Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 42 NextCloud 31.0.5: Critical Path Traversal Risk Update

31.0.5 release RHBZ#2364462 RHBZ#2366729 RHBZ#2366735. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d636dbcc45 2025-06-04 02:09:45.732933+00:00 -------------------------------------------------------------------------------- Name : nextcloud Product : Fedora 42 Version : 31.0.5 Release : 1.fc42 URL : http://nextcloud.com Summary : Private file sync and share server Description : NextCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your devices and enables basic editing right on the web. NextCloud is extendable via a simple but powerful API for applications and plugins. -------------------------------------------------------------------------------- Update Information: 31.0.5 release RHBZ#2364462 RHBZ#2366729 RHBZ#2366735 -------------------------------------------------------------------------------- ChangeLog: * Mon May 26 2025 Andrew Bauer - 31.0.5-1 - 31.0.5 release RHBZ#2364462 RHBZ#2366729 RHBZ#2366735 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2364462 - nextcloud-31.0.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2364462 [ 2 ] Bug #2366729 - CVE-2025-48050 nextcloud: DOMPurify Path Traversal Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2366729 [ 3 ] Bug #2366735 - CVE-2025-48050 nextcloud: DOMPurify Path Traversal Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2366735 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d636dbcc45' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . NextCloud version 31.0.5 running on Fedora 42 introduces essential updates addressing significant DOMPurify path traversal vulnerabilities.. NextCloud Path Traversal, Fedora Security Update, File Sync Software. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 04, 2025 Critical Fedora
89

Fedora 37: FEDORA-2023-fa2d7b25d9 Critical: File Sync Security Fix

Update to version 1.26.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.26.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-fa2d7b25d9 2023-11-18 01:32:59.408277 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 37 Version : 1.26.0 Release : 1.fc37 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.26.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.26.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 9 2023 Fabio Valentini - 1.26.0-1 - Update to version 1.26.0; Fixes RHBZ#2248507 * Thu Nov 9 2023 Fabio Valentini - 1.25.0-2 - Ignore some test timeouts on s390x * Thu Nov 9 2023 Fabio Valentini - 1.25.0-1 - Update to version 1.25.0; Fixes RHBZ#2242032 * Thu Nov 9 2023 Fabio Valentini - 1.24.0-1 - Update to version 1.24.0; Fixes RHBZ#2237824 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2248412 - syncthing: golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2248412 -------------------------------------------------------------------------------- This update can be installed with the "dnf"update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-fa2d7b25d9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Upgrade to Syncthing version 1.26.0 on Fedora 37, improving file transfer capabilities and boosting security protocols.. syncthing update, Fedora software update, file sync release. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 18, 2023 Critical Fedora
89

Fedora 34 NextCloud 20.0.11: Critical Security Flaws Addressed

Update to 20.0.11; Fixes one high severity and multiple low severity CVEs. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-9b421b78af 2021-07-22 01:13:10.976131 --------------------------------------------------------------------------------Name : nextcloud Product : Fedora 34 Version : 20.0.11 Release : 1.fc34 URL : http://nextcloud.com Summary : Private file sync and share server Description : NextCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your devices and enables basic editing right on the web. NextCloud is extendable via a simple but powerful API for applications and plugins. --------------------------------------------------------------------------------Update Information: Update to 20.0.11; Fixes one high severity and multiple low severity CVEs --------------------------------------------------------------------------------ChangeLog: * Mon Jul 12 2021 Christopher Engelhard 20.0.11-1 - Update to 20.0.11; Fixes RHBZ#1981503; Fixes RHBZ#1981505 --------------------------------------------------------------------------------References: [ 1 ] Bug #1981503 - CVE-2021-32688 nextcloud: Improper permission check permits tokens to change their own permissions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1981503 [ 2 ] Bug #1981505 - CVE-2021-32680 nextcloud: Improper audit logging for expiration date events [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1981505 [ 3 ] Bug #1981817 - CVE-2021-32678 nextcloud: ratelimit not applied on OCS API responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1981817 [ 4 ] Bug #1981819 - CVE-2021-32679 nextcloud: filenames not escaped by default in controllers using DownloadResponse [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1981819 [ 5 ] Bug #1981821 - CVE-2021-32703 nextcloud: lack of ratelimit on shareinfo endpoint [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1981821 [ 6 ] Bug #1981824 - CVE-2021-32705 nextcloud: lack of ratelimit on public DAV endpoint [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1981824 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-9b421b78af' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The update for NextCloud version 20.0.11 in Fedora 34 resolves both critical and minor vulnerabilities, enhancing the safety of file sharing functionalities.. NextCloud Update, Fedora Security, File Sync Server, High Severity Issues, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 21, 2021 Critical Fedora
89

