Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
203

Mageia 9: perl-YAML-LibYAML Important File Mod Risk CVE-2025-40908

MGASA-2025-0275 - Updated perl-YAML-LibYAML packages fix security vulnerability. MGASA-2025-0275 - Updated perl-YAML-LibYAML packages fix security vulnerability Publication date: 12 Nov 2025 URL: https://advisories.mageia.org/MGASA-2025-0275.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-40908 Description: YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified. (CVE-2025-40908) References: - https://bugs.mageia.org/show_bug.cgi?id=34448 - - https://www.cve.org/CVERecord?id=CVE-2025-40908 SRPMS: - 9/core/perl-YAML-LibYAML-0.860.0-1.1.mga9 . Mageia 9 issue: perl-YAML-LibYAML update addresses critical file modification vulnerability.. Mageia security fix, perl-YAML-LibYAML, security update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 12, 2025 Important Mageia
100

SUSE Linux 12 SP5: 2025:02297-1 important: python36 symlink fix

* bsc#1233012 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059 . # Security update for python36 Announcement ID: SUSE-SU-2025:02297-1 Release Date: 2025-07-11T16:03:57Z Rating: important References: * bsc#1233012 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059 * bsc#1244060 * bsc#1244061 * bsc#1244401 * bsc#1244705 Cross-References: * CVE-2024-12718 * CVE-2025-4138 * CVE-2025-4330 * CVE-2025-4435 * CVE-2025-4516 * CVE-2025-4517 * CVE-2025-6069 CVSS scores: * CVE-2024-12718 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-12718 ( NVD ): 10.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-12718 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-4138 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2025-4138 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-4330 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2025-4330 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-4435 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2025-4435 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-4516 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-4516 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4516 ( NVD ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-4517 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-4517 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-4517 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2025-6069 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H * CVE-2025-6069 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2025-6069 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities and has two security fixes can now be installed. ## Description: This update for python36 fixes the following issues: * CVE-2024-12718: Fixed extraction filter bypass that allowed file metadata modification outside extraction directory (bsc#1244056) * CVE-2025-4138: Fixed issue that might allow symlink targets to point outside the destination directory, and the modification of some file metadata (bsc#1244059) * CVE-2025-4330: Fixed extraction filter bypass that allowed linking outside extraction directory (bsc#1244060) * CVE-2025-4435: Fixed Tarfile extracts filtered members when errorlevel=0 (bsc#1244061) * CVE-2025-4516: Fixed denial of service due to DecodeError handling vulnerability (bsc#1243273) * CVE-2025-4517: Fixed arbitrary filesystem writes outside the extraction directory during extraction with filter="data" (bsc#1244032) * CVE-2025-6069: Fixed worst case quadratic complexity when processing certain crafted malformed inputs with HTMLParser (bsc#1244705) Other fixes: \- Add python36-* provides/obsoletes to enable SLE-12 -> SLE-15 migration (bsc#1233012) \- Update vendored ipaddress module to 3.8 equivalent \- Limit buffer size for IPv6 address parsing (bsc#1244401). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or"zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-2297=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-2297=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python36-devel-3.6.15-84.1 * libpython3_6m1_0-3.6.15-84.1 * python36-debugsource-3.6.15-84.1 * python36-3.6.15-84.1 * python36-debuginfo-3.6.15-84.1 * python36-base-3.6.15-84.1 * libpython3_6m1_0-debuginfo-3.6.15-84.1 * python36-base-debuginfo-3.6.15-84.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libpython3_6m1_0-debuginfo-32bit-3.6.15-84.1 * libpython3_6m1_0-32bit-3.6.15-84.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpython3_6m1_0-debuginfo-32bit-3.6.15-84.1 * python36-devel-3.6.15-84.1 * libpython3_6m1_0-3.6.15-84.1 * python36-debugsource-3.6.15-84.1 * python36-3.6.15-84.1 * libpython3_6m1_0-32bit-3.6.15-84.1 * python36-debuginfo-3.6.15-84.1 * python36-base-3.6.15-84.1 * libpython3_6m1_0-debuginfo-3.6.15-84.1 * python36-base-debuginfo-3.6.15-84.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12718.html * https://www.suse.com/security/cve/CVE-2025-4138.html * https://www.suse.com/security/cve/CVE-2025-4330.html * https://www.suse.com/security/cve/CVE-2025-4435.html * https://www.suse.com/security/cve/CVE-2025-4516.html * https://www.suse.com/security/cve/CVE-2025-4517.html * https://www.suse.com/security/cve/CVE-2025-6069.html * https://bugzilla.suse.com/show_bug.cgi?id=1233012 * https://bugzilla.suse.com/show_bug.cgi?id=1243273 * https://bugzilla.suse.com/show_bug.cgi?id=1244032 * https://bugzilla.suse.com/show_bug.cgi?id=1244056 * https://bugzilla.suse.com/show_bug.cgi?id=1244059 *https://bugzilla.suse.com/show_bug.cgi?id=1244060 * https://bugzilla.suse.com/show_bug.cgi?id=1244061 * https://bugzilla.suse.com/show_bug.cgi?id=1244401 * https://bugzilla.suse.com/show_bug.cgi?id=1244705 . The recent python36 patch from SUSE deals with various security vulnerabilities; vital for maintaining the security and reliability of your systems. Take action now!. SUSE Linux, python36 security, package updates, file extraction issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 11, 2025 Important SuSE
91

