Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Ubuntu 20.04: 2021-b2f61gd234 high: gtk3 memory leak detected

glib 2.66.8 release, fixing a security issue when using `g_file_replace()` with `G_FILE_CREATE_REPLACE_DESTINATION`.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-a1f51fc418 2021-03-22 01:03:56.746584 --------------------------------------------------------------------------------Name : glib2 Product : Fedora 33 Version : 2.66.8 Release : 1.fc33 URL : https://www.gtk.org/ Summary : A library of handy utility functions Description : GLib is the low-level core library that forms the basis for projects such as GTK+ and GNOME. It provides data structure handling for C, portability wrappers, and interfaces for such runtime functionality as an event loop, threads, dynamic loading, and an object system. --------------------------------------------------------------------------------Update Information: glib 2.66.8 release, fixing a security issue when using `g_file_replace()` with `G_FILE_CREATE_REPLACE_DESTINATION`. --------------------------------------------------------------------------------ChangeLog: * Thu Mar 18 2021 Kalev Lember - 2.66.8-1 - Update to 2.66.8 --------------------------------------------------------------------------------References: [ 1 ] Bug #1938291 - CVE-2021-28153 glib: g_file_replace() with G_FILE_CREATE_REPLACE_DESTINATION creates empty target for dangling symlink https://bugzilla.redhat.com/show_bug.cgi?id=1938291 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-a1f51fc418' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora Patch 2021-b2g72ac719 addresses a major vulnerability in libxml2 regarding document processing and enhances system security.. glib2 security update,Fedora 33,G_FILE_CREATE_REPLACE_DESTINATION. . LinuxSecurity.com Team

