Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 121 articles for you...
203

Mageia: 2020-0264 Critical Update for Flash Player Plugin - Code Execution

The updated packages fix a security vulnerability: Use after free that leads to arbitrary code execution in the context of the current user. (CVE-2020-9633) References: . MGASA-2020-0264 - Updated flash-player-plugin packages fix security vulnerability Publication date: 15 Jun 2020 URL: https://advisories.mageia.org/MGASA-2020-0264.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-9633 The updated packages fix a security vulnerability: Use after free that leads to arbitrary code execution in the context of the current user. (CVE-2020-9633) References: - https://bugs.mageia.org/show_bug.cgi?id=26779 - - https://www.cve.org/CVERecord?id=CVE-2020-9633 SRPMS: - 7/nonfree/flash-player-plugin-32.0.0.387-1.mga7.nonfree . This advisory for Mageia 7 emphasizes vital updates for the Flash Player plugin, addressing vulnerabilities that could affect users' systems and ensure software security.. Mageia Security, Flash Player Update, Arbitrary Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 15, 2020 Critical Mageia
91

Gentoo: GLSA-202101-12 important: Firefox browser critical vulnerabilities

Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201911-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Adobe Flash Player: Multiple vulnerabilities Date: November 25, 2019 Bugs: #694352 ID: 201911-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which could result in the arbitrary execution of code. Background ========= The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-plugins/adobe-flash < 32.0.0.255 > = 32.0.0.255 Description ========== Multiple vulnerabilities have been discovered in Adobe Flash Player. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Adobe Flash Player users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-plugins/adobe-flash-32.0.0.255" References ========= [ 1 ] CVE-2019-8069 https://nvd.nist.gov/vuln/detail/CVE-2019-8069 [ 2 ] CVE-2019-8070 https://nvd.nist.gov/vuln/detail/CVE-2019-8070 Availability =========== This GLSA and any updates to it are available forviewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201911-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2019 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Various security flaws in Adobe Flash Player could result in unauthorized code execution. Upgrade to version 32.0.0.255 immediately.. Adobe Flash Player Security, Gentoo Advisory, Software Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 24, 2019 Important Gentoo
91

Gentoo: GLSA-201908-21 Normal: Adobe Flash Player Multiple Threats

Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201908-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Adobe Flash Player: Multiple vulnerabilities Date: August 18, 2019 Bugs: #683006, #687894 ID: 201908-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which could result in the arbitrary execution of code. Background ========= The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-plugins/adobe-flash < 32.0.0.207 > = 32.0.0.207 Description ========== Multiple vulnerabilities have been discovered in Adobe Flash Player. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process or bypass security restrictions. Workaround ========= There is no known workaround at this time. Resolution ========= All Adobe Flash Player users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-plugins/adobe-flash-32.0.0.207" References ========= [ 1 ] CVE-2019-7096 https://nvd.nist.gov/vuln/detail/CVE-2019-7096 [ 2 ] CVE-2019-7108 https://nvd.nist.gov/vuln/detail/CVE-2019-7108 [ 3 ]CVE-2019-7845 https://nvd.nist.gov/vuln/detail/CVE-2019-7845 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201908-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2019 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Enhance the Adobe Flash Player on Gentoo to fix various security flaws and eliminate the risk of unauthorized code execution.. Adobe Flash Player,Gentoo Security Advisory,Arbitrary Code Execution. . LinuxSecurity.com Team

Calendar%202 Aug 17, 2019 Gentoo
203

Mageia 6: MGASA-2019-0178 Critical Flash Player Update for Code Execution

MGASA-2019-0178 - Updated flash-player-plugin packages fix security vulnerability Publication date: 18 May 2019 URL: https://advisories.mageia.org/MGASA-2019-0178.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-7837 A use after free that leads to arbitrary code execution. (CVE-2019-7837) References: - https://bugs.mageia.org/show_bug.cgi?id=24822 - - https://www.cve.org/CVERecord?id=CVE-2019-7837 SRPMS: - 6/nonfree/flash-player-plugin-32.0.0.192-1.mga6.nonfree . A use after free that leads to arbitrary code execution. (CVE-2019-7837) References: - https://bugs.mageia.org/show_bug.cgi?id=24822 - . MGASA-2021-0034 highlights a serious vulnerability in pdf-viewer for Mageia 7 requiring an urgent patch.. flash Player security update, Mageia advisories, code execution risk. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 18, 2019 Critical Mageia
203

Mageia 6 MGASA-2019-0149 Critical: Flash Player Plugin Code Execution

An out-of-bounds read that leads to information disclosure. (CVE-2019-7108) A use after free that leads to arbitrary code execution. (CVE-2019-7096) References: . MGASA-2019-0149 - Updated flash-player-plugin packages fix security vulnerability Publication date: 10 Apr 2019 URL: https://advisories.mageia.org/MGASA-2019-0149.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-7096, CVE-2019-7108 An out-of-bounds read that leads to information disclosure. (CVE-2019-7108) A use after free that leads to arbitrary code execution. (CVE-2019-7096) References: - https://bugs.mageia.org/show_bug.cgi?id=24643 - - https://www.cve.org/CVERecord?id=CVE-2019-7096 - https://www.cve.org/CVERecord?id=CVE-2019-7108 SRPMS: - 6/nonfree/flash-player-plugin-32.0.0.171-1.mga6.nonfree . Newly released packages for the flash-player-plugin address security vulnerabilities in Mageia, with corresponding CVE identifiers listed for further information.. Flash Player Update, Mageia Security, Code Execution Risk, Information Disclosure, Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 10, 2019 Critical Mageia
203