Gentoo Linux GLSA-202210-26 Normal: Shadow TOCTOU Race Risk

A TOCTOU race has been discovered in Shadow, which could result in the unauthorized modification of files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202210-26 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Shadow: TOCTOU Race Date: October 31, 2022 Bugs: #830486 ID: 202210-26 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A TOCTOU race has been discovered in Shadow, which could result in the unauthorized modification of files. Background ========= Shadow contains utilities to deal with user accounts Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/shadow < 4.12.2 > = 4.12.2 Description ========== A TOCTOU race condition was discovered in shadow. A local attacker with write privileges in a directory removed or copied by usermod/userdel could potentially exploit this flaw when the administrator invokes usermod/userdel. Impact ===== An unauthorized user could potentially modify files which they do not have write permissions for. Workaround ========= There is no known workaround at this time. Resolution ========= All Shadow users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-apps/shadow-4.12.2" References ========= [ 1 ] CVE-2013-4235 https://nvd.nist.gov/vuln/detail/CVE-2013-4235 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202210-26 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Uncover a TOCTOU conflict in Illuminate that jeopardizes unapproved data alterations. Remain protected with this warning.. Gentoo Shadow Security, TOCTOU Race Condition, File Modification Advisory. . LinuxSecurity.com Team

Calendar 2 Oct 30, 2022 Gentoo
203

Mageia: 2019-0263 Moderate: Sympa File Modification Flaw

Updated sympa packages fix security vulnerability: Michael Kaczmarczik discovered a vulnerability in the web interface template editing function of Sympa, a mailing list manager. Owner and listmasters could use this flaw to create or modify arbitrary files in . MGASA-2019-0263 - Updated sympa packages fix security vulnerability Publication date: 12 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0263.html Type: security Affected Mageia releases: 6 CVE: CCVE-2018-1000550 Updated sympa packages fix security vulnerability: Michael Kaczmarczik discovered a vulnerability in the web interface template editing function of Sympa, a mailing list manager. Owner and listmasters could use this flaw to create or modify arbitrary files in the server with privileges of sympa user or owner view list config files even if edit_list.conf prohibits it (CVE-2018-1000550). References: - https://bugs.mageia.org/show_bug.cgi?id=23536 - https://www.sympa.community/security/2018-001.html - https://lists.debian.org/debian-security-announce/2018/msg00215.html - https://www.cve.org/CVERecord?id=CVE-CCVE-2018-1000550 SRPMS: - 6/core/sympa-6.2.16-1.1.mga6 . Mageia has released updates for the Sympa packages to address a critical security vulnerability that enabled unauthorized file manipulations. Discover further information here.. Mageia Security Update, Sympa Vulnerability Fix, File Modification Flaw, Security Advisory. . LinuxSecurity.com Team

