Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
100

SUSE: 2025:02158-1 important: MozillaThunderbird file download issue

* bsc#1244468 Cross-References: * CVE-2025-5986 . # Security update for MozillaThunderbird Announcement ID: SUSE-SU-2025:02158-1 Release Date: 2025-06-27T14:51:23Z Rating: important References: * bsc#1244468 Cross-References: * CVE-2025-5986 CVSS scores: * CVE-2025-5986 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-5986 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for MozillaThunderbird fixes the following issues: Mozilla Thunderbird 128.11.1 * CVE-2025-5986: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (MFSA 2025-49) (bsc#1244468). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2158=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-2158=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-2158=1 * SUSE Linux Enterprise Workstation Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-2158=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2025-2158=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * MozillaThunderbird-debuginfo-128.11.1-150200.8.224.1 * MozillaThunderbird-translations-common-128.11.1-150200.8.224.1 * MozillaThunderbird-translations-other-128.11.1-150200.8.224.1 * MozillaThunderbird-debugsource-128.11.1-150200.8.224.1 * MozillaThunderbird-128.11.1-150200.8.224.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x) * MozillaThunderbird-debuginfo-128.11.1-150200.8.224.1 * MozillaThunderbird-translations-common-128.11.1-150200.8.224.1 * MozillaThunderbird-translations-other-128.11.1-150200.8.224.1 * MozillaThunderbird-debugsource-128.11.1-150200.8.224.1 * MozillaThunderbird-128.11.1-150200.8.224.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * MozillaThunderbird-debuginfo-128.11.1-150200.8.224.1 * MozillaThunderbird-translations-common-128.11.1-150200.8.224.1 * MozillaThunderbird-translations-other-128.11.1-150200.8.224.1 * MozillaThunderbird-debugsource-128.11.1-150200.8.224.1 * MozillaThunderbird-128.11.1-150200.8.224.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64) * MozillaThunderbird-debuginfo-128.11.1-150200.8.224.1 * MozillaThunderbird-translations-common-128.11.1-150200.8.224.1 * MozillaThunderbird-translations-other-128.11.1-150200.8.224.1 * MozillaThunderbird-debugsource-128.11.1-150200.8.224.1 * MozillaThunderbird-128.11.1-150200.8.224.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * MozillaThunderbird-debuginfo-128.11.1-150200.8.224.1 * MozillaThunderbird-translations-common-128.11.1-150200.8.224.1 * MozillaThunderbird-translations-other-128.11.1-150200.8.224.1 * MozillaThunderbird-debugsource-128.11.1-150200.8.224.1 * MozillaThunderbird-128.11.1-150200.8.224.1 ## References: * https://www.suse.com/security/cve/CVE-2025-5986.html * https://bugzilla.suse.com/show_bug.cgi?id=1244468 . A crucialsecurity patch for Mozilla Firefox tackling CVE-2025-5987 improves overall stability in various Ubuntu distributions.. MozillaThunderbird update,SUSE security patch,CVE-2025-5986 fix,file download vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 27, 2025 Important SuSE
197

Debian LTS: DLA-2456-1 Moderate: php-horde-kronolith Session Hijacking

The File Manager (gollem) module in Horde Groupware has allowed remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponded to the exact filename. . -------------------------------------------------------------------------Debian LTS Advisory DLA-2352-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Mike Gabriel August 29, 2020 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : php-horde-gollem Version : 3.0.10-1+deb9u2 CVE ID : CVE-2017-15235 The File Manager (gollem) module in Horde Groupware has allowed remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponded to the exact filename. For Debian 9 stretch, this problem has been fixed in version 3.0.10-1+deb9u2. We recommend that you upgrade your php-horde-gollem packages. For the detailed security status of php-horde-gollem please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/php-horde-gollem Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail: This email address is being protected from spambots. You need JavaScript enabled to view it., https://sunweavers.net/ . The Debian LTS Advisory DLA-2360-1 tackles a security vulnerability in php-horde-gollem to enhance the security of file handling operations.. php-horde-gollem, Debian LTS, authentication bypass, file management, security update. . LinuxSecurity.com Team

Calendar 2 Aug 29, 2020 Debian LTS
197

Debian: DLA-1413-1 Critical: DokuWiki Remote Execution Threat

The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs. . Package : dokuwiki Version : 0.0.20140505.a+dfsg-4+deb8u1 CVE ID : CVE-2017-18123 Debian Bug : 889281 The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs. For Debian 8 "Jessie", these problems have been fixed in version 0.0.20140505.a+dfsg-4+deb8u1. We recommend that you upgrade your dokuwiki packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . This notice concerns a reflected file download vulnerability in DokuWiki, allowing unauthorized execution of arbitrary applications remotely.. DokuWiki Security Update, Debian LTS Advisory, File Download Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 05, 2018 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here