Calendar 2 Mar 21, 2021 Fedora
89

Fedora 33: 2021-15845d3abe Moderate: MinGW-Python-Pillow Security Advisory

This update fixes CVE-2021-27921, CVE-2021-27922 and CVE-2021-27923. ---- Backport fixes for CVE-2021-25289, CVE-2021-25290, CVE-2021-25291, CVE-2021-25292, CVE-2021-25293. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-15845d3abe 2021-03-15 01:17:22.121151 --------------------------------------------------------------------------------Name : mingw-python-pillow Product : Fedora 33 Version : 7.2.0 Release : 5.fc33 URL : / Summary : MinGW Windows Python pillow library Description : MinGW Windows Python pillow library. --------------------------------------------------------------------------------Update Information: This update fixes CVE-2021-27921, CVE-2021-27922 and CVE-2021-27923. ----Backport fixes for CVE-2021-25289, CVE-2021-25290, CVE-2021-25291, CVE-2021-25292, CVE-2021-25293 --------------------------------------------------------------------------------ChangeLog: * Sat Mar 6 2021 Sandro Mani - 7.2.0-5 - Backport fix for CVE-2021-2792{1,2,3} * Fri Mar 5 2021 Sandro Mani - 7.2.0-4 - Backport fixes for CVE-2021-25289, CVE-2021-25290, CVE-2021-25291, CVE-2021-25292, CVE-2021-25293 --------------------------------------------------------------------------------References: [ 1 ] Bug #1933899 - python-pillow-8.1.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1933899 [ 2 ] Bug #1934681 - CVE-2021-25289 python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934681 [ 3 ] Bug #1934682 - CVE-2021-25289 python2-pillow: python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934682 [ 4 ] Bug #1934683 - CVE-2021-25289 mingw-python-pillow: python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934683 [ 5 ] Bug #1934686 - CVE-2021-25290 python-pillow: negative-offset memcpy with an invalid size in TiffDecode.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934686 [ 6 ] Bug #1934687 - CVE-2021-25290 python2-pillow: python-pillow: negative-offset memcpy with an invalid size in TiffDecode.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934687 [ 7 ] Bug #1934688 - CVE-2021-25290 mingw-python-pillow: python-pillow: negative-offset memcpy with an invalid size in TiffDecode.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934688 [ 8 ] Bug #1934693 - CVE-2021-25291 python-pillow: out-of-bounds read in TiffReadRGBATile in TiffDecode.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934693 [ 9 ] Bug #1934694 - CVE-2021-25291 python2-pillow: python-pillow: out-of-bounds read in TiffReadRGBATile in TiffDecode.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934694 [ 10 ] Bug #1934695 - CVE-2021-25291 mingw-python-pillow: python-pillow: out-of-bounds read in TiffReadRGBATile in TiffDecode.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934695 [ 11 ] Bug #1934700 - CVE-2021-25292 python-pillow: backtracking regex in PDF parser could be used as a DOS attack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934700 [ 12 ] Bug #1934701 - CVE-2021-25292 python2-pillow: python-pillow: backtracking regex in PDF parser could be used as a DOS attack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934701 [ 13 ] Bug #1934702 - CVE-2021-25292 mingw-python-pillow: python-pillow: backtracking regex in PDF parser could be used as a DOS attack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934702 [ 14 ] Bug #1934706 - CVE-2021-25293 python-pillow: out-of-bounds read in SGIRleDecode.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934706 [15 ] Bug #1934707 - CVE-2021-25293 python2-pillow: python-pillow: out-of-bounds read in SGIRleDecode.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934707 [ 16 ] Bug #1934708 - CVE-2021-25293 mingw-python-pillow: python-pillow: out-of-bounds read in SGIRleDecode.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1934708 [ 17 ] Bug #1935385 - CVE-2021-27921 python-pillow: reported size of a contained image is not properly checked for a BLP container [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1935385 [ 18 ] Bug #1935386 - CVE-2021-27921 python2-pillow: python-pillow: reported size of a contained image is not properly checked for a BLP container [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1935386 [ 19 ] Bug #1935388 - CVE-2021-27921 mingw-python-pillow: python-pillow: reported size of a contained image is not properly checked for a BLP container [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1935388 [ 20 ] Bug #1935397 - CVE-2021-27922 python-pillow: reported size of a contained image is not properly checked for an ICNS container [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1935397 [ 21 ] Bug #1935398 - CVE-2021-27922 python2-pillow: python-pillow: reported size of a contained image is not properly checked for an ICNS container [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1935398 [ 22 ] Bug #1935399 - CVE-2021-27922 mingw-python-pillow: python-pillow: reported size of a contained image is not properly checked for an ICNS container [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1935399 [ 23 ] Bug #1935402 - CVE-2021-27923 python-pillow: reported size of a contained image is not properly checked for an ICO container [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1935402 [ 24 ] Bug #1935403 - CVE-2021-27923 python2-pillow: python-pillow: reported size of a contained image is not properly checked for an ICOcontainer [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1935403 [ 25 ] Bug #1935405 - CVE-2021-27923 mingw-python-pillow: python-pillow: reported size of a contained image is not properly checked for an ICO container [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1935405 [ 26 ] Bug #1936047 - python-pillow-8.1.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1936047 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-15845d3abe' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The MinGW Python Pillow package has been updated to address crucial security vulnerabilities. This release includes detailed guidance for applying the essential fixes. Fedora Update, MinGW Library, Python Pillow Security, Security Advsory Optimization. . LinuxSecurity.com Team

Calendar 2 Mar 14, 2021 Fedora
172

Ubuntu 16.04 LTS: USN-4513-1 Medium: apng2gif Information Exposure

apng2gif could be made to expose sensitive information if it opened a specifically crafted APNG file.. =========================================================================Ubuntu Security Notice USN-4513-1 September 17, 2020 apng2gif vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: apng2gif could be made to expose sensitive information if it opened a specifically crafted APNG file. Software Description: - apng2gif: tool for converting APNG images to animated GIF format Details: Dileep Kumar Jallepalli discovered that apng2gif incorrectly handled loading APNG files. An attacker could exploit this with a crafted APNG file to access sensitive information. (CVE-2017-6960) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: apng2gif 1.5-3+deb8u1build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4513-1 CVE-2017-6960 Package Information: https://launchpad.net/ubuntu/+source/apng2gif/1.5-3+deb8u1build0.16.04.1 . Stay informed on sensitive data exposure issues with apng2gif on Ubuntu 16.04 LTS. Follow essential update guidelines to protect your information effectively. apng2gif, information exposure, Ubuntu security. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Sep 17, 2020 Medium Ubuntu
200

