found in Thunderbird which could result in the execution of arbitrary code or the unintended installation of extensions. For Debian 9 stretch, these problems have been fixed in version 1:68.12.0-1~deb9u1. We recommend that you upgrade your thunderbird packages. For the detailed security status of thunderbird please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/thunderbird Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Several vulnerabilities in Thunderbird might enable unauthorized code execution and unintended plugin installations.. Debian Security, Thunderbird Update, Security Advisory, Critical Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 31, 2020 Critical Debian LTS
87

Debian: DSA-4754-1 Important: Thunderbirds Code Vulnerabilities Found

Multiple security issues have been found in Thunderbird which could result in the execution of arbitrary code or the unintended installation of extensions. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4754-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff August 29, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : thunderbird CVE ID : CVE-2020-15664 CVE-2020-15669 Multiple security issues have been found in Thunderbird which could result in the execution of arbitrary code or the unintended installation of extensions. For the stable distribution (buster), these problems have been fixed in version 1:68.12.0-1~deb10u1. We recommend that you upgrade your thunderbird packages. For the detailed security status of thunderbird please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/thunderbird Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Numerous security flaws found in Firefox may allow unauthorized code execution or unintended plugin additions.. Thunderbird Security, Debian DSA-4754-1, Software Updates, Security Advisory, Debian Security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 29, 2020 Important Debian
203

Mageia 2020-0348 Moderate: Firefox Extension Installation Risks

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed (CVE-2020-15664). . MGASA-2020-0348 - Updated firefox packages fix security vulnerabilities Publication date: 27 Aug 2020 URL: https://advisories.mageia.org/MGASA-2020-0348.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-15664, CVE-2020-15669 By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed (CVE-2020-15664). When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code (CVE-2020-15669). References: - https://bugs.mageia.org/show_bug.cgi?id=27193 - https://groups.google.com/g/mozilla.dev.tech.nspr/c/YLamaq1rVco - https://www.mozilla.org/en-US/security/advisories/mfsa2020-37/ - https://www.cve.org/CVERecord?id=CVE-2020-15664 - https://www.cve.org/CVERecord?id=CVE-2020-15669 SRPMS: - 7/core/nspr-4.28-1.mga7 - 7/core/firefox-68.12.0-2.mga7 - 7/core/firefox-l10n-68.12.0-1.mga7 . Mageia 2020-0349 released new LibreOffice versions addressing significant security flaws that impact users. Discover more!. Mageia Security Advisory, Firefox Update, MalwareProtection, ExtensionSecurity, CVEFixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 27, 2020 Important Mageia
98

RedHat: RHSA-2020-3558-01 Important: Firefox Security Issues

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: firefox security update Advisory ID: RHSA-2020:3558-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:3558 Issue date: 2020-08-26 CVE Names: CVE-2020-15664 CVE-2020-15669 ==================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 68.12.0 ESR. Security Fix(es): * Mozilla: Attacker-induced prompt for extension installation (CVE-2020-15664) * Mozilla: Use-After-Free when aborting an operation (CVE-2020-15669) For more details about the security issue(s), including the impact, aCVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1872531 - CVE-2020-15664 Mozilla: Attacker-induced prompt for extension installation 1872532 - CVE-2020-15669 Mozilla: Use-After-Free when aborting an operation 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: firefox-68.12.0-1.el6_10.src.rpm i386: firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm x86_64: firefox-68.12.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.12.0-1.el6_10.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): x86_64: firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: firefox-68.12.0-1.el6_10.src.rpm x86_64: firefox-68.12.0-1.el6_10.i686.rpm firefox-68.12.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: firefox-68.12.0-1.el6_10.src.rpm i386: firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm ppc64: firefox-68.12.0-1.el6_10.ppc64.rpm firefox-debuginfo-68.12.0-1.el6_10.ppc64.rpm s390x: firefox-68.12.0-1.el6_10.s390x.rpm firefox-debuginfo-68.12.0-1.el6_10.s390x.rpm x86_64: firefox-68.12.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.12.0-1.el6_10.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): x86_64: firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm Red Hat Enterprise Linux Workstation (v.6): Source: firefox-68.12.0-1.el6_10.src.rpm i386: firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm x86_64: firefox-68.12.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.12.0-1.el6_10.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): x86_64: firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-15664 https://access.redhat.com/security/cve/CVE-2020-15669 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX0Ydm9zjgjWX9erEAQiTbxAAnqD4io8xJpJOgaIHIx3lDssrCjt0wDj4 E0nHxJlu8t1ocmBgMsgqaaA94orVdENQnAN+Mgt+VFhsMtjrAjLpj2Ef5x4vcxqs FMwHH6xlxYMlyMxRKIZ8YPokawo65v8jdSHDkZuIi65dI0Vz3iy4C5PPQ4/XFuR4 i7uqpKPKkyZG+uix+SlJjzJep1Wfv0iZU2t924ys1Lkqa7In59wjuF4fBe2hDStB l88nybsH1MePstX0RgOInDa4qBSWGjPtzmzEzk4qmyhfVGYlVEpsDAnA7cQZ2lCU 8NlAd9Jq2fvacHNlO07Tr8gEGhyaw8INxUGD8mfLWPMkzjduKugi64/cWq2Gl9DB dNe/6eSK+Y4TIQ+4Wbym/2HY3V69LWCwJLa0/bNBxEsow5GEphty2uc/KjS6iJPi /n5mcbVzBaXi3334+Vxw3/1104aUZxXaBwafa4YrTlJSMzPowdwIhW33TVg4sQ4d qPIyU2iVNka456OmA/JhunDQUc6K1mX84E9L2Ui2QN4psMU30mC3U24DqmhW1iWy XjCPZAd00pFydv9nrUiqS0pfoZNZSr4DNeYuNyK0sT7dueozFetc1euPLWFx9TaS qWVbuPV9UdFzfdc3IEb/wEU/3VsM0RG/03ypGaply4xz2FA5Bn5aSvBvvBskGsqb cJ2VPPSapyk=bNkP -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial Chrome security patch released for CentOS 7, addressing severe vulnerabilities. Update immediately.. Red Hat Enterprise Linux, firefox, security update, important patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 26, 2020 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here