Fedora 32: 2020-10-19 Nextcloud 18.0.9 Moderate Security Issues

Update to Nextcloud 18.0.9, fixes CVE-2020-81-39, CVE-2020-8173, CVE-2020-8183, CVE-2020-8223, CVE-2020-8154, CVE-2020-8155. Updating the Mail & Groupfolders apps from within Nextcloud also fixes CVE-2020-8153, CVE-2020-8156. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-c9863904de 2020-10-19 16:56:49.452478 --------------------------------------------------------------------------------Name : nextcloud Product : Fedora 32 Version : 18.0.9 Release : 1.fc32 URL : http://nextcloud.com Summary : Private file sync and share server Description : NextCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your devices and enables basic editing right on the web. NextCloud is extendable via a simple but powerful API for applications and plugins. --------------------------------------------------------------------------------Update Information: Update to Nextcloud 18.0.9, fixes CVE-2020-81-39, CVE-2020-8173, CVE-2020-8183, CVE-2020-8223, CVE-2020-8154, CVE-2020-8155. Updating the Mail & Groupfolders apps from within Nextcloud also fixes CVE-2020-8153, CVE-2020-8156 --------------------------------------------------------------------------------ChangeLog: * Sun Oct 11 2020 Christopher Engelhard - 18.0.9-1 - Update to Nextcloud 18.0.9 --------------------------------------------------------------------------------References: [ 1 ] Bug #1838275 - CVE-2020-8153 CVE-2020-8154 CVE-2020-8155 CVE-2020-8156 nextcloud: multiple vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1838275 [ 2 ] Bug #1838535 - CVE-2020-8139 nextcloud: hide-download shares to be downloadable when appending /download to the URL [fedora-31] https://bugzilla.redhat.com/show_bug.cgi?id=1838535 [ 3 ] Bug #1873704 - Please update to 18.0.8 on Fedora32 https://bugzilla.redhat.com/show_bug.cgi?id=1873704 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-c9863904de' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Nextcloud 18.0.9 for Fedora 32 resolves several security vulnerabilities. Upgrade today to bolster your file synchronization protection.. Nextcloud Update, Fedora Security, File Sync, App Fixes. . LinuxSecurity.com Team

Calendar 2 Oct 19, 2020 Fedora
89

Fedora Core 4: 2006-701 Critical: Rsync Software Update

Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-701 2006-06-12 ---------------------------------------------------------------------Product : Fedora Core 4 Name : rsync Version : 2.6.8 Release : 1.FC4.1 Summary : A program for synchronizing files over a network. Description : Rsync uses a reliable algorithm to bring remote and host files into sync very quickly. Rsync is fast because it just sends the differences in the files over the network instead of sending the complete files. Rsync is often used as a very powerful mirroring process or just as a more capable replacement for the rcp command. A technical report which describes the rsync algorithm is included in this package. ---------------------------------------------------------------------* Mon Jun 12 2006 Jay Fenlason 2.6.8-1.FC4.1 - Add my xattrs_bug patch to fix a bug where xattrs don't get sent correctly. - Add BuildRequires to make sure libattr-devel and libacl-devel are avaliable - replace --with... with --enable... so they actually work - Add make, autoconf and gcc to BuildRequires ---------------------------------------------------------------------This update can be downloaded from: 7d53cbe51e170993f68418b65d8162edd949b3df SRPMS/rsync-2.6.8-1.FC4.1.src.rpm 7d53cbe51e170993f68418b65d8162edd949b3df noarch/rsync-2.6.8-1.FC4.1.src.rpm f2477bfde62ff935d65877de4cefcaaff1d00038 ppc/rsync-2.6.8-1.FC4.1.ppc.rpm bba627409b462e1cfe57c33bc1e54a0e21123db4 ppc/debug/rsync-debuginfo-2.6.8-1.FC4.1.ppc.rpm 33a25a41d610f3028e4becba12ddd89f33da96a1 x86_64/rsync-2.6.8-1.FC4.1.x86_64.rpm b0f8cd707063d2e89e6ccfcd6c0bd1743417739f x86_64/debug/rsync-debuginfo-2.6.8-1.FC4.1.x86_64.rpm 348e84d7b28e6eb7d52b022d4f27c9befbc780ea i386/rsync-2.6.8-1.FC4.1.i386.rpm b938a11177fc4a055c2637c719046dfe30e02c41 i386/debug/rsync-debuginfo-2.6.8-1.FC4.1.i386.rpm This update can be installed with the 'yum' update program. Use 'yumupdate package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Crucial enhancement for rsync integrating numerous patches for Fedora Core 4, aimed at streamlining file transfer processes.. Rsync Update, Fedora Core, Critical Security Fix, File Sync, Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 12, 2006 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here