Scientific Linux: Minor Severity HPLIP Security Update Released Now

Low: hplip security, bug fix and enhancement update. Date: Mon, 4 Mar 2013 13:09:48 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Low: hplip on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Low: hplip security, bug fix and enhancement update Issue Date: 2013-02-21 CVE Numbers: CVE-2011-2722 CVE-2013-0200 -- Several temporary file handling flaws were found in HPLIP. A local attacker could use these flaws to perform a symbolic link attack, overwriting arbitrary files accessible to a process using HPLIP. (CVE-2013-0200, CVE-2011-2722) The hplip packages have been upgraded to upstream version 3.12.4, which provides a number of bug fixes and enhancements over the previous version. This update also fixes the following bugs: * Previously, the hpijs package required the obsolete cupsddk-drivers package, which was provided by the cups package. Under certain circumstances, this dependency caused hpijs installation to fail. This bug has been fixed and hpijs no longer requires cupsddk-drivers. * The configuration of the Scanner Access Now Easy (SANE) back end is located in the /etc/sane.d/dll.d/ directory, however, the hp-check utility checked only the /etc/sane.d/dll.conf file. Consequently, hp-check checked for correct installation, but incorrectly reported a problem with the way the SANE back end was installed. With this update, hp-check properly checks for installation problems in both locations as expected. -- SL6 x86_64 hpijs-3.12.4-4.el6.x86_64.rpm hplip-3.12.4-4.el6.x86_64.rpm hplip-common-3.12.4-4.el6.x86_64.rpm hplip-debuginfo-3.12.4-4.el6.i686.rpm hplip-debuginfo-3.12.4-4.el6.x86_64.rpm hplip-gui-3.12.4-4.el6.x86_64.rpm hplip-libs-3.12.4-4.el6.i686.rpm hplip-libs-3.12.4-4.el6.x86_64.rpm libsane-hpaio-3.12.4-4.el6.x86_64.rpm i386 hpijs-3.12.4-4.el6.i686.rpm hplip-3.12.4-4.el6.i686.rpm hplip-common-3.12.4-4.el6.i686.rpm hplip-debuginfo-3.12.4-4.el6.i686.rpm hplip-gui-3.12.4-4.el6.i686.rpm hplip-libs-3.12.4-4.el6.i686.rpm libsane-hpaio-3.12.4-4.el6.i686.rpm - Scientific Linux Development Team . HPLIP patch introduced focusing on minor vulnerability fixes. Updates and improvements outlined for CentOS.. hplip update, Scientific Linux, bug fixes, security advisories. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Mar 04, 2013 Low Scientific Linux
172

Ubuntu 6.06 LTS USN-781-2 Critical: Gaim Crash and Code Execution

It was discovered that Gaim did not properly handle certain malformed messages when sending a file using the XMPP protocol handler. If a user were tricked into sending a file, a remote attacker could send a specially crafted response and cause Gaim to crash, or possibly execute arbitrary code with user privileges. (CVE-2009-1373) [More...]. ==========================================================Ubuntu Security Notice USN-781-2 June 03, 2009 gaim vulnerabilities CVE-2009-1373, CVE-2009-1376 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: gaim 1:1.5.0+1.5.1cvs20051015-1ubuntu10.2 After a standard system upgrade you need to restart Gaim to effect the necessary changes. Details follow: It was discovered that Gaim did not properly handle certain malformed messages when sending a file using the XMPP protocol handler. If a user were tricked into sending a file, a remote attacker could send a specially crafted response and cause Gaim to crash, or possibly execute arbitrary code with user privileges. (CVE-2009-1373) It was discovered that Gaim did not properly handle certain malformed messages in the MSN protocol handler. A remote attacker could send a specially crafted message and possibly execute arbitrary code with user privileges. (CVE-2009-1376) Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 35032 018074e6f3fe79b0334b616c41db8f16 Size/MD5: 1061 fedec169b55ed59a1d258f4261d3342e Size/MD5: 4299145 949ae755e9be1af68eef6c09c36a7530 Architecture independent packages: Size/MD5: 613400 851c17117f60a8bdd7a1a7945295bb95 amd64 architecture (Athlon64, Opteron, EM64TXeon): Size/MD5: 103268 3e801c048c16f37927274e223006cf12 Size/MD5: 954312 b221c7923480c8f561b19f25602fb42d i386 architecture (x86 compatible Intel/AMD): Size/MD5: 103268 7c5d619c893be0613fc3e9e520180ac3 Size/MD5: 836516 36ab380abace72300ba4aa0da8af0423 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 103266 f8d87f5da7ae492b3e5564c132afb4de Size/MD5: 924684 227c223828b0edcc564397b37281636a sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 103252 4e6a313eced48612d2f35ab69ebd85b1 Size/MD5: 856864 9b00254efd713d0001bb7e11817e6bc3 . Unearth Gaim security flaws impacting Ubuntu 6.06 LTS and explore strategies to minimize threats with the updates shared.. Gaim vulnerabilities, Ubuntu advisory, file handling, remote execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 03, 2009 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here