Calendar 2 Sep 12, 2019 Mageia
198

Arch Linux 2015-03-16 Moderate: Librsync Checksum Collision Threat

The package librsync before version 1.0.0-1 is vulnerable to checksum collision leading to possible file modification or corruption via a birthday attack. . Arch Linux Security Advisory ASA-201503-10 ========================================= Severity: Medium Date : 2015-03-16 CVE-ID : CVE-2014-8242 Package : librsync Type : checksum collision Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package librsync before version 1.0.0-1 is vulnerable to checksum collision leading to possible file modification or corruption via a birthday attack. Resolution ========= Upgrade to 1.0.0-1. # pacman -Syu "librsync> =1.0.0-1" The problem has been fixed upstream in version 1.0.0. Workaround ========= None. Description ========== librsync previously used a truncated MD4 "strong" check sum to match blocks. However, MD4 is not cryptographically strong. It's possible that an attacker who can control the contents of one part of a file could use it to control other regions of the file, if it's transferred using librsync/rdiff. For example this might occur in a database, mailbox, or VM image containing some attacker-controlled data. To mitigate this issue, signatures will by default be computed with a 256-bit BLAKE2 hash. Old versions of librsync will complain about a bad magic number when given these signature files. Impact ===== An attacker is able to take advantage of the weak checksum calculation by using a birthday attack in order to corrupt or modify files that are transfered. References ========= https://www.openwall.com/lists/oss-security/2014/07/28/1 https://access.redhat.com/security/cve/CVE-2014-8242 https://github.com/librsync/librsync/issues/5 https://bugs.archlinux.org/task/44175 . Arch Linux Security Notice ASA-202305-15 Medium importance regarding a potential vulnerability in zlib compression handling. Immediate update recommended.. ArchLinux,librsync,checksum collision,security advisory,file integrity. .Severity: Medium. LinuxSecurity.com Team

Calendar 2 Mar 16, 2015 Medium ArchLinux
172

Ubuntu 14.04 LTS: USN-2242-1 Critical: Dpkg Unauthorized File Access

A malicious source package could write files outside the unpack directory.. =========================================================================Ubuntu Security Notice USN-2242-1 June 10, 2014 dpkg vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS - Ubuntu 13.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: A malicious source package could write files outside the unpack directory. Software Description: - dpkg: Debian package management system Details: It was discovered that dpkg incorrectly handled certain patches when unpacking source packages. If a user or an automated system were tricked into unpacking a specially crafted source package, a remote attacker could modify files outside the target unpack directory, leading to a denial of service or potentially gaining access to the system. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: libdpkg-perl 1.17.5ubuntu5.3 Ubuntu 13.10: libdpkg-perl 1.16.12ubuntu1.3 Ubuntu 12.04 LTS: libdpkg-perl 1.16.1.2ubuntu7.5 Ubuntu 10.04 LTS: dpkg-dev 1.15.5.6ubuntu4.9 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2242-1 CVE-2014-3864, CVE-2014-3865 Package Information: https://launchpad.net/ubuntu/+source/dpkg/1.17.5ubuntu5.3 https://launchpad.net/ubuntu/+source/dpkg/1.16.12ubuntu1.3 https://launchpad.net/ubuntu/+source/dpkg/1.16.1.2ubuntu7.5 https://launchpad.net/ubuntu/+source/dpkg/1.15.5.6ubuntu4.9 . Ubuntu Security Notice USN-2242-1 reveals critical dpkg vulnerabilities allowing unauthorized file access.. Dpkg Vulnerabilities, File Modification Security, Unauthorized Access Ubuntu. . Severity: Critical.LinuxSecurity.com Team