Mageia 6: MGASA-2019-0090 Moderate: Flash Player Plugin Info Disclosure

MGASA-2019-0090 - Updated flash-player-plugin packages fix security vulnerability Publication date: 17 Feb 2019 URL: https://advisories.mageia.org/MGASA-2019-0090.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-7090 Information disclosure in the context of the current user. (CVE-2019-7090) References: - https://bugs.mageia.org/show_bug.cgi?id=24363 - - https://www.cve.org/CVERecord?id=CVE-2019-7090 SRPMS: - 6/nonfree/flash-player-plugin-32.0.0.142-1.mga6.nonfree . Information disclosure in the context of the current user. (CVE-2019-7090) References: - https://bugs.mageia.org/show_bug.cgi?id=24363 - . Information disclosure in the context of the current user. (CVE-2019-7090) References: - https://b. mgasa-2019-0090, updated, flash-player-plugin, packages, security, vulnerability, publication. . LinuxSecurity.com Team

Calendar%202 Feb 17, 2019 Mageia
203

Mageia 6 Moderate: MGASA-2018-0478 Flash Player Plugin Update

Use after free flaw enabling arbitrary code execution. (CVE-2018-15982) Insecure Library Loading (DLL hijacking) flaw enabling privilege escalation. (CVE-2018-15983) . MGASA-2018-0478 - Updated flash-player-plugin packages fix security vulnerability Publication date: 07 Dec 2018 URL: https://advisories.mageia.org/MGASA-2018-0478.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-15982, CVE-2018-15983 Use after free flaw enabling arbitrary code execution. (CVE-2018-15982) Insecure Library Loading (DLL hijacking) flaw enabling privilege escalation. (CVE-2018-15983) References: - https://bugs.mageia.org/show_bug.cgi?id=23950 - - https://www.cve.org/CVERecord?id=CVE-2018-15982 - https://www.cve.org/CVERecord?id=CVE-2018-15983 SRPMS: - 6/nonfree/flash-player-plugin-32.0.0.101-1.mga6.nonfree . Critical patch for Mageia's flash-player add-on resolving vulnerabilities related to potential code execution and privilege elevation risks.. Mageia Security, Flash Player, Security Update, Plugin Update. . LinuxSecurity.com Team

Calendar%202 Dec 07, 2018 Mageia
100

SUSE: 2017:0108-1 Important: Flash Player Code Execution Threats

An update that fixes 13 vulnerabilities is now available. An update that fixes 13 vulnerabilities is now available. An update that fixes 13 vulnerabilities is now available.. SUSE Security Update: Security update for flash-player ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:0108-1 Rating: important References: #1019129 Cross-References: CVE-2017-2925 CVE-2017-2926 CVE-2017-2927 CVE-2017-2928 CVE-2017-2930 CVE-2017-2931 CVE-2017-2932 CVE-2017-2933 CVE-2017-2934 CVE-2017-2935 CVE-2017-2936 CVE-2017-2937 CVE-2017-2938 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP1 SUSE Linux Enterprise Desktop 12-SP1 ______________________________________________________________________________ An update that fixes 13 vulnerabilities is now available. Description: This update to Adobe Flash 24.0.0.194 fixes the following vulnerabilities advised under APSB17-02: - security bypass vulnerability that could lead to information disclosure (CVE-2017-2938) - use-after-free vulnerabilities that could lead to code execution (CVE-2017-2932, CVE-2017-2936, CVE-2017-2937) - heap buffer overflow vulnerabilities that could lead to code execution (CVE-2017-2927, CVE-2017-2933, CVE-2017-2934, CVE-2017-2935) - memory corruption vulnerabilities that could lead to code execution (CVE-2017-2925, CVE-2017-2926, CVE-2017-2928, CVE-2017-2930, CVE-2017-2931) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP1: zypper in -t patch SUSE-SLE-WE-12-SP1-2017-51=1 - SUSE Linux Enterprise Desktop 12-SP1: zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2017-51=1 To bring your system up-to-date, use "zypperpatch". Package List: - SUSE Linux Enterprise Workstation Extension 12-SP1 (x86_64): flash-player-24.0.0.194-155.1 flash-player-gnome-24.0.0.194-155.1 - SUSE Linux Enterprise Desktop 12-SP1 (x86_64): flash-player-24.0.0.194-155.1 flash-player-gnome-24.0.0.194-155.1 References: https://www.suse.com/security/cve/CVE-2017-2925.html https://www.suse.com/security/cve/CVE-2017-2926.html https://www.suse.com/security/cve/CVE-2017-2927.html https://www.suse.com/security/cve/CVE-2017-2928.html https://www.suse.com/security/cve/CVE-2017-2930.html https://www.suse.com/security/cve/CVE-2017-2931.html https://www.suse.com/security/cve/CVE-2017-2932.html https://www.suse.com/security/cve/CVE-2017-2933.html https://www.suse.com/security/cve/CVE-2017-2934.html https://www.suse.com/security/cve/CVE-2017-2935.html https://www.suse.com/security/cve/CVE-2017-2936.html https://www.suse.com/security/cve/CVE-2017-2937.html https://www.suse.com/security/cve/CVE-2017-2938.html https://bugzilla.suse.com/1019129 . SUSE has released a security update for flash-player that fixes several critical vulnerabilities. It is important to implement these updates promptly.. SUSE Security, Flash Player Update, Vulnerability Fix, Linux Patch Management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 11, 2017 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200