Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
203

Mageia 6: 2019-0066 Moderate: Golang Remote Code Execution Issues

Remote code execution in go get, when executed with the -u flag (CVE-2018-16873). An arbitrary filesystem write in go get, which could lead to code execution (CVE-2018-16874). . MGASA-2019-0066 - Updated golang packages fix security vulnerability Publication date: 13 Feb 2019 URL: https://advisories.mageia.org/MGASA-2019-0066.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-16873, CVE-2018-16874, CVE-2018-16875, CVE-2019-6486 Remote code execution in go get, when executed with the -u flag (CVE-2018-16873). An arbitrary filesystem write in go get, which could lead to code execution (CVE-2018-16874). Denial of Service in the crypto/x509 package during certificate chain validation (CVE-2018-16875). Go before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks (CVE-2019-6486). References: - https://bugs.mageia.org/show_bug.cgi?id=24014 - - https://lists.debian.org/debian-security-announce/2019/msg00019.html - https://www.cve.org/CVERecord?id=CVE-2018-16873 - https://www.cve.org/CVERecord?id=CVE-2018-16874 - https://www.cve.org/CVERecord?id=CVE-2018-16875 - https://www.cve.org/CVERecord?id=CVE-2019-6486 SRPMS: - 6/core/golang-1.11.5-1.mga6 . Recent updates to Golang packages in Mageia have addressed serious vulnerabilities, including potential remote code execution and denial of service issues, as of February 2019.. Mageia Security Update, Golang Vulnerability, Remote Code Execution, Denial of Service, Package Update. . LinuxSecurity.com Team

Calendar 2 Feb 13, 2019 Mageia
202

openSUSE: 2018:4181-1 Important: go1.11 Remote Code Execution and More

An update that solves three vulnerabilities and has four fixes is now available. Description: Description: This new package for go1.11 fixes the following issues: Security issues fixed: - CVE-2018-16873: Fixed a remote code execution in go get, when executed [More...] with the -u flag (bsc#1118897) with the -u flag (bsc#1118897) [More...] - CVE-2018-16874: Fixed an arbitrary filesystem write in go [More...]. openSUSE Security Update: Security update for go1.11 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:4181-1 Rating: important References: #1098017 #1113978 #1118897 #1118898 #1118899 #1119634 #1119706 Cross-References: CVE-2018-16873 CVE-2018-16874 CVE-2018-16875 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 ______________________________________________________________________________ An update that solves three vulnerabilities and has four fixes is now available. Description: This new package for go1.11 fixes the following issues: Security issues fixed: - CVE-2018-16873: Fixed a remote code execution in go get, when executed with the -u flag (bsc#1118897) - CVE-2018-16874: Fixed an arbitrary filesystem write in go get, which could lead to code execution (bsc#1118898) - CVE-2018-16875: Fixed a Denial of Service in the crypto/x509 package during certificate chain validation(bsc#1118899) Non-security issues fixed: - Fixed build error with PIE linker flags on ppc64le (bsc#1113978 bsc#1098017) - Make profile.d/go.sh no longer set GOROOT=, in order to make switching between versions no longer break. This ends up removing the need for go.sh entirely (because GOPATH is also set automatically) (bsc#1119634) The following tracked regression fix is included: - Fix a regression that broke go get for import path patterns containing "..."(bsc#1119706) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-1572=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1572=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): go1.11-1.11.4-2.1 go1.11-doc-1.11.4-2.1 - openSUSE Leap 42.3 (x86_64): go1.11-race-1.11.4-2.1 - openSUSE Leap 15.0 (x86_64): go1.11-1.11.4-lp150.2.1 go1.11-doc-1.11.4-lp150.2.1 go1.11-race-1.11.4-lp150.2.1 References: https://www.suse.com/security/cve/CVE-2018-16873.html https://www.suse.com/security/cve/CVE-2018-16874.html https://www.suse.com/security/cve/CVE-2018-16875.html https://bugzilla.suse.com/1098017 https://bugzilla.suse.com/1113978 https://bugzilla.suse.com/1118897 https://bugzilla.suse.com/1118898 https://bugzilla.suse.com/1118899 https://bugzilla.suse.com/1119634 https://bugzilla.suse.com/1119706 -- . Significant openSUSE upgrade for go1.11 tackles various security vulnerabilities with crucial patches.. go Security Update, openSUSE Patch, go1.11 Exploits, Software Vulnerabilities, openSUSE Security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 19, 2018 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here