Calendar 2 Jun 10, 2014 Critical Ubuntu
87

Debian: DSA-2953-1 Critical Security Flaw Found in Dpkg Path Management

Multiple vulnerabilities were discovered in dpkg that allow file modification through path traversal when unpacking source packages with especially-crafted patch files. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2953-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Raphael Geissert June 08, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : dpkg CVE ID : CVE-2014-3864 CVE-2014-3865 Debian Bug : 746498 749183 Multiple vulnerabilities were discovered in dpkg that allow file modification through path traversal when unpacking source packages with especially-crafted patch files. This update had been scheduled before the end of security support for the oldstable distribution (squeeze), hence an exception has been made and was released through the security archive. However, no further updates should be expected. For the oldstable distribution (squeeze), these problems have been fixed in version 1.15.11. For the stable distribution (wheezy), these problems have been fixed in version 1.16.15. For the testing distribution (jessie), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 1.17.10. We recommend that you upgrade your dpkg packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance dpkg to address numerous security flaws that facilitate unauthorized file alterations via path traversal on Debian platforms.. Debian Security Advisory, Dpkg Update, Path Traversal Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 08, 2014 Critical Debian
91

Gentoo: GLSA-201206-24 Normal: Apache Tomcat File Access Risks

Multiple vulnerabilities were found in Apache Tomcat, the worst of which allowing to read, modify and overwrite arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201206-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Apache Tomcat: Multiple vulnerabilities Date: June 24, 2012 Bugs: #272566, #273662, #303719, #320963, #329937, #373987, #374619, #382043, #386213, #396401, #399227 ID: 201206-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities were found in Apache Tomcat, the worst of which allowing to read, modify and overwrite arbitrary files. Background ========= Apache Tomcat is a Servlet-3.0/JSP-2.2 Container. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-servers/tomcat *< 5.5.34 *> = 6.0.35 *< 6.0.35 > = 7.0.23 < 7.0.23 Description ========== Multiple vulnerabilities have been discovered in Apache Tomcat. Please review the CVE identifiers referenced below for details. Impact ===== The vulnerabilities allow an attacker to cause a Denial of Service, to hijack a session, to bypass authentication, to inject webscript, to enumerate valid usernames, to read, modify and overwrite arbitrary files, to bypass intended access restrictions, to delete work-directory files, to discover the server's hostname or IP, to bypass read permissions for files or HTTP headers, to read or write files outside of theintended working directory, and to obtain sensitive information by reading a log file. Workaround ========= There is no known workaround at this time. Resolution ========= All Apache Tomcat 6.0.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-servers/tomcat-6.0.35" All Apache Tomcat 7.0.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-servers/tomcat-7.0.23" References ========= [ 1 ] CVE-2008-5515 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5515 [ 2 ] CVE-2009-0033 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0033 [ 3 ] CVE-2009-0580 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0580 [ 4 ] CVE-2009-0781 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0781 [ 5 ] CVE-2009-0783 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0783 [ 6 ] CVE-2009-2693 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2693 [ 7 ] CVE-2009-2901 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2901 [ 8 ] CVE-2009-2902 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2902 [ 9 ] CVE-2010-1157 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1157 [ 10 ] CVE-2010-2227 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2227 [ 11 ] CVE-2010-3718 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3718 [ 12 ] CVE-2010-4172 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4172 [ 13 ] CVE-2010-4312 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4312 [ 14 ] CVE-2011-0013 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0013 [ 15 ] CVE-2011-0534 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0534 [ 16 ] CVE-2011-1088 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1088 [ 17 ] CVE-2011-1183 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1183 [ 18 ] CVE-2011-1184 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1184 [ 19 ] CVE-2011-1419 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1419 [ 20 ] CVE-2011-1475 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1475 [ 21 ] CVE-2011-1582 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1582 [ 22 ] CVE-2011-2204 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2204 [ 23 ] CVE-2011-2481 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2481 [ 24 ] CVE-2011-2526 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2526 [ 25 ] CVE-2011-2729 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2729 [ 26 ] CVE-2011-3190 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3190 [ 27 ] CVE-2011-3375 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3375 [ 28 ] CVE-2011-4858 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4858 [ 29 ] CVE-2011-5062 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5062 [ 30 ] CVE-2011-5063 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5063 [ 31 ] CVE-2011-5064 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5064 [ 32 ] CVE-2012-0022 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0022 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201206-24 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2012 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Linux advisory GLSA 202301-15 alerts about potential security vulnerabilities in OpenSSH and advises implementing necessary patches.. Gentoo Apache Tomcat Security, Webserver Threats, Linux Security Advisories. . LinuxSecurity.com Team

Calendar 2 Jun 24, 